Skip to main content

Legal

Privacy Policy

Last updated: 6 April 2026Regulation: UK GDPR

1 Who We Are

CareSentinel is a health and safety compliance management platform operated by SentinelHQ Limited, a company registered in England & Wales (Company No. 17242389). We provide software-as-a-service to care homes and similar organisations to help them manage their health and safety obligations.

For the purposes of UK data protection law, SentinelHQ Limited is the Data Controller for personal data collected in connection with the provision of the Service (including account data and billing contacts). We also act as Data Processor on behalf of your organisation for the operational health and safety records your staff enter into the platform, for which your organisation is the Data Controller.

Data Controller: SentinelHQ Limited
Registered address: England & Wales · Company No. 17242389
Contact: hello@sentinelhq.co.uk
ICO registration: ZC175485

2 What Data We Collect

We collect and process the following categories of personal data:

  • Account data: name, email address, job title, department, and role within your organisation.
  • Organisation data: organisation name, address, and contact details provided during onboarding.
  • Health & safety records: incident reports, RIDDOR logs, training records, inspection reports, maintenance records, document registers, asset registers, risk assessments, and method statements — all entered by your organisation's staff.
  • Usage data: log entries recording which actions were taken, by which user, and when (for audit trail purposes).
  • Authentication data: email address and encrypted password managed by Supabase Auth.

We do not collect sensitive personal data (as defined by UK GDPR Article 9) unless it is incidentally included in records entered by your organisation's staff.

3 Why We Collect It (Legal Basis)

  • Contract performance (Article 6(1)(b)): Processing necessary to provide the CareSentinel service you have subscribed to.
  • Legitimate interests (Article 6(1)(f)): Security logging, fraud prevention, and platform improvement.
  • Legal obligation (Article 6(1)(c)): Where we are required to retain records to comply with applicable law.

4 How We Store Your Data

All data is stored on Supabase infrastructure hosted in the EU West (Ireland) region. Data is encrypted at rest (AES-256), encrypted in transit (TLS 1.2+), subject to row-level security (RLS) policies ensuring each organisation can only access its own data, and backed up automatically by Supabase. The application is hosted on Vercel, with servers in the EU region where possible.

5 How Long We Keep Your Data

  • During your subscription: all data is retained and accessible.
  • After cancellation: data is retained for 30 days to allow export, then permanently deleted.
  • Backups: may be retained for up to 90 days after deletion before being purged.

You may request earlier deletion by contacting hello@sentinelhq.co.uk.

6 Your Rights Under UK GDPR

  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: ask us to correct inaccurate or incomplete data.
  • Right to erasure: ask us to delete your data, subject to legal retention obligations.
  • Right to portability: request your data in a machine-readable format (JSON or CSV).
  • Right to restrict processing: ask us to limit how we use your data in certain circumstances.
  • Right to object: object to processing based on legitimate interests.
  • Right to withdraw consent: where processing is based on consent, withdraw it at any time.

Contact us at hello@sentinelhq.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the ICO at ico.org.uk.

7 Data Sharing

We do not sell, rent, or share your personal data with third parties for marketing purposes. We use the following sub-processors to deliver the service:

Sub-processorPurposeLocation
Supabase Inc.Database, authentication, and storageEU West (Ireland)
Vercel Inc.Application hosting and content deliveryEU region (where available)

All sub-processors are contractually bound to process data only on our instructions and in compliance with UK/EU GDPR. We may disclose data if required by law or court order.

8 Cookies

CareSentinel uses session cookies only — strictly necessary to maintain your authenticated session. We do not use advertising cookies, tracking pixels, or third-party analytics services.

9 Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, SentinelHQ Limited will notify the relevant supervisory authority within 72 hours of becoming aware, and will inform affected organisations without undue delay.

10 Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or in-app notice at least 14 days before changes take effect. Continued use of the service constitutes acceptance.

11 Contact Us

SentinelHQ Limited
Registered in England & Wales · Company No. 17242389
hello@sentinelhq.co.uk

Security

Security at CareSentinel

Last updated: 8 May 2026ICO: ZC175485

CareSentinel is trusted with information that matters — incident records, compliance documents, hazardous substance data, and resident and staff information. SentinelHQ Limited takes that responsibility seriously. This page sets out exactly how we protect your data.

