REFERRAL FORM

 Privacy Policy 

 

Privacy Notice

IntraQuest Community CIC

Version 4 – August 2026

At IntraQuest Community CIC (“IntraQuest”, “we”, “us” or “our”), protecting your privacy and personal information is extremely important to us.

We provide therapeutic, psychological assessment, learning, training, wellbeing and community services to children, young people, adults, families, schools, professionals and organisations.

Because of the nature of our work, some of the information entrusted to us can be particularly sensitive. We are committed to handling all personal information lawfully, fairly, transparently and securely.

This Privacy Notice explains:

  • what personal information we collect;

  • why we collect and use it;

  • where information may come from;

  • how we protect it;

  • when we may share it;

  • how long we keep it;

  • your data protection rights; and

  • how you can contact us about your information.

This notice applies to people who use or enquire about our services, clients, parents and carers, children and young people, people referred to us by other organisations, training participants, customers, professionals, commissioners, website visitors and others who interact with IntraQuest.


1. Who we are

IntraQuest Community CIC is a Community Interest Company providing therapeutic, assessment, learning, wellbeing, training and community services.

For data protection purposes, IntraQuest Community CIC will generally be the data controller for personal information where we determine the purposes and means of processing.

This means we are responsible for deciding how and why your personal information is used and for ensuring it is handled in accordance with applicable data protection law, including the UK GDPR, the Data Protection Act 2018 and other relevant UK data protection legislation.

Contact us

IntraQuest Community CIC
IntraQuest Wellbeing Centre
Stonebreaks House
Stonebreaks Road
Springhead
Oldham
OL4 4BY

Telephone: 07831 204043

Email: [email protected]

Website: www.intraquest.co.uk

Information Commissioner’s Office registration

IntraQuest is registered with the Information Commissioner’s Office (ICO).

ICO Registration Reference: ZA274206


2. The personal information we collect

The information we collect depends upon your relationship with IntraQuest and the service being provided.

It may include:

Identity and contact information

This may include:

  • name;

  • address;

  • telephone number;

  • email address;

  • date of birth;

  • age;

  • gender or preferred pronouns;

  • emergency contact information;

  • parent or carer information;

  • school, employer or organisation;

  • relationship to the person being referred.

Referral information

Where someone is being referred for therapy, assessment or another service, we may collect information including:

  • reason for referral;

  • presenting difficulties or concerns;

  • family circumstances;

  • educational information;

  • developmental history;

  • previous or current professional involvement;

  • relevant medical information;

  • safeguarding information;

  • information about support already received;

  • information supplied by the individual, parent, carer, school, local authority, healthcare professional or other referring organisation.

Health, therapeutic and assessment information

Where appropriate to the service we provide, we may process information relating to:

  • physical and mental health;

  • emotional wellbeing;

  • neurodevelopment;

  • ADHD;

  • autism;

  • learning needs;

  • disability;

  • medication;

  • developmental history;

  • psychological wellbeing;

  • therapy;

  • counselling;

  • family relationships;

  • behaviour;

  • educational needs;

  • assessment results;

  • clinical observations;

  • psychometric or diagnostic assessment information;

  • therapeutic or clinical notes;

  • reports;

  • correspondence with other professionals;

  • risk assessments;

  • safeguarding concerns.

Children and young people’s information

A significant part of our work involves children and young people.

Depending upon the service, we may collect personal information directly from a child or young person and/or from:

  • their parent or carer;

  • their school;

  • a local authority;

  • an adoption service;

  • healthcare professionals;

  • social care professionals;

  • other organisations involved in their support.

We recognise that children and young people’s personal information requires particular care and protection.

Financial and transaction information

We may process:

  • invoices;

  • amounts paid;

  • amounts outstanding;

  • payment dates;

  • funding arrangements;

  • purchase history;

  • billing addresses;

  • information needed to administer staged payments or funded services.

Where card payments are processed through an external payment provider, payment card information is normally processed directly by that provider rather than retained by IntraQuest.

Training and course information

If you attend training, supervision, an event, online learning or another professional development activity, we may hold:

  • contact information;

  • organisation and job role;

  • course bookings;

  • attendance information;

  • course progress;

  • certificates;

  • correspondence;

  • payment information;

  • feedback and evaluation information.

