HomePrivacy Policy

Data Protection

Privacy Policy

Operated by WillMachi Limited (t/a Care-Meter)
Effective July 2026
Version 1.4
ICO registration ZC107807
1

Who We Are

Care-Meter is a digital care record and inspection-readiness platform for UK adult social care homes, operated by WillMachi Limited (trading as “Care-Meter”, “we”, “us”, “our”), a company incorporated in England and Wales.

We are the data controller for personal data processed through this platform and website. We are registered with the Information Commissioner’s Office (ICO) under registration number ZC107807. Verify at ico.org.uk.

Data protection contact
Email: privacy@care-meter.co.uk
Post: Data Protection, WillMachi Limited, 8 Raite Green, Sittingbourne, Kent, ME10 5JY

WillMachi Limited also operates EzeAla (property management platform) under the same ICO registration. This Privacy Policy covers Care-Meter only.

2

Who This Policy Covers

This policy applies to all individuals whose personal data we process in connection with Care-Meter:

  • Registered managers and owners of care homes who create a Care-Meter account
  • Care staff (carers, senior carers) who use the platform under a care home account
  • Residents of care homes using Care-Meter, whose care records are managed on the platform
  • Website visitors who browse care-meter.co.uk
Important for care home operators
If you are a care home operator using Care-Meter, you are the data controller for your residents’ and staff data. You have separate obligations under UK GDPR. See the Data Processing Agreement and the Resident Privacy Notice template.
3

What Personal Data We Collect

3.1 Account holders (managers, owners, administrators)

  • Identity data: full name, email address, account role, job title
  • Authentication data: hashed password, account identifier, session tokens
  • Organisation data: care home name, CQC registration number, address, number of beds
  • Subscription data: subscription tier, billing history (no card numbers; held exclusively by our payment processor)
  • Usage data: IP address, browser type, pages visited, timestamps of actions within the platform

3.2 Care staff (carers, senior carers, registered nurses)

  • Identity data: full name, email address, role, assigned residents
  • Activity data: care notes created, captures submitted, voice notes (where used)
  • Voice audio (optional): raw audio files where voice note capture is used for transcription only. Deleted within 30 days of upload; no biometric template is created.
  • Operational records: shift records, training completion and due dates, NMC revalidation evidence (PIN, expiry, reflective account), supervision records. Surfaced through the Copilot to support operational visibility and statutory compliance evidencing (CQC Regulations 18 and 19, NMC revalidation). Manager-class roles can read free-text fields verbatim; non-manager queries return status and aggregates only.
Staff data is not used for performance management
Care-Meter does not use the staff-data tool surface to evaluate individual employee performance, produce comparative staff rankings, inform disciplinary action, or feed automated decisions affecting an employee’s job. This is a contractual commitment (Data Processing Agreement clause 5.9) and is enforced in code via build-blocking safety evaluations.

3.3 Resident data (processed as data processor on behalf of care homes)

  • Care notes, medication records, incident descriptions, safeguarding records
  • Mood and behaviour observations, nutrition and hydration records
  • Resident identifiers (name, date of birth, key worker, as entered by the care home)

We process resident data on behalf of the care home operator as their data processor under our Data Processing Agreement. The care home is the data controller for this data.

Medication records (MAR).Medication orders and administration records — including the controlled-drug register and covert-administration decisions — are special-category health data. We process them under UK GDPR Article 9(2)(h) (provision of health and social care) for the safe management of medicines, and retain them in line with the audit-retention schedule set out in Section 8.

3.4 Data we do NOT collect

Care-Meter does not collect
Payment card numbers (held exclusively by our payment processor) · Government Gateway credentials · Voice biometric templates · Special-category data beyond health and care records · Data from persons under 18 (the platform is not directed at children)
4

Lawful Basis for Processing

UK GDPR requires us to have a valid lawful basis before processing personal data. The table below sets out the basis we rely on for each purpose.

PurposeData categoriesLawful basis
Creating and managing your accountIdentity, authentication, organisationContract, Art. 6(1)(b)
Processing subscription paymentsIdentity, subscription dataContract, Art. 6(1)(b)
Processing resident care records (as processor)Resident health data, care notesLegal obligation (Reg 17 CQC) Art. 6(1)(c); Health/social care Art. 9(2)(h)
AI classification of care notesCare note text, risk indicatorsLegal obligation, Art. 6(1)(c); Art. 9(2)(h)
Governance alerts and exception monitoringCare notes, flags, timestampsLegal obligation, Art. 6(1)(c)
Sending operational emails (receipts, alerts, notifications)Identity, contactContract, Art. 6(1)(b)
Platform security, fraud prevention, audit logsUsage, technicalLegitimate interests, Art. 6(1)(f)
Improving the platform (anonymised analytics only)Usage data (anonymised)Legitimate interests, Art. 6(1)(f)
Voice note capture (optional)Voice audio (transcription only; deleted within 30 days; no biometric template created)Explicit consent, Art. 6(1)(a); health/social care, Art. 9(2)(h)
Staff-data tools (Copilot operational visibility, training, NMC, supervision)Staff identity, shift records, training and supervision records, NMC revalidationContract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) — CQC Reg 18 / 19, NMC; employment, Art. 9(2)(b) where supervision or revalidation notes incidentally include special-category content

Where we rely on legitimate interests, we have carried out a balancing test and concluded that our interests do not override yours. You have the right to object, see Section 10.

