Privacy Policy

Autism & ADHD Ltd Last updated: 22/07/2026

1. Introduction

Autism & ADHD Ltd (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal information with transparency, care, and respect. This Privacy Policy explains how we collect, use, store, and protect personal data in accordance with the UK General Data Protection Regulation (UK‑GDPR) and the Data Protection Act 2018.

We work remotely and use a postal‑only address:

Autism & ADHD Ltd Unit 81 Centaur Court Claydon Business Park Gt. Blakenham Ipswich Suffolk IP6 0NL (This is a postal address only; our team works remotely.)

If you have any questions about this Privacy Policy or how we handle your data, please contact our Data Protection Officer at: abigail@autismandadhd.org

2. GDPR & Data Protection Statement

The General Data Protection Regulation (GDPR) is a legal framework that sets out how personal information must be collected, processed, and protected for individuals within the European Union (EU). It outlines the principles of data management, the rights of individuals, and the responsibilities of organisations that handle personal data. GDPR came into effect on 25 May 2018 and applies to all companies that process the data of EU citizens.

Autism & ADHD collects and holds personal data relating to clients, staff, parents, volunteers, visitors, suppliers, and other data subjects. GDPR requires us not only to minimise the risk of unauthorised access or loss of personal data, but also to demonstrate and document how we process and protect that data.

Our Commitment to GDPR Compliance

We are actively:

  • Documenting our processing activities and ensuring we have a lawful basis for each type of processing

  • Auditing our processes to identify potential risks and creating plans to reduce those risks

  • Reviewing and documenting the GDPR compliance of third‑party providers, including updating contracts where necessary

  • Maintaining clear processes and procedures to uphold the rights of data subjects

  • Regularly reviewing the technical and organisational measures we use to protect data

  • Ensuring all staff members are trained in GDPR and our internal data‑handling procedures

We collect and process significant amounts of personal data, and we take our responsibilities as custodians of that data extremely seriously. GDPR provides opportunities to strengthen how we manage and protect information, and we are committed to continually improving our privacy practices.

Our GDPR work is ongoing. We will continue to develop our privacy programme to ensure that all data is handled lawfully, respectfully, and securely. These improvements will never negatively impact the support we provide to clients or the wellbeing of families, staff, or volunteers.

3. The Data We Collect

We may collect and process the following categories of personal data:

Personal identification information

  • Name

  • Address

  • Email address

  • Phone number

  • Date of birth

Client‑related information

  • Background information shared during enquiries

  • Assessment information

  • Support needs

  • Communication records

  • Appointment history

Website and technical data

  • IP address

  • Browser type

  • Device information

  • Cookie data (see Section 10)

Professional information

  • For schools, training providers, and businesses: contact details, role, organisation name, booking information

Special category data (only where necessary)

  • Health information

  • Neurodevelopmental information

  • Relevant safeguarding information

We only collect special category data when it is essential for providing support, and we handle it with heightened protection.

4. How We Use Your Data

We use personal data for the following purposes:

  • Responding to enquiries

  • Providing support, assessments, and services

  • Managing appointments and communication

  • Processing payments and invoices

  • Delivering training and organisational services

  • Maintaining accurate records

  • Meeting legal and safeguarding obligations

  • Improving our services and website

  • Ensuring the security and integrity of our systems

We do not sell personal data or use it for marketing without explicit consent.

5. Lawful Bases for Processing

Under UK‑GDPR, we rely on the following lawful bases:

  • Consent – when you voluntarily provide information or agree to specific processing

  • Contract – when processing is necessary to deliver a service you have requested

  • Legal obligation – for safeguarding, tax, or regulatory requirements

  • Vital interests – where processing may protect someone’s life or wellbeing

  • Legitimate interests – for running and improving our services, provided this does not override your rights

6. How We Store and Protect Your Data

We use a combination of technical and organisational measures to keep your data secure, including:

  • Encrypted systems

  • Secure cloud‑based storage

  • Access controls

  • Staff training

  • Regular audits

  • Documented data‑handling procedures

We work remotely, and all data is stored securely within GDPR‑compliant systems.

7. Sharing Your Data

We may share personal data with:

  • Trusted third‑party providers (e.g., secure platforms, payment processors)

  • Professionals involved in your support (with consent)

  • Regulatory or safeguarding bodies (where legally required)

All third‑party providers are reviewed for GDPR compliance, and contracts are updated where necessary.

We never sell personal data.

8. Data Retention

We keep personal data only for as long as necessary to fulfil the purpose it was collected for, including legal, safeguarding, and contractual requirements.

Retention periods vary depending on the type of data and the nature of the service.

9. Your Rights Under UK‑GDPR

You have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request deletion (in certain circumstances)

  • Restrict processing

  • Object to processing

  • Request data portability

  • Withdraw consent at any time

  • Make a complaint to the Information Commissioner’s Office (ICO)

To exercise any of these rights, contact: abigail@autismandadhd.org

10. Cookies

Our website uses cookies to improve functionality and user experience. For full details, please see our Cookie Policy: autismandadhd.org/cookies

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.

12. Contact Information

For all data protection matters, please contact our Data Protection Officer: abigail@autismandadhd.org