Corporate details in full

GHFHEALTH LIMITED, a company registered in the United Kingdom, at 19 Wingate Way, ST. ALBANS - AL1 5RF, United Kingdom (GB). The platform designs described on this site began under the developer name GHFHealth and continue under the company name GHFHEALTH LIMITED. The word GHFHealth and the word GHFHEALTH LIMITED both refer to the same business line, and either name may appear on an invoice or an email.

1 Introduction and who we are

Welcome to the privacy notice of GHFHEALTH LIMITED. This business began as the work of the developer GHFHealth, who designs software for carers, and it now operates at the address at the foot of this page. We make care coordination platforms, remote monitoring dashboards, rota and handover systems, medication schedule trackers, family notification portals and care audit trails for community health teams in the United Kingdom and beyond.

Some of the personal data we handle relates to staff who use our platforms. Some relates to people receiving care, whose records we may process on behalf of a care provider. Some relates to visitors to this website. This policy sets out how each kind of data is treated, the rights you hold and the way to exercise them with us.

Where we process records for a care provider under our own direction, we act as a data controller. Where we run software purely for a provider who decides what the software does with health records, we act as a data processor under that provider instruction. Read the relevant section below to see which role applies to you.

2 Scope of this policy

This policy applies to this website, to every platform and service offered by GHFHEALTH LIMITED, to our direct communications with you and to any software we supply to a care organisation. It does not apply to websites run by other companies, even when a link on our pages points there.

If you use a care platform that our company hosts for your employer or care provider, then that provider is often the controller of your work and your records. This notice still explains our standards, but questions about the lawfulness of a particular use should first go to the organisation that chose the platform.

3 Information we collect

We collect the minimum needed to run a safe service. The main categories are listed here so there is no surprise about what we hold.

We do not ask for more than our service needs, and we do not collect payment card numbers directly on this website.

When we do hold health detail, we treat it apart from the routine running of the website. A visitor who just reads a page and a carer who writes a midnight observation are in different worlds of risk, and our collection reflects that: the website knows almost nothing about you, while the platform holds exactly what care demands and nothing extra.

4 Sources of your information

Most information comes straight from you when you fill in a form, write to us or use our software. Where a care provider runs a platform for your benefit, that provider supplies the records with the consent or lawful authority it holds with you.

We may also receive information indirectly, for example when your employer adds you to a rota, when a referral organisation shares a care plan, or when analytics software reports how our pages are used. In every case we rely on one of the lawful bases set out below.

5 How we use your information

We use personal information only for clear and stated purposes. The main uses are listed below so you can see what we do and why.

We never sell personal information to anyone, and we never use health records for advertising.

In practical terms this means that when a record is added at 03:00 in a care home, it exists so that the person who needs a check is checked, the family who asks is told and the next shift begins with the truth before it. Every extra use we invent has to pass a simple test: does it help the care, protect the people or keep the law, and can we show the data subject why it is happening. Any processing that fails that test is removed from the design before it reaches a real ward.

For a small software company the temptation is to collect data first and think later. We deliberately reverse that. A roster of residents, a pulse log or a handover note is somebody real life written in code, so we treat it with the same gravity that a nurse gives a chart. Where a purpose is unclear or no longer needed, the data does not creep along in the system waiting for an accidental use; it is stopped at the design stage or erased as soon as the reason lapses.

6 Lawful bases for processing

Lawful basis is the legal reason we are allowed to process your data. For a care-focused business the choices matter, so we state them plainly.

We keep a record of the basis chosen so that the choice can be explained to you at any point.

7 Special categories of data

Health data is a special category under data protection law because it is sensitive and can reveal a great deal about a person when misused. Our platforms may carry readings such as blood pressure, pulse, oxygen and temperature, together with medication and care details, so the risks are real.

We apply the strictest protections to this data. It is encrypted, access is limited to people who need it for care, and our sharing is confined to the teams and clinicians who have a lawful role. Processing of special category data happens only where one of the recognised conditions for health, social care or vital interests is met.

The practical effect of this discipline is visible in the software itself. Only the staff genuinely caring for a person see that person readings, the family portal shows only what the resident allows and the message that travels to a relative is written in plain words with no clinical shorthand that could be misread. When we cannot justify keeping a sensitive fact we do not keep it, and when a provider asks us to add a field we ask what it is for before we build it.

We also keep a clear line between decision support and a human judgement. A reading that looks low flags a concern, but the decision to act stays with a qualified person who can see the whole resident. That boundary means the sensitive data supports rather than replaces the judgement that the law and good care rely upon.

8 Privacy for children

Some of our platforms may be used to coordinate care that touches children, though the ordinary focus is on older and community residents. Where children are involved we follow the stricter rules that apply to the young.

We collect only what the care of a child requires, we keep that care the responsibility of the provider, and we never use a child record for marketing. If a parent or guardian believes we hold a child record without proper authority, that person should write to the address below and we will review the matter promptly.

9 Who we share data with

We share personal information only where it is necessary and lawful. The sharing is limited and never includes selling your details.

Every recipient is bound by confidentiality or a data agreement unless a law overrides it. We list the categories here rather than individual names because suppliers change as we keep our service modern.

10 Cookies and analytics

This website uses small files called cookies to remember simple choices and to understand how visitors move around. None of our cookies are used to build a profile for advertising and none pass health data.

