Data Protection Policy
This policy states how we protect personal data
Careful Systems Limited processes personal data in three capacities: as processor of patient and staff data on behalf of the healthcare organisations that deploy CAREFUL, which are the controllers; as controller of the data of our own staff, contacts and website users; and as controller of limited operational data needed to run the service. This policy applies to all staff and contractors in every capacity. Our published Privacy Notice tells individuals what we do with their data; this policy tells us how we must do it.
The Data Protection Officer is Dr Shane McKeown, responsible for advising on obligations, monitoring compliance, and acting as contact point for individuals and the Information Commissioner's Office. Every member of staff must complete data protection training annually and must report suspected breaches immediately.
We consider data protection before we start, not after
No new project, feature, integration, sub-processor or new purpose for existing data may commence without data protection screening. The Data Protection Officer determines whether a Data Protection Impact Assessment is required, applying ICO guidance; a DPIA must be completed before any processing likely to result in high risk to individuals, and in any case before any new deployment of CAREFUL to a healthcare organisation. Sub-processors are assessed and approved by the Data Protection Officer before engagement, and controllers are notified in accordance with our processing agreements. Where a risk cannot be reduced, we consult the ICO before proceeding.
Example of the standard we apply: error-monitoring telemetry is configured so that message content is removed on the user's device before transmission, and this control was required to be live before contract signature.
We collect and keep the minimum
Personal data is collected only for specified purposes and is limited to what those purposes need. The platform is designed accordingly: push notifications carry no patient-identifiable or clinical content; no server-held patient data is stored on user devices; and CAREFUL holds coordination data, not the clinical record. Data is retained no longer than the retention schedule allows; patient data processed on behalf of a controller follows that controller's instructions and our processing agreement, and is returned or deleted at contract end.
Only people who need data can see it
Access to personal data is on a need-to-know basis. Within the platform, patient visibility is gated by team membership with role-based access control, and every access-relevant transaction is recorded in an attributable audit trail. Within the company, production access is restricted to named engineers, secrets are held in a managed vault and rotated, and access is removed on the day a person leaves or changes role.
We tell people what we do with their data
We maintain a published Privacy Notice and a sub-processor list, reviewed at least annually and whenever processing changes. Where we act as processor, we support each controller's own transparency obligations, including patient-facing notices.
Rights, breaches and incidents follow defined procedures
Requests from individuals to exercise their rights are handled within one month, under the Subject Access and Rights Procedure. Suspected personal data breaches are reported internally without delay, assessed by the Data Protection Officer, notified to affected controllers promptly so that the 72-hour obligations under our processing agreements and UK GDPR can be met, and recorded with remedial actions. Breach and rights records are reviewed at the Risk, Safety and Governance Committee.
Governance
This policy is owned by the Data Protection Officer, approved by the Chief Executive, and reviewed annually or on material change to our processing, our sub-processors or the law. Non-compliance by staff is a disciplinary matter.
Change history
Version
Date
Author
Summary
Approved by
0.1
20-Aug-2026
S McKeown / DJ Hamblin-Brown
First draft, superseding the 2021 draft Data Protection Policies & Procedures; aligned with Privacy Notice v2.1 and current processing agreements.
—