5

AI-Assisted Features

Care-Meter uses artificial intelligence to assist with classifying care notes, identifying potential governance risk, and supporting manager oversight. AI outputs are decision-support only. Care-Meter does not make significant decisions about residents based solely on automated processing within the meaning of UK GDPR Articles 22A–22D (as amended by the Data (Use and Access) Act 2025).

What the AI doesWhat the AI does NOT do
Sorts and categorises care notes against CQC quality statementsMake decisions about a resident's care
Assigns a risk score (1-10) to flag notes for manager reviewTake any action without human oversight
Identifies whether a note may be incident-relatedReplace the professional judgement of registered managers or care staff
Assists managers in preparing governance summariesAccess data from any other care provider
Meaningful human involvement
Every AI output is presented as a suggestion for review by a qualified manager before it is recorded as confirmed, used to trigger a governance alert, or referenced in a regulatory submission. The reviewer can accept, modify, or reject the suggestion at the point the decision is taken. We keep an audit record of every review. This is what UK data protection law calls “meaningful human involvement” and is what takes our AI features outside the scope of solely-automated decision-making.

You have the right to request information about how a decision involving AI was reached, to make representations about it, to obtain human review, and to contest it. Email privacy@care-meter.co.uk.

AI model inference runs exclusively through AWS Bedrock in the UK (London). AWS Bedrock does not use customer prompts or responses to train models. Care-Meter does not use customer data, including in anonymised form, to train third-party AI models. Data does not leave the UK.

Copilot conversation transcripts.When the Copilot feature is active, the turns of each manager’s chat session (their queries and the AI’s responses) are stored as a private transcript, readable only by that user and not accessible to other staff, other tenants, or Care-Meter staff. Transcripts are retained for 60 days from last activity, then automatically and permanently deleted by a time-to-live (TTL) mechanism. They are not part of the governance audit trail or any care-record. Managers may request export (Arts. 15 & 20 — structured JSON containing the thread and its messages) or hard-deletion (Art. 17) at any time, independently of the 60-day TTL, by emailing privacy@care-meter.co.uk. A Temporary Chat mode is also available in feature settings that retains no transcript whatsoever.

Care-Meter does not use a vector or semantic retrieval tier for personal data. Care-evidence retrieval uses a deterministic ontology-tag projection; operational retrieval uses structured queries against the personal data store. This design choice bounds the surface area for model hallucination and keeps retrieval inspectable.

Resident Summary: a derived, deterministic view
For non-clinical staff (notably Activities Coordinators) we generate a Resident Summary — a small set of safe-to-engage facts (allergies, dietary texture, mobility, behaviour cues, communication needs, end-of-life status) derived from the resident's clinical record by a versioned deterministic rules engine. It is not an AI inference: the same inputs always produce the same outputs, no large language model is involved, and every regeneration is logged in our audit record. The lawful basis for this derived view is Article 9(2)(h) (provision of social care). Carers and clinical roles continue to read the underlying care plan and risk assessments directly; the Resident Summary is a read-only orientation surface only.
6

Third-Party Data Processors

We share personal data with the following third parties strictly as necessary to operate the platform. Each is bound by a Data Processing Agreement and processes data only on our documented instructions.

ProcessorPurposeData transferredLocation
Amazon Web Services (AWS)Cloud hosting, DynamoDB, S3, Lambda, Cognito, CloudWatchAll platform dataUK (London)
AWS Bedrock — Anthropic ClaudeAI model inference: OCR structuring, classification, copilot, PIR draftingCare note text, staff operational records, manager queriesUK (London)
AWS Bedrock — Amazon NovaAI model inference: CQC classificationCare note textUK (London)
Amazon TextractOCR processing of handwritten care notesImages/PDFs of handwritten notesUK (London)
Amazon TranscribeServer-side audio transcription (fallback only)Raw voice audio filesUK (London)
Stripe Payments Europe Ltd (Stripe Inc. as US backup processor)Payment processing for subscription billingBilling contact email, billing address, payment method tokens, transaction history. No resident or care data.Ireland (EU/UK primary); USA (backup) — UK IDTA / SCCs
ResendTransactional and operational email: receipts, invites, verification, notices, and automated risk/safeguarding alertsRecipient name and email address, and the content of the message sentUSA (UK IDTA/SCCs)
Google LLC (Google Sign-In)Optional federated sign-in / identity verification for users who choose Google Sign-InAuthenticating user's Google identity (email, name, account ID); no resident or care dataUSA / global (UK IDTA/SCCs)

Retired sub-processor. Amazon OpenSearch Service was previously listed for vector-search AI assistance. This processor has been retired; care-evidence retrieval now uses a deterministic ontology-tag projection. No personal data remains in OpenSearch.

