Legal
Privacy Notice.
How we collect, use, and protect your personal data — written for humans, accurate under UK GDPR.
Last updated 26 July 2026 (v1.2)
1. Who we are
CarerNest Ltd is the data controller for the personal information described in this notice. We are registered with the UK Information Commissioner's Office (ICO) under registration number ZA123456.
You can reach our data team at [email protected] or in writing at:
CarerNest Ltd — Data Protection Officer
[Registered office — registered address on file with Companies House]
[City, Postcode]
United Kingdom
Our Data Protection Officer is responsible for this notice and may be contacted directly at [email protected]. The DPO is the named contact for any UK GDPR or Data Protection Act 2018 enquiry.
In the unlikely event you have a concern we cannot resolve, you have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk or by calling 0303 123 1113. We would, however, appreciate the chance to deal with your concerns before you approach the ICO — please contact our DPO first.
2. What personal information we collect
- Account information: name, email, telephone, location.
- Care-recipient information: household-member name and age, care needs, communication notes.
- Verification information: DBS certificate references, ID document scans, right-to-work evidence (carers only).
- Booking information: dates, times, locations, special instructions, photographs of completed shifts.
- Payment information: held by our payment processor Stripe; we never see full card numbers.
- Communications: messages between families and carers; phone call logs; GPS pings during active shifts.
3. Why we collect it
We collect your information to:
- Match families with suitable carers.
- Schedule and pay for care.
- Verify carer qualifications and right to work in the UK.
- Provide safeguarding oversight.
- Comply with regulatory obligations (CQC-equivalent, HMRC, ICO).
- Provide customer support.
- Improve our services (with anonymised data).
Our lawful basis for processing is the legitimate interests of operating a safe care marketplace, the performance of the contract you enter with us when you book a carer, and your explicit consent for marketing communications.
4. Special-category (sensitive) data
Some of what we handle is special-category personal data under Article 9 of the UK GDPR — data that requires an extra layer of protection because it can reveal intimate details about a person's health, beliefs, or identity. Article 9(2) conditions alone are not enough: each one must be paired with a Schedule in the Data Protection Act 2018. Below is a full enumeration of the special-category data we process, the Article 9 condition, and the DPA 2018 condition that underwrites it:
- Health and care data — diagnoses, medications, allergies, mobility needs, continence plans, cognitive state, mental-health history of the care recipient. Article 9(2)(h) — preventive or occupational medicine, or the management of health or social care systems, paired with DPA 2018 Schedule 1 Part 1 paragraph 2 (health or social care purposes). This condition applies where a regulated professional is involved in the care plan (for example, a CQC-registered manager at an agency on our platform). Where a regulated professional is not in scope — for example, family-arranged visits with a self-employed carer — we rely on Article 9(2)(a) — explicit consent (paired with DPA 2018 Schedule 1 Part 1 paragraph 1 (consent)), captured in the profile wizard. Both routes respect the individual's right to refuse.
- Medical dietary needs — allergies, prescription-only diets, dysphagia requirements. Article 9(2)(h) + DPA 2018 Schedule 1 Part 1 paragraph 2, on the same basis as health and care data.
- Faith-based dietary preferences and prayer-time accommodation — collected only with a separate, readily-withdrawable Article 9(2)(a) explicit consent (paired with DPA 2018 Schedule 1 Part 1 paragraph 1) in the profile wizard. We ask these as a distinct choice rather than a single bundle, because religious belief is a different Article 9 category from medical dietary need and deserves its own consent step.
- Biometric data — where ID verification uses a self-image match or liveness check. Article 9(2)(a) — explicit consent (paired with DPA 2018 Schedule 1 Part 1 paragraph 1), captured at the verification step (a separate consent moment from sign-up terms).
- Safeguarding concerns — flags raised when a carer or family member believes an individual is at risk. Article 9(2)(g) — substantial public interest, paired with DPA 2018 Schedule 1 Part 2 paragraph 18 (safeguarding of children and of individuals at risk). This paragraph covers both children and adults at risk in a single condition.
Below is a full enumeration of the special-category data we process. We do not collect any further category beyond those listed above — particularly: genetic data, sexual orientation, political opinions, trade-union membership, or philosophical beliefs are not collected by CarerNest.
Where we rely on Schedule 1 Part 1 paragraphs 1 or 2, or Schedule 1 Part 2 paragraph 18, CarerNest maintains a written Appropriate Policy Document as required by Section 35 of the Data Protection Act 2018. A summary version of that document is published at /policies/appropriate-policy-document.
Where care decisions touch on adults who may lack mental capacity, our processing supports — and is consistent with — the Mental Capacity Act 2005 and the Liberty Protection Safeguards introduced by the Mental Capacity (Amendment) Act 2019. We do not make capacity determinations; we only store the data a family or clinician has already recorded.
The consent we capture is granular: each Special-category field is asked as a distinct, time-bounded choice in the profile wizard (for dietary or religious-belief data) or at the verification step (for biometric identity data). Each capture moment records what is being consented to, when, and the withdrawal route. We do not bundle consent for one category with consent for another.
How to withdraw. Withdraw or change any consent at any time via the in-app /settings/privacy page, or by emailing [email protected]. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5. Who we share it with
- The carer sees the information a family has shared with them about a specific booking.
- Stripe and other payment processors handle payment details.
- DBS and our verification partners see identity documents.
- Regulators (CQC, ICO, HMRC) on lawful request.
- We never sell your personal data. We never share it with advertising networks.
6. How long we keep it
- Account information: while your account is active, plus 7 years for HMRC compliance after closure.
- Booking records: 7 years after the booking completes.
- Care notes (clinical-grade, e.g. medication administration): 8 years per the CQC's clinical-record standard.
- Marketing consent records: until you opt out, plus 2 years.
- Special-category Article 9 data is deleted once the care relationship ends, unless we have a clinical or safeguarding reason to retain a redacted subset (e.g. an incident report). The default is deletion, the exception is documented and audited.
7. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your data (subject to our legal retention obligations).
- Restrict or object to processing.
- Port your data in a machine-readable format.
- Withdraw consent at any time (for processing based on consent).
- Lodge a complaint with the ICO at ico.org.uk.
You can exercise most of these rights from your account page, or by emailing [email protected]. We will respond within 30 days.
Access requests via the /admin/gdpr console are logged and audited. The same right is also available via the in-app Privacy Settings page.
8. International transfers
We use Stripe (US-based) for payment processing. Stripe's UK and EEA data handling complies with UK GDPR's international transfer rules (Standard Contractual Clauses and the UK–US Data Bridge).
9. Changes to this notice
If we make a material change to how we handle your data, we'll notify you by email at least 30 days before the change takes effect. The change-log for this notice is below.
- 26 July 2026 — v1.0, initial publication.
- 26 July 2026 — v1.1: Section 4 added (Article 9 special-category disclosure with paired DPA 2018 schedule cites), Section 1 expanded with DPO contact, faith-based vs medical dietary preference split, and the negative-enumeration rephrased as positive enumeration.
- 26 July 2026 — v1.2: Section 1 expanded with the ICO complaint line (0303 123 1113) and contact-DPO-first guidance. Section 4 added the Section 35 DPA 2018 Appropriate Policy Document reference (full APD now published at /policies/appropriate-policy-document), Mental Capacity Act 2005 + Liberty Protection Safeguards cross-reference, DPA 2018 Schedule 1 Part 1 paragraph 1 (consent) cite added to all three Article 9(2)(a) bases (health/care fallback, faith-based dietary, biometrics), and the granular consent capture disclosure now points to /settings/privacy as the withdrawal surface.
Questions? Email our team at [email protected].

