Privacy Policy

Last updated: 27 June 2026

This Privacy Policy explains how The Metis Organisation Ltd, trading as The Metis Institute (“we”, “us”, “our”), collects, uses, stores, shares, and protects personal information in connection with our website, enquiries, events, training programmes, applications, online teaching, marketing, advertising, and related professional activities.

We are committed to handling personal information lawfully, fairly, transparently, securely, and in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (“PECR”), and other applicable UK data protection law.

1. Data controller

The data controller is:

The Metis Organisation Ltd
Trading as The Metis Institute
Worth School
Paddockhurst Road
Turners Hill
West Sussex
RH10 4SD
United Kingdom

Email: admin@metisinstitute.co.uk

Our Data Protection Lead may be contacted at the email address above.

Our ICO registration number will be added to this policy once registration is completed, where registration is required.

2. Scope of this policy

This Privacy Policy applies to personal information processed in connection with:

  • psychotherapy training;

  • TA101 courses;

  • CPD workshops;

  • open evenings;

  • applications, interviews, references, and admissions;

  • residential and non-residential training events;

  • supervision groups, CTA preparation groups, and related professional activities;

  • mailing lists, newsletters, and marketing communications;

  • website enquiries;

  • Eventbrite ticketing and bookings;

  • online events and online teaching;

  • Google advertising and analytics tools;

  • Meta and LinkedIn advertising tools, where used in future;

  • photography, testimonials, and event publicity;

  • complaints, data protection complaints, contractual claims, and related administration.

This policy does not replace any specific contract, training agreement, student handbook, complaints procedure, or professional code of ethics that may also apply.

3. Personal information we may collect

Depending on your relationship with us, we may collect and process the following categories of personal information:

3.1 Identity and contact information

This may include your name, email address, phone number, postal address, professional role, workplace or organisation, and other contact details.

3.2 Professional and training information

This may include your training history, qualifications, professional registrations or memberships, therapy and supervision experience, placement information, professional interests, references, application answers, interview material, attendance records, assessment records, certificate records, and records relating to training progression.

3.3 Application and admissions information

Applications are currently collected through Google Forms or by other electronic means. Application information may include personal statements, training history, professional background, references, answers to selection questions, and information relevant to assessing suitability for training.

3.4 Training and student records

Where you become a student or trainee, we may process records relating to your attendance, participation, progression, assessment, feedback, training requirements, ethical issues, fitness-to-practise concerns, reasonable adjustments, certification, and correspondence with you.

3.5 Event and ticketing information

When you book an event, course, open evening, workshop, or training weekend, we may collect booking details, attendance information, payment status, dietary requirements, accessibility requirements, and related correspondence.

Ticket bookings are usually managed through Eventbrite. Eventbrite will also process your personal information in accordance with its own privacy information.

3.6 Payment and financial information

We may process information relating to invoices, payments, refunds, receipts, deposits, instalments, bank transfers, Eventbrite payments, accounting records, and financial correspondence. We do not normally store full card payment details ourselves.

3.7 Marketing information

This may include your marketing preferences, mailing list status, consent records, event interests, course interests, engagement with our emails, and unsubscribe or suppression records.

3.8 Website, analytics, advertising, and cookie information

When you visit our website or interact with our online advertising, we may process technical and usage information such as IP address, device information, browser type, pages visited, referral source, approximate location, cookie identifiers, advertising identifiers, and conversion data.

We currently use or may use Google advertising tools. We may in future use Meta and LinkedIn advertising tools, such as pixels, tags, insight tools, lead forms, conversion tracking, remarketing, or similar technologies.

3.9 Special category information

In some circumstances, we may process special category personal data. This may include information about health, disability, neurodiversity, accessibility needs, dietary requirements that reveal health or religious information, ethnicity, gender identity, sexual orientation, religion or belief, therapy history, or other sensitive information disclosed during an application, training process, complaint, or request for support.

We will only process special category data where we have both a lawful basis under Article 6 UK GDPR and a special category condition under Article 9 UK GDPR.

