1. Controller details and accountability
Contact for enquiries about this Privacy Policy: Joseph Connor, Data Controller and Senior Responsible Officer, CarefulAI Ltd, Springboard Technium, NP44 3AW.
The Data Protection Officer (DPO) is Joseph Connor, who provides independent advice and monitoring of CarefulAI’s use of personal information. Where CarefulAI acts as a processor for a healthcare or NHS client, the DPO is supported by a nominated Information Governance (IG) Lead who is accountable to, and reports regularly to, the CarefulAI board or equivalent governance body on data security and protection matters.
2. Our data minimisation principle
As a matter of policy we aim not to collect personal data. Where you wish to contact us, we may collect: your full name; who you represent; your email address; your phone number; the nature of your enquiry; and feedback on our models. If you become a CarefulAI model or system user you are issued a unique reference number linked to your name, title, email address or phone number.
3. Lawful basis for processing
We process your data because you have consented, or because processing is necessary to respond to your enquiries or to control your data. Where CarefulAI processes personal data for healthcare purposes on behalf of an NHS or healthcare client, CarefulAI acts as a processor and processes that data solely on the documented written instructions of the client (controller), under the lawful basis determined by that controller (typically public task and, for special category health data, the provision of health or social care under UK GDPR Article 9(2)(h)). CarefulAI does not rely on consent as the lawful basis for the processing of NHS patient data.
4. Why we need your data
to correspond with you on matters of joint interest;
to evidence that you have consented to engage us;
to accurately represent your views in research analysis;
to improve the products and services we design;
to conduct business with you; and
to control the data you have shared with us or with a system we have developed.
5. International transfers and where your data is processed
Personal data processed for healthcare purposes is processed and stored exclusively on data centres located in the United Kingdom. Such healthcare data is not transferred outside the United Kingdom.
Where any other personal data is transferred outside the United Kingdom or the EEA, CarefulAI puts in place an appropriate transfer safeguard before the transfer takes place. This means an International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, together with a documented Transfer Risk Assessment for each recipient. CarefulAI maintains a sub-processor register recording the identity, processing activity and hosting location of every sub-processor.
As a design practice you may be asked to store data on your own system (for example a mobile phone) rather than on a server we control. You choose whether to share your data via a Data Sharing Agreement.
6. How long we keep your data
We keep your data only for as long as the law requires or for the purposes listed above. In practice we hold personal data for a minimum of 24 hours and a maximum of 3 years, after which it is securely deleted and destroyed. Retention periods for healthcare processing are set by the client (controller) and recorded in the applicable Data Processing Agreement and in our Record of Processing Activities; on termination, personal data is deleted or returned at the controller’s choice.
7. Who we share your data with
During data science projects we share your data in line with a Data Sharing Agreement. Analysis of your data may be shared with organisations involved in the research, design, development or deployment of CarefulAI products and services. Data may also be shared with organisations that provide our email, document management, storage or agentic systems. All such sub-processors are engaged under a written contract imposing the data protection obligations required by UK GDPR Article 28, and are subject to due diligence before engagement and at intervals thereafter.
We will share your data if required to do so by law — for example by court order, or to prevent fraud or other crime.
8. How we protect your data and keep it secure
We are committed to keeping your data secure and operate systems and processes to prevent unauthorised access or disclosure. Our technical and organisational measures include: encryption of personal data in transit and at rest using current industry-standard algorithms; role-based access control on a least-privilege, need-to-know basis with multi-factor authentication for administrative access; logging and monitoring of access to personal data; segregation of client data; and secure software development practices.
CarefulAI maintains the confidentiality, integrity, availability and resilience of its processing systems through documented backup, disaster-recovery and business-continuity arrangements, with defined recovery-time and recovery-point objectives that are tested at planned intervals.
CarefulAI holds Cyber Essentials certification and operates an information security management framework aligned to ISO/IEC 27001. Where CarefulAI processes NHS patient data or accesses NHS systems, CarefulAI completes and publishes an annual Data Security and Protection Toolkit (DSPT) assessment to a ‘Standards Met’ status.
CarefulAI regularly tests, assesses and evaluates the effectiveness of these measures through testing, vulnerability scanning, internal audit and Data Protection Impact Assessments, and remediates findings on a risk-prioritised basis.
9. Records of processing
CarefulAI maintains a Record of Processing Activities in accordance with UK GDPR Article 30, recording the categories of data subjects and personal data, the purposes of processing, the recipients and sub-processors, any transfers and applicable safeguards, retention periods and a general description of the security measures applied.
10. Your rights
You have the right to request: information about how your personal data is processed and a copy of that data; rectification of inaccuracies; completion of incomplete data; erasure where there is no longer a justification for processing; and restriction of processing in certain circumstances. Where processing is based on consent you may withdraw consent at any time and request a copy of your data in a structured, commonly used, machine-readable format.
CarefulAI operates a documented procedure for responding to data subject rights requests. Where CarefulAI acts as a processor, it assists the controller in responding to such requests, and to personal data breaches, within the statutory timescales, including notifying the controller without undue delay and in any event within 24 hours of becoming aware of a personal data breach.
11. Questions and complaints
Contact [email protected] if you have questions, believe your data has been misused, or wish to make a subject access request. You may also complain to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, 0303 123 1113 (reference ZB830059). Any complaint to the Commissioner is without prejudice to your right to seek redress through the courts.
12. Changes to this notice
We may change this privacy notice. When we do, the ‘last updated’ date will change and, where changes affect how your data is processed, CarefulAI will take reasonable steps to inform you.