Logo
CarerCo
Services
Locations
About us
Contact us
Legal

Privacy Policy

For customers, service users, representatives and platform visitors · Version 1.0

CarerCore (“we”, “us”, “our”) is committed to protecting your personal information and respecting your privacy. This Privacy Policy explains what personal information we collect, why and how we use it, who we share it with, and the rights you have under the UK General Data Protection Regulation, the Data Protection Act 2018, and applicable Irish and EU data-protection law.

Contents

  1. 1. Who we are and when this Policy applies
  2. 2. The information we collect
  3. 3. Where information comes from
  4. 4. How and why we use personal information
  5. 5. Health and other sensitive information
  6. 6. Who we share information with
  7. 7. International transfers
  8. 8. How long we keep information
  9. 9. How we protect information
  10. 10. Your data-protection rights
  11. 11. Children, capacity and representatives
  12. 12. Cookies, analytics and marketing
  13. 13. Automated tools and matching
  14. 14. Data-protection complaints
  15. 15. Changes and contact details

1. Who we are and when this Policy applies

CarerCore is the trading name used by the relevant CarerCore company providing or arranging the service.

United Kingdom and Northern Ireland

For services delivered in Northern Ireland or elsewhere in the United Kingdom, the controller is CarerCo Ltd, company number 13635212, registered office 128 City Road, London, EC1V 2NX and operational address 5-7 William Street, Portadown, BT62 3NX.

Republic of Ireland

For services delivered in the Republic of Ireland, the controller is CarerCo ROI Clinical and Community Services Limited, company number 808136, registered and operational office 2 Paddocks Way, Adamstown, Lucan, Dublin, K78 AN81.

The company that provides or arranges your service will normally be the controller of your personal information. The two CarerCore companies may share limited information for group administration, service continuity, technology, quality and compliance. Where they separately decide how information is used, each acts as an independent controller for its own processing.

This Policy applies to website visitors, account holders, prospective and current customers, Service Users, authorised representatives, family contacts, emergency contacts and other people whose information is supplied in connection with a care request or service.

2. The information we collect

The information we collect depends on how you use CarerCore and the services involved. It may include:

  • identity and contact details, including name, date of birth, address, email address, telephone number and identifiers used by health or social-care services;
  • account and security information, including login details, verification records, account preferences and audit logs;
  • care and health information, including medical conditions, disabilities, medication, allergies, mobility, cognition, communication, behaviour, nutrition, personal-care needs, risks and care preferences;
  • information about capacity, consent, representatives, parental responsibility, powers of attorney, guardianship or other legal authority;
  • booking and service information, including assessments, Care Plans, visit records, care notes, medication records, incidents, complaints, safeguarding concerns and communications;
  • payment and funding information, including billing details, transaction records, Direct Payment or Commissioner information and payment status;
  • family, emergency-contact and professional-contact information;
  • images, call recordings, CCTV disclosures, electronic visit-verification data and location confirmation where used lawfully for service delivery, safety or verification;
  • website, app and device information, including IP address, browser, device identifiers, cookies, login activity and platform usage; and
  • any other information you choose to provide or that is reasonably necessary to assess, arrange or deliver the requested service.

We generally do not retain full payment-card details where payment is processed by an approved payment provider. The provider processes those details under its own security and privacy arrangements.

3. Where information comes from

We may obtain information directly from you or from:

  • a Customer, Service User, family member or authorised Representative;
  • Care Professionals and CarerCore staff providing or coordinating services;
  • HSC Trusts, the HSE, local authorities, Commissioners, insurers or Direct Payment administrators;
  • GPs, hospitals, pharmacists, nurses, social workers, therapists and other health or social-care professionals;
  • previous or proposed care providers, with appropriate authority;
  • emergency services, safeguarding bodies, regulators or public authorities;
  • payment, identity-verification, technology and security providers; and
  • publicly available sources where lawful and relevant.

When someone gives us information about another person, they should have a lawful reason to do so and should make that person aware that the information has been provided where appropriate.

4. How and why we use personal information

We only use personal information where we have a lawful basis. The main purposes and bases are set out below.