3.10 Photographs, video, audio, and testimonials

We may take photographs at events or use testimonials. We will not normally publish identifiable images, names, or professional details of students or participants without permission.

Where online sessions are recorded, we will tell participants in advance. We aim not to record participant contributions unless this has been expressly explained and, where required, consent has been obtained.

4. How we collect personal information

We may collect personal information when:

  • you contact us by email, website form, phone, social media, or in person;

  • you complete a Google Form application;

  • you book an event through Eventbrite;

  • you attend an open evening, workshop, TA101, CPD event, or training programme;

  • you apply for psychotherapy training or another programme;

  • you provide references or referees provide references about you;

  • you subscribe to a mailing list or newsletter;

  • you interact with our website, adverts, or social media pages;

  • you complete feedback forms or surveys;

  • you make a complaint, data protection complaint, or subject access request;

  • you provide a testimonial or consent to photography;

  • third parties provide information where appropriate, lawful, and ethical, such as referees, supervisors, placement providers, professional bodies, assessors, or regulatory/accrediting organisations.

5. Purposes and lawful bases for processing

We process personal information for the following purposes.

5.1 Enquiries and communication

We use your information to respond to enquiries, provide information about our training and events, arrange meetings, and communicate with you.

Lawful basis: legitimate interests; contract or steps prior to entering into a contract.

5.2 Applications and admissions

We use application information to assess suitability, manage admissions, arrange interviews, request and review references, and make decisions about training places.

Lawful basis: contract or steps prior to entering into a contract; legitimate interests; legal obligation where applicable.

Where special category data is processed, we rely on explicit consent, legal claims, or another applicable Article 9 condition depending on the context.

5.3 Training delivery and student administration

We use personal information to provide training, maintain student records, monitor attendance, assess progression, support trainees, issue certificates, manage supervision and placement-related information, and meet professional or ethical responsibilities.

Lawful basis: contract; legitimate interests; legal obligation where applicable.

Where special category data is processed, we rely on explicit consent, legal claims, or another applicable Article 9 condition depending on the context.

5.4 Event management

We use information to manage bookings, attendance, access requirements, dietary requirements, venue arrangements, communication, feedback, certificates, refunds, and post-event administration.

Lawful basis: contract; legitimate interests; consent where required.

5.5 Eventbrite bookings

Where Eventbrite is used, you provide information to Eventbrite as part of the booking process. We may access or download attendee information for event administration. We erase downloaded attendee lists when they are no longer needed, unless the information has to be retained for another lawful purpose, such as attendance certification, accounting, complaints, or marketing where you have opted in.

Lawful basis: contract; legitimate interests; consent for marketing where required.

5.6 Marketing and newsletters

We may use your contact details to send information about our courses, open evenings, CPD events, training programmes, newsletters, and related professional activities.

Where required by law, we will obtain your consent before sending marketing emails. Where we rely on legitimate interests for business-to-business or professional communications, you may object at any time.

All marketing emails will include an unsubscribe option. We may retain minimal suppression information to ensure we do not contact you again after you unsubscribe.

Lawful basis: consent; legitimate interests; legal obligation for suppression records.

5.7 Website analytics and advertising

We may use Google Ads, Google Analytics, Google conversion tracking, Google remarketing, and similar tools. We may in future use Meta and LinkedIn advertising tools, including pixels, tags, conversion tracking, remarketing, and lead generation forms.

These technologies may help us understand how people find our website, measure the effectiveness of adverts, show relevant adverts, and improve our services.

Where legally required, non-essential cookies, pixels, tracking tags, and advertising technologies will only be used after consent has been given through our cookie banner or preference tool. You may withdraw or change cookie consent at any time through the website’s cookie settings, where available.

We do not sell personal information.

Lawful basis: consent for non-essential cookies and advertising technologies; legitimate interests for limited, privacy-preserving measurement where lawful; legal obligation where applicable.

