Who We Are
Care-Meter is a digital care record and inspection-readiness platform for UK adult social care homes, operated by WillMachi Limited (trading as “Care-Meter”, “we”, “us”, “our”), a company incorporated in England and Wales.
We are the data controller for personal data processed through this platform and website. We are registered with the Information Commissioner’s Office (ICO) under registration number ZC107807. Verify at ico.org.uk.
Post: Data Protection, WillMachi Limited, 8 Raite Green, Sittingbourne, Kent, ME10 5JY
WillMachi Limited also operates EzeAla (property management platform) under the same ICO registration. This Privacy Policy covers Care-Meter only.
Who This Policy Covers
This policy applies to all individuals whose personal data we process in connection with Care-Meter:
- Registered managers and owners of care homes who create a Care-Meter account
- Care staff (carers, senior carers) who use the platform under a care home account
- Residents of care homes using Care-Meter, whose care records are managed on the platform
- Website visitors who browse care-meter.co.uk
What Personal Data We Collect
3.1 Account holders (managers, owners, administrators)
- Identity data: full name, email address, account role, job title
- Authentication data: hashed password, account identifier, session tokens
- Organisation data: care home name, CQC registration number, address, number of beds
- Subscription data: subscription tier, billing history (no card numbers; held exclusively by our payment processor)
- Usage data: IP address, browser type, pages visited, timestamps of actions within the platform
3.2 Care staff (carers, senior carers, registered nurses)
- Identity data: full name, email address, role, assigned residents
- Activity data: care notes created, captures submitted, voice notes (where used)
- Voice audio (optional): raw audio files where voice note capture is used for transcription only. Deleted within 30 days of upload; no biometric template is created.
- Operational records: shift records, training completion and due dates, NMC revalidation evidence (PIN, expiry, reflective account), supervision records. Surfaced through the Copilot to support operational visibility and statutory compliance evidencing (CQC Regulations 18 and 19, NMC revalidation). Manager-class roles can read free-text fields verbatim; non-manager queries return status and aggregates only.
3.3 Resident data (processed as data processor on behalf of care homes)
- Care notes, medication records, incident descriptions, safeguarding records
- Mood and behaviour observations, nutrition and hydration records
- Resident identifiers (name, date of birth, key worker, as entered by the care home)
We process resident data on behalf of the care home operator as their data processor under our Data Processing Agreement. The care home is the data controller for this data.
Medication records (MAR).Medication orders and administration records — including the controlled-drug register and covert-administration decisions — are special-category health data. We process them under UK GDPR Article 9(2)(h) (provision of health and social care) for the safe management of medicines, and retain them in line with the audit-retention schedule set out in Section 8.
3.4 Data we do NOT collect
Lawful Basis for Processing
UK GDPR requires us to have a valid lawful basis before processing personal data. The table below sets out the basis we rely on for each purpose.
| Purpose | Data categories | Lawful basis |
|---|---|---|
| Creating and managing your account | Identity, authentication, organisation | Contract, Art. 6(1)(b) |
| Processing subscription payments | Identity, subscription data | Contract, Art. 6(1)(b) |
| Processing resident care records (as processor) | Resident health data, care notes | Legal obligation (Reg 17 CQC) Art. 6(1)(c); Health/social care Art. 9(2)(h) |
| AI classification of care notes | Care note text, risk indicators | Legal obligation, Art. 6(1)(c); Art. 9(2)(h) |
| Governance alerts and exception monitoring | Care notes, flags, timestamps | Legal obligation, Art. 6(1)(c) |
| Sending operational emails (receipts, alerts, notifications) | Identity, contact | Contract, Art. 6(1)(b) |
| Platform security, fraud prevention, audit logs | Usage, technical | Legitimate interests, Art. 6(1)(f) |
| Improving the platform (anonymised analytics only) | Usage data (anonymised) | Legitimate interests, Art. 6(1)(f) |
| Voice note capture (optional) | Voice audio (transcription only; deleted within 30 days; no biometric template created) | Explicit consent, Art. 6(1)(a); health/social care, Art. 9(2)(h) |
| Staff-data tools (Copilot operational visibility, training, NMC, supervision) | Staff identity, shift records, training and supervision records, NMC revalidation | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) — CQC Reg 18 / 19, NMC; employment, Art. 9(2)(b) where supervision or revalidation notes incidentally include special-category content |
Where we rely on legitimate interests, we have carried out a balancing test and concluded that our interests do not override yours. You have the right to object, see Section 10.
