Privacy Policy
1. Who we are
Ceadar Healthcare ("Ceadar Healthcare", "we", "our", "us") is a provider of domiciliary care, supported living, and agency staffing services in the United Kingdom. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller for the personal information we collect about you.
For questions about how we handle your personal data, please contact us using the details on our website.
2. Scope of this policy
This policy explains how we handle personal data collected through our website (ceadarhealthcare.com), enquiry forms, phone and email contact, and the delivery of our care and staffing services. It applies to people who use our services, their family members and representatives, prospective and current staff, and visitors to our website.
3. Information we collect
Depending on your relationship with us, we may collect:
- Contact details — your name, address, email, phone number, and the name of anyone contacting us on your behalf.
- Care and health information— details of your care needs, medical history, medication, mobility, mental capacity, GP and other clinician details, care plans, and progress notes. This is "special category" data and is handled with additional safeguards.
- Financial and identity information — where required to arrange care, verify identity, invoice, or process payments.
- Employment and vetting information — for applicants and staff, this includes CV data, references, right-to-work documents, DBS checks, training records, and payroll information.
- Website and technical data — IP address, browser type, pages visited, and similar information gathered through cookies and analytics.
4. How we use your information
We use personal data to:
- Respond to enquiries and provide quotes for our services.
- Assess needs, plan and deliver care, and keep accurate care records as required by our regulator.
- Recruit, vet, train, and manage our staff and agency workers.
- Manage billing, payments, complaints, safeguarding concerns, and incidents.
- Improve our services, our website, and the safety of the people we support.
- Meet our legal, regulatory, and safeguarding obligations, including cooperation with the Care Quality Commission (CQC) and local authorities.
5. Lawful bases
We rely on the following lawful bases under UK GDPR:
- Contract — to take steps at your request before entering into a contract and to deliver our services.
- Legal obligation — to comply with employment, health and safety, safeguarding, tax, and care-regulation law.
- Legitimate interests — to run and improve our business, secure our website, and communicate with prospective clients, where these interests are not overridden by your rights.
- Vital interests— where processing is necessary to protect someone's life in an emergency.
- Consent — for optional communications and non-essential cookies. You can withdraw consent at any time.
For special category data (such as health information), we rely on Article 9(2)(h) UK GDPR (provision of health and social care) alongside the Data Protection Act 2018 conditions in Schedule 1.
6. Sharing your information
We only share personal data where necessary and on a need-to-know basis. Recipients may include:
- Health and social care professionals involved in your care (e.g. GPs, district nurses, hospitals, local authorities).
- Regulators including the CQC and, where required, safeguarding bodies and the police.
- Trusted service providers who help us run our business (IT and hosting, payroll, DBS checks, professional advisors). These partners act on our instructions and are bound by contract.
- HMRC, courts, and other public bodies where we are required by law.
We do not sell your personal data. Where data is transferred outside the UK, we put appropriate safeguards in place, such as the UK International Data Transfer Agreement.
7. How long we keep it
Care records are retained in line with the NHS Records Management Code of Practice and applicable social-care guidance. Employment and vetting records are kept for the periods required by law and our regulator. Website enquiry data is kept for [RETENTION PERIOD] unless it becomes part of a client record. When we no longer need personal data, we securely delete or anonymise it.
8. Keeping your information secure
We use technical and organisational measures to protect personal data, including access controls, encryption in transit, staff training, and confidentiality agreements. Paper records are kept in locked storage and destroyed securely when no longer needed.
9. Your rights
Under UK GDPR you have the right to:
- Ask for a copy of the personal data we hold about you.
- Ask us to correct inaccurate or incomplete data.
- Ask us to erase data, restrict processing, or object to processing, in certain circumstances.
- Withdraw consent where we rely on it, without affecting past lawful processing.
- Ask for your data in a portable format, where applicable.
To exercise any of these rights, please contact us using the details on our website. If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk or by calling 0303 123 1113. We would appreciate the chance to address your concerns first.
10. Cookies
Our website uses essential cookies to make the site work and, with your consent, analytics cookies to understand how visitors use it. You can control cookies through your browser settings. See our cookie preferences link for further detail.
11. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top shows when it was last revised. Material changes will be highlighted on our website.