This summary provides key points from our Privacy Notice, but you can find out more details about any
of these topics by clicking the link following each key point or by using our table of contents
below to find the section you are looking for.
When you visit, use, or navigate our Services, we may process personal information depending on
how you interact with us and the Services, the choices you make, and the products and features
you use. Learn more about personal information you disclose to us.
Some of the information may be considered "special" or "sensitive" in certain jurisdictions, for
example your racial or ethnic origins, sexual orientation, and religious beliefs. We may process
sensitive personal information when necessary, with your consent or as otherwise permitted by
applicable law.
We may collect information from public databases, marketing partners, social media platforms,
and other outside sources. Learn more about information collected from other sources.
We process your information to provide, improve, and administer our Services, communicate with
you, for security and fraud prevention, and to comply with law. We may also process your
information for other purposes with your consent. We process your information only when we have
a valid legal reason to do so. Learn more about how we process your information.
We may share information in specific situations and with specific third parties. Learn more
about when and with whom we share your personal information.
We have adequate organisational and technical processes and procedures in place to protect your
personal information. However, no electronic transmission over the internet or information
storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that
hackers, cybercriminals, or other unauthorised third parties will not be able to defeat our
security and improperly collect, access, steal, or modify your information.
Depending on where you are located geographically, the applicable privacy law may mean you have
certain rights regarding your personal information. Learn more about your privacy rights.
The easiest way to exercise your rights is by submitting a data subject access request, or by
contacting us. We will consider and act upon any request in accordance with applicable data
protection laws.
1. What information do we collect?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register on the
Services,
express an interest in obtaining information about us or our products and Services, when you
participate in activities on the Services, or otherwise when you contact us.
Personal information Provided by You
The personal information that we collect depends on the context of your interactions with us
and the
Services, the choices you make, and the products and features you use. The personal
information we
collect may include the following:
- Names
- Date of birth
- Phone numbers
- Email addresses
- Mailing addresses
- Job titles
- Usernames
- Contact preferences
- Billing addresses
- Debit/credit cards numbers
- Contact or authentication data
Sensitive Information
When necessary, with your consent or as otherwise permitted by applicable law, we process the
following categories of sensitive informations:
- Health data
- Information revealing race or ethnic origin
- Social security numbers or other government identifiers
- Biometric data
Careround24 may collect and process certain categories of Sensitive Personal Information
(also known
as Special Category Data) in order to deliver safe, high-quality care services and to meet
our
legal, regulatory, and contractual obligations. This data is handled with the utmost
confidentiality
and is processed only when necessary for lawful and clearly defined purposes.
For Care Receivers (Clients)
To deliver regulated care services in line with clinical and safeguarding requirements, we
may
collect and process sensitive information including health and medical details (such as
diagnoses,
medications, treatment plans, care assessments, allergies, and mobility support needs),
mental
health or cognitive status (including dementia or learning disabilities), and religious or
philosophical beliefs where relevant to personal care preferences. We may also collect
information
relating to racial or ethnic background for the purpose of providing culturally sensitive
support,
as well as sexual orientation or gender identity where adaptations in care are needed.
Additional
information collected may include safeguarding concerns, advance care planning, family and
social
circumstances (including next of kin and power of attorney details), and limited financial
information where required for invoicing or funding purposes.
For Care Staff (Employees, Applicants, and Contractors)
To meet employment, safeguarding, and regulatory requirements—including PVG scheme compliance
and
Care Inspectorate expectations—we may collect sensitive information such as health-related
data
(e.g. fitness to work, vaccinations, and medical conditions), criminal conviction and
offence data
(e.g. disclosure or PVG checks), and equality monitoring data such as racial or ethnic
background or
religious beliefs (where voluntarily provided). Information on trade union membership,
emergency
contacts, and visual media (e.g. staff photos for ID, training, or marketing—only with
consent) may
also be processed.
Why We Collect This Data
We collect and process sensitive personal data only when there is a lawful basis to do so.
This
includes situations where the processing is necessary for the provision of health or social
care
services, required by employment law, health and safety obligations, or safeguarding
regulations. In
certain circumstances, we may also process data based on your explicit consent or when it is
necessary to protect vital interests—for example, in emergencies.
Data Protection and Security
All sensitive personal data held by Careround24 is stored securely and accessed only by
authorised
personnel who require it to perform their duties. We do not share this information with
third
parties unless there is a lawful basis or explicit consent. Personal data is retained only
for as
long as necessary to meet our care, legal, or regulatory obligations, in line with data
protection
best practices.
Payment data: we may collect data necessary to process your payment if you
choose to
use our services. All payment data is handled and stored by Gocardless and stripe. You may
find
their privacy notice in their website.
Social Media Login data: We may provide you with the option to register with
us
using your existing social media account details, like Facebook, or other social media
account. If
you choose to register in this way, we will collect certain profile information about you
from the
social media provider.
All personal information that you provide to us must be true, complete, and accurate, and you
must
notify us of any changes to such personal information.
Information automatically collected
In Short: Some information — such as your Internet Protocol (IP) address and/or browser and
device
characteristics — is collected automatically when you visit our Services.
We automatically collect certain information when you visit, use, or navigate the Services.
This
information does not reveal your specific identity (like your name or contact information)
but may
include device and usage information, such as your IP address, browser and device
characteristics,
operating system, language preferences, referring URLs, device name, country, location,
information
about how and when you use our Services, and other technical information. This information
is
primarily needed to maintain the security and operation of our Services, and for our
internal
analytics and reporting purposes.
Like many businesses, we also collect information through cookies and similar technologies.
2. How do we process your information?
In Short: We process your information to provide, improve, and administer our Services,
communicate
with you, for security and fraud prevention, and to comply with law. We may also process
your
information for other purposes with your consent.
We process your personal information for a variety of reasons, depending on how you interact
with our
Services, including:
To facilitate account creation and authentication and otherwise manage user accounts
We may process your information so you can create and log in to your account, as well as keep
your
account in working order.
To deliver and facilitate services
We may process your information to provide you with the requested service.
To save or protect an individual’s vital interest
We may process your information to provide you with the requested service.
At Careround24, we collect and process personal data in full compliance with the UK General
Data
Protection Regulation (UK GDPR) and the Data Protection Act 2018. The legal basis for our
processing
activities depends on the nature of the data and the context in which it is collected. We
rely on
the following lawful grounds:
Firstly, we process personal data as necessary for the performance of a contract,
particularly when
providing agreed care services, entering or managing service user agreements, and employing
or
contracting care staff. This includes gathering essential information to plan and deliver
safe,
tailored care, conduct assessments, and coordinate support.
Secondly, for sensitive categories of data—especially health-related information—we rely on
provisions under Article 9(2)(h) of the UK GDPR, which allows processing when it is required
for the
provision or management of health or social care services. This legal basis underpins our
work in
assessing care needs, delivering personal and medical care, developing support plans,
promoting
health and safety, and reporting to regulatory bodies such as the Care Inspectorate.
In addition, we may process personal data to meet our legal obligations, including those
relating to
employment law, tax compliance, safeguarding and adult protection duties, and fulfilling
regulatory
checks such as PVG scheme vetting for staff.
In certain circumstances, we may process data based on our legitimate interests, for example,
to
monitor the quality of our services, manage risks, improve service delivery, or ensure the
safety of
clients and staff. Where we rely on this basis, we ensure that our interests are balanced
with your
data protection rights and freedoms.
Finally, in situations where none of the above bases apply—such as for sending marketing
materials or
using photographs for promotional purposes—we will always request your explicit consent
before
processing. You have the right to withdraw this consent at any time without affecting the
quality of
care you receive.
3. What legal bases do we rely on to process your Personal Information?
In Short: We only process your personal information when we believe it is necessary and we
have a
valid legal reason (i.e. legal basis) to do so under applicable law, like with your consent,
to
comply with laws, to provide you with services to enter into or fulfil our contractual
obligations,
to protect your rights, or to fulfil our legitimate business interests.
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid
legal bases
we rely on to process your personal information. As such, we may rely on the following legal
bases
to process your personal information:
Consent
We may process your information if you have given us permission, i.e., consent to use your
personal
information for a specific purpose. You can withdraw your consent at any time.
Performance of a contract
We may process your personal information when we believe it is necessary to fulfil our
contractual
obligations to you, including providing our services or at your request prior to entering
into a
contract with you.
Legal Obligations
We may process your personal information when we believe it is necessary for compliance with
our
legal obligations, such as to cooperate with a law enforcement body or regulatory agency,
exercise
or defend our legal rights, or disclose your information as evidence in litigation in which
we are
involved.
