1. Who We Are
CareBMSS ("CareBMSS", "we", "us", "our") is the data controller for personal data we collect about agency administrators and other account-level users of our platform. For personal data relating to care workers and supervisors, we act as a data processor on behalf of the care agency (the data controller).
Our Data Protection Officer can be contacted at dpo@carebmss.com.
This policy applies to all users of the CareBMSS platform and to visitors to our public-facing website and pages.
2. Personal Data We Collect
Agency administrators
- Name, email address, and job title provided at registration.
- Billing information (handled via our payment processor; we do not store full card numbers).
- Login activity, session tokens, and IP addresses for security purposes.
- Correspondence with our support team.
Care workers
- Full name, contact details, and job role/grade as entered by the agency.
- Shift records including actual clock-in and clock-out times and GPS location data where enabled.
- Break deduction, basic hours, and total hours worked per shift.
- Performance ratings and notes recorded by supervisors at clock-out.
- Any documents uploaded to the platform (e.g. identification, right-to-work evidence).
Supervisors
- Full name and role/title as entered at sign-off.
- Digital signature captured at the time of shift sign-off.
- Device information associated with the sign-off session.
Care home contacts
- Name and email address of the care home contact to whom timesheets are emailed, as entered by the agency administrator.
Technical data (all users)
- Browser type, operating system, and device identifiers.
- Log data including pages visited, actions taken, and timestamps.
- Cookies and similar tracking technologies (see Section 10).
3. How We Use Personal Data
We use personal data for the following purposes:
- Platform delivery: To operate, maintain, and improve the CareBMSS platform, including processing shift records, generating timesheets, and delivering them to care homes.
- Account management: To create and manage agency accounts, authenticate users, and provide customer support.
- Billing: To process Subscription payments and issue invoices.
- Security & fraud prevention: To detect and prevent unauthorised access, abuse, and fraudulent activity.
- Legal compliance: To comply with our legal obligations, including employment law record-keeping and tax requirements.
- Product improvement: To analyse aggregated, anonymised usage data to improve our features and user experience. We do not use identifiable worker data for this purpose.
- Communications: To send transactional emails (e.g. timesheet confirmations), account notices, and, where you have opted in, product updates.
4. Lawful Basis for Processing
We rely on the following lawful bases under UK GDPR (Article 6) for processing personal data:
- Contract (Article 6(1)(b)): Processing necessary to perform our contract with the agency, including delivering the platform and processing shift data.
- Legal obligation (Article 6(1)(c)): Processing required by law, such as maintaining payroll-related records or responding to regulatory enquiries.
- Legitimate interests (Article 6(1)(f)): Processing for fraud prevention, platform security, and product analytics where our interests are not overridden by individuals' rights.
- Consent (Article 6(1)(a)): For optional communications such as marketing emails, where we have obtained your consent. You may withdraw consent at any time.
Where we process special category data (e.g. any health information that may be incidentally included in shift notes), we rely on explicit consent or, where applicable, the substantial public interest condition under Article 9(2)(g) in connection with employment and social security law.
6. Retention Periods
We retain personal data only as long as necessary for the purposes described in this policy:
- Shift records and timesheets: 6 years from the date of the shift, in line with HMRC employer record-keeping requirements.
- Worker profiles: For the duration of the agency's Subscription, plus 6 years following account closure.
- Supervisor signatures: Retained as part of the timesheet record (6 years).
- Account and billing records: 7 years from the end of the financial year in which the transaction occurred.
- Support correspondence: 3 years from the date of last contact.
- Security logs: 12 months on a rolling basis.
Upon account termination, we will provide a full data export and then delete personal data within 30 days, unless a longer retention period is required by law.
7. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. These include:
- Encryption of data in transit (TLS 1.2+) and at rest.
- Role-based access controls ensuring users can only access data relevant to their role.
- Regular security assessments and penetration testing.
- Secure credential storage using industry-standard hashing algorithms.
- Staff training on data protection and information security.
- Incident response procedures for detecting, reporting, and addressing data breaches.
In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and will notify affected agencies without undue delay.
8. International Data Transfers
CareBMSS processes and stores personal data within the UK and the European Economic Area (EEA). Where we use service providers located outside the UK/EEA, we ensure appropriate safeguards are in place, such as:
- UK adequacy regulations (for transfers to countries deemed adequate by the UK Secretary of State).
- UK International Data Transfer Agreements (IDTAs) or addenda to EU Standard Contractual Clauses.
You may request details of the specific safeguards in place for any international transfers by contacting our DPO.
9. Your Rights
Under UK GDPR and the Data Protection Act 2018, individuals have the following rights:
- Access: The right to request a copy of personal data we hold about you.
- Rectification: The right to have inaccurate data corrected.
- Erasure: The right to request deletion of personal data where there is no legitimate reason for its continued processing.
- Restriction: The right to request that we restrict processing of your data in certain circumstances.
- Portability: The right to receive your data in a structured, machine-readable format.
- Object: The right to object to processing based on legitimate interests or for direct marketing.
- Withdraw consent: Where processing is based on consent, the right to withdraw it at any time without affecting the lawfulness of prior processing.
Care workers wishing to exercise their rights should contact their Agency in the first instance, as the Agency is the data controller for worker data. Agencies may contact us at dpo@carebmss.co.uk.
We will respond to rights requests within one calendar month of receipt.
11. Children's Data
CareBMSS is not directed at individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.
12. Data Processing Agreement
As a data processor for care worker and supervisor personal data, CareBMSS operates under a Data Processing Agreement (DPA) with each agency. The DPA is incorporated by reference into our Terms & Conditions and governs:
- The subject matter, duration, and nature of processing.
- The types of personal data and categories of data subjects.
- Obligations and rights of the controller (the agency).
- Sub-processor arrangements and change notification procedures.
A copy of our standard DPA is available on request from dpo@carebmss.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
We encourage you to review this policy periodically. Continued use of the platform following notification of changes constitutes acceptance of the updated policy.
14. Contact & Complaints
For any privacy-related queries, requests, or concerns, please contact our Data Protection Officer:
- Email: dpo@carebmss.com
- Post: Data Protection Officer, CareBMSS, [Your Registered Address]
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF