Data Protection & Privacy

Privacy Policy

How Superb Care Services Ltd collects, uses and protects your personal data in line with the UK GDPR, the Data Protection Act 2018 and PECR.

Last updated: 10 September 2026

1. Introduction and Scope

Superb Care Services Ltd (“Superb Care”, “we”, “us” or “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, share and otherwise process personal data when you visit our website, contact us, request or receive our care services, apply to work with us, or otherwise interact with us.

This policy has been prepared to meet the requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR). Throughout this policy, references to “the law” mean these laws as amended, together with any other applicable data protection legislation in the United Kingdom.

By using our website or providing your personal data to us, you confirm that you have read and understood this Privacy Policy. This policy should be read together with any other privacy notice we may provide at the point of collection.

2. Who We Are (Data Controller)

For the purposes of the UK GDPR and the Data Protection Act 2018, Superb Care Services Ltd is a controller in respect of the personal data it processes. Our details are:

Data ControllerSuperb Care Services Ltd
Registered officeCastle Hill House, 12 Castle Hill, Windsor, SL4 1PD, United Kingdom
Emailinfo@superbcare.co.ukTelephone+44 7984 885069

In some circumstances we process personal data as a data processor on behalf of health, social care and funding partners. Where we act as a processor, the relevant partner is the data controller for that data and their own privacy notice will also apply.

4. The Personal Data We Collect

Depending on how you interact with us, we may collect and process the following categories of personal data:

  • Identity data: your name, title, date of birth, gender and, where required, your national identification number, passport or other identifier.
  • Contact data: your postal address, email address and telephone number.
  • Care and wellbeing data: information needed to plan and deliver care, such as care needs, daily routines, mobility, nutrition and dietary requirements, medication, allergies, medical history and next of kin and emergency contacts (see section 5).
  • Financial data: billing details, payment information, bank details and information about funding sources such as local authority support, insurers or a power of attorney.
  • Employment data: for applicants and staff: recruitment information, references, identity and right-to-work documents, background screening results and training records.
  • Technical data: your internet protocol (IP) address, browser type and version, device type, location and cookie identifiers collected when you use our website.
  • Usage data: information about how you use our website, the pages you visit and the services you enquire about.
  • Communications data: records of your correspondence with us, including phone calls, emails, enquiry forms and appointment requests.

We do not collect more personal data than we need, and we do not collect it for purposes other than those described in this policy.

5. Special Category Data (Including Health Data)

Under the UK GDPR, information about your health, as well as personal data revealing racial or ethnic origin, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify you, and data concerning your sex life or sexual orientation, is treated as “special category data” and attracts a higher level of protection. Personal data relating to criminal convictions and offences is subject to similar safeguards.

Because we provide care services, we necessarily process special category data — for example, information about a client’s medical conditions, medication, mental health, mobility and care requirements. We only process special category data where a lawful condition in Article 9 of the UK GDPR is met, most commonly:

  • the explicit consent of the individual (or their lawful representative);
  • the provision of health or social care, or the management of those care systems, by a person who owes a duty of confidentiality;
  • the protection of the individual’s vital interests, for example in a medical emergency; or
  • the establishment, exercise or defence of legal claims, or compliance with a legal obligation, such as safeguarding duties.

Special category data is subject to additional safeguards, including restricted access on a need-to-know basis, encryption, strict staff confidentiality obligations, secure storage and secure destruction when it is no longer needed.

6. How We Collect Your Personal Data

We collect personal data in the following ways:

  • Directly from you: when you complete a form on our website, call or email us, request a care assessment, book an appointment or otherwise correspond with us.
  • In person: during home assessments and care visits, and through the care records our carers complete.
  • From your family or representatives: where a relative, attorney, deputy or other authorised person contacts us on your behalf.
  • From third parties: such as healthcare professionals, hospitals, general practitioners, local authorities, funding bodies, insurers, and background-check or reference providers.
  • Automatically: when you use our website, we may collect technical and usage data using cookies and similar technologies (see section 9).

7. Lawful Bases for Processing

The law requires every processing activity to be founded on one or more lawful bases, as set out in Article 6 of the UK GDPR. Depending on the circumstances, we rely on the following lawful bases:

  • Consent: you have given us clear, informed permission to process your personal data for a specific purpose. Where we rely on consent, you may withdraw it at any time.
  • Performance of a contract: processing is necessary to enter into or perform a contract with you, such as providing the care services you have requested.
  • Compliance with a legal obligation: processing is necessary for us to comply with the law, including safeguarding, tax, employment and regulatory requirements.
  • Protection of vital interests: processing is necessary to protect your life or the life of another person, for example in a medical emergency.
  • Performance of a task in the public interest: processing is necessary for the performance of a task carried out in the public interest, for example cooperating with health and social care authorities.
  • Legitimate interests: processing is necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests — for example, keeping our website secure, preventing fraud and improving our services.