5.8 Photography, recordings, and testimonials

We may use photographs, recordings, or testimonials for training administration, publicity, quality improvement, or marketing, but only where this has been explained and where permission has been obtained where required.

Lawful basis: consent; legitimate interests where appropriate and where your rights do not override our interests.

5.9 Complaints, data protection complaints, claims, and legal matters

We may process personal information to handle complaints, data protection complaints, contractual disputes, professional concerns, legal claims, insurance matters, or regulatory issues.

Lawful basis: legitimate interests; legal obligation; establishment, exercise, or defence of legal claims.

Where special category data is processed in this context, we may rely on the legal claims condition or another applicable Article 9 condition.

5.10 Safeguarding and risk

Our training is intended for adults and we do not normally collect safeguarding information. However, if a serious risk, safeguarding concern, legal issue, or ethical concern arises, we may process or share relevant information where lawful, necessary, and proportionate.

Lawful basis: legitimate interests; vital interests; legal obligation; substantial public interest or legal claims where applicable.

6. Special category data

We recognise that psychotherapy training, applications, group learning, and personal development contexts may involve sensitive disclosures.

We will not ask for unnecessary special category data. Where such information is needed, we will explain why. Examples may include accessibility adjustments, dietary requirements, fitness-to-practise issues, ethical concerns, complaints, or support needs.

We will process special category data only where:

  • we have identified a lawful basis under Article 6 UK GDPR;

  • we have identified a special category condition under Article 9 UK GDPR;

  • the processing is necessary, proportionate, and relevant;

  • additional safeguards are in place.

7. Sharing personal information

We may share personal information where lawful, necessary, appropriate, and ethical with:

  • trainers, tutors, supervisors, assessors, and administrative staff;

  • Eventbrite and other ticketing providers;

  • website, hosting, email, cloud storage, and IT providers;

  • Google Workspace, Google Forms, Google Ads, Google Analytics, and related Google services;

  • Meta and LinkedIn advertising platforms, where used;

  • Hostinger or another mailing list/email marketing platform, where used;

  • Zoom or other online meeting platforms;

  • payment processors, banks, accountants, and bookkeepers;

  • venues, accommodation providers, caterers, and residential providers;

  • external trainers, supervisors, assessors, moderators, or examiners;

  • placement providers, where relevant;

  • professional bodies, accrediting organisations, and regulators, including EATA, UKCP, NCPS, or other relevant bodies where appropriate;

  • insurers, legal advisers, and professional advisers;

  • public authorities, courts, regulators, or law enforcement where required by law or necessary to protect rights, safety, or legal interests.

We do not share personal information more widely than necessary.

8. Eventbrite

We use Eventbrite to manage ticketing and bookings for many events. When you book through Eventbrite, Eventbrite collects and processes personal information about you. Eventbrite may act as an independent controller for some of its processing and as a processor or service provider for other processing.

We may access attendee information through Eventbrite for event administration, attendance, communications, refunds, accessibility and dietary arrangements, and post-event follow-up.

If you opt into our mailing list through Eventbrite or another booking route, we may use your contact details for marketing. If you do not opt in, we will use your booking information only for event administration and related lawful purposes.

If you do not wish to book through Eventbrite, you may contact us at admin@metisinstitute.co.uk to ask whether an alternative booking route is available.

9. Google Forms

Applications may be collected through Google Forms. Information submitted through Google Forms may be processed by Google as a service provider. We use the information submitted to assess applications and manage admissions.

Applicants should avoid including unnecessary sensitive information unless it is relevant to the application or to support needs.

10. Google Ads, Meta Ads, LinkedIn Ads, and online advertising

We currently use Google advertising and may use Meta and LinkedIn advertising in the future.

Advertising tools may use cookies, pixels, scripts, tags, or similar technologies to:

  • measure advert performance;

  • record conversions;

  • understand how visitors interact with our website;

  • avoid showing irrelevant adverts;

  • show adverts to people who may be interested in our training and events;

  • create aggregated reports about advert effectiveness.