We do not sell, rent, or trade your personal data to any third party for marketing purposes.

7

International Data Transfers

All processing by our AWS sub-processors takes place within the United Kingdom (UK, London). Care records — care notes, health data, assessments, and everything derived from them — are stored and processed only in the UK and are never sent to a sub-processor outside it. Our subscription-billing and transactional-email sub-processors process limited personal data outside the UK (Ireland/USA), and Google Sign-In verifies the identity of users who choose it via Google infrastructure — each under UK-approved IDTAs or Standard Contractual Clauses.

One case where a resident's name leaves the UK
Our transactional-email provider is US-based. Where a care home invites a resident’s family or next of kin to the Family Portal, that invitation email contains the resident’s name and the care home’s name so the recipient understands what it relates to. No care notes, health data, or other record content is ever sent by email. The transfer is covered by a UK-approved IDTA. Controllers should reflect this in their own resident privacy notice — the Resident Privacy Notice template we provide already does.

Our payment processor and email delivery service involve transfers to the USA. Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place: UK-approved International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses.

You may request a copy of the relevant transfer safeguard by emailing privacy@care-meter.co.uk.

8

How Long We Keep Your Data

We keep personal data only for as long as necessary for the purpose it was collected, or as required by law.

Data categoryRetention periodLegal basis
Account and profile data3 years after account closureDispute resolution; audit trail
Care notes, incident records, care plans7 years from date of recordNHS Records Management Code of Practice 2021; CQC Reg 17
Audit records7 years, held under a write-once retention lockReg 17 accountability; DSPT requirement
Voice audio recordings (where used)30 days from upload or note finalisationProportionality: transcribed text is the durable record
Quick-capture source images of handwritten notes7 years, moved to archival storage after 90 daysThe image is the original care record: it evidences what was written before structuring. Retained on the same basis as the note itself (NHS RMCOP; CQC Reg 17)
AI copilot session / rate-limit dataShort-lived (session TTL)Ephemeral — not a transcript; cleared on session end
AI copilot conversation transcripts60 days from last activityPer-user private; auto-deleted by TTL; hard-delete on request (Art. 17); export on request (Arts. 15 & 20)
AI copilot run records (tool calls, cost and safety metadata — no conversation content)12 monthsSpend control, safety monitoring, and investigating an AI output after the fact
Application and access logs13 monthsSecurity monitoring; long enough to investigate an incident found in a later audit cycle
Anonymised analyticsIndefinite (no personal data retained)Service improvement

When retention periods expire, data is securely deleted or irreversibly anonymised. Previous versions of our retention schedule are available on request.

9

How We Protect Your Data

  • Encryption in transit: all data transmitted over TLS 1.2+. HTTP redirected to HTTPS.
  • Encryption at rest: all data encrypted at rest by default. Evidence and document storage holding special-category data uses customer-managed encryption keys with automatic key rotation.
  • Access control: role-based access control — Administrator, Manager, Carer, and Family roles, each with least-privilege permissions. Every request is scoped to the care home organisation the signed-in user belongs to, and the most sensitive record types are additionally scoped on the server from the verified sign-in token rather than by the browser. We are extending that server-side scoping to the remaining record types; until that work completes we do not claim it covers every read.
  • Multi-factor authentication: required in the platform for every administrator, manager and clinical lead account. Where you sign in with Google, the second factor is the one set on your Google account.
  • Session security: authenticated sessions end automatically after 30 minutes without activity, with a warning beforehand so nothing in progress is lost. Signing in on a new device signs you out on any other device, so an account is only ever active in one place.
  • Security headers: Content Security Policy, HSTS, X-Frame-Options DENY, X-Content-Type-Options nosniff.
  • Rate limiting: API endpoints and AI endpoints are rate-limited to prevent abuse.
  • Tamper-evident audit record: all governance-critical actions are recorded in a protected audit record with write-protection on storage.
  • Data breach response: ICO notification within 72 hours and affected customer notification within 24 hours, as required by UK GDPR Arts. 33-34.
10

Your UK GDPR Rights

You have the following rights under the UK General Data Protection Regulation and the Data Protection Act 2018. We will respond within one calendar month as required by UK GDPR Art. 12.

