Carers on Demand Ltd Privacy Notice v1 May 2018

Privacy Notice and Cookies

Please read this Notice carefully and ensure that you understand our rights and responsibilities under it.

We are Carers on Demand Ltd, a company registered in the United Kingdom under number 10279141, whose registered offices are at Kemp House, 152 – 160 Kemp House, City Road, London, England, EC1V 2NX. We are the data controller of personal data provided to us and are registered as a data controller with the ICO under registration number ZA366732. We have appointed a Data Protection Officer who is responsible for addressing data protection matters, including any questions you may have in relation to this Notice. You can contact our Data Protection Officer at manager@carersondemand.uk

Access to our Privacy Notice is available via our website (www.carersondemand.uk) (“the Site”).

1. Summary

Full details are set out in the relevant sections of this Notice below, but in summary:

1.1. we generally receive personal data relating to you directly from you. For example, we will receive that data if you contact us through our website or otherwise, if you are a client of ours or correspond with us in relation to a matter on which we are advising, or if we do business with you; 1.2. personal data may occasionally be provided to us by third parties with whom each of you and us have a separate relationship. 1.3. we use your data to provide our services to you, correspond with you, improve our Site, keep appropriate records and meet our legal obligations; 1.4. we only provide your personal data to third parties for our limited business purposes or as permitted by law. We don’t share your data with third party advertisers; 1.5. we store data for specified periods for our limited business purposes; 1.6. you have certain rights, prescribed by law, in relation to the processing of your data, such as rights to request access, rectification or deletion of your personal data; 1.7. our Site does not use cookies apart from Google Analytics; and 1.8. you can contact us to enquire about any of the contents of this Notice. 1.9. We will ask you at time of enquiry as to whether you wise to receive marketing communications regarding our products and services. We will not contact you with marketing communication unless you have opted in.

2. Personal data we obtain from you

2.1. If you are an applicant or prospective carer, we may collect and use the following types of personal data about you:

2.1.1. recruitment information such as application form and CV, references, qualifications and membership of any professional bodies and details of any pre-employment assessments; contact details and date of birth; 2.1.2. contact details for your emergency contacts; 2.1.3. your gender; 2.1.4. your marital status and family details; 2.1.5. information about any prior contract of employment (or services) including start and end dates of employment, role and location, working hours, details of promotion, salary (including details of previous remuneration), pension, benefits and holiday entitlement; 2.1.6. bank details and information in relation to your tax status including your national insurance number or UTR number; 2.1.7. identification documents including passport and driving licence and information in relation to your immigration status and/or right to work, plus results of DBS checks; 2.1.8. information relating to disciplinary or grievance investigations and proceedings involving you (whether or not you were the main subject of those proceedings); 2.1.9. information relating to your performance and behaviour at work; 2.1.10. training records; 2.1.11. any other category of personal data which we may notify you of from time to time.

2.2. If you are a client or prospective client (or a third party seeking services for an individual), we may collect and use the following types of personal information about you (or about the person for whom you are seeking the services):

2.2.1. Contact details and date of birth;

2.2.2. Contact details for emergency contacts; 2.2.3. Gender; 2.2.4. details of care needs for the individual client (for example a summary of health condition, sufficient to enable an introduction to an appropriate care giver).

2.3. If you access our Site we may process data about your use of our website (usage data). This may include your geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your use. This data is obtained through Google Analytics and will be aggregated and anonymised in such a way that it contains no information pertaining to any identifiable individual at all – as such it is not actually personal data but we address it in this Notice for completeness’s sake. We process usage data for the purpose of improving our Site.

3. Our legal basis of processing

3.1. We will process personal data only on lawful bases. In particular, we will process personal data on the following lawful bases identified in Article 6 GDPR:

3.1.1. for the performance of a contract with you, or to take steps at your request prior to entering into a contract with you; 3.1.2. for our legitimate interests; 3.1.3. with your express consent; 3.1.4. in the case of special category data, for the purposes of the assessment of the working capacity of an individual or the provision of health or social care; and 3.1.5. in the case of information regarding criminal convictions, for the purposes of the assessment of the working capacity of an individual.

3.2. We may also process any of your personal data where such processing is necessary for compliance with a legal obligation to which we are subject or in order to protect your vital interests or the vital interests of another individual.

4. Providing your personal data to others

4.1. We may disclose personal data to our suppliers or subcontractors in connection with the uses described above. For example, we may disclose any personal data in our possession to suppliers which host the servers on which our data is stored. Our current host is based in the EEA.

5. Data security

5.1. We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.

5.2. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

6. Retaining and deleting personal data

6.1. Personal data that we process for any purposes shall not be kept for longer than is necessary for those purposes.

6.2. We will retain and delete your personal data as follows:

6.2.1. We will store private client’s information for 12 months after the service ends. 6.2.2. We will keep live-in carer /applicant information for 12 months from submission. If we receive correspondence from the carer/applicant within 12 months, then the retention period will re-commence. 6.2.3. For business clients’ we will store contact details and any relevant information for three years from initial receipt. If we receive correspondence within the three -year period then the retention period will recommence.

7. Amendments

7.1. We may update this Notice from time to time by notification to you, or by publishing a new version on the Site.

8. Your rights

8.1. We have summarized below the rights that you have under data protection law. Some of the rights are complex, and not all of the details have been included in our summaries. You can read guidance from the Information Commissioner’s Office at www.ico.org.uk for a fuller explanation of your rights.

8.2. Your main rights under data protection law are:

8.2.1. the right to access; 8.2.2. the right to rectification; 8.2.3. the right to erasure; 8.2.4. the right to restrict processing; 8.2.5. the right to object to processing; 8.2.6. the right to data portability; and 8.2.7. the right to complain to a supervisory authority.

8.3. You have the right to confirmation of whether we process your personal data and, where we do, to access to the personal data, together with certain additional information. That additional information includes details of the purposes of the processing, the categories of personal data concerned and the recipients of the personal data. Providing the rights and freedoms of others are not affected, we will supply to you a copy of your personal data. The first copy will be provided free of charge, but additional copies may be subject to a reasonable fee.

8.4. You have the right to have any inaccurate personal data about you rectified and, taking into account the purposes of the processing, to have any incomplete personal data about you completed.

8.5. You may exercise any of your rights in relation to your personal data by written notice to us.

9. Our details

9.1. You can contact us at Carers on Demand Ltd, Kemp House, 152 – 160 Kemp House, City Road, London, England, EC1V 2NX or by email at manager@carersondemand.uk