AI-Assisted Features
Care-Meter uses artificial intelligence to assist with classifying care notes, identifying potential governance risk, and supporting manager oversight. AI outputs are decision-support only. Care-Meter does not make significant decisions about residents based solely on automated processing within the meaning of UK GDPR Articles 22A–22D (as amended by the Data (Use and Access) Act 2025).
| What the AI does | What the AI does NOT do |
|---|---|
| Sorts and categorises care notes against CQC quality statements | Make decisions about a resident's care |
| Assigns a risk score (1-10) to flag notes for manager review | Take any action without human oversight |
| Identifies whether a note may be incident-related | Replace the professional judgement of registered managers or care staff |
| Assists managers in preparing governance summaries | Access data from any other care provider |
You have the right to request information about how a decision involving AI was reached, to make representations about it, to obtain human review, and to contest it. Email privacy@care-meter.co.uk.
AI model inference runs exclusively through AWS Bedrock in the UK (London). AWS Bedrock does not use customer prompts or responses to train models. Care-Meter does not use customer data, including in anonymised form, to train third-party AI models. Data does not leave the UK.
Copilot conversation transcripts.When the Copilot feature is active, the turns of each manager’s chat session (their queries and the AI’s responses) are stored as a private transcript, readable only by that user and not accessible to other staff, other tenants, or Care-Meter staff. Transcripts are retained for 60 days from last activity, then automatically and permanently deleted by a time-to-live (TTL) mechanism. They are not part of the governance audit trail or any care-record. Managers may request export (Arts. 15 & 20 — structured JSON containing the thread and its messages) or hard-deletion (Art. 17) at any time, independently of the 60-day TTL, by emailing privacy@care-meter.co.uk. A Temporary Chat mode is also available in feature settings that retains no transcript whatsoever.
Care-Meter does not use a vector or semantic retrieval tier for personal data. Care-evidence retrieval uses a deterministic ontology-tag projection; operational retrieval uses structured queries against the personal data store. This design choice bounds the surface area for model hallucination and keeps retrieval inspectable.
Third-Party Data Processors
We share personal data with the following third parties strictly as necessary to operate the platform. Each is bound by a Data Processing Agreement and processes data only on our documented instructions.
| Processor | Purpose | Data transferred | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, DynamoDB, S3, Lambda, Cognito, CloudWatch | All platform data | UK (London) |
| AWS Bedrock — Anthropic Claude | AI model inference: OCR structuring, classification, copilot, PIR drafting | Care note text, staff operational records, manager queries | UK (London) |
| AWS Bedrock — Amazon Nova | AI model inference: CQC classification | Care note text | UK (London) |
| Amazon Textract | OCR processing of handwritten care notes | Images/PDFs of handwritten notes | UK (London) |
| Amazon Transcribe | Server-side audio transcription (fallback only) | Raw voice audio files | UK (London) |
| Stripe Payments Europe Ltd (Stripe Inc. as US backup processor) | Payment processing for subscription billing | Billing contact email, billing address, payment method tokens, transaction history. No resident or care data. | Ireland (EU/UK primary); USA (backup) — UK IDTA / SCCs |
| Resend | Transactional and operational email: receipts, invites, verification, notices, and automated risk/safeguarding alerts | Recipient name and email address, and the content of the message sent | USA (UK IDTA/SCCs) |
| Google LLC (Google Sign-In) | Optional federated sign-in / identity verification for users who choose Google Sign-In | Authenticating user's Google identity (email, name, account ID); no resident or care data | USA / global (UK IDTA/SCCs) |
Retired sub-processor. Amazon OpenSearch Service was previously listed for vector-search AI assistance. This processor has been retired; care-evidence retrieval now uses a deterministic ontology-tag projection. No personal data remains in OpenSearch.
We do not sell, rent, or trade your personal data to any third party for marketing purposes.