1 Your data, your control

CareSentinel uses a multi-tenant architecture — many organisations use the same platform, but your organisation's data is completely isolated from every other organisation's data, enforced at the database level via Row-Level Security (RLS).

100% RLS coverage across all 32 tables. Audited internally — the database itself refuses to return another organisation's data even if there were an application-level bug.

2 Where your data lives

Application hostingVercel (London region for UK customers)
Database & file storageSupabase (EU region, hosted on AWS)
Email deliveryResend
AI processingAnthropic (UK/EU regions where available)

Your data does not leave the UK / EU during normal operation. All providers are enterprise-grade with their own SOC 2 and ISO 27001 certifications.

3 How we protect it

Encryption in transit
TLS 1.3
Every connection to CareSentinel uses the latest transport security.
Encryption at rest
AES-256
All database content and file storage encrypted by Supabase.
Authentication
Signed & time-limited
Password hashing via bcrypt. Sessions expire automatically.
File access
Signed URLs only
SDS sheets and uploads are never accessible by URL guessing.

4 Who has access

CareSentinel uses role-based access control. Admins manage all records and users. Care leads / Operations leads have module-level access. Staff / Viewers have read-only or limited access.

SentinelHQ Limited staff do not access your data as part of normal operations. Access is only granted with your explicit permission (e.g. to debug a specific issue) and all such access is logged.

5 AI and your data

  • AI requests are processed by Anthropic under contract. Anthropic does not train models on your data.
  • No human at Anthropic reads your data as part of routine processing.
  • Voice transcripts are processed in real time by your browser via the Web Speech API — audio is not sent to our servers or stored.
  • Document and SDS uploads are sent to Anthropic for processing; the response is returned to your database. Nothing is shared externally.
  • AI conversations are processed in real time, not retained for AI training purposes.

To disable AI features for your organisation, contact hello@sentinelhq.co.uk.

6 Compliance and certifications

  • UK GDPR and the Data Protection Act 2018
  • ICO registration: ZC175485
i

SentinelHQ Limited does not currently hold ISO 27001 or SOC 2 certification — these are on our roadmap as we grow. Our infrastructure providers (Vercel, Supabase, Anthropic) hold these certifications themselves.

7 Incident response

If SentinelHQ Limited identifies a security incident affecting your data, we will:

  1. Notify you within 72 hours of confirming the incident, in line with UK GDPR requirements.
  2. Provide a clear summary of what happened, what data was involved, and what actions we've taken.
  3. Notify the ICO within 72 hours where required by law.
  4. Support you with any onward notifications to residents, staff, or regulators if needed.

8 Reporting a security concern

If you believe you've found a security vulnerability in CareSentinel, email hello@sentinelhq.co.uk. We commit to acknowledging your report within one working day and investigating promptly. We do not take legal action against good-faith security researchers who follow responsible disclosure.

9 Questions

SentinelHQ Limited
Registered in England & Wales · Company No. 17242389
hello@sentinelhq.co.uk

Legal

Terms of Service

Last updated: 6 April 2026Jurisdiction: England & Wales

1 Acceptance of Terms

By accessing or using CareSentinel (“the Service”), you agree to be bound by these Terms of Service (“Terms”) and our Privacy Policy. If you are using the Service on behalf of an organisation, you represent that you have authority to bind that organisation to these Terms.

!

If you do not agree to these Terms, you must not use the Service.

2 Description of Service

CareSentinel is a health and safety compliance management platform provided by SentinelHQ Limited, registered in England & Wales (Company No. 17242389). It provides tools to help care homes and similar organisations manage incidents, training, inspections, documents, assets, and compliance records on a software-as-a-service (SaaS) basis.

SentinelHQ Limited reserves the right to modify, suspend, or discontinue features of the Service at any time, with reasonable notice.

3 User Accounts and Responsibilities

You are responsible for keeping your login credentials secure and confidential, all activity that occurs under your account, ensuring all invited users comply with these Terms, and notifying us promptly at hello@sentinelhq.co.uk if you suspect unauthorised access. You must be at least 18 years old to create an account. Credentials must not be shared — each user must have their own account.