We use an analytics service that reports, in round numbers, how many people visit, which pages they read and how long they stay. That service may set its own cookie. You can refuse cookies through your browser, and this site still works when you do.

Because this is a low-touch informational site, we keep analytics limited. The privacy of a person who simply reads our pages matters to us as much as the security of a person whose care record sits in our platform.

11 Security of the information

Protecting health records is the heart of our duty, so we design security as a layer rather than an add-on. Data is encrypted while it travels and while it is stored at rest. Access follows the principle of least privilege, so a night carer sees only the area where that carer works.

Every login is individual and every sensitive action is logged. We run updates, monitor for unusual activity and test our systems on a cycle. Staff are trained so that a strong password habit and a careful handover protect the records just as a locked medication trolley protects a dose.

No system is without risk, but we work continuously so that the chance of harm stays low and the impact of any incident stays contained.

We also protect the smaller and easier to overlook surfaces. Printer trays in a care office holding a listed resident, a shared tablet logged in at the station, a phone that carries a shift handover message, a family group message that mentions a condition without care: each is a place a record can leak sideways. Our training covers these quiet gaps and our controls reach beyond the server room, so the standard we promise in code is matched by the habits we grow in the teams who use it.

Because no control is perfect, we build resilience into the answer as well. Backups are tested on a cycle, recovery is rehearsed and the people who would run an incident have written steps rather than a hope. The whole posture mirrors a well run night: quiet, watchful and ready to respond well when something does break.

12 Retention of the information

We keep personal information only for as long as a lawful purpose remains. Care records follow the professional guidance that applies to the provider, usually several years after the care ends so that the history can answer a query or protect a person later.

Website enquiries and routine correspondence are kept for a shorter period, normally the time needed to serve you plus a reasonable margin. When a retention period ends we erase or anonymise the data so it can no longer identify an individual.

Where your care provider decides how long a medical record must stay, that provider rule wins and we follow it.

A useful mental picture is a paper chart that is never thrown away early. In a real home, a completed record is filed and kept because a memory clinic, a coroner or a future carer may legitimately need it years later. We mirror that habit in the electronic world: retention is generous where care requires it and tight where it does not, and every erasure follows the same care as the original filing. We would rather keep a record a little longer within the law than destroy evidence that a family or a regulator later needs.

At the far end of the process we do not simply delete a file and forget it. We certify erasure, we remove the copies in backups on schedule and we check that no stray export survives on a laptop or a desktop. Only when every trace is gone or properly anonymised do we count the matter closed, and we can show a reviewer the plan that got us there.

13 International transfers

Because support teams and infrastructure may operate across borders, personal data can sometimes travel outside the country where it was collected. We only allow this where adequate protection exists.

For health data in particular we are careful. Standard contractual clauses, certification and checks on the destination legal regime all play a role. We will tell you, on request, the countries to which your data may be transferred and the protection in place for that transfer.

14 Your rights

Data protection law gives you clear rights over your personal information. We respect them and make them easy to exercise. The main rights are listed here.

To exercise any right, write to the address below with enough detail for us to find the record. We answer within the time the law allows, free of charge, and we may ask you to confirm your identity first so no record goes to the wrong person.

Some care records are held under a provider authority rather than built by us. When you want a record of that kind copied, corrected or erased, the quickest route is often the organisation that runs your care, because that organisation decides the day to day use. We will help that organisation honour your request, and if you bring the request to us first we will pass it on and confirm that it has been received rather than leaving you to chase.

There are lawful limits on every right, and we explain them honestly when we rely on one. For example, a care record cannot always be erased while a duty of care or a legal retention still stands, and a right to access does not let one resident see another resident observation. When we decline we give a reason and a route to complain, so a refusal never feels like a dead end.

15 Marketing choices

We rarely send direct marketing, and when we do it is always based on your consent or a lawful business interest that you may refuse. You can hear about a new rota tool or a platform update without losing any service.

Every marketing message carries a simple way to stop receiving them. If you withdraw consent or object, we update our lists within a short time and keep no record beyond what the law requires for our own defence.

17 Data breaches

A data breach means any accident or misuse that harms the confidentiality, integrity or availability of personal information. We take every report seriously and run an incident plan rather than improvise.

When a breach poses a risk to your rights and freedoms, we inform you and the relevant regulator within the time the law sets out. We also review what failed and change the controls so the same mistake is not repeated. Plain honesty is part of our duty to the people who trust us with sensitive records.

18 Job applicants and staff

When you apply for a role with us, we process your CV, your application and, where lawful, the references and checks that a care-related job needs. Much of the data is about employment rather than health, but we keep it just as carefully.

Staff who use our own platforms to deliver care are subject to the same controls as any other user. Their access is individual, logged and limited to the wards where they work.

19 Changes to this policy

We review this policy as our services grow and as the law changes. When a change matters, we revise the effective date at the top and, where we hold your contact details, we may tell you directly.

The current version always sits on this page. We recommend that you glance back from time to time, though the substance is unlikely to alter without notice in the places that protect your rights.

20 Contact the company about privacy

Any question about how your information is handled should reach us by post, email or phone. We aim to acknowledge a privacy enquiry within a few working days and to resolve it quickly.