How I handle your data
OCD: Conditions for Allowing · Last updated: 10 July 2026
This page explains what personal information I collect when you buy the book, use the portal, book a call, or work with me — and what I do with it. I've written it in plain English on purpose. If anything is unclear, email me and I'll give you a straight answer.
I'm David Laing, and I run OCD: Conditions for Allowing as a sole trader, based in Eastbourne, East Sussex, United Kingdom. For data protection law, I'm the "controller" of your information — meaning I'm the one responsible for looking after it.
When you buy something (the book, the Starter Kit, the Recovery Circle, or a programme): your name, email address, what you bought, and payment confirmation. Payments are processed by Stripe — your card details go directly to Stripe and never touch my systems.
When you book a call with me: your name, email, phone number, and your answers to the booking questions. Some of those questions ask about your experience of OCD and how you're doing — that's sensitive health information, and it gets special treatment (see section 3).
When you create a portal account (portal.ocdisbeliefsbook.com): your email and login, your course progress, and — if you're in a programme — the things you choose to log there: daily practices, reflections, check-ins. Much of that is also sensitive health information (section 3 again).
When you're on my email list: which emails you open and which links you click (this is how email platforms work; I use it to stop sending things you clearly don't want).
When you visit the website: see section 6 (cookies and analytics).
When we're working together (Recovery Circle or a programme): what you share on calls, in the community, in check-ins, and — for Implementation Programme clients — in our WhatsApp thread.
I don't collect anything I haven't listed here, and I never buy data about you from anyone.
Because of what this work is, some of what you share with me is information about your mental health. The law calls this "special category data" and requires explicit consent to use it. Here's how that works honestly:
You can withdraw consent at any time by emailing me — I'll delete the information (unless a legal duty, like tax records, requires keeping the purchase itself).
I'm a small business; these companies store or move data on my behalf. Each is bound by a contract limiting them to exactly that:
| Provider | What for |
|---|---|
| HighLevel ("LeadConnector") | Customer records, email sending, booking, checkout pages, SMS |
| Stripe | Payment processing (they hold the card details, not me) |
| Supabase | The portal database (accounts, progress, logs) |
| Vercel | Hosting the website and portal |
| Zoom | Calls and sessions |
| Fathom | Call transcription |
| Google Workspace | Business email |
| Skool | The community (their platform, their own privacy policy applies there). Zapier passes your email to Skool to send your invite. |
| Meta / Microsoft | Advertising and analytics — see section 6 |
I never sell your data. Nobody gets it for their own marketing.
The website (conditionsforallowing.com) currently uses:
You'll be asked before any of the advertising/analytics ones load, and "no" is a one-click answer. You can also block cookies in your browser settings at any time; the site works fine without them.
The checkout pages (checkout.conditionsforallowing.com, run through my checkout provider) also use the Meta Pixel. The consent prompt above covers this website; on the checkout pages the Pixel currently loads without a prompt — I'm extending the same consent control there.
Some of the providers above (HighLevel, Stripe, Meta, Microsoft, Zoom, Google, and Supabase) store data in the United States. Those transfers are covered by the UK's approved safeguards — the UK–US Data Bridge where the provider is certified, or the UK's standard contractual terms (IDTA/Addendum) where not.
You can ask me, at any time, to: see what I hold about you; correct it; delete it; restrict what I do with it; hand it over in a portable format; or stop using it for marketing (that last one, I must and will do, no questions). Email david@conditionsforallowing.com — I'll respond within a month, usually much faster.
If you're unhappy with how I've handled your data, you can complain to the UK regulator: the Information Commissioner's Office — ico.org.uk / 0303 123 1113. (I'd appreciate the chance to fix it first, but that's your right regardless.)
My products and programmes are for adults — 18 and over. If you're a parent, guardian or carer of a young person with OCD, you're welcome here — but the account, the purchase and the data are yours, as the adult. I don't knowingly collect information from anyone under 18; if that's happened, email me and I'll delete it.
If I change this policy in any way that matters, I'll update the date at the top and — for anything significant — tell the email list. The current version always lives at this address.
I'm not a therapist or doctor, and nothing here is therapy, medical advice, diagnosis, or treatment. I teach from lived experience of OCD and complete recovery. This work can sit alongside professional care, but it isn't a replacement for it — and please don't change or stop any medication without talking to whoever prescribed it.
If you're in crisis right now, please don't wait for an email or a call with me. In the UK: call Samaritans free on 116 123 (any time, day or night), call NHS 111 and choose the mental health option, or dial 999 if you or someone else is in immediate danger. Outside the UK, contact your local emergency number or a crisis line where you are. Reaching for that kind of help is never a step backwards.