Legal
Privacy Policy
1 Who We Are
CareSentinel is a health and safety compliance management platform operated by SentinelHQ Limited, a company registered in England & Wales (Company No. 17242389). We provide software-as-a-service to care homes and similar organisations to help them manage their health and safety obligations.
For the purposes of UK data protection law, SentinelHQ Limited is the Data Controller for personal data collected in connection with the provision of the Service (including account data and billing contacts). We also act as Data Processor on behalf of your organisation for the operational health and safety records your staff enter into the platform, for which your organisation is the Data Controller.
Registered address: England & Wales · Company No. 17242389
Contact: hello@sentinelhq.co.uk
ICO registration: ZC175485
2 What Data We Collect
We collect and process the following categories of personal data:
- Account data: name, email address, job title, department, and role within your organisation.
- Organisation data: organisation name, address, and contact details provided during onboarding.
- Health & safety records: incident reports, RIDDOR logs, training records, inspection reports, maintenance records, document registers, asset registers, risk assessments, and method statements — all entered by your organisation's staff.
- Usage data: log entries recording which actions were taken, by which user, and when (for audit trail purposes).
- Authentication data: email address and encrypted password managed by Supabase Auth.
We do not collect sensitive personal data (as defined by UK GDPR Article 9) unless it is incidentally included in records entered by your organisation's staff.
3 Why We Collect It (Legal Basis)
- Contract performance (Article 6(1)(b)): Processing necessary to provide the CareSentinel service you have subscribed to.
- Legitimate interests (Article 6(1)(f)): Security logging, fraud prevention, and platform improvement.
- Legal obligation (Article 6(1)(c)): Where we are required to retain records to comply with applicable law.
4 How We Store Your Data
All data is stored on Supabase infrastructure hosted in the EU West (Ireland) region. Data is encrypted at rest (AES-256), encrypted in transit (TLS 1.2+), subject to row-level security (RLS) policies ensuring each organisation can only access its own data, and backed up automatically by Supabase. The application is hosted on Vercel, with servers in the EU region where possible.
5 How Long We Keep Your Data
- During your subscription: all data is retained and accessible.
- After cancellation: data is retained for 30 days to allow export, then permanently deleted.
- Backups: may be retained for up to 90 days after deletion before being purged.
You may request earlier deletion by contacting hello@sentinelhq.co.uk.
6 Your Rights Under UK GDPR
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: ask us to correct inaccurate or incomplete data.
- Right to erasure: ask us to delete your data, subject to legal retention obligations.
- Right to portability: request your data in a machine-readable format (JSON or CSV).
- Right to restrict processing: ask us to limit how we use your data in certain circumstances.
- Right to object: object to processing based on legitimate interests.
- Right to withdraw consent: where processing is based on consent, withdraw it at any time.
Contact us at hello@sentinelhq.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the ICO at ico.org.uk.
7 Data Sharing
We do not sell, rent, or share your personal data with third parties for marketing purposes. We use the following sub-processors to deliver the service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, and storage | EU West (Ireland) |
| Vercel Inc. | Application hosting and content delivery | EU region (where available) |
All sub-processors are contractually bound to process data only on our instructions and in compliance with UK/EU GDPR. We may disclose data if required by law or court order.
8 Cookies
CareSentinel uses session cookies only — strictly necessary to maintain your authenticated session. We do not use advertising cookies, tracking pixels, or third-party analytics services.
9 Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, SentinelHQ Limited will notify the relevant supervisory authority within 72 hours of becoming aware, and will inform affected organisations without undue delay.
10 Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via email or in-app notice at least 14 days before changes take effect. Continued use of the service constitutes acceptance.
