Data Protection Statement
Our organisational commitments as a data controller and processor under UK GDPR and the Data Protection Act 2018.
This policy is a working draft. Some details shown in [square brackets] are being finalised. For any question, contact hello@mycareprint.co.uk.
Our commitment
TheQuestLab CIC, operating CarePrint, is committed to handling personal data lawfully, fairly and transparently. This statement complements our Privacy Policy and sets out the organisational measures behind it.
Controller and processor roles
CarePrint is the data controller for the platform’s own accounts and for recognition submitted directly through public links. Where a care provider uses CarePrint to manage recognition for its own workforce, that provider is the controller and CarePrint acts as its processor, handling data only on documented instructions.
Data protection principles
- We collect only what we need for recognition, and nothing clinical.
- We use data only for the purposes described in our Privacy Policy.
- We keep data accurate and let people correct it.
- We keep it only as long as needed, then delete or anonymise it.
- We protect it with appropriate technical and organisational measures.
Security measures
- Data is encrypted in transit, and access is controlled by row-level security so users see only what they are entitled to.
- Recognition is verified before it is shown, and verified entries are tamper-evident with tracked changes.
- Access to systems is limited to authorised people on a need-to-know basis.
- [Add: backup, breach-detection and access-review arrangements as implemented.]
Our processors (sub-processors)
We use a small number of trusted providers to run CarePrint, under contracts that meet UK GDPR requirements:
- [Hosting & database — e.g. Lovable Cloud / Supabase] — application hosting and database, [UK/EU] region.
- [Email delivery provider, if any] — sending service and notification emails.
- [Any other processor] — [purpose].
International transfers
We aim to keep personal data in the UK/EU. Where any transfer outside the UK is necessary, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or an adequacy decision.
Personal data breaches
We have a process to detect, report and investigate personal data breaches. Where a breach is likely to risk people’s rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay where required.
Contact
For any data protection matter — including access, correction or erasure requests — contact hello@mycareprint.co.uk. [If a Data Protection Officer or lead is appointed, name them and their contact here.] You may also complain to the ICO at ico.org.uk.
Last reviewed [date]. CarePrint is operated by TheQuestLab CIC. This page is provided for transparency and is not legal advice.