Where required, we will ask for consent before using advertising or remarketing cookies and similar technologies. You can change your cookie preferences through our website cookie controls, where available, and you may also manage advertising preferences through the relevant advertising platform.

We will not knowingly install advertising tags on pages that collect highly sensitive information unless we have assessed the risks and lawful basis and implemented appropriate safeguards.

11. Cookies and similar technologies

Cookies and similar technologies include cookies, tracking pixels, scripts, tags, local storage, device identifiers, link decoration, and other technologies that store information on, or access information from, your device.

We may use:

Strictly necessary cookies

These are required for the website to function and cannot usually be switched off.

Preference or functionality cookies

These help remember choices such as cookie preferences or display settings.

Analytics cookies

These help us understand how visitors use our website. Where analytics cookies fall within a lawful exception, we may use them with a clear means of objection. Where consent is required, we will ask for consent.

Advertising and tracking cookies

These may be used by Google and, in future, Meta or LinkedIn to measure adverts, track conversions, support remarketing, or show relevant adverts. These will only be used where legally permitted and, where required, after consent has been given.

Our cookie banner should provide meaningful choice, including the ability to accept, reject, or manage non-essential cookies. Non-essential advertising cookies should not be pre-enabled.

We will periodically review the cookies and tracking technologies used on our website.

12. International transfers

Some of our providers may process personal information outside the United Kingdom. This may include providers such as Google, Eventbrite, Meta, LinkedIn, Zoom, Hostinger, payment processors, email providers, cloud storage providers, and other technology services.

Where personal information is transferred outside the UK, we will take reasonable steps to ensure that appropriate safeguards are in place. These may include adequacy regulations, international data transfer agreements, standard contractual clauses, data processing agreements, or other lawful transfer mechanisms.

13. How long we keep personal information

We will not keep personal information for longer than is necessary for the purposes for which it was collected, unless a longer period is required or justified by law, contract, professional requirements, insurance, accreditation, complaints, legal claims, or legitimate business needs.

The following retention periods are our proposed standard periods. We may keep information longer where necessary, for example if there is an unresolved complaint, safeguarding issue, legal claim, professional concern, regulatory matter, or insurance requirement.

Record typeProposed retention period
General website enquiries12 months after last contact, unless the enquiry becomes an application, booking, contract, or complaint
Mailing list recordsUntil you unsubscribe or we stop operating the list
Unsubscribe/suppression recordsAs long as necessary to ensure we do not contact you again
Marketing consent recordsDuration of consent plus up to 6 years
Cookie consent recordsUp to 2 years, or longer if required to evidence compliance
Eventbrite attendee lists downloaded for administration onlyErased when no longer needed after the event, usually within 3 months
Event attendance records7 years after the event, where needed for certificates, CPD, administration, or professional verification
Dietary requirements for one-off eventsDeleted shortly after the event, usually within 1 month, unless needed for another lawful reason
Accessibility requirements for one-off eventsDeleted shortly after the event, usually within 3 months, unless needed for ongoing support or legal reasons
Financial, invoice, payment, and accounting records6 years from the end of the relevant company financial year, or longer where legally required
Unsuccessful training applications12 months after the admissions decision, or up to 24 months where needed for equality monitoring, dispute handling, or reapplication history
Successful applicationsHeld as part of the student record for the duration of training plus 7 years
References for unsuccessful applicants12 months after the admissions decision
References for successful applicantsDuration of training plus 7 years
Student core training recordsDuration of training plus 7 years
Assessment, progression, attendance, and fitness-to-practise recordsDuration of training plus 7 years, or longer where required by professional, legal, accreditation, or insurance obligations
Certificate and award verification recordsUp to 40 years, or indefinitely in minimal form where needed to verify training or certification
Complaints records6 years after closure, unless longer retention is required
Data protection complaints records6 years after closure, unless longer retention is required
Legal claims and dispute records6 years after closure, or longer where proceedings, insurance, or legal advice require
Photographs used for publicityReviewed every 3 years and removed earlier if consent is withdrawn, where withdrawal is practical
TestimonialsReviewed every 3 years and removed earlier if consent is withdrawn, where withdrawal is practical
Online recordingsUsually deleted within 3 months unless a longer period has been clearly explained and justified

14. Security

We take reasonable technical and organisational measures to protect personal information against unauthorised access, loss, misuse, alteration, or disclosure.

