Privacy Policy
Elmes Homecare is committed to protecting the privacy of the people we care for, their families, our staff and everyone who contacts us. This policy explains what personal information we hold, why we hold it, and the rights you have over it.
Who we are
Elmes Homecare UK Ltd (“Elmes Homecare”, “we”, “us”) is a CQC-registered domiciliary care agency providing care at home across the London Borough of Bromley and the southern part of the London Borough of Croydon. We are the “data controller” for the personal information described in this policy, which means we are responsible for how it is used and protected.
- Registered office: 46 Church Avenue, Beckenham, BR3 1DT
- Company registration number: 10596140 (registered in England & Wales)
- ICO registration: ZB664170
- Data Protection Officer: Katharine Hayward — mail@elmeshomecare.com
When we process personal information we comply with the UK GDPR and the Data Protection Act 2018.
What information we collect
The information we hold depends on your relationship with us.
People we care for
- Contact and identity details — name, address, date of birth, phone and email
- Next-of-kin and nominated family or representative contacts
- Health and care information — care needs, care plans, risk assessments, medication records and visit logs (this is “special category” data — see below)
- Information from your GP record where you have agreed to this (see GP Connect below)
Family members and representatives
- Contact details and your relationship to the person we care for, so we can keep you informed with the client’s consent
People who contact us
- The name, contact details and message you provide when you use our enquiry form, call or email us
Website visitors
- Basic technical and usage information collected through cookies and analytics (see Cookies below)
We also process information about our staff and job applicants. That is covered by a separate staff privacy notice, available on request.
Why we use your information, and our lawful basis
We only use personal information where the law allows. Our reasons include:
- To provide and manage your care — under our contract with you, and, for health information, because it is necessary for the provision of health and social care (UK GDPR Article 9(2)(h))
- To respond to enquiries — on the basis of your consent and our legitimate interest in answering you
- To meet our legal and regulatory duties — including safeguarding, CQC requirements and tax law
- To run and improve our service — on the basis of our legitimate interests, in a way that does not override your rights
Where we rely on your consent, you can withdraw it at any time; this will not affect anything done beforehand.
Health information
As a care provider we necessarily hold sensitive information about your health and care needs. This is treated with particular care: it is accessible only to staff who need it to provide your care, access is logged, and it is held securely in line with the safeguards described below. We hold and use it because it is necessary for us to provide your care and to meet our duties as a regulated care provider.
Who we share your information with
We never sell your information. We share it only where necessary to provide your care, run our service, or meet a legal duty. This includes:
- Health and care partners — your GP and other NHS services, the local authority, and other health professionals involved in your care
- Our care management platform (Birdie) — which securely holds care plans, risk assessments, rotas and visit logs, and provides the family app for nominated family members
- Our payroll and accountancy software (Xero) — for staff and financial records
- Our website and IT providers — our hosting provider (GoDaddy), enquiry-form and email tools, website security (Sucuri), cookie-consent tool (CookieYes), analytics (Google Analytics), and spam protection on our forms (Google reCAPTCHA)
- Regulators and authorities — such as the CQC or safeguarding bodies, where we are required or permitted to do so
Where a provider processes information for us, they act only on our instructions under a written agreement. Most information is held in the UK. Where a provider (for example, Google) processes some data outside the UK, it is protected by appropriate safeguards recognised under UK data protection law.
GP Connect
With your agreement, authorised Elmes Homecare staff can securely view parts of your GP record through the NHS GP Connect service — such as your medications, allergies, immunisations and recent GP notes — so we can give you safe, well-informed care. You have the right to object to your GP record being shared in this way, and we will respect your choice. Access is strictly controlled, limited to staff who need it, and every access is audited.
Cookies
Our website uses cookies to make the site work, to keep it secure, and to understand how visitors use it so we can improve it. When you first visit, our cookie banner lets you choose which non-essential cookies to allow, and you can change your choice at any time through the cookie settings on the site. Essential cookies (needed for the site to function) are always on; analytics and other non-essential cookies are used only with your consent.
How long we keep your information
We keep personal information only as long as we need it, then securely delete or destroy it. Our main retention periods are:
| Type of record | How long we keep it |
|---|---|
| Adult social care records, including care plans | 8 years after care ends (NHS Records Management Code of Practice) |
| Website enquiries that don’t become care | Up to 2 years, then deleted |
| Financial and payroll records | 6 years (HMRC requirements) |
| Website analytics data | As set by our analytics tool’s standard retention |
Full retention periods for all record types are set out in our internal Data Security and Data Retention policy, available on request.
How we keep your information safe
We take data security seriously. Our measures include restricting access to those who need it, password protection and encryption where appropriate, secure systems for care records, staff training in data protection, and secure disposal of records we no longer need. We meet the NHS Data Security and Protection Toolkit “Standards Met” assurance.
Your rights
Under UK data protection law you have the right to:
- Ask for a copy of the personal information we hold about you
- Ask us to correct information that is wrong or incomplete
- Ask us to delete your information, in certain circumstances
- Ask us to restrict how we use your information, in certain circumstances
- Ask us to provide your information in a portable format, in certain circumstances
- Object to certain uses of your information
Some of these rights apply only in particular situations, and there are exemptions — for example, we may need to keep some care records to meet our legal duties. We do not make any decisions about you by automated means alone. To exercise any of these rights, contact us using the details below; we will respond within one month.
Complaints
If you are concerned about how we have handled your personal information, please contact us first so we can put things right. We will respond to your complaint within 30 days.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator, at any time:
- Website: ico.org.uk/concerns
- Telephone: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Contact us
For any question about this policy or your personal information, contact our Data Protection Officer, Katharine Hayward:
- Email: mail@elmeshomecare.com
- Phone: 020 8658 7285
- Post: Elmes Homecare UK Ltd, 46 Church Avenue, Beckenham, BR3 1DT
We may update this policy from time to time. Any changes will be posted on this page with a revised “last updated” date.