Vital Interests
We may process your personal information where we believe it is necessary to protect your
vital
interests or the vital interests of a third party, such as situations involving potential
threats to
the safety of any person.
4. When and With Whom do we share your Personal Information?
In Short: We may share information in specific situations described in this section and/or
with the
following third parties.
We may need to share your personal information in the following situations:
Business Transfers
We may share or transfer your information in connection with, or during negotiations of, any
merger,
sale of company assets, financing, or acquisition of all or a portion of our business to
another
company.
Affiliates
We may share your information with our affiliates, in which case we will require those
affiliates to
honor this Privacy Notice. Affiliates include our parent company and any subsidiaries, joint
venture
partners, or other companies that we control or that are under common control with us.
Business Partners
We may share your information with our business partners to offer you certain products,
services, or
promotions.
5. Do we use Cookies and other Tracking Technologies?
In Short: We may use cookies and other tracking technologies to collect and store your
information.
We may use cookies and similar tracking technologies (like web beacons and pixels) to gather
information when you interact with our Services. Some online tracking technologies help us
maintain
the security of our Services, prevent crashes, fix bugs, save your preferences, and assist
with
basic site functions.
We also permit third parties and service providers to use online tracking technologies on our
Services for analytics and advertising, including to help manage and display advertisements,
to
tailor advertisements to your interests, or to send abandoned shopping cart reminders
(depending on
your communication preferences). The third parties and service providers use their
technology to
provide advertising about products and services tailored to your interests which may appear
either
on our Services or on other websites.
Specific information about how we use such technologies and how you can refuse certain
cookies is set
out in our Cookie Notice.
6. How do we handle your Social Logins?
In Short: If you choose to register or log in to our Services using a social media account,
we may
have access to certain information about you.
Our Services offer you the ability to register and log in using your third-party social media
account
details (like your Facebook or X logins). Where you choose to do this, we will receive
certain
profile information about you from your social media provider. The profile information we
receive
may vary depending on the social media provider concerned, but will often include your name,
email
address, friends list, and profile picture, as well as other information you choose to make
public
on such a social media platform.
We will use the information we receive only for the purposes that are described in this
Privacy
Notice or that are otherwise made clear to you on the relevant Services. Please note that we
do not
control, and are not responsible for, other uses of your personal information by your
third-party
social media provider. We recommend that you review their privacy notice to understand how
they
collect, use, and share your personal information, and how you can set your privacy
preferences on
their sites and apps.
7. Is your information Transferred Internationally?
In Short: We may transfer, store, and process your information in countries other than your
own.
Our servers are located in [insert location]. If you are accessing our Services from outside
[insert
location], please be aware that your information may be transferred to, stored by, and
processed by
us in our facilities and in the facilities of the third parties with whom we may share your
personal
information (see "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?" above), in
[insert
other countries].
If you are a resident in the European Economic Area (EEA), United Kingdom (UK), or
Switzerland, then
these countries may not necessarily have data protection laws or other similar laws as
comprehensive
as those in your country. However, we will take all necessary measures to protect your
personal
information in accordance with this Privacy Notice and applicable law.
Binding Corporate Rules
These include a set of Binding Corporate Rules (BCRs) established and implemented by us. Our
BCRs
have been recognised by EEA and UK data protection authorities as providing an adequate
level of
protection to the personal information we process internationally.
8. How long do we keep your Information?
In Short: We keep your information for as long as necessary to fulfill the purposes outlined
in this
Privacy Notice unless otherwise required by law.
We will only keep your personal information for as long as it is necessary for the purposes
set out
in this Privacy Notice, unless a longer retention period is required or permitted by law
(such as
tax, accounting, or other legal requirements). No purpose in this notice requires us to keep
your
personal information for longer than seventy-two months past the termination of the user’s
account.
When we have no ongoing legitimate business need to process your personal information, we
will either
delete or anonymize such information, or, if this is not possible (for example, because your
personal information has been stored in backup archives), then we will securely store your
personal
information and isolate it from any further processing until deletion is possible.
9. Do we collect Information from Minors?
In Short: We do not knowingly collect data from or market to children under 18 years of age.
We do not knowingly collect, solicit data from, or market to children under 18 years of age,
nor do
we knowingly sell such personal information. By using the Services, you represent that you
are at
least 18 or that you are the parent or guardian of such a minor and consent to such minor
dependent’s use of the Services.
