Privacy Policy
Autism & ADHD Ltd Last updated: 22/07/2026
1. Introduction
Autism & ADHD Ltd (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal information with transparency, care, and respect. This Privacy Policy explains how we collect, use, store, and protect personal data in accordance with the UK General Data Protection Regulation (UK‑GDPR) and the Data Protection Act 2018.
We work remotely and use a postal‑only address:
Autism & ADHD Ltd Unit 81 Centaur Court Claydon Business Park Gt. Blakenham Ipswich Suffolk IP6 0NL (This is a postal address only; our team works remotely.)
If you have any questions about this Privacy Policy or how we handle your data, please contact our Data Protection Officer at: abigail@autismandadhd.org
2. GDPR & Data Protection Statement
The General Data Protection Regulation (GDPR) is a legal framework that sets out how personal information must be collected, processed, and protected for individuals within the European Union (EU). It outlines the principles of data management, the rights of individuals, and the responsibilities of organisations that handle personal data. GDPR came into effect on 25 May 2018 and applies to all companies that process the data of EU citizens.
Autism & ADHD collects and holds personal data relating to clients, staff, parents, volunteers, visitors, suppliers, and other data subjects. GDPR requires us not only to minimise the risk of unauthorised access or loss of personal data, but also to demonstrate and document how we process and protect that data.
Our Commitment to GDPR Compliance
We are actively:
Documenting our processing activities and ensuring we have a lawful basis for each type of processing
Auditing our processes to identify potential risks and creating plans to reduce those risks
Reviewing and documenting the GDPR compliance of third‑party providers, including updating contracts where necessary
Maintaining clear processes and procedures to uphold the rights of data subjects
Regularly reviewing the technical and organisational measures we use to protect data
Ensuring all staff members are trained in GDPR and our internal data‑handling procedures
We collect and process significant amounts of personal data, and we take our responsibilities as custodians of that data extremely seriously. GDPR provides opportunities to strengthen how we manage and protect information, and we are committed to continually improving our privacy practices.
Our GDPR work is ongoing. We will continue to develop our privacy programme to ensure that all data is handled lawfully, respectfully, and securely. These improvements will never negatively impact the support we provide to clients or the wellbeing of families, staff, or volunteers.
3. The Data We Collect
We may collect and process the following categories of personal data:
Personal identification information
Name
Address
Email address
Phone number
Date of birth
Client‑related information
Background information shared during enquiries
Assessment information
Support needs
Communication records
Appointment history
Website and technical data
IP address
Browser type
Device information
Cookie data (see Section 10)
Professional information
For schools, training providers, and businesses: contact details, role, organisation name, booking information
Special category data (only where necessary)
Health information
Neurodevelopmental information
Relevant safeguarding information
We only collect special category data when it is essential for providing support, and we handle it with heightened protection.
4. How We Use Your Data
We use personal data for the following purposes:
Responding to enquiries
Providing support, assessments, and services
Managing appointments and communication
Processing payments and invoices
Delivering training and organisational services
Maintaining accurate records
Meeting legal and safeguarding obligations
Improving our services and website
Ensuring the security and integrity of our systems
We do not sell personal data or use it for marketing without explicit consent.
5. Lawful Bases for Processing
Under UK‑GDPR, we rely on the following lawful bases:
Consent – when you voluntarily provide information or agree to specific processing
Contract – when processing is necessary to deliver a service you have requested
Legal obligation – for safeguarding, tax, or regulatory requirements
Vital interests – where processing may protect someone’s life or wellbeing
Legitimate interests – for running and improving our services, provided this does not override your rights
6. How We Store and Protect Your Data
We use a combination of technical and organisational measures to keep your data secure, including:
Encrypted systems
Secure cloud‑based storage
Access controls
Staff training
Regular audits
Documented data‑handling procedures
We work remotely, and all data is stored securely within GDPR‑compliant systems.
7. Sharing Your Data
We may share personal data with:
Trusted third‑party providers (e.g., secure platforms, payment processors)
Professionals involved in your support (with consent)
Regulatory or safeguarding bodies (where legally required)
All third‑party providers are reviewed for GDPR compliance, and contracts are updated where necessary.
We never sell personal data.
8. Data Retention
We keep personal data only for as long as necessary to fulfil the purpose it was collected for, including legal, safeguarding, and contractual requirements.
Retention periods vary depending on the type of data and the nature of the service.
9. Your Rights Under UK‑GDPR
You have the right to:
Access your personal data
Request correction of inaccurate data
Request deletion (in certain circumstances)
Restrict processing
Object to processing
Request data portability
Withdraw consent at any time
Make a complaint to the Information Commissioner’s Office (ICO)
To exercise any of these rights, contact: abigail@autismandadhd.org
10. Cookies
Our website uses cookies to improve functionality and user experience. For full details, please see our Cookie Policy: autismandadhd.org/cookies
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.
12. Contact Information
For all data protection matters, please contact our Data Protection Officer: abigail@autismandadhd.org