PurposeMain lawful basis
Responding to enquiries, creating accounts, assessing requests and forming a service contract.Steps before entering a contract; performance of a contract; legitimate interests in operating and improving our services.
Assessing needs, preparing Care Plans and delivering, coordinating and reviewing care.Performance of a contract; legal obligations; legitimate interests; health or social-care conditions for sensitive information.
Medication support, incident response, safeguarding, emergency action and protecting life or welfare.Legal obligations; vital interests; legitimate interests; substantial public interest or health and social-care conditions where applicable.
Managing visits, staffing, communications, payments, funding, records, complaints and service quality.Performance of a contract; legal obligations; legitimate interests in running a safe, effective and accountable care service.
Preventing fraud, misuse, cyber incidents and threats to users, staff or the Platform.Legal obligations; legitimate interests in security, fraud prevention and protecting people and systems.
Complying with regulators, Commissioners, courts, tax, insurance and legal claims.Legal obligations; legitimate interests in establishing, exercising or defending legal rights.
Analytics, service improvement and non-essential cookies.Consent where required; legitimate interests for limited, necessary and proportionate operational analytics.
Marketing and updates about CarerCore services.Consent or another lawful electronic-marketing basis where permitted. You can opt out at any time.

Where we rely on legitimate interests, we consider the expected benefit, necessity and impact on the individual. Our interests include providing safe care, managing the Platform, preventing fraud, protecting people, improving services and maintaining appropriate business records.

Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect processing already carried out lawfully and does not prevent us using another lawful basis where one applies.

5. Health and other sensitive information

Care services require us to use health information and may also reveal disability, ethnicity, religion, sexual orientation or other sensitive information. We only use this information when necessary and where an additional legal condition applies.

Depending on the circumstances, we may rely on:

  • processing necessary for the provision or management of health or social care, subject to applicable law and duties of confidentiality;
  • protecting the vital interests of a person who cannot provide consent;
  • substantial public-interest grounds supported by law, including safeguarding and protection from serious harm;
  • establishing, exercising or defending legal claims; or
  • explicit consent where this is appropriate and genuinely optional.

We do not use health information for unrelated advertising, and we do not sell personal or health information.

6. Who we share information with

We share only information that is reasonably necessary for the relevant purpose. Recipients may include:

  • CarerCore employees, Care Professionals, managers, coordinators and authorised contractors;
  • health and social-care professionals, pharmacies, hospitals, previous or new providers and emergency services;
  • HSC Trusts, the HSE, local authorities, Commissioners, Direct Payment administrators, insurers and funders;
  • safeguarding bodies, regulators, professional bodies, ombudsmen, courts, police and other public authorities where lawful;
  • payment processors, cloud hosting, care-management, communications, analytics, identity, IT support and cyber-security providers;
  • lawyers, auditors, insurers, accountants and other professional advisers;
  • another CarerCore entity where necessary for shared systems, administration, continuity or compliance; and
  • a purchaser, investor or successor in connection with a genuine business restructuring, subject to confidentiality and legal safeguards.

Some recipients act as processors under CarerCore's instructions. Others, such as health professionals, Commissioners, regulators and payment providers, may act as independent controllers under their own legal duties.

7. International transfers

Because CarerCore operates in both the United Kingdom and the Republic of Ireland, information may move between the UK and the European Economic Area where necessary for the purposes described in this Policy.

Some technology or support providers may process information in other countries. Where transfer restrictions apply, we use an approved legal mechanism, such as an adequacy decision or regulation, standard contractual clauses, the UK International Data Transfer Agreement or Addendum, together with any required transfer assessment and additional safeguards.

8. How long we keep information

We keep information only for as long as reasonably necessary for care, legal, regulatory, safeguarding, insurance, accounting and dispute-resolution purposes.

Retention periods depend on the record and may be set by law, a regulator, professional standard, Commissioner contract or CarerCore retention schedule. In general:

  • active account and service records are kept while the relationship continues;
  • contracts, invoices and payment records are generally retained for at least the applicable statutory limitation and accounting period;
  • Care Plans, care notes, medication, incident and safeguarding records may be retained for longer where required for continuity, regulation, protection or legal claims;
  • enquiry records that do not lead to a service are retained only for a limited follow-up and accountability period;
  • marketing information is retained until consent is withdrawn or an objection is made, with a limited suppression record kept to respect that choice; and
  • anonymised statistical information may be retained because it no longer identifies an individual.

We may restrict access or place information under a legal hold where a complaint, investigation, safeguarding matter or claim is ongoing.

9. How we protect information

We use proportionate technical and organisational safeguards, including access controls, authentication, encryption where appropriate, audit logs, secure hosting, staff confidentiality, training, supplier due diligence, backups, incident-management procedures and regular review of permissions.