RightUK GDPR Art.How to exercise
Right of Access: obtain a copy of your personal dataArt. 15Email privacy@care-meter.co.uk. Copilot conversation transcripts are exportable on request as structured JSON (thread + messages).
Right to Rectification: correct inaccurate or incomplete dataArt. 16Update in Settings, or email us
Right to Erasure: ‘right to be forgotten’Art. 17Email us. Note: some data must be retained by law (see Section 8). Copilot conversation transcripts may be hard-deleted on request at any time, independent of the 60-day TTL and independent of any statutory-retention obligation.
Right to Restrict ProcessingArt. 18Email privacy@care-meter.co.uk
Right to Data Portability: structured, machine-readable formatArt. 20Email us to request a data export. Copilot conversation transcripts are exported as structured JSON on request.
Right to Object to processing based on legitimate interestsArt. 21Email privacy@care-meter.co.uk
Right to withdraw consent (where consent is the lawful basis)Art. 7(3)Email us. Does not affect prior processing.
Right to safeguards in automated decisions (information, representation, human review, contest)Arts. 22A-22D (as amended by the DUA Act 2025)Email privacy@care-meter.co.uk. We will explain how a decision was reached and arrange human review.

You also have the right to lodge a complaint with the ICO at any time: ico.org.uk/make-a-complaint or call 0303 123 1113. We would appreciate the chance to address your concerns first.

11

Cookies

Care-Meter stores a small amount of data on your device. Almost all of it is browser storage rather than cookies, but it is covered by the same rules and we list it here in full:

Name / typePurposeDurationCategory
Sign-in tokens (browser localStorage)Keeps you signed in and authenticates your requests. Held in browser storage by our authentication library, not in a cookie.Until sign-out, session timeout, or token expiryStrictly necessary
cm-last-activity (localStorage)Records when you last interacted with the platform, so the 30-minute inactivity sign-out is shared across all your open tabsOverwritten continuously; cleared on sign-outStrictly necessary
cm_consent (localStorage)Records your cookie preference so the banner is not shown on every visitPersistentStrictly necessary
cm_consent_versions (localStorage)Remembers which version of these documents you have accepted, so you are only asked again when they materially changePersistentStrictly necessary
cm-theme (localStorage)Remembers your light/dark mode choicePersistentStrictly necessary (set only by your own choice)
Interface state (cm-page-guide-seen, cm-command-bar-minimised, current home selection, list filters, alert read-state)Remembers small interface choices — guides you have dismissed, whether a panel is minimised, which care home and filters you last used, and which alerts you have already seen so they are not shown againPersistentStrictly necessary (set only by your own choice)

We use no third-party advertising, analytics, or tracking cookies, and we set nothing for marketing or profiling. If that ever changes we will update this policy and ask for your consent before deploying it. See our full Cookie Policy for details, including how to clear this data.

12

Children's Privacy

The Care-Meter platform is intended solely for use by individuals aged 18 and over. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, please contact privacy@care-meter.co.uk and we will delete it promptly.

13

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and display a prominent notice in the platform at least 14 days before the changes take effect.

The effective date at the top of this page reflects the current version. Previous versions are available on request by emailing privacy@care-meter.co.uk. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

14

Data Protection Complaints

If you believe we have not complied with UK data protection law, you have the right to make a complaint to us before escalating to the Information Commissioner’s Office. We will acknowledge receipt of your complaint within 30 days and respond without undue delay, consistent with section 164A of the Data Protection Act 2018 (as inserted by the Data (Use and Access) Act 2025).

MethodDetail
OnlineSubmit at care-meter.co.uk/complaint
EmailEmail privacy@care-meter.co.uk with subject line “Data Protection Complaint”
PostData Protection Complaints, WillMachi Limited, 8 Raite Green, Sittingbourne, Kent, ME10 5JY

If you remain dissatisfied after our response, you may escalate to the ICO at ico.org.uk/make-a-complaint or by calling 0303 123 1113. You may also approach the ICO directly at any time.

What we record
We record every complaint received, the date of receipt, our acknowledgement, the steps taken, and the outcome. We retain these records for 3 years for audit and regulatory purposes.
15

Contact Us

EnquiryContact
Data protection and privacy rightsprivacy@care-meter.co.uk
Legal enquirieslegal@care-meter.co.uk
Supportsupport@care-meter.co.uk
Registered addressWillMachi Limited, 8 Raite Green, Sittingbourne, Kent, ME10 5JY
Response timeAll privacy requests: within 30 days as required by UK GDPR Art. 12. Complex requests may be extended by a further two months with notification.