International Data Transfers
All processing by our AWS sub-processors takes place within the United Kingdom (UK, London). Care records — care notes, health data, assessments, and everything derived from them — are stored and processed only in the UK and are never sent to a sub-processor outside it. Our subscription-billing and transactional-email sub-processors process limited personal data outside the UK (Ireland/USA), and Google Sign-In verifies the identity of users who choose it via Google infrastructure — each under UK-approved IDTAs or Standard Contractual Clauses.
Our payment processor and email delivery service involve transfers to the USA. Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place: UK-approved International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses.
You may request a copy of the relevant transfer safeguard by emailing privacy@care-meter.co.uk.
How Long We Keep Your Data
We keep personal data only for as long as necessary for the purpose it was collected, or as required by law.
| Data category | Retention period | Legal basis |
|---|---|---|
| Account and profile data | 3 years after account closure | Dispute resolution; audit trail |
| Care notes, incident records, care plans | 7 years from date of record | NHS Records Management Code of Practice 2021; CQC Reg 17 |
| Audit records | 7 years, held under a write-once retention lock | Reg 17 accountability; DSPT requirement |
| Voice audio recordings (where used) | 30 days from upload or note finalisation | Proportionality: transcribed text is the durable record |
| Quick-capture source images of handwritten notes | 7 years, moved to archival storage after 90 days | The image is the original care record: it evidences what was written before structuring. Retained on the same basis as the note itself (NHS RMCOP; CQC Reg 17) |
| AI copilot session / rate-limit data | Short-lived (session TTL) | Ephemeral — not a transcript; cleared on session end |
| AI copilot conversation transcripts | 60 days from last activity | Per-user private; auto-deleted by TTL; hard-delete on request (Art. 17); export on request (Arts. 15 & 20) |
| AI copilot run records (tool calls, cost and safety metadata — no conversation content) | 12 months | Spend control, safety monitoring, and investigating an AI output after the fact |
| Application and access logs | 13 months | Security monitoring; long enough to investigate an incident found in a later audit cycle |
| Anonymised analytics | Indefinite (no personal data retained) | Service improvement |
When retention periods expire, data is securely deleted or irreversibly anonymised. Previous versions of our retention schedule are available on request.
How We Protect Your Data
- Encryption in transit: all data transmitted over TLS 1.2+. HTTP redirected to HTTPS.
- Encryption at rest: all data encrypted at rest by default. Evidence and document storage holding special-category data uses customer-managed encryption keys with automatic key rotation.
- Access control: role-based access control — Administrator, Manager, Carer, and Family roles, each with least-privilege permissions. Every request is scoped to the care home organisation the signed-in user belongs to, and the most sensitive record types are additionally scoped on the server from the verified sign-in token rather than by the browser. We are extending that server-side scoping to the remaining record types; until that work completes we do not claim it covers every read.
- Multi-factor authentication: required in the platform for every administrator, manager and clinical lead account. Where you sign in with Google, the second factor is the one set on your Google account.
- Session security: authenticated sessions end automatically after 30 minutes without activity, with a warning beforehand so nothing in progress is lost. Signing in on a new device signs you out on any other device, so an account is only ever active in one place.
- Security headers: Content Security Policy, HSTS, X-Frame-Options DENY, X-Content-Type-Options nosniff.
- Rate limiting: API endpoints and AI endpoints are rate-limited to prevent abuse.
- Tamper-evident audit record: all governance-critical actions are recorded in a protected audit record with write-protection on storage.
- Data breach response: ICO notification within 72 hours and affected customer notification within 24 hours, as required by UK GDPR Arts. 33-34.
Your UK GDPR Rights
You have the following rights under the UK General Data Protection Regulation and the Data Protection Act 2018. We will respond within one calendar month as required by UK GDPR Art. 12.
