CA
Care App
← Back to home
Legal

Privacy Policy

Inkfinity Print Solutions Ltd  ·  ICO Reg: 00017970075  ·  Co. No. 15776217  ·  Last updated: May 2025

This Privacy Policy explains how Inkfinity Print Solutions Ltd ("we", "us", "our") collects, uses, and protects personal data in connection with the Care App platform and the care-app.uk website. We are registered with the Information Commissioner's Office (ICO) and comply fully with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

Data Controller (our own business data): Inkfinity Print Solutions Ltd is the Data Controller for personal data relating to our website visitors, prospective customers, and our own business operations.

Data Processor (Care App platform data): For personal data entered into the Care App platform by subscribing care organisations — including data about their staff and clients — Inkfinity Print Solutions Ltd acts solely as a Data Processor. Each subscribing organisation is the Data Controller for that data and is responsible for its lawful processing. We process such data only on the documented instructions of the relevant controller.

Registered address: Innovation Centre, Maidstone Road, Chatham, Kent, ME5 9FD

Contact: hello@care-app.uk

2. Data We Collect About Website Visitors

When you visit care-app.uk, our web server automatically records standard access log information, including your IP address, browser type, pages visited, and the time and date of your visit. This data is held for up to 30 days for security and diagnostic purposes and is not used for profiling or marketing.

If you submit an enquiry via our contact or sign-up form, we collect:

  • Your name and email address (required)
  • Your phone number (optional)
  • Your organisation name and approximate staff count (optional)
  • Your chosen plan and any message you include

Lawful basis: Legitimate interests (responding to your enquiry and assessing whether our service is suitable for your organisation).

Retention: Enquiry data is retained for 12 months, after which it is deleted unless you have become a subscriber.

3. Data We Collect Within the Care App Platform

When a care organisation subscribes to Care App, their staff and administrators enter data into the platform in the course of their work. This may include personal data relating to care clients (including health and care records, which are special category data under UK GDPR) and staff members.

As Data Processor, we process this data only to provide and maintain the service. The subscribing organisation (Data Controller) is responsible for ensuring their use of the platform has a lawful basis, and for responding to data subject rights requests from their staff and clients.

Our processing activities and obligations as Data Processor are set out in our Data Processing Agreement.

4. How We Protect Your Data

  • Encryption in transit: All data is transmitted over TLS 1.2 or higher
  • Encryption at rest: Data is stored using AES-256 encryption via Google Firebase
  • UK hosting: All data is stored exclusively in the europe-west2 (London) region — it never leaves the UK or EEA
  • Role-based access controls: Staff can only access data relevant to their role
  • Multi-factor authentication: Administrative access to the platform requires a second authentication factor
  • Audit logging: All key actions are recorded with a timestamp and user identity
  • Idle session timeout: Sessions are automatically terminated after 30 minutes of inactivity
  • App Check: The platform uses Google reCAPTCHA App Check to block unauthorised API access

5. Sub-processors

We use one sub-processor to deliver the Care App service:

  • Google LLC (Firebase / Google Cloud) — cloud database, authentication, file storage, and hosting. All data is held in the London region (europe-west2). Google LLC is certified under ISO 27001 and SOC 2 Type II, and participates in the UK GDPR international transfer framework. Google Cloud holds Cyber Essentials Plus certification.

We do not share personal data with any other third party for the purposes of delivering the Care App service.

6. Lawful Basis for Processing

Processing activity Lawful basis
Responding to website enquiries Legitimate interests
Providing the Care App subscription service Contract (with the subscribing organisation)
Processing care records within the platform As Data Processor — on the instructions of the Data Controller (the subscribing organisation)
Maintaining security and audit logs Legitimate interests / Legal obligation
Billing and financial records Contract and Legal obligation (HMRC / Companies Act)

7. Data Retention

Data typeRetention periodReason
Website enquiry data12 monthsLegitimate interests — sales follow-up window
Server access logs30 daysSecurity and diagnostics
Client care records & support plans7 years post-dischargeCare sector best practice & potential legal claims
Medication records (MAR charts)2 years minimumMedicines Management guidance
Incident & accident records3 yearsRegulatory & insurance requirements
Staff records & timesheets6 years post-employmentEmployment law & HMRC requirements
Financial & billing records6 yearsCompanies Act 2006 / HMRC
Audit logs3 yearsGDPR accountability & regulatory inspection
Platform account data (post-termination)90 daysData export window, then permanent deletion

8. Cookies and Local Storage

Care App does not use tracking or advertising cookies. We do not use Google Analytics or any third-party analytics service on this website or within the platform.

The Care App platform uses browser local storage and IndexedDB to maintain your login session via Firebase Authentication and to cache application data for offline use. This is strictly necessary for the service to function — without it you would be signed out every time you navigate between pages. No data stored in local storage is shared with third parties or used for advertising.

The care-app.uk website itself sets no cookies. Any session state from your browser is handled entirely client-side and is cleared when you sign out or close your browser session.

9. Your Rights Under UK GDPR

You have the following rights in relation to personal data we hold about you as Data Controller (i.e. your website enquiry data or our business relationship with you):

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — ask us to correct inaccurate data
  • Right to erasure — ask us to delete your data where there is no legitimate reason to continue holding it
  • Right to restrict processing — ask us to pause processing while accuracy is contested
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests

If your request relates to data held within the Care App platform (for example, your staff profile or a care record), please contact your organisation's administrator in the first instance, as they are the Data Controller for that data. We will support them in fulfilling any request we are required to assist with.

To exercise any of the above rights, contact us at hello@care-app.uk. We will respond within one calendar month.

10. Data Breach Notification

In the event of a personal data breach affecting data for which we are the Data Controller, we will notify the ICO within 72 hours where required by law, and affected individuals without undue delay where there is a high risk to their rights and freedoms.

Where a breach affects data for which we are a Data Processor, we will notify the relevant Data Controller (the subscribing organisation) within 24 hours of becoming aware of the breach, in accordance with our Data Processing Agreement. Our full breach response procedure is set out in our Incident Response Procedure.

11. International Transfers

We do not transfer personal data outside the UK or EEA. All data is stored and processed in Google Cloud's europe-west2 (London) region. Google LLC participates in the UK GDPR international data transfer framework and standard contractual clauses are in place where required.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The date at the top of this page reflects the most recent revision. For material changes, we will notify subscribing organisations by email. Continued use of the service after a change constitutes acceptance of the updated policy.

13. Related Documents

Legal

Data Processing Agreement

Our Article 28 UK GDPR compliant DPA covering all processing obligations.

Compliance

GDPR Compliance

Technical and organisational security measures we have in place.

Security

Incident Response

How we detect, contain, and report data breaches and security incidents.

Legal

Terms of Service

The terms governing use of the Care App platform.

Contact & Supervisory Authority

For any privacy-related queries or to exercise your rights:

  • Email: hello@care-app.uk
  • Post: Inkfinity Print Solutions Ltd, Innovation Centre, Maidstone Road, Chatham, Kent, ME5 9FD

If you are not satisfied with our response, you have the right to lodge a complaint with the UK supervisory authority:

Information Commissioner's Office (ICO)
ico.org.uk  ·  0303 123 1113  ·  Wycliffe House, Water Lane, Wilmslow, SK9 5AF

© 2026 Inkfinity Print Solutions Ltd  ·  care-app.uk  ·  ICO Reg: 00017970075
Privacy Policy Terms of Service Data Processing Agreement GDPR Compliance Incident Response Home