CarePointIQ — Insight, Care, Excellence

CarePointIQ · Legal

Privacy Policy

This policy explains what personal data CarePointIQ handles, why we handle it, how long we keep it and the rights available to the people it belongs to. It covers both our public website and the CarePointIQ platform used by care providers.

Last updated: 14 August 2026

1. Who we are

CarePointIQ is a care management platform operated from 195-197 Wood Street, London, E17 3NU, United Kingdom. For enquiries about this policy, or to exercise any of the rights described below, contact [email protected].

Our role depends on the data in question. For the enquiry and account information we collect through our own website, we act as the data controller. For the care records, staff records and other operational data that a care provider enters into the platform, the care provider is the controller and CarePointIQ acts as a data processor on their written instructions.

2. Data we collect through this website

  • Contact details you give us voluntarily through the contact form, demo booking form or the free record-transformer tool, such as your name, email address, telephone number and organisation.
  • The text of any care note you paste into the public record-transformer tool so that it can be processed and returned to you.
  • Technical information needed to serve the site securely, such as your IP address, browser type and the pages you visited.

3. Data processed inside the platform

When a care provider uses CarePointIQ they enter data about the people they support and about their own staff. This includes special category data as defined by Article 9 of the UK GDPR, in particular health data.

  • Records about people receiving care, including identifying details, care plans, risk assessments, daily notes, medicines administration records, incidents, body maps and family contact details.
  • Records about staff, including contact details, roles, training records, shift patterns, absence and time and attendance data.
  • Operational and audit data, including the identity of the user who created or changed a record and the time at which they did so.

4. Why we process it and our lawful basis

  • To provide the platform under our contract with the care provider. Lawful basis: performance of a contract.
  • To respond to enquiries and demonstration requests you send us. Lawful basis: legitimate interests, namely responding to a request you initiated.
  • To keep the service secure, prevent misuse and maintain an audit trail. Lawful basis: legitimate interests and, where applicable, legal obligation.
  • Where special category health data is processed inside the platform, the care provider relies on Article 9(2)(h) of the UK GDPR, processing necessary for the provision of health or social care, together with the associated conditions in Schedule 1 of the Data Protection Act 2018. CarePointIQ processes that data only on the provider’s instructions.

5. Artificial intelligence features

Several features use large language models to draft, summarise or restructure text. Where a feature does this, the relevant text is sent to a third party model provider for processing and the result is returned to the platform. Model providers used by CarePointIQ are engaged under contractual terms that prohibit the use of customer content to train their models.

All AI output is presented as a draft for a person to review. It is not a clinical decision, and the platform requires a named user to accept a draft before it becomes part of a record. Where the model cannot verify a detail it is expected to flag it rather than infer it, and the accepting user remains responsible for the accuracy of the finished record.

6. Sharing and sub-processors

We do not sell personal data. We share it only with the service providers needed to run the platform, each engaged under a written contract that restricts them to our instructions.

  • Cloud hosting and database services used to run and store the platform.
  • Cloud file storage used for documents, photographs and uploads.
  • Large language model providers used by the AI drafting features described above.
  • Transactional email delivery used for notifications, invitations and alerts.
  • Payment processing for subscription billing. Card details are handled by the payment provider and are never stored by CarePointIQ.

7. Where data is held and international transfers

Platform data is held on infrastructure within the United Kingdom or the European Economic Area wherever the underlying service allows it. Where a sub-processor operates outside the UK, the transfer is covered by the UK International Data Transfer Agreement or the UK Addendum to the European Commission standard contractual clauses, supported by a transfer risk assessment.

8. How long we keep it

  • Website enquiries: up to 24 months from the last contact, unless you ask us to delete them sooner.
  • Text submitted to the public record-transformer tool: retained only for as long as needed to return the result and to investigate misuse, and no longer than 30 days.
  • Platform data: retained for as long as the care provider’s account is active. On termination the provider may export their data, after which it is deleted within 90 days unless they instruct us otherwise or we are required to retain it by law.
  • Audit logs: retained for six years to support inspection and safeguarding enquiries.

9. Security

  • Data is encrypted in transit using TLS and at rest by the underlying storage platform.
  • Access is controlled by role. Records can be restricted to named services and named individuals so that staff only see the people they are allocated to.
  • Multi-factor authentication is available and can be required for accounts with elevated access.
  • Every create, change and view of a care record is written to an audit trail attributed to a named user.
  • We are working towards ISO 27001 and Cyber Essentials Plus certification. Neither certification is held at the date of this policy, and we do not claim otherwise.

10. Your rights

Under the UK GDPR you have the right to be informed, and rights of access, rectification, erasure, restriction, portability and objection, together with rights in relation to automated decision making.

If your data is held inside a care provider’s account, please contact that provider first, as they control the record. We will assist them in responding. If we hold your data as controller, contact [email protected] and we will respond within one month.

You may also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would ask you to raise it with us first so that we have the chance to put it right.

11. Children

Some care providers using CarePointIQ support children and young people. Where that is the case, the provider is the controller for those records and is responsible for the lawful basis, consent arrangements and any local safeguarding requirements. The platform provides sector-specific language and escalation routes to support this.

12. Changes to this policy

We will update this page when our processing changes and will revise the date shown above. Where a change materially affects how personal data is handled we will notify account administrators directly.