Privacy Policy
Last updated: December 2024
1. About Us
Care Directory is operated by NE26 Limited, a company registered in England and Wales.
- Company Number: 16030871
- ICO Registration: ZC054682
- Registered Address: First Floor Office, 3 Hornton Place, London, United Kingdom, W8 4LZ
- Email: support@caredirectory.org.uk
- Phone: 0808 501 0191
2. Information We Collect
We collect the following types of personal information:
For Care Seekers (Families)
- Name and email address when you create an account
- Phone number (optional) when submitting enquiries
- Messages and enquiry content sent to care providers
- Search preferences and browsing activity on our platform
For Care Providers
- Business contact information (name, email, phone)
- Care home/service details (address, services, pricing)
- CQC registration information (publicly available)
- Payment information processed securely via Stripe
3. How We Use Your Information
We use your personal data to:
- Connect families with suitable care providers
- Process and forward enquiries to care providers
- Send transactional emails (account confirmations, enquiry notifications)
- Process subscription payments for care providers
- Improve our services and user experience
- Comply with legal obligations
4. AI Care Assistant
Our AI Care Assistant chatbot helps you find suitable care services. When you use this feature:
- Conversation history is stored locally in your browser and is not linked to your account
- Messages are processed by AI providers (OpenAI) to generate helpful responses
- We log anonymised usage analytics (session counts, search queries) to improve the service
- Rate limits apply (10 requests per day per IP address) to ensure fair usage
- Safeguarding keyword detection may trigger immediate support resource responses to protect vulnerable users
Important: The AI assistant provides general guidance only and should not be relied upon for medical, legal, or professional advice. Always consult qualified professionals for such matters.
5. Legal Basis for Processing
We process your data under the following legal bases:
- Contract: To provide our services when you create an account or submit enquiries
- Legitimate Interests: To improve our platform and communicate relevant updates
- Consent: For marketing communications (you can opt out at any time)
- Legal Obligation: To comply with UK laws and regulations
6. Data Sharing
We share your data with:
- Care Providers: Your enquiry details are shared with providers you contact
- Payment Processors: Stripe processes payments securely (they have their own privacy policy)
- Email Service: Resend delivers our transactional emails
- AI Providers: OpenAI processes AI assistant conversations to generate responses
- Analytics: Google Analytics helps us understand site usage (anonymised)
We never sell your personal data to third parties for marketing purposes.
7. International Data Transfers
Some of our service providers process data outside the UK:
- Supabase: Database and authentication services (EU/US)
- Stripe: Payment processing (US)
- OpenAI: AI assistant processing (US)
- Resend: Email delivery services (US)
We ensure appropriate safeguards are in place for these transfers, including Standard Contractual Clauses approved by the UK ICO. All service providers are required to protect your data to standards equivalent to UK GDPR.
8. Data Retention
We retain your data for:
- Account data: Until you request deletion
- Enquiry data: 3 years from submission
- Payment records: 7 years (legal requirement)
- Marketing preferences: Until you withdraw consent
- AI chat sessions: 90 days (anonymised analytics retained longer)
9. Your Rights
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data (\"right to be forgotten\")
- Portability: Receive your data in a portable format
- Object: Object to certain processing activities
- Withdraw Consent: For any consent-based processing
To exercise these rights, email us at support@caredirectory.org.uk or call 0808 501 0191.
10. Cookies
We use cookies to improve your experience. Our cookie banner allows you to manage your preferences. Essential cookies are required for the site to function. Analytics and marketing cookies are optional.
See our cookie settings by clicking \"Cookie Settings\" in the footer.
11. Security
We implement appropriate technical and organisational measures to protect your data, including:
- Encrypted data transmission (HTTPS/TLS)
- Secure authentication systems
- Regular security reviews
- Access controls and staff training
12. Contact Us
For privacy-related queries or to exercise your rights:
- Email: support@caredirectory.org.uk
- Phone: 0808 501 0191
- Post: NE26 Limited, First Floor Office, 3 Hornton Place, London, W8 4LZ
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
ICO Registration Number: ZC054682
13. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes via email or a notice on our website.