Privacy Policy

Last updated: 6 August 2026

1. Who We Are

CareLedger AI Ltd ("we", "us", "our") is a company registered in England and Wales. We are the data controller for the personal data we process. Contact us at: dpo@careledgerai.tech

2. Data We Collect

We collect and process the following categories of personal data:

  • Account Data: Email address, agency name, encrypted password hash.
  • Financial Operations Data: Pseudonymised carer IDs, pseudonymised client IDs, scheduled/actual visit minutes, visit dates, funding band codes.
  • Usage Data: Log-in timestamps, feature usage analytics, browser type.

3. Privacy Shield — Data We Do NOT Collect

Our Privacy Shield technology programmatically strips the following data during CSV upload, before it reaches our servers:

  • Clinical notes and care observations
  • Personal health information (PHI)
  • Patient names, addresses, or NHS numbers
  • Free-text fields of any kind

This constitutes Data Protection by Design and by Default under GDPR Article 25.

4. Legal Basis for Processing (GDPR Article 6)

  • Contract (Art. 6(1)(b)): Processing your agency's care log data to provide the reconciliation service.
  • Legitimate Interest (Art. 6(1)(f)): Platform security, fraud prevention, service improvement.
  • Consent (Art. 6(1)(a)): Marketing communications (opt-in only).

5. Data Sharing

We do not sell your data. We share data only with:

  • Infrastructure Providers: Supabase (PostgreSQL hosting, EU region), Vercel (frontend hosting).
  • Legal Requirements: Where required by law or regulatory authority.

6. Data Retention

Account data is retained while your account is active. Reconciliation data is retained for 7 years to comply with HMRC financial record-keeping requirements. You may request deletion of your account at any time.

7. Your Rights (GDPR Articles 15-22)

You have the right to:

  • Access: Request a copy of your personal data.
  • Rectification: Correct inaccurate data.
  • Erasure: Request deletion ("right to be forgotten").
  • Portability: Receive your data in a machine-readable format.
  • Object: Object to processing based on legitimate interest.
  • Restrict: Restrict processing in certain circumstances.

Contact dpo@careledgerai.tech to exercise any of these rights. We will respond within 30 days.

8. Data Security

We implement appropriate technical and organisational measures including: TLS 1.3 encryption in transit, AES-256 encryption at rest, Row Level Security for tenant isolation, regular security audits, and access logging.

9. International Transfers

Your data is processed within the European Economic Area. Where transfers outside the EEA occur (e.g., support tools), we ensure adequate safeguards under GDPR Article 46, including Standard Contractual Clauses.

10. Cookies

We use strictly necessary cookies for authentication and session management. We do not use advertising or tracking cookies. No cookie consent banner is required for strictly necessary cookies under UK PECR.

11. Complaints

You have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk

12. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email to registered users.