If we learn that personal information from users less than 18 years of age has been
collected, we
will deactivate the account and take reasonable measures to promptly delete such data from
our
records. If you become aware of any data we may have collected from children under age 18,
please
contact us at info@careround24.com.
10. How do we keep your Information Safe?
In Short: We aim to protect your personal information through a system of organizational and
technical security measures.
We have implemented appropriate and reasonable technical and organizational security measures
designed to protect the security of any personal information we process. However, despite
our
safeguards and efforts to secure your information, no electronic transmission over the
internet or
information storage technology can be guaranteed to be 100% secure, so we cannot promise or
guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able
to
defeat our security and improperly collect, access, steal, or modify your information.
Although we will do our best to protect your personal information, transmission of personal
information to and from our services is at your own risk. You should only access the
services within
a secure environment.
11. What are your Privacy Rights?
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018,
you have
several important rights relating to the personal information Careround24 holds about you.
These
rights are designed to give you greater transparency, control, and protection over how your
data is
used.
You have the right to request access to the personal data we hold about you and to understand
how and
why it is being processed. If any of your information is inaccurate or incomplete, you can
request
that it be corrected or updated. In certain cases, you also have the right to request that
your data
be deleted—commonly known as the ‘right to be forgotten’—if it is no longer necessary for
the
purposes for which it was collected, though we may need to retain certain information to
meet legal
or regulatory requirements.
You can ask us to restrict the processing of your data in specific circumstances, such as
when
accuracy is in question, or you have raised an objection to its use. Where applicable, you
may also
request the transfer of your data to another organization or directly to yourself in a
commonly
used, structured format. Additionally, you have the right to object to how we use your
information
when we rely on legitimate interests, or where your data is being used for direct marketing
purposes.
If our processing is based on your consent—such as for promotional communications or the use
of
photographs—you have the right to withdraw that consent at any time. It’s also important to
note
that Careround24 does not use automated decision-making or profiling that affects
individuals.
To exercise any of your data protection rights, please contact our Data Protection Lead using
the
contact details provided below. We will respond to your request within one calendar month,
in
accordance with data protection law, and may ask for proof of identity to confirm your
request. If
you have concerns about how your personal data is being handled and are not satisfied with
our
response, you have the right to lodge a complaint with the Information Commissioner’s Office
(ICO)
at www.ico.org.uk.
Email: info@careround24.com
In Short: You may review, change, or terminate your account at any time, depending on your
country,
province, or state of residence.
Withdrawing your consent: If we are relying on your consent to process your
personal
information, which may be express and/or implied consent depending on the applicable law,
you have
the right to withdraw your consent at any time. You can withdraw your consent at any time by
contacting us using the contact details provided in the section "HOW CAN YOU CONTACT US
ABOUT THIS
NOTICE?" below.
However, please note that this will not affect the lawfulness of the processing before its
withdrawal
nor, when applicable law allows, will it affect the processing of your personal information
conducted in reliance on lawful processing grounds other than consent.
Account Information
If you would at any time like to review or change the information in your account or
terminate your
account, you can:
Upon your request to terminate your account, we will deactivate or delete your account and
information from our active databases. However, we may retain some information in our files
to
prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal
terms and/or
comply with applicable legal requirements.
12. Controls for DO-NOT-TRACK Features
Most web browsers and some mobile operating systems and mobile applications include a
Do-Not-Track
("DNT") feature or setting you can activate to signal your privacy preference not to have
data about
your online browsing activities monitored and collected. At this stage, no uniform
technology
standard for recognizing and implementing DNT signals has been finalized.
As such, we do not currently respond to DNT browser signals or any other mechanism that
automatically
communicates your choice not to be tracked online. If a standard for online tracking is
adopted that
we must follow in the future, we will inform you about that practice in a revised version of
this
Privacy Notice.
13. Do we make Updates to this Notice?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this Privacy Notice from time to time. The updated version will be indicated by
an
updated "Revised" date at the top of this Privacy Notice. If we make material changes to
this
Privacy Notice, we may notify you either by prominently posting a notice of such changes or
by
directly sending you a notification.
We encourage you to review this Privacy Notice frequently to be informed of how we are
protecting
your information.
14. Can you Review, Update, or Delete the data we collect from you?
15. How can you contact us about this notice?
If you have questions or comments about this notice, you may contact us by:
Careround24
48 West George Street,
Glasgow,
G2 1BP
Phone: 01412125150
Email: info@careround24.com