Communications

We may keep records of communications with you, including:

  • emails;

  • letters;

  • enquiries;

  • referral communications;

  • appointment communications;

  • complaints;

  • feedback;

  • information you provide through website forms.

Website and technical information

When you use our website or online services, certain technical information may be collected through cookies and similar technologies, such as:

  • IP address;

  • browser or device information;

  • website usage;

  • pages viewed;

  • interactions with our website;

  • cookie preferences.

Further information is provided in our Cookie Policy.


3. Special Category Personal Data

Some of the information IntraQuest processes is legally defined as special category personal data because of its sensitive nature.

This may include information about:

  • physical or mental health;

  • disability;

  • racial or ethnic origin;

  • religious or philosophical beliefs;

  • sexual orientation;

  • sex life;

  • biometric information, where applicable.

Health, psychological, therapeutic and neurodevelopmental information form an important part of some of the services we provide.

We only process special category information when we have both:

  1. a lawful basis for processing personal information under Article 6 of the UK GDPR; and

  2. an appropriate condition for processing special category information under Article 9 of the UK GDPR.

Depending on the circumstances, this may include processing necessary for the provision or management of health or social care by professionals subject to appropriate confidentiality requirements, safeguarding, substantial public interest purposes, legal claims, or where explicit consent is appropriate.

We do not rely on consent where another lawful basis is more appropriate simply because the information is sensitive.


4. How we obtain your information

We may obtain information directly from you when you:

  • contact us;

  • complete an enquiry or referral form;

  • telephone or email us;

  • book an appointment;

  • receive therapy or assessment;

  • attend a training course;

  • purchase a service or product;

  • complete an assessment questionnaire;

  • participate in an evaluation;

  • attend an event;

  • use our website;

  • communicate with a member of our team.

We may also receive information about you from another person or organisation.


5. When somebody else refers you to IntraQuest

Many people are introduced or referred to IntraQuest by another person or organisation.

Information may therefore be provided to us by:

  • parents or carers;

  • schools and colleges;

  • local authorities;

  • adoption services;

  • NHS or other healthcare professionals;

  • social workers;

  • employers;

  • charities or community organisations;

  • other therapists or professionals;

  • organisations funding or commissioning our services.

The information we receive will depend upon the reason for the referral.

Where appropriate, we will explain to the person receiving the service what information we hold, where it came from and how it will be used.


6. Services commissioned by local authorities and other organisations

IntraQuest provides services commissioned or funded by local authorities, schools, adoption services and other public, voluntary and private-sector organisations.

Where another organisation commissions IntraQuest to provide a service, our respective responsibilities for personal information depend upon the nature of the service and how decisions about that information are made.

In some circumstances, IntraQuest may process personal information on behalf of the commissioning organisation as a data processor.

In other circumstances, including where IntraQuest has independent professional, clinical, safeguarding or legal responsibilities, IntraQuest may act as an independent data controller.

Where required, these responsibilities are documented within the relevant contract, data processing agreement or data sharing arrangement.

We only share information with commissioning organisations where there is an appropriate lawful basis and where the information shared is necessary and proportionate.

Where a service is commissioned or funded by another organisation, we will not automatically provide that organisation with unrestricted access to confidential therapeutic or clinical information simply because it is paying for the service.

The information that may be shared will depend upon the service being provided, the contractual arrangements in place, safeguarding responsibilities, confidentiality obligations and applicable law.


7. Why we use your personal information

We may use personal information to:

  • respond to enquiries;

  • receive and review referrals;

  • determine whether our service is appropriate;

  • arrange initial consultations;

  • provide therapeutic services;

  • provide psychological or neurodevelopmental assessments;

  • provide learning needs assessments;

  • provide coaching or wellbeing services;

  • communicate with clients, families and professionals;

  • book and manage appointments;

  • maintain appropriate therapeutic and clinical records;

  • prepare reports;

  • administer training and professional development;

  • provide access to online training and resources;

  • administer payments and invoices;

  • manage services funded by schools, local authorities, adoption organisations or other commissioners;

  • fulfil contracts;

  • meet safeguarding responsibilities;

  • manage risk;

  • meet professional, legal, regulatory and insurance requirements;

  • deal with complaints or concerns;

  • improve our services;

  • measure the impact of funded or community programmes;

  • conduct appropriately anonymised or aggregated reporting;

  • maintain the security and operation of our website and systems;

  • send marketing communications where permitted;

  • keep appropriate business and financial records.

