Privacy notice
Last updated: 2026-07-20
This notice explains how Handby Ltd (company number 17092920), the company that operates the CarersDoc platform (“CarersDoc”, “we”), handles personal data. For most of the data on the platform we act as a data processor for our customers: care providers regulated by the CQC who use CarersDoc to manage their workforce records. The care provider that employs you is the controller of your data; CarersDoc processes it on their instruction. This notice covers our processor-side commitments, the data CarersDoc collects directly to operate the platform (account email, sign-in telemetry, audit-log entries tied to your user ID), and the enquiry data we collect as a controller when you book a demo on carersdoc.com.
Controller / processor
Your employer (the care provider using CarersDoc) is the controller of personal data about you and the people in their care. CarersDoc is the processor; we hold and process that data under written instruction in our Data Processing Agreement with each tenant. For data-subject rights requests (access, rectification, erasure), contact your employer first; they will use CarersDoc's built-in DSAR tooling to fulfil your request.
What we collect
- Account identity: your email address, name, role (carer / office staff / manager / HR admin / read-only director), and the tenant you belong to. Provided when your employer invites you.
- Sign-in telemetry: timestamps of successful and failed sign-ins, hashed IP addresses for fraud detection, and the MFA factor type used. Retained per the audit-trail floor for your employer's tenancy.
- Tenant content: the documents, signatures, training records, supervision and appraisal records, and onboarding evidence created by your employer and you under their employment relationship. CarersDoc processes this under instruction; we do not analyse it or use it to train any model.
- Vetting records: where your employer uses CarersDoc's compliance features, DBS certificate details (including fields extracted from an uploaded certificate by optical character recognition) and right-to-work check details. Sensitive identifiers in these records, such as date of birth and certificate numbers, are stored encrypted, and status checks are only performed with your consent where the law requires it.
- Incident and accident records: where your employer uses CarersDoc's incident reporting, the details of an incident you report or are involved in, including the type of injury, the part of the body affected, any first aid given, safeguarding flags, and encrypted photo or document attachments. These records can include special-category health data about you, and free-text notes may refer to people in your employer's care.
- Reference data: when your employer requests an employment reference, the referee's name, organisation, email address and phone number, and the opinions they give, including dates employed, conduct, whether they would re-employ, and any safeguarding views. Referees submit through a secure single-use link and can attach a letter on their own letterhead. We process this data so your employer can verify employment history, as the law on recruiting into regulated care requires.
- Rota and scheduling data: where your employer connects or uploads their rota, imported rota assignments including shift times, visit types, and coded service-user references.
- Communications log: a record of emails and SMS messages CarersDoc sent on your employer's behalf (recipient address / number, timestamp, subject line, provider message ID, delivery status). The full message body is not retained beyond what's needed for delivery, typically a few minutes.
- Audit trail: every significant action you take in the platform is recorded in an append-only event log tied to your user ID. This is required for CQC inspection and UK GDPR Article 30 record-keeping. The audit log is retained for the life of your employer's tenancy plus the statutory floor for the relevant class of record.
- Signing evidence: when you sign a document, we record your IP address and device (browser user-agent) at the moment of signing as electronic-signature attribution evidence. This is shown only in the inspector evidence pack for a signed document, never on the copy shared with other parties.
Demo requests and prospective customers
If you book a demo or enquire about CarersDoc through carersdoc.com, Handby Ltd is the controller of the details you give us: your name, work email address, phone number, organisation name, and any optional details you choose to add (CQC registration number, number of sites or carers, free-text notes). We use these details only to arrange your demo, answer your enquiry, and, if you go ahead, set up your organisation's secure space. The lawful basis is taking steps at your request before entering into a contract (UK GDPR Article 6(1)(b)) and our legitimate interest in responding to enquiries. We do not add you to marketing lists or share these details with anyone else. We keep enquiry details while your enquiry is open and for a reasonable period afterwards; you can ask us to delete them at any time by emailing info@carersdoc.com.
Lawful basis
Where CarersDoc acts as a controller of platform-operations data (your account email, IP-derived sign-in telemetry hashed for fraud prevention, and audit-log entries identifying which user took which action), we rely on legitimate interest (operating a secure platform our customers can trust) and contractual necessity (we cannot provide the service without identifying who is signed in). For everything your employer stores in the platform, the lawful basis is your employer's to establish as controller, typically legal obligation and legitimate interest connected to your employment in regulated care.
Sub-processors
CarersDoc uses the following sub-processors to operate the platform. Each is bound by a data-processing agreement that flows down the controller-side obligations from your employer. The list also includes one recipient marked as an independent controller: a government service that processes data under its own legal duties rather than on our instructions.
- Vercel Inc.: application hosting (functions in region: London, UK; US-headquartered operator).
- Amazon Web Services: document storage (S3) and optical character recognition of uploaded DBS certificates (Textract), region: London, UK (eu-west-2).
- Mailgun Technologies, Inc. (a Sinch company): transactional email delivery, EU region. Processes recipient name, email address, and message content transiently for delivery.
- Neon, Inc.: managed PostgreSQL database holding the application data. Data is stored in the UK (AWS region eu-west-2, London); Neon, Inc. is US-headquartered and may access it as the operator, under UK GDPR Article 46 safeguards.