Where we rely on your consent, you have the right to withdraw it at any time by contacting us using the details in section 20. Withdrawing consent does not affect the lawfulness of any processing carried out before the withdrawal.

8. How We Use Your Personal Data

We use personal data for the following purposes:

  • to assess your needs and create a personalised care plan;
  • to provide, manage and review the care and support services we deliver;
  • to match you with suitable carers and schedule visits;
  • to communicate with you and your representatives about appointments, care and changes to services;
  • to process payments, manage invoices and administer funding arrangements;
  • to safeguard our clients and staff and to respond to emergencies;
  • to recruit, screen, train and manage our employees and carers;
  • to comply with our legal, regulatory, safeguarding and professional obligations;
  • to respond to enquiries, complaints and requests for information;
  • to maintain and secure our website and IT systems;
  • to prevent and detect fraud and to protect our legal rights; and
  • to improve our services, including through anonymised analytics and feedback.

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason that is compatible with the original purpose. If we need to use your data for an unrelated purpose, we will notify you and explain the lawful basis for doing so.

9. Cookies and Website Analytics

Our website uses cookies and similar technologies to make the site work, to remember your preferences and to help us understand how visitors use the site. Cookies are small text files placed on your device. Where a cookie is not strictly necessary, we rely on your consent in accordance with PECR and the UK GDPR.

  • Strictly necessary cookies: required for the website to function and to keep it secure; these cannot be switched off in our systems.
  • Performance and analytics cookies: help us understand how visitors use our website, which pages are popular and how we can improve the site.
  • Functionality cookies: remember your choices and provide enhanced features.
  • Marketing cookies (where used): help us and our partners show relevant content and measure the effectiveness of campaigns.

You can set your browser to refuse or delete cookies and you can withdraw consent for non-essential cookies at any time. If you disable cookies, some parts of the website may not work properly.

The technical data we collect through cookies (such as your IP address) is used to administer our website, keep it secure and analyse usage. We do not use it to identify you personally unless we are required to do so for security or legal reasons. The use of cookies is regulated by PECR, and further guidance for members of the public is available from the ICO.

10. Sharing Your Personal Data

We do not sell your personal data. We may share it with the following categories of recipients, but only where it is necessary and lawful to do so:

  • Our carers and care staff: who need the information to deliver your care safely and effectively.
  • Health and social care professionals: such as general practitioners, hospitals, district nurses, therapists, local authorities and care regulators.
  • Funding bodies and payment providers: including local authorities, insurers, banks and payment processors, to administer funding and process payments.
  • Service providers (data processors): such as IT, hosting, email, secure records and communications providers that support our operations.
  • Professional advisers: including lawyers, accountants, auditors and insurers.
  • Regulators and public authorities: such as the Information Commissioner’s Office (ICO), health and social care regulators, tax authorities and law enforcement, where we are required or permitted by law to disclose information.
  • Emergency services: where disclosure is necessary to protect life or health.

Where we share personal data with a processor, we have a written contract in place requiring the processor to protect it, to act only on our instructions and to comply with the law. We do not sell, rent or trade your personal data, and we do not use it for third-party marketing without your consent.

11. International Transfers of Personal Data

Because we use cloud-based software and some of our service providers may be located outside the United Kingdom, your personal data may be transferred to, stored in, or accessed from countries outside the UK.

We only transfer personal data outside the UK where the law allows us to do so — for example, where the destination country benefits from UK adequacy regulations, or where we have put appropriate safeguards in place, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. Before transferring personal data outside the UK, we take reasonable steps to ensure that it will not be used for purposes other than those we have authorised and that it will receive an adequate level of protection.

You may contact us using the details in section 20 for more information about the safeguards we use for international transfers.

12. Data Security

We have put in place appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include:

  • access controls that limit access to personal data on a need-to-know basis;
  • confidentiality obligations for all staff and carers, supported by regular data protection and safeguarding training;
  • encryption of personal data in transit and at rest, where appropriate;
  • secure hosting, firewalls, malware protection and regular security updates;
  • regular backups and tested recovery procedures;
  • secure storage, handling and disposal of paper and electronic records;
  • written information security and data protection policies, reviewed regularly; and
  • an incident response process to detect, contain and report data breaches (see section 17).

Although we use these safeguards, no method of transmission over the internet is completely secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately using the details in section 20.

13. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes we collected it for, including to satisfy any legal, regulatory, accounting or reporting requirements.

