Privacy Policy
How Superb Care Services Ltd collects, uses and protects your personal data in line with the UK GDPR, the Data Protection Act 2018 and PECR.
Last updated: 10 September 2026
Contents
- 1. Introduction and Scope
- 2. Who We Are (Data Controller)
- 3. Legal Framework and Principles
- 4. Personal Data We Collect
- 5. Special Category Data
- 6. How We Collect Personal Data
- 7. Lawful Bases for Processing
- 8. How We Use Your Personal Data
- 9. Cookies and Analytics
- 10. Sharing Your Personal Data
- 11. International Transfers
- 12. Data Security
- 13. Data Retention
- 14. Your Rights as a Data Subject
- 15. Children and Vulnerable Adults
- 16. Automated Decision-Making
- 17. Data Breach Notification
- 18. Accountability
- 19. Changes to This Policy
- 20. Contact Us and Complaints
1. Introduction and Scope
Superb Care Services Ltd (“Superb Care”, “we”, “us” or “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, share and otherwise process personal data when you visit our website, contact us, request or receive our care services, apply to work with us, or otherwise interact with us.
This policy has been prepared to meet the requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR). Throughout this policy, references to “the law” mean these laws as amended, together with any other applicable data protection legislation in the United Kingdom.
By using our website or providing your personal data to us, you confirm that you have read and understood this Privacy Policy. This policy should be read together with any other privacy notice we may provide at the point of collection.
2. Who We Are (Data Controller)
For the purposes of the UK GDPR and the Data Protection Act 2018, Superb Care Services Ltd is a controller in respect of the personal data it processes. Our details are:
In some circumstances we process personal data as a data processor on behalf of health, social care and funding partners. Where we act as a processor, the relevant partner is the data controller for that data and their own privacy notice will also apply.
3. Our Legal Framework and Data Protection Principles
Data protection in the United Kingdom is governed primarily by the UK GDPR and the Data Protection Act 2018, and is enforced by the Information Commissioner’s Office (ICO). We follow the ICO’s guidance and the requirements of the Privacy and Electronic Communications Regulations 2003 (PECR), which govern cookies and electronic marketing.
We apply the seven principles of data protection set out in Article 5 of the UK GDPR to everything we do:
- Lawfulness, fairness and transparency: we process personal data lawfully, fairly and in a way that is transparent to you.
- Purpose limitation: we collect personal data only for specific, explicit and legitimate purposes and do not process it in a way that is incompatible with those purposes.
- Data minimisation: we collect only the personal data that is adequate, relevant and limited to what is necessary.
- Accuracy: we take reasonable steps to keep personal data accurate, up to date and, where necessary, corrected or deleted.
- Storage limitation: we keep personal data in a form that identifies you only for as long as is necessary for the purposes we collected it for.
- Integrity and confidentiality: we protect personal data with appropriate technical and organisational security measures.
- Accountability: we are able to demonstrate our compliance with these principles and we take responsibility for the personal data we hold.
We are accountable for the personal data we hold and we can demonstrate how we comply with the law. When we send you electronic marketing we do so only where you have consented or where the law otherwise permits, and every message gives you the opportunity to opt out. Cookies and similar technologies are governed by PECR (see section 9).
4. The Personal Data We Collect
Depending on how you interact with us, we may collect and process the following categories of personal data:
- Identity data: your name, title, date of birth, gender and, where required, your national identification number, passport or other identifier.
- Contact data: your postal address, email address and telephone number.
- Care and wellbeing data: information needed to plan and deliver care, such as care needs, daily routines, mobility, nutrition and dietary requirements, medication, allergies, medical history and next of kin and emergency contacts (see section 5).
- Financial data: billing details, payment information, bank details and information about funding sources such as local authority support, insurers or a power of attorney.
- Employment data: for applicants and staff: recruitment information, references, identity and right-to-work documents, background screening results and training records.
- Technical data: your internet protocol (IP) address, browser type and version, device type, location and cookie identifiers collected when you use our website.
- Usage data: information about how you use our website, the pages you visit and the services you enquire about.
- Communications data: records of your correspondence with us, including phone calls, emails, enquiry forms and appointment requests.
We do not collect more personal data than we need, and we do not collect it for purposes other than those described in this policy.
5. Special Category Data (Including Health Data)
Under the UK GDPR, information about your health, as well as personal data revealing racial or ethnic origin, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify you, and data concerning your sex life or sexual orientation, is treated as “special category data” and attracts a higher level of protection. Personal data relating to criminal convictions and offences is subject to similar safeguards.
