CA
Care App
← Back to home
Compliance

GDPR Compliance

Inkfinity Print Solutions Ltd  ·  ICO Reg: 00017970075  ·  Co. No. 15776217

Care App is built with data protection at its core. We are registered with the Information Commissioner's Office (ICO) and comply fully with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Our Role

Inkfinity Print Solutions Ltd operates as a data processor on behalf of care organisations that use the Care App platform. Each subscribing organisation is the data controller for the personal data of their staff and clients.

This means we only process personal data on the documented instructions of each organisation, and we never use that data for our own purposes.

How We Protect Your Data

  • Encryption in transit: All data is transmitted over TLS 1.2 or higher
  • Encryption at rest: Data is stored using AES-256 encryption via Google Firebase
  • UK/EEA hosting: All data is stored in the europe-west2 (London) region — it never leaves the UK or EEA
  • Role-based access: Staff only see the data they need to do their job
  • Audit logging: All key actions are recorded with a timestamp and user identity
  • Access controls: Accounts are protected by Firebase Authentication

Sub-processors

We use one sub-processor to deliver the service:

  • Google LLC (Firebase) — cloud database, authentication, file storage, and hosting. Data is held in the London region (europe-west2). Google is certified under ISO 27001 and participates in the UK GDPR international transfer framework.

Data Retention

Personal data is retained for the duration of the subscription. On termination, data is retained for 90 days to allow for export, after which it is permanently deleted in line with our Data Processing Agreement.

The following retention periods apply to specific data types held within the platform:

Data TypeRetention PeriodReason
Client care records & support plans7 years post-dischargeCare sector best practice & potential legal claims
Medication records (MAR charts)2 years minimumMedicines Management guidance
Incident & accident records3 yearsRegulatory & insurance requirements
Staff records & timesheets6 years post-employmentEmployment law & HMRC requirements
Financial records (invoices, subscriptions)6 yearsCompanies Act 2006 / HMRC
Audit logs3 yearsGDPR accountability & regulatory inspection
Account data (post-termination)90 daysData export window, then permanent deletion

Retention periods reflect the requirements of the data controller (the subscribing care organisation). We retain data on the controller's behalf for the duration of the subscription. Controllers are responsible for ensuring their own retention policies comply with applicable law.

Your Rights

Individuals whose data is held within Care App have the following rights under UK GDPR:

  • Right of access (Subject Access Request)
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object

Requests relating to individual rights should be directed to the subscribing organisation (the data controller) in the first instance. We will support controllers in fulfilling any requests we are required to assist with.

Breach Notification

In the event of a personal data breach, we follow a documented incident response procedure. We notify affected organisations within 24 hours of confirming a breach and report to the ICO within 72 hours where required by law.

Legal Documents

The following documents form our full data protection framework:

Legal

Data Processing Agreement

Our Article 28 UK GDPR compliant DPA, covering all processing obligations.

Security

Incident Response Procedure

How we detect, contain, and report data breaches and security incidents.

Legal

Terms of Service

The terms governing use of the Care App platform.

Cookies and Local Storage

Care App does not use tracking cookies. However, to provide a secure and functional service, we use browser local storage to maintain your login session via Firebase Authentication. This is essential for the Service to work — without it you would be signed out every time you navigate between pages.

No data stored in local storage is shared with third parties or used for advertising. It contains only your authentication token and session state, which is cleared when you sign out.

Contact

For any data protection queries:

  • Email: hello@care-app.uk
  • Post: Inkfinity Print Solutions Ltd, Innovation Centre, Maidstone Road, Chatham, Kent, ME5 9FD

The UK Supervisory Authority is the Information Commissioner's Office (ICO): ico.org.uk  ·  0303 123 1113

© 2026 Inkfinity Print Solutions Ltd  ·  care-app.uk  ·  ICO Reg: 00017970075
Privacy Policy Terms of Service Data Processing Agreement GDPR Compliance Incident Response Home