| Right | UK GDPR Art. | How to exercise |
|---|---|---|
| Right of Access: obtain a copy of your personal data | Art. 15 | Email privacy@care-meter.co.uk. Copilot conversation transcripts are exportable on request as structured JSON (thread + messages). |
| Right to Rectification: correct inaccurate or incomplete data | Art. 16 | Update in Settings, or email us |
| Right to Erasure: ‘right to be forgotten’ | Art. 17 | Email us. Note: some data must be retained by law (see Section 8). Copilot conversation transcripts may be hard-deleted on request at any time, independent of the 60-day TTL and independent of any statutory-retention obligation. |
| Right to Restrict Processing | Art. 18 | Email privacy@care-meter.co.uk |
| Right to Data Portability: structured, machine-readable format | Art. 20 | Email us to request a data export. Copilot conversation transcripts are exported as structured JSON on request. |
| Right to Object to processing based on legitimate interests | Art. 21 | Email privacy@care-meter.co.uk |
| Right to withdraw consent (where consent is the lawful basis) | Art. 7(3) | Email us. Does not affect prior processing. |
| Right to safeguards in automated decisions (information, representation, human review, contest) | Arts. 22A-22D (as amended by the DUA Act 2025) | Email privacy@care-meter.co.uk. We will explain how a decision was reached and arrange human review. |
You also have the right to lodge a complaint with the ICO at any time: ico.org.uk/make-a-complaint or call 0303 123 1113. We would appreciate the chance to address your concerns first.
Cookies
Care-Meter stores a small amount of data on your device. Almost all of it is browser storage rather than cookies, but it is covered by the same rules and we list it here in full:
| Name / type | Purpose | Duration | Category |
|---|---|---|---|
| Sign-in tokens (browser localStorage) | Keeps you signed in and authenticates your requests. Held in browser storage by our authentication library, not in a cookie. | Until sign-out, session timeout, or token expiry | Strictly necessary |
| cm-last-activity (localStorage) | Records when you last interacted with the platform, so the 30-minute inactivity sign-out is shared across all your open tabs | Overwritten continuously; cleared on sign-out | Strictly necessary |
| cm_consent (localStorage) | Records your cookie preference so the banner is not shown on every visit | Persistent | Strictly necessary |
| cm_consent_versions (localStorage) | Remembers which version of these documents you have accepted, so you are only asked again when they materially change | Persistent | Strictly necessary |
| cm-theme (localStorage) | Remembers your light/dark mode choice | Persistent | Strictly necessary (set only by your own choice) |
| Interface state (cm-page-guide-seen, cm-command-bar-minimised, current home selection, list filters, alert read-state) | Remembers small interface choices — guides you have dismissed, whether a panel is minimised, which care home and filters you last used, and which alerts you have already seen so they are not shown again | Persistent | Strictly necessary (set only by your own choice) |
We use no third-party advertising, analytics, or tracking cookies, and we set nothing for marketing or profiling. If that ever changes we will update this policy and ask for your consent before deploying it. See our full Cookie Policy for details, including how to clear this data.
Children's Privacy
The Care-Meter platform is intended solely for use by individuals aged 18 and over. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, please contact privacy@care-meter.co.uk and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and display a prominent notice in the platform at least 14 days before the changes take effect.
The effective date at the top of this page reflects the current version. Previous versions are available on request by emailing privacy@care-meter.co.uk. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
Data Protection Complaints
If you believe we have not complied with UK data protection law, you have the right to make a complaint to us before escalating to the Information Commissioner’s Office. We will acknowledge receipt of your complaint within 30 days and respond without undue delay, consistent with section 164A of the Data Protection Act 2018 (as inserted by the Data (Use and Access) Act 2025).
| Method | Detail |
|---|---|
| Online | Submit at care-meter.co.uk/complaint |
| Email privacy@care-meter.co.uk with subject line “Data Protection Complaint” | |
| Post | Data Protection Complaints, WillMachi Limited, 8 Raite Green, Sittingbourne, Kent, ME10 5JY |
If you remain dissatisfied after our response, you may escalate to the ICO at ico.org.uk/make-a-complaint or by calling 0303 123 1113. You may also approach the ICO directly at any time.
Contact Us
| Enquiry | Contact |
|---|---|
| Data protection and privacy rights | privacy@care-meter.co.uk |
| Legal enquiries | legal@care-meter.co.uk |
| Support | support@care-meter.co.uk |
| Registered address | WillMachi Limited, 8 Raite Green, Sittingbourne, Kent, ME10 5JY |
| Response time | All privacy requests: within 30 days as required by UK GDPR Art. 12. Complex requests may be extended by a further two months with notification. |