We aim to collect only information that is relevant and necessary for the purpose for which it is being used.


8. Our lawful bases for processing information

The lawful basis we rely upon depends upon why we are processing the information.

These may include:

Contract

Processing may be necessary to provide a service you have requested or to take steps before entering into a contract with you.

For example, this may apply when you purchase training, commission a service or enter into an agreement for assessment or therapy.

Legitimate interests

We may process information where doing so is necessary for our legitimate interests or those of another organisation, provided those interests are not overridden by your rights and freedoms.

Examples may include:

  • responding to enquiries;

  • maintaining appropriate business records;

  • improving our services;

  • managing our relationship with commissioners and professional contacts;

  • establishing, exercising or defending legal claims;

  • preventing fraud or misuse of our systems.

We consider the impact upon individuals before relying on legitimate interests.

Legal obligation

We may need to process information to comply with legal or regulatory obligations.

Vital interests

In exceptional circumstances we may use personal information where this is necessary to protect someone’s life or physical safety.

Consent

We use consent where consent is the appropriate legal basis.

For example, we may seek consent for certain marketing communications, testimonials, photography or other optional activities.

Where processing is based upon consent, you can withdraw your consent at any time.

Withdrawal does not affect processing already carried out lawfully before consent was withdrawn.

Withdrawal of consent does not necessarily require us to delete information where we have another lawful reason or professional or legal requirement to retain it.


9. Confidentiality and therapeutic information

Information shared during therapy or assessment is treated with a high level of confidentiality.

However, confidentiality is not always absolute.

There may be circumstances where we need to share relevant information without consent, including where:

  • we believe a child or vulnerable person may be at risk of harm;

  • there is a serious risk of harm to you or another person;

  • safeguarding action is required;

  • disclosure is required by law;

  • a court or other legally authorised body requires information;

  • disclosure is otherwise necessary and lawful to protect someone’s vital interests.

Where appropriate and safe to do so, we aim to explain when information needs to be shared and why.

We only seek to share information that is necessary and proportionate to the situation.


10. Information about children and young people

Children and young people have data protection rights in their own right.

We aim to handle children’s information in a way that recognises:

  • their age;

  • their level of understanding;

  • their evolving capacity;

  • their best interests;

  • the nature of the service they are receiving;

  • their right to privacy.

Parents and carers will often be involved in a child’s care or service.

However, this does not automatically mean that every piece of information a child or young person shares can always be disclosed to a parent or carer.

How information is handled will depend on the child’s age, understanding, the professional service being delivered, safeguarding considerations and applicable law.

Where appropriate, information about privacy will be explained to children and young people in language that they can understand.

IntraQuest may also provide a separate Child and Young Person Privacy Notice.


11. Sharing information

We do not sell personal information.

We do not provide client information to unrelated organisations so that they can use it for their own marketing.

We may share information where necessary with appropriately authorised people or organisations involved in providing, supporting, administering or commissioning a service.

Depending upon the circumstances, this may include:

  • members of the IntraQuest team involved in your service;

  • therapists;

  • psychologists;

  • appropriately contracted associates;

  • parents and carers where appropriate;

  • schools or educational settings;

  • local authorities;

  • adoption services;

  • health or social care professionals;

  • commissioners or organisations funding services;

  • safeguarding authorities;

  • professional advisers;

  • insurers;

  • auditors;

  • regulators;

  • courts, law enforcement or public authorities where legally required.

Where a third party commissions a service, we will consider carefully what information it is appropriate to provide back to that organisation.

We do not automatically give a commissioning organisation access to confidential therapeutic information simply because it is paying for a service.

The information shared will depend upon the service, contractual arrangements, confidentiality expectations, safeguarding requirements and applicable law.


12. Organisations that help us provide our services

We use carefully selected technology and service providers to help operate IntraQuest.

These may include providers supporting:

  • case management;

  • secure client records;

  • appointment management;

  • email and business communications;

  • cloud storage;

  • website hosting;

  • online learning;

  • payment processing;

  • accounting;

  • assessment systems;

  • document management;

  • IT and security;

  • marketing communications.

Current systems used by IntraQuest may include services such as Splose, Microsoft 365, Kajabi and Stripe, together with specialist clinical, assessment and business systems where appropriate.