4 Subscription and Payment

  • Subscriptions are billed in advance on a monthly or annual basis.
  • Fees are non-refundable except where required by applicable law.
  • Failure to pay may result in suspension or termination of your account.
  • Prices are not subject to VAT (SentinelHQ Limited is not currently VAT registered).

5 Acceptable Use Policy

You agree not to use the Service to upload false, misleading, or fraudulent records; attempt unauthorised access to any other organisation's data; reverse engineer or extract the source code; use the Service unlawfully; transmit malware; scrape or systematically extract data; or place an unreasonable load on our infrastructure. SentinelHQ Limited reserves the right to suspend accounts that violate this policy without prior notice.

6 Data Ownership

You own your data. All records, documents, and information entered into CareSentinel by your organisation remain the property of your organisation (the Data Controller). You grant SentinelHQ Limited a limited licence to store and process that data solely for the purpose of providing the Service.

SentinelHQ Limited does not use your organisation's operational data to train AI models, sell to third parties, or for any purpose other than delivering the Service. Upon termination, you may export your data within the 30-day retention window; after that period, data is permanently deleted.

7 Intellectual Property

The CareSentinel platform, including its software, design, features, and documentation, is owned by SentinelHQ Limited and protected by copyright, trademark, and other intellectual property laws. Your subscription grants you a limited, non-exclusive, non-transferable licence to use the Service. You retain all rights to content and records you create within the Service.

8 Limitation of Liability

!

CareSentinel is a management and record-keeping tool. It is not a substitute for professional health and safety advice, qualified H&S consultancy, or compliance with your legal obligations under applicable health and safety legislation.

To the maximum extent permitted by law: SentinelHQ Limited is not liable for any indirect, incidental, special, or consequential loss; our total liability in any 12-month period shall not exceed the subscription fees you paid in that period; and we make no warranty that the Service will be error-free or uninterrupted. Nothing in these Terms limits liability for death or personal injury caused by negligence, fraud, or any liability that cannot be excluded by law.

9 Termination

By you: Cancel your subscription at any time via account settings or by contacting us. Access continues until the end of the current billing period.

By us: SentinelHQ Limited may terminate or suspend your account immediately if you materially breach these Terms or fail to pay. We will give at least 30 days' notice of service discontinuation except in cases of breach. On termination, we retain your data for 30 days to allow export, then permanently delete it.

10 Governing Law

These Terms are governed by the laws of England and Wales. Any dispute shall be subject to the exclusive jurisdiction of the courts of England and Wales.

11 Changes to These Terms

SentinelHQ Limited may update these Terms at any time. We will notify you by email or in-app notice at least 14 days before material changes take effect. Continued use after the effective date constitutes acceptance.

12 Contact Us

SentinelHQ Limited
Registered in England & Wales · Company No. 17242389
hello@sentinelhq.co.uk

Legal

Data Processing Agreement

Last updated: 6 April 2026Standard: UK GDPR Article 28

1 Parties

Data Controller: the care home or organisation that has subscribed to CareSentinel (“the Organisation”).

Data Processor: SentinelHQ Limited, registered in England & Wales (Company No. 17242389), the operator of CareSentinel (“we”, “us”, “CareSentinel”).

This DPA forms part of, and is incorporated into, the Terms of Service between the parties. In the event of a conflict, this DPA takes precedence with respect to data protection matters.

2 Subject Matter and Duration

This DPA governs the processing of personal data by SentinelHQ Limited on behalf of the Organisation for the purpose of providing the CareSentinel health and safety compliance management service. It is effective from the date the Organisation first uses the Service and remains in force until termination of the subscription or deletion of all personal data, whichever is earlier.

3 Nature and Purpose of Processing

SentinelHQ Limited processes personal data on behalf of the Organisation to: store and retrieve health and safety records entered by the Organisation's staff; send automated compliance alerts and notifications; provide audit trails and activity logs for regulatory purposes; and generate compliance reports on behalf of the Organisation. We process personal data only on the Organisation's documented instructions and do not process data for our own purposes.