Because we provide care services, we necessarily process special category data — for example, information about a client’s medical conditions, medication, mental health, mobility and care requirements. We only process special category data where a lawful condition in Article 9 of the UK GDPR is met, most commonly:
- the explicit consent of the individual (or their lawful representative);
- the provision of health or social care, or the management of those care systems, by a person who owes a duty of confidentiality;
- the protection of the individual’s vital interests, for example in a medical emergency; or
- the establishment, exercise or defence of legal claims, or compliance with a legal obligation, such as safeguarding duties.
Special category data is subject to additional safeguards, including restricted access on a need-to-know basis, encryption, strict staff confidentiality obligations, secure storage and secure destruction when it is no longer needed.
6. How We Collect Your Personal Data
We collect personal data in the following ways:
- Directly from you: when you complete a form on our website, call or email us, request a care assessment, book an appointment or otherwise correspond with us.
- In person: during home assessments and care visits, and through the care records our carers complete.
- From your family or representatives: where a relative, attorney, deputy or other authorised person contacts us on your behalf.
- From third parties: such as healthcare professionals, hospitals, general practitioners, local authorities, funding bodies, insurers, and background-check or reference providers.
- Automatically: when you use our website, we may collect technical and usage data using cookies and similar technologies (see section 9).
7. Lawful Bases for Processing
The law requires every processing activity to be founded on one or more lawful bases, as set out in Article 6 of the UK GDPR. Depending on the circumstances, we rely on the following lawful bases:
- Consent: you have given us clear, informed permission to process your personal data for a specific purpose. Where we rely on consent, you may withdraw it at any time.
- Performance of a contract: processing is necessary to enter into or perform a contract with you, such as providing the care services you have requested.
- Compliance with a legal obligation: processing is necessary for us to comply with the law, including safeguarding, tax, employment and regulatory requirements.
- Protection of vital interests: processing is necessary to protect your life or the life of another person, for example in a medical emergency.
- Performance of a task in the public interest: processing is necessary for the performance of a task carried out in the public interest, for example cooperating with health and social care authorities.
- Legitimate interests: processing is necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests — for example, keeping our website secure, preventing fraud and improving our services.
Where we rely on your consent, you have the right to withdraw it at any time by contacting us using the details in section 20. Withdrawing consent does not affect the lawfulness of any processing carried out before the withdrawal.
8. How We Use Your Personal Data
We use personal data for the following purposes:
- to assess your needs and create a personalised care plan;
- to provide, manage and review the care and support services we deliver;
- to match you with suitable carers and schedule visits;
- to communicate with you and your representatives about appointments, care and changes to services;
- to process payments, manage invoices and administer funding arrangements;
- to safeguard our clients and staff and to respond to emergencies;
- to recruit, screen, train and manage our employees and carers;
- to comply with our legal, regulatory, safeguarding and professional obligations;
- to respond to enquiries, complaints and requests for information;
- to maintain and secure our website and IT systems;
- to prevent and detect fraud and to protect our legal rights; and
- to improve our services, including through anonymised analytics and feedback.
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason that is compatible with the original purpose. If we need to use your data for an unrelated purpose, we will notify you and explain the lawful basis for doing so.
11. International Transfers of Personal Data
Because we use cloud-based software and some of our service providers may be located outside the United Kingdom, your personal data may be transferred to, stored in, or accessed from countries outside the UK.
We only transfer personal data outside the UK where the law allows us to do so — for example, where the destination country benefits from UK adequacy regulations, or where we have put appropriate safeguards in place, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. Before transferring personal data outside the UK, we take reasonable steps to ensure that it will not be used for purposes other than those we have authorised and that it will receive an adequate level of protection.
You may contact us using the details in section 20 for more information about the safeguards we use for international transfers.
12. Data Security
We have put in place appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include:
- access controls that limit access to personal data on a need-to-know basis;
- confidentiality obligations for all staff and carers, supported by regular data protection and safeguarding training;
- encryption of personal data in transit and at rest, where appropriate;
- secure hosting, firewalls, malware protection and regular security updates;
- regular backups and tested recovery procedures;
- secure storage, handling and disposal of paper and electronic records;
- written information security and data protection policies, reviewed regularly; and
- an incident response process to detect, contain and report data breaches (see section 17).
Although we use these safeguards, no method of transmission over the internet is completely secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately using the details in section 20.
13. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes we collected it for, including to satisfy any legal, regulatory, accounting or reporting requirements.
To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and the retention periods required by applicable law and professional guidance.
- Care records: kept for the period required by applicable health and social care record-keeping requirements after the end of care.
- Financial and transaction records: kept for the period required by applicable tax and accounting law.
- Recruitment records: for unsuccessful applicants, normally kept for up to twelve (12) months, unless you ask us to keep them longer or to delete them sooner.
- Website and marketing records: kept only for as long as necessary for the purpose for which they were collected, or until you withdraw your consent.
When we no longer need personal data, we securely delete or anonymise it so that it can no longer be associated with you.
14. Your Rights as a Data Subject
Subject to the conditions and limitations set out in the UK GDPR, you have the following rights in relation to your personal data:
- Right to be informed: about how we use your personal data, which is what this policy explains.
- Right of access: to obtain confirmation of whether we hold your personal data and a copy of it.
- Right to rectification: to have inaccurate or incomplete personal data corrected.
- Right to erasure: to have your personal data deleted where there is no lawful reason for us to continue processing it.
- Right to restriction of processing: to limit how we use your personal data in certain circumstances.
- Right to object: to object to processing based on legitimate interests, and to object to direct marketing at any time.
- Right to data portability: to receive the personal data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
- Right not to be subject to automated decisions: not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects.
- Right to withdraw consent: at any time, where processing is based on consent.
- Right to lodge a complaint: with the Information Commissioner’s Office (ICO) (see section 20).
- Right to compensation: you have the right to seek compensation from a controller or processor for material or non-material damage caused by a breach of data protection law.
To exercise any of these rights, please contact us using the details in section 20. We will respond without undue delay and, in any event, within one (1) month as required by the UK GDPR. We may need to verify your identity, and where you are acting on behalf of someone else, your authority to act. We do not normally charge a fee, but we may charge a reasonable fee where a request is manifestly unfounded, excessive or repetitive.
15. Children’s and Vulnerable Adults’ Data
Our services are primarily directed at adults. Where we process the personal data of a child, we do so only where we have the consent of a parent or guardian (for a child under 13 where consent is required for online services), where the processing is in the child’s vital interests, or where we are otherwise permitted or required to do so by law. We also have regard to the ICO’s Age Appropriate Design Code (the Children’s Code) and take the best interests of the child into account.
Where we process personal data on behalf of an adult who lacks capacity to make decisions about their own data, we act in accordance with our safeguarding duties and, where a legal representative, attorney or deputy has been appointed, with their lawful instructions.
16. Automated Decision-Making and Profiling
We do not generally make decisions about you based solely on automated processing, including profiling, that produce legal or similarly significant effects. Where we use automated tools to support care planning, rostering or administration, we ensure that a human being reviews the outcome before it materially affects you, and you have the right to request human intervention, to express your point of view and to contest the decision.
17. Data Breach Notification
We have procedures in place to detect, report and investigate personal data breaches. Where a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of it, in accordance with the UK GDPR.
Where a breach is likely to result in a high risk to your rights and freedoms, we will also communicate it to you without undue delay, together with the nature of the breach and the measures we have taken or propose to take to address it.
We keep a record of all personal data breaches, including those that do not need to be reported, as required by the UK GDPR.
18. Accountability
We take our accountability obligations seriously and can demonstrate how we comply with data protection law. In particular, we:
- maintain a record of our processing activities, as required by Article 30 of the UK GDPR;
- carry out data protection impact assessments before undertaking processing that is likely to result in a high risk to individuals, as required by Article 35 of the UK GDPR;
- provide regular data protection training to our staff and carers; and
- review our data protection policies and procedures regularly.
If you have any questions about our accountability practices or how we protect personal data, please contact us using the details in section 20.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our services or the law. The date at the top of this page shows when the policy was last updated. Where changes are material, we will take reasonable steps to bring them to your attention, for example by posting a prominent notice on our website. We encourage you to review this page periodically.
20. How to Contact Us and How to Complain
If you have any questions, requests or concerns about this Privacy Policy or about how we handle your personal data, please contact us:
Complaining to the ICO
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent regulator for data protection. The ICO can be contacted through its website at www.ico.org.uk or by calling 0303 123 1113, or +44 1625 545 745 if calling from outside the UK.
We would appreciate the opportunity to resolve your concern first, so please contact us before approaching a regulator.
Questions about your personal data?
Our team is happy to help you exercise your data protection rights, understand this policy, or discuss how we handle your information.
