🇬🇧 GDPR

GDPR statement

Carein.one is designed so that a care provider can meet its UK GDPR obligations without extra spreadsheets or workarounds.

Roles

Your organisation is the controller of the care records it creates. Switch Technologies Ltd is the processor, acting only on your documented instructions. A data processing agreement is available on request and is incorporated into every subscription.

Lawful basis for care records

Care providers typically rely on legal obligation and legitimate interests for care delivery records, with special category data processed under the health and social care condition of the Data Protection Act 2018. Family portal access is consent-based and consent is recorded in the platform.

Data minimisation by design

Role-based access means carers see only the people they support. Family portal permissions are granular — mood summaries and visit schedules without clinical notes or carer contact details.

Security measures

Encryption in transit and at rest, row-level access controls per organisation, full audit trails on records including care notes, timesheets and medication entries, and least-privilege internal access.

Subject access and erasure

Records can be exported per person as CSV or PDF to support subject access requests. Erasure requests are handled in line with your retention obligations, since some care records must be kept for a statutory period.

International transfers and sub-processors

Care data is hosted in UK and EU data centres. A current list of sub-processors, and the safeguards applied to each, is available on request.

Questions about this page? Email hello@carein.one and we will respond within five working days. Switch Technologies Ltd is the data controller for carein.one account data and a data processor for care records held on behalf of your organisation.