Some suppliers act as data processors on our instructions.

Others may act as independent data controllers for particular activities.

Where suppliers process information on our behalf, we seek to ensure appropriate contractual and security arrangements are in place.


13. International transfers

Some technology providers used by IntraQuest may process or store information outside the United Kingdom.

Where personal information is transferred internationally, we take appropriate steps to ensure that the transfer complies with UK data protection law.

Depending upon the destination and provider, safeguards may include:

  • UK adequacy regulations;

  • recognised international data-transfer safeguards;

  • contractual protections;

  • the UK International Data Transfer Agreement;

  • the UK Addendum to approved Standard Contractual Clauses;

  • other lawful transfer mechanisms.

We assess relevant suppliers and transfer arrangements where required.


14. Keeping your information secure

We take the security of personal information seriously.

We use appropriate technical and organisational measures designed to protect information from:

  • unauthorised access;

  • accidental loss;

  • alteration;

  • inappropriate disclosure;

  • destruction;

  • misuse.

Depending upon the system and type of information, safeguards may include:

  • controlled access;

  • individual user accounts;

  • password protection;

  • secure cloud systems;

  • access permissions;

  • staff confidentiality requirements;

  • secure communications;

  • security updates;

  • backups;

  • staff training;

  • contractual requirements for service providers.

Access to client information is limited according to role and legitimate need.

No method of storing or transmitting information can be guaranteed to be completely secure, but we take reasonable and proportionate measures to reduce risks.


15. How long we keep personal information

We do not keep all information indefinitely.

Different categories of information need to be retained for different periods.

We consider factors including:

  • the nature of the information;

  • the age of the person receiving the service;

  • professional and clinical requirements;

  • safeguarding requirements;

  • statutory requirements;

  • insurance requirements;

  • contractual requirements;

  • limitation periods for potential legal claims;

  • accounting and tax requirements;

  • the reason the information was collected.

Clinical and therapeutic records may need to be retained for significant periods, particularly where services have been provided to a child.

Financial records may be retained for periods required by tax, accounting and company law.

Routine enquiries that do not progress to a service will generally not need to be retained for the same period as clinical records.

Marketing information will be retained only while there is an appropriate reason to hold it, although we may retain a limited suppression record where necessary to ensure that someone who has opted out is not inadvertently contacted again.

IntraQuest maintains appropriate internal retention arrangements for different categories of records.

When information no longer needs to be retained, we will securely delete, destroy or anonymise it where appropriate.


16. Payments

Payments for IntraQuest services may be processed using specialist third-party payment providers.

Where payments are processed directly by a payment provider, IntraQuest does not normally receive or retain your complete debit or credit card details.

Payment providers operate their own secure systems and may process certain information as independent data controllers.

We may retain information about the transaction itself, such as:

  • your name;

  • invoice;

  • amount due;

  • amount paid;

  • payment date;

  • payment status;

  • transaction reference.

This allows us to maintain appropriate financial and accounting records.


17. Marketing

We may send information about IntraQuest services, training, events, resources or opportunities where we are lawfully permitted to do so.

Where consent is required for electronic marketing, we will seek appropriate consent.

There are circumstances in which UK privacy and electronic communications rules allow organisations to contact business or professional contacts without individual consent.

Where we do this, we will still comply with applicable data protection and electronic communications requirements.

Every electronic marketing communication we send will provide an appropriate way to unsubscribe or tell us that you no longer wish to receive marketing.

You can change your marketing preferences at any time by:

Opting out of marketing will not prevent us from sending necessary administrative communications relating to a service you are receiving.


18. Testimonials, photographs and case studies

We may sometimes invite clients, training participants or other individuals to provide:

  • feedback;

  • testimonials;

  • photographs;

  • videos;

  • case studies;

  • stories about their experience of IntraQuest.

Where identifiable personal or special category information is intended for publication or promotional use, we will establish an appropriate lawful basis and obtain the permissions or consent required for that particular use.

Participation is optional.

We will take particular care where children or vulnerable individuals are involved.

Where possible, case studies used for reporting or promotional purposes may be anonymised.


19. Research, evaluation, impact and funding reports

As a Community Interest Company, IntraQuest may evaluate the effectiveness and impact of its services and programmes.

We may use information to:

  • monitor service outcomes;

  • understand community need;

  • improve services;

  • report to funders or commissioners;

  • demonstrate social impact;

  • support funding applications.