4 Categories of Personal Data

  • Identity data: staff full names.
  • Contact data: staff email addresses.
  • Employment data: job titles, departments, roles within the organisation.
  • Training records: course names, completion dates, expiry dates, training status.
  • Incident data: incident descriptions, dates, locations, persons involved, injury details, investigation notes, RIDDOR reportable information.
  • DBS / safeguarding data: DBS check status, issue dates, expiry dates (where entered by the organisation).
  • Activity log data: user actions and timestamps for audit trail purposes.

5 Categories of Data Subjects

  • Organisation staff, employees, and volunteers.
  • Residents and service users, where their details appear in incident or safeguarding records.
  • Third-party contractors, where their details appear in maintenance or inspection records.

6 Processor Obligations

SentinelHQ Limited agrees to: process personal data only on the Organisation's documented instructions; ensure all personnel with access to personal data are subject to confidentiality obligations; implement the technical and organisational security measures described in Section 9; not engage sub-processors without prior authorisation (see Section 7); assist the Organisation in responding to data subject rights requests under UK GDPR Articles 15–22; notify the Organisation without undue delay upon becoming aware of a personal data breach; and at the Organisation's choice, delete or return all personal data on termination.

7 Sub-Processors

The Organisation provides general authorisation for SentinelHQ Limited to engage the following sub-processors:

Sub-ProcessorPurposeLocation
Supabase Inc.Database, authentication, and file storageEU West (Ireland)
Vercel Inc.Application hosting and content deliveryEU region (where available)
Anthropic PBCAI assistant features (where enabled)United Kingdom / EU

SentinelHQ Limited will notify the Organisation of any intended changes to sub-processors by updating this DPA. The Organisation may object within 30 days; if no objection is received, the change is deemed accepted.

8 Data Subject Rights Assistance

SentinelHQ Limited will provide reasonable technical assistance to help the Organisation respond to data subject requests, including data export functionality, deletion of individual user records on instruction, and provision of audit logs. The Organisation, as Data Controller, remains responsible for handling all data subject requests in accordance with UK GDPR.

9 Security Measures

  • Encryption at rest: AES-256 via Supabase.
  • Encryption in transit: TLS 1.2 or higher (HTTPS).
  • Access controls: row-level security (RLS) policies ensuring strict data isolation between organisations.
  • Authentication: secure password hashing via bcrypt; strong password policies supported.
  • Role-based access: admin, care lead, operations lead, reviewer, viewer roles.
  • Audit logging: all material changes logged with user identity and timestamp.
  • Backup: automatic daily backups with point-in-time recovery maintained by Supabase.
  • Vulnerability management: dependencies monitored and updated regularly.

10 Data Breach Notification

In the event of a personal data breach affecting the Organisation's data, SentinelHQ Limited will notify the Organisation within 72 hours of becoming aware, provide details of the nature of the breach and categories of data subjects affected, and describe measures taken to address the breach. The Organisation remains responsible for notifying the ICO and affected data subjects under UK GDPR Articles 33 and 34.

11 Data Deletion on Termination

  • Data remains accessible for 30 days after termination to allow export.
  • After 30 days, all personal data is permanently and irreversibly deleted from production systems.
  • Backup copies may persist for up to 90 days before being purged.
  • SentinelHQ Limited will provide written confirmation of deletion upon request.

12 Audit Rights

The Organisation may, with at least 30 days' written notice and no more than once per calendar year, request an audit of SentinelHQ Limited's data processing activities. We may satisfy audit requests by providing up-to-date certifications or third-party audit reports, responding to written questionnaires, or facilitating an on-site audit at a mutually agreed time (costs borne by the Organisation).

13 International Transfers

All sub-processors used by SentinelHQ Limited operate within the UK or EU. Personal data processed under this DPA does not leave the UK or EEA during normal operation. In the event that any future sub-processor operates outside these regions, SentinelHQ Limited will notify the Organisation and ensure appropriate safeguards are in place before any transfer occurs.

14 Governing Law

This DPA is governed by the laws of England and Wales. Disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

SentinelHQ Limited
Registered in England & Wales · Company No. 17242389
hello@sentinelhq.co.uk