- Cloudflare, Inc.: DNS, domain registration, and inbound email routing; US-headquartered operator with a global edge network.
- Inngest, Inc.: scheduled jobs and background processing. Receives only pseudonymous trigger metadata (identifiers, status codes, timestamps; no names, email addresses, or document content). US-hosted, under UK GDPR Article 46 safeguards.
- Twilio Inc.: SMS delivery to UK mobile numbers via EU routing. Processes recipient mobile numbers and message content for delivery, and holds an opt-out (STOP) suppression list.
- Functional Software Inc. (Sentry): error monitoring for the platform, with EU data residency. Error reports are scrubbed of personal data before they leave our infrastructure.
- GOV.UK DBS Update Service (independent controller): a UK government service that confirms the current status of a DBS certificate. For staff who are subscribed to the Update Service and have given consent, we send the DBS certificate number, surname, and date of birth, together with the name of your employer's organisation and of the person carrying out the check; checks run monthly and on demand. The service is an independent government controller, not a sub-processor acting on our instructions.
This page is the canonical public register of our sub-processors. We update it, and give tenant controllers at least 30 days' notice by email, before engaging a new sub-processor.
Retention
Documents are retained per statutory floors enforced in code (see /admin/retention inside each tenant). The classes are: adult social-care personnel records, 8 years post-employment (CQC + NHS Records Management Code); general HR records, 6 years; child-related records, until the subject reaches age 25 (these require manual review and are not auto-actioned). These enforced floors apply to documents held in the service, which include supervision and appraisal records and sealed reference evidence. When your employer marks you as a leaver, document retention clocks are anchored to your recorded last day of employment, so post-employment periods run from the day your employment actually ended. Incident and accident records are kept for 8 years after the incident is closed. Complaint records are kept for 8 years after the complaint is closed. Reference records are kept with the personnel record for 8 years after employment ends. Imported rota data is kept for 2 years after the shift date. The same daily sweep enforces these periods in code, and your employer can extend them, never shorten them. A retention sweep runs daily at 06:00 Europe/London to action documents past their deadline: documents are first soft-deleted, then permanently purged, and backups containing them roll off within 35 days. Account-level data (email, sign-in telemetry, audit-log entries identifying which user took which action) is retained for the life of your employer's tenancy. On tenancy termination, deletion follows the wind-down schedule in our Terms of Service (export window, then production deletion, then backup rolloff).
Your rights
Under the UK GDPR you have the following rights in relation to your personal data. To exercise them, contact your employer (the controller) directly. They can use CarersDoc's DSAR workflow to fulfil access and portability requests within one calendar month.
- Right of access: see what personal data we hold about you.
- Right to rectification: correct inaccurate personal data.
- Right to erasure: ask for your data to be deleted, subject to statutory retention floors.
- Right to restriction: limit how we process your data while a dispute is being resolved.
- Right to portability: receive your personal data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interest.
Security
Personal data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Stored documents are additionally envelope-encrypted with per-tenant data keys, so a document blob is unreadable without that tenant's key. Multi-factor authentication is mandatory for privileged roles (platform administrators and registered managers). Multi-tenant data is isolated at the database level by PostgreSQL Row-Level Security: a query bug in our application returns no rows rather than leaking across tenants. The full audit trail is append-only, hash-chained, and tamper-evident, and data exports (DSAR bundles, audit-log exports) are encrypted at rest.
Personal data breaches
Personal data breaches affecting your data will be notified to your employer (the controller) without undue delay after CarersDoc becomes aware of them, in line with UK GDPR Article 33(2). Your employer is obliged under UK GDPR Article 33(1) to notify the ICO within 72 hours of becoming aware of a notifiable breach; our notification is designed to give them enough lead time to meet that obligation. CarersDoc operates the breach workflow surfaces at /admin/breach that support both sides of the chain.
International data transfers
Personal data is stored in the United Kingdom: application hosting on Vercel (region lhr1, London), document storage on AWS (region eu-west-2, London), and the application database on Neon (stored in AWS eu-west-2, London). Transactional email is processed by Mailgun in its EU region, and SMS messages are routed by Twilio through EU infrastructure; the UK Government has an adequacy decision covering the EEA, so those transfers do not need further safeguards. Some of our sub-processors are US-headquartered operators: Neon, Inc. (database operator), Inngest, Inc. (background jobs, which receive only pseudonymous trigger metadata), Vercel Inc., Cloudflare, Inc., Mailgun Technologies, Inc. and Twilio Inc. Limited processing or operator access may therefore occur outside the UK or EEA. Where it does, the transfer is covered by UK GDPR Article 46 safeguards (UK International Data Transfer Agreement / standard contractual clauses) under each provider's data-processing agreement. The register above lists each sub-processor's role and region.
Contact
CarersDoc is operated by Handby Ltd, a company registered in England and Wales (company number 17092920). For questions about this notice, or to exercise data-subject rights against Handby Ltd as a controller of platform-operations or enquiry data, email info@carersdoc.com.
Changes to this notice
We will update this notice as the platform evolves. Material changes will be flagged in the application UI for at least 30 days before they take effect.