To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and the retention periods required by applicable law and professional guidance.

  • Care records: kept for the period required by applicable health and social care record-keeping requirements after the end of care.
  • Financial and transaction records: kept for the period required by applicable tax and accounting law.
  • Recruitment records: for unsuccessful applicants, normally kept for up to twelve (12) months, unless you ask us to keep them longer or to delete them sooner.
  • Website and marketing records: kept only for as long as necessary for the purpose for which they were collected, or until you withdraw your consent.

When we no longer need personal data, we securely delete or anonymise it so that it can no longer be associated with you.

14. Your Rights as a Data Subject

Subject to the conditions and limitations set out in the UK GDPR, you have the following rights in relation to your personal data:

  • Right to be informed: about how we use your personal data, which is what this policy explains.
  • Right of access: to obtain confirmation of whether we hold your personal data and a copy of it.
  • Right to rectification: to have inaccurate or incomplete personal data corrected.
  • Right to erasure: to have your personal data deleted where there is no lawful reason for us to continue processing it.
  • Right to restriction of processing: to limit how we use your personal data in certain circumstances.
  • Right to object: to object to processing based on legitimate interests, and to object to direct marketing at any time.
  • Right to data portability: to receive the personal data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Right not to be subject to automated decisions: not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects.
  • Right to withdraw consent: at any time, where processing is based on consent.
  • Right to lodge a complaint: with the Information Commissioner’s Office (ICO) (see section 20).
  • Right to compensation: you have the right to seek compensation from a controller or processor for material or non-material damage caused by a breach of data protection law.

To exercise any of these rights, please contact us using the details in section 20. We will respond without undue delay and, in any event, within one (1) month as required by the UK GDPR. We may need to verify your identity, and where you are acting on behalf of someone else, your authority to act. We do not normally charge a fee, but we may charge a reasonable fee where a request is manifestly unfounded, excessive or repetitive.

15. Children’s and Vulnerable Adults’ Data

Our services are primarily directed at adults. Where we process the personal data of a child, we do so only where we have the consent of a parent or guardian (for a child under 13 where consent is required for online services), where the processing is in the child’s vital interests, or where we are otherwise permitted or required to do so by law. We also have regard to the ICO’s Age Appropriate Design Code (the Children’s Code) and take the best interests of the child into account.

Where we process personal data on behalf of an adult who lacks capacity to make decisions about their own data, we act in accordance with our safeguarding duties and, where a legal representative, attorney or deputy has been appointed, with their lawful instructions.

16. Automated Decision-Making and Profiling

We do not generally make decisions about you based solely on automated processing, including profiling, that produce legal or similarly significant effects. Where we use automated tools to support care planning, rostering or administration, we ensure that a human being reviews the outcome before it materially affects you, and you have the right to request human intervention, to express your point of view and to contest the decision.

17. Data Breach Notification

We have procedures in place to detect, report and investigate personal data breaches. Where a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of it, in accordance with the UK GDPR.

Where a breach is likely to result in a high risk to your rights and freedoms, we will also communicate it to you without undue delay, together with the nature of the breach and the measures we have taken or propose to take to address it.

We keep a record of all personal data breaches, including those that do not need to be reported, as required by the UK GDPR.

18. Accountability

We take our accountability obligations seriously and can demonstrate how we comply with data protection law. In particular, we:

  • maintain a record of our processing activities, as required by Article 30 of the UK GDPR;
  • carry out data protection impact assessments before undertaking processing that is likely to result in a high risk to individuals, as required by Article 35 of the UK GDPR;
  • provide regular data protection training to our staff and carers; and
  • review our data protection policies and procedures regularly.

If you have any questions about our accountability practices or how we protect personal data, please contact us using the details in section 20.

19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our services or the law. The date at the top of this page shows when the policy was last updated. Where changes are material, we will take reasonable steps to bring them to your attention, for example by posting a prominent notice on our website. We encourage you to review this page periodically.

20. How to Contact Us and How to Complain

If you have any questions, requests or concerns about this Privacy Policy or about how we handle your personal data, please contact us:

Postal addressCastle Hill House, 12 Castle Hill, Windsor, SL4 1PD, United Kingdom
Emailinfo@superbcare.co.ukTelephone+44 7984 885069Websitewww.superbcare.co.uk

Complaining to the ICO

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent regulator for data protection. The ICO can be contacted through its website at www.ico.org.uk or by calling 0303 123 1113, or +44 1625 545 745 if calling from outside the UK.

We would appreciate the opportunity to resolve your concern first, so please contact us before approaching a regulator.

Questions about your personal data?

Our team is happy to help you exercise your data protection rights, understand this policy, or discuss how we handle your information.