These measures may include:

  • password protection;

  • access controls;

  • secure cloud storage;

  • restricted administrative access;

  • encrypted services where available;

  • staff and trainer confidentiality expectations;

  • data minimisation;

  • secure deletion;

  • periodic review of records and systems.

No online transmission or storage system is completely secure. We therefore ask that you do not send unnecessary sensitive information by email unless required.

15. Your rights

Subject to legal conditions and exemptions, you may have the right to:

  • be informed about how your information is used;

  • access a copy of your personal information;

  • ask us to correct inaccurate or incomplete information;

  • ask us to erase information in certain circumstances;

  • ask us to restrict processing in certain circumstances;

  • object to processing based on legitimate interests;

  • object to direct marketing;

  • withdraw consent where processing is based on consent;

  • request data portability in certain circumstances;

  • complain to us about how we handle your personal information;

  • complain to the Information Commissioner’s Office.

To exercise your rights, please contact admin@metisinstitute.co.uk.

We may need to verify your identity before responding. We will normally respond to data protection rights requests within one month, unless an extension is permitted by law.

16. Data protection complaints

If you are concerned about how we have handled your personal information, you may make a data protection complaint to us.

Please contact:

Data Protection Lead
The Metis Organisation Ltd
Worth School
Paddockhurst Road
Turners Hill
West Sussex
RH10 4SD
United Kingdom

Email: admin@metisinstitute.co.uk

A data protection complaint may include concerns that we have:

  • used your personal information unfairly or unlawfully;

  • kept your information for too long;

  • failed to respond properly to a data protection rights request;

  • shared your information inappropriately;

  • failed to keep your information secure;

  • used your information for marketing without a lawful basis;

  • failed to explain how your information is processed.

When we receive a data protection complaint, we will:

  • acknowledge receipt within 30 days;

  • take appropriate steps to investigate the complaint without undue delay;

  • keep you informed of progress where appropriate;

  • tell you the outcome without undue delay;

  • aim to provide a substantive response within three months, unless the matter is complex or exceptional circumstances apply;

  • keep a record of the complaint and outcome for 6 years unless a longer period is required.

If you are not satisfied with our response, you may complain to the Information Commissioner’s Office.

17. Marketing preferences

You can unsubscribe from marketing emails at any time by using the unsubscribe link in our emails or by contacting admin@metisinstitute.co.uk.

If you unsubscribe, we may keep minimal information on a suppression list so that we do not contact you again for marketing.

18. Children

Our training, events, and services are intended for adults aged 18 and over. We do not knowingly collect information from children for training purposes.

If we become aware that information has been provided by a person under 18 in a context where this is not appropriate, we will take reasonable steps to delete it or manage it appropriately.

19. Third-party links and platforms

Our website, emails, social media pages, adverts, and event pages may link to third-party websites or platforms. These may include Eventbrite, Google, Meta, LinkedIn, Zoom, Hostinger, payment processors, professional bodies, venues, and other providers.

We are not responsible for the privacy practices of third-party websites or platforms. You should read their privacy notices before providing information to them.

20. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, technology, advertising tools, or data protection practices.

The updated version will be published on our website with a revised “last updated” date.

21. Governing law and jurisdiction

This Privacy Policy, and any claim, complaint, dispute, or legal matter arising from our services, contractual relationship, privacy practices, or processing of personal information, shall be governed by the laws of England and Wales.

Subject to any mandatory legal rights that cannot be excluded, the courts of England and Wales shall have jurisdiction over any such claim, complaint, dispute, or legal matter.

Nothing in this section limits your statutory right to complain to the Information Commissioner’s Office or to exercise your rights under applicable data protection law.