Wherever appropriate, this information will be aggregated or anonymised so that individuals cannot be identified.

Where identifiable information needs to be used, we will ensure that there is an appropriate lawful basis and that people are provided with relevant privacy information.


20. Automated decision-making and artificial intelligence

IntraQuest does not make significant clinical or therapeutic decisions about individuals solely through automated decision-making systems.

Technology, including digital tools and artificial intelligence, may from time to time be used to support appropriate administrative or business activities.

Where technology is used in connection with personal information, we remain responsible for ensuring its use complies with applicable data protection, confidentiality and information-security requirements.

We do not use artificial intelligence as a substitute for professional clinical judgement where an assessment, therapeutic or safeguarding decision requires appropriate human professional involvement.

If our use of automated decision-making changes materially, this Privacy Notice will be updated as required.


21. Website cookies and similar technologies

Our website uses cookies and may use other technologies that store or access information on your device.

These may help us:

  • operate the website securely;

  • remember preferences;

  • understand how the website is being used;

  • improve website performance;

  • provide embedded content;

  • measure marketing effectiveness where permitted.

Some technologies are necessary for the website to operate.

Other technologies may require your consent before they are used.

Where required, our website provides controls allowing you to accept, reject or manage optional cookies or similar technologies.

More information is available in our separate Cookie Policy.


22. Your data protection rights

Depending upon the circumstances, UK data protection law gives you a number of rights.

These may include:

Right to be informed

You have the right to know how your personal information is collected and used.

Right of access

You can ask us for a copy of the personal information we hold about you.

This is commonly known as a Subject Access Request.

Right to rectification

You can ask us to correct inaccurate personal information or complete information that is incomplete.

Right to erasure

In certain circumstances, you can ask us to delete personal information.

This right is not absolute.

For example, we may need to retain particular clinical, safeguarding, financial or legal records.

Right to restrict processing

In certain circumstances, you can ask us to limit how your information is used.

Right to object

You may have the right to object where we process information on the basis of legitimate interests.

You have the right to object to processing for direct marketing purposes.

Right to data portability

In certain circumstances, you may have the right to receive particular personal information in a structured, commonly used and machine-readable format.

Rights relating to automated decision-making

You have rights relating to certain decisions made solely using automated processing where those decisions have legal or similarly significant effects.

Right to withdraw consent

Where we rely upon consent, you may withdraw that consent at any time.

Not all rights apply in every situation.

We may need to confirm your identity before responding to a request, particularly where sensitive client information is involved.


23. Accessing a child’s information

Requests for children’s records require particular consideration.

Although a parent or carer may make a request on behalf of a child, personal information ultimately relates to the child.

Whether information can be released to a parent, carer or another person will depend upon factors including:

  • the child’s age;

  • maturity and understanding;

  • their capacity to exercise their own data protection rights;

  • confidentiality;

  • safeguarding;

  • legal responsibility;

  • whether disclosure could cause harm to the child or another person;

  • the rights and information of other individuals contained within the record.

We consider these requests individually rather than assuming that a parent or carer automatically has an unrestricted right to all information contained in a child’s therapeutic or clinical record.


24. Making a data protection request

If you wish to exercise a data protection right or have questions about your information, please contact us:

IntraQuest Community CIC
Stonebreaks House
Stonebreaks Road
Springhead
Oldham
OL4 4BY

Telephone: 07831 204043

Email: [email protected]

Please include enough information for us to understand and respond to your request.


25. Complaints about the way we use your information

We would encourage you to contact IntraQuest first if you have a concern about how your personal information has been handled so that we have an opportunity to investigate and resolve the matter.

You also have the right to complain to the UK’s independent data protection regulator:

Information Commissioner’s Office (ICO)

IntraQuest ICO Registration Reference: ZA274206

Information about making a complaint is available through the ICO’s website at www.ico.org.uk.


26. Changes to this Privacy Notice

We may update this Privacy Notice from time to time to reflect:

  • changes to our services;

  • changes to the systems we use;

  • changes to legislation or regulatory guidance;

  • changes to the way we process personal information.

The latest version will be published on our website.

Where a change is particularly significant and it is appropriate to do so, we may also notify affected individuals directly.

Current version: Version 4
Last reviewed: August 2026