No system can be guaranteed completely secure. If a personal-data breach occurs, we will investigate it and notify affected individuals and regulators where the law requires.

10. Your data-protection rights

Depending on the circumstances and applicable law, you may have the right to:

  • ask for access to your personal information and related information about its use;
  • ask us to correct inaccurate or incomplete information;
  • ask for deletion where there is no continuing lawful reason to keep the information;
  • ask us to restrict how information is used;
  • object to processing based on legitimate interests or to direct marketing;
  • receive certain information in a portable format or ask for it to be sent to another provider;
  • withdraw consent where consent is the basis for processing;
  • ask for human review of certain solely automated decisions with legal or similarly significant effects; and
  • complain to CarerCore or the relevant data-protection regulator.

Rights are not absolute. For example, we may need to retain information to provide care safely, protect another person, comply with law or manage a legal claim. We may request proof of identity and authority before responding.

Requests should be sent to support@carercore.com and marked “Data Protection”. We will respond within the applicable legal time limit and will explain any lawful restriction.

11. Children, capacity and representatives

Where information concerns a child or a person who may not be able to manage their own affairs, we may work with a parent, guardian, attorney, controller or other authorised Representative. We may request evidence of authority and will continue to respect the Service User's rights, wishes, communication needs and legal capacity.

A Representative's access is limited to information they are legally entitled to receive. We may withhold information where disclosure would breach another person's rights, confidentiality, safeguarding obligations or the Service User's valid wishes.

12. Cookies, analytics and marketing

Cookies and similar technologies

We use necessary cookies and similar technologies to operate accounts, remember preferences, maintain security and support essential Platform functions. With consent where required, we may also use analytics or other non-essential technologies to understand usage and improve the Platform.

Cookie choices can be managed through the cookie banner or settings provided on the Platform. Blocking necessary cookies may prevent some functions from working. For full details see our Cookie Policy.

Marketing

We may send information about CarerCore services where you have consented or where another lawful electronic-marketing basis applies. You can unsubscribe using the link in a message or by contacting us. Service, safety and account communications are not marketing and may still be sent where necessary.

13. Automated tools and matching

CarerCore may use software to assist with postcode checks, availability, scheduling, Care Professional matching, risk flags, fraud prevention and service administration.

These tools support rather than replace professional judgement. We do not intend to make solely automated decisions using health information that have legal or similarly significant effects unless the processing is lawful and appropriate safeguards, including human review where required, are in place.

14. Data-protection complaints

You can raise a data-protection complaint with CarerCore if you believe we have not handled your information properly. You do not need to use legal language.

Haris Ali, Data Protection Lead

Email: support@carercore.com, with “Data Protection Complaint” in the subject line

Postal address: 5-7 William Street, Portadown, BT62 3NX for UK matters, or 2 Paddocks Way, Adamstown, Lucan, Dublin, K78 AN81 for Irish matters.

We will acknowledge and investigate complaints in accordance with applicable law and our data-protection complaints procedure. In the UK, data-protection complaints will be acknowledged within 30 days.

You also have the right to complain to:

  • Information Commissioner's Office (ICO) for UK processing: www.ico.org.uk; or
  • Data Protection Commission (DPC) for Republic of Ireland processing: www.dataprotection.ie.

We encourage you to contact CarerCore first so that we have the opportunity to investigate and resolve the matter.

15. Changes and contact details

We may update this Policy to reflect changes in law, regulation, technology or CarerCore services. The latest version will be published on the Platform with its effective date. We will provide additional notice where a material change requires it.

For privacy questions, rights requests or complaints, contact:

Haris Ali, Data Protection Lead

Email: support@carercore.com

Telephone: 07841 677 740

UK operational address: 5-7 William Street, Portadown, BT62 3NX

Republic of Ireland address: 2 Paddocks Way, Adamstown, Lucan, Dublin, K78 AN81

Important: this Policy explains how CarerCore uses personal information. It does not replace individual consent discussions, Care Plans, statutory information, Commissioner notices or service-specific privacy information where those are required.

© 2026 CarerCore. All rights reserved.

Logo
CarerCo
Services
Locations
About us
Contact us
Logo
CarerCo
Careers
About Us
FAQs
Locations
Contact us
Instagram
X
Facebook

© 2026 CarerCore. All rights reserved

Privacy PolicyTerms of Service