Privacy Policy
Last updated: 6 August 2026
1. Who We Are
CareLedger AI Ltd ("we", "us", "our") is a company registered in England and Wales. We are the data controller for the personal data we process. Contact us at: dpo@careledgerai.tech
2. Data We Collect
We collect and process the following categories of personal data:
- Account Data: Email address, agency name, encrypted password hash.
- Financial Operations Data: Pseudonymised carer IDs, pseudonymised client IDs, scheduled/actual visit minutes, visit dates, funding band codes.
- Usage Data: Log-in timestamps, feature usage analytics, browser type.
3. Privacy Shield — Data We Do NOT Collect
Our Privacy Shield technology programmatically strips the following data during CSV upload, before it reaches our servers:
- Clinical notes and care observations
- Personal health information (PHI)
- Patient names, addresses, or NHS numbers
- Free-text fields of any kind
This constitutes Data Protection by Design and by Default under GDPR Article 25.
4. Legal Basis for Processing (GDPR Article 6)
- Contract (Art. 6(1)(b)): Processing your agency's care log data to provide the reconciliation service.
- Legitimate Interest (Art. 6(1)(f)): Platform security, fraud prevention, service improvement.
- Consent (Art. 6(1)(a)): Marketing communications (opt-in only).
5. Data Sharing
We do not sell your data. We share data only with:
- Infrastructure Providers: Supabase (PostgreSQL hosting, EU region), Vercel (frontend hosting).
- Legal Requirements: Where required by law or regulatory authority.
6. Data Retention
Account data is retained while your account is active. Reconciliation data is retained for 7 years to comply with HMRC financial record-keeping requirements. You may request deletion of your account at any time.
7. Your Rights (GDPR Articles 15-22)
You have the right to:
- Access: Request a copy of your personal data.
- Rectification: Correct inaccurate data.
- Erasure: Request deletion ("right to be forgotten").
- Portability: Receive your data in a machine-readable format.
- Object: Object to processing based on legitimate interest.
- Restrict: Restrict processing in certain circumstances.
Contact dpo@careledgerai.tech to exercise any of these rights. We will respond within 30 days.
8. Data Security
We implement appropriate technical and organisational measures including: TLS 1.3 encryption in transit, AES-256 encryption at rest, Row Level Security for tenant isolation, regular security audits, and access logging.
9. International Transfers
Your data is processed within the European Economic Area. Where transfers outside the EEA occur (e.g., support tools), we ensure adequate safeguards under GDPR Article 46, including Standard Contractual Clauses.
10. Cookies
We use strictly necessary cookies for authentication and session management. We do not use advertising or tracking cookies. No cookie consent banner is required for strictly necessary cookies under UK PECR.
11. Complaints
You have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk
12. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to registered users.