PRIVACY & DATA PROTECTION POLICY
​
Effective Date: 19/08/2026
Data Controller: The Care Lens (Partnership) Â
Lead Data Contact: Kimberley (kimberley@thecarelens.co.uk) Â
ICO Registration Status: ZC211435Â Â
----------------------------------------------------------------------
1. IMPORTANT INFORMATION & WHO WE ARE
The Care Lens ("we," "our," or "us") is an independent care advisory consultancy committed to protecting the privacy, dignity, and personal data of the families and individuals we support.Â
This Privacy Policy details how we collect, use, store, and safeguard your personal and sensitive health data when you use our website, communicate with us, engage our advisory services, or subscribe to our updates.
----------------------------------------------------------------------
2. INFORMATION WE COLLECT
To provide tailored care guidance and advocacy, we collect and process the following information:
* Standard Personal Data: Names, email addresses, phone numbers, home addresses, and communication preferences.
* Special Category Data (Health & Care Details): Physical or mental health conditions (including dementia diagnoses), daily living needs, care plans, local authority funding status, and existing care support structures.
* Financial Data: Transaction records for booked consultation slots. (Note: All payments are processed via secure payment link providers; we never store or process credit card numbers directly).
* Technical Data: Basic website interaction data (e.g., IP address, browser type) to ensure site security and functionality.
----------------------------------------------------------------------
3. HOW WE COLLECT & DIGITIZE YOUR DATA
* Direct Consultations: Initial details may be shared during phone calls, video consultations (e.g., Skype), or face-to-face meetings. Initial handwritten notes taken during these meetings are digitized and processed using secure AI tools to create structured care summaries.
* Digital Forms & Email: Submissions via our website contact forms or direct email inquiries.
* Authorized Third Parties: Information provided on your behalf by family members, legal representatives, or professional care services.
----------------------------------------------------------------------
4. OUR LEGAL BASES FOR PROCESSING UNDER UK GDPR
* Consent (Article 6(1)(a)): When you fill out an inquiry form or opt in to our newsletter.
* Contractual Performance (Article 6(1)(b)): Processing necessary to provide our care advisory packages and facilitate booking allocations via secure payment links.
* Legal Obligation (Article 6(1)(c)): Retaining required financial and business records for UK tax and regulatory compliance.
* Explicit Consent for Health Data (Article 9(2)(a) & Article 9(2)(h)): Special Category Health Data is processed strictly with your explicit consent and for the provision and management of social care advisory support.
----------------------------------------------------------------------
5. PRACTICAL THIRD-PARTY SHARING (FAMILY ADVOCACY)
We will never sell, rent, or trade your personal or health data to care homes, marketing agencies, or data brokers.Â
To act effectively on your family’s behalf, we may—strictly with your authorization—share relevant details with trusted third parties, including:
* NHS teams, hospital discharge departments, and GPs.
* Social services and local authority care assessors.
* Care home managers and domiciliary care providers.
* Care equipment, adaptation, and fitting services.
* Private ambulance and non-emergency transport services.
* Legal advisors (Power of Attorney specialists) and independent financial advisors.
* Funeral directors and end-of-life care providers.
----------------------------------------------------------------------
6. TECHNICAL SECURITY & DATA STORAGE
* Google Workspace Infrastructure: All electronic client records, digitized notes, and email communications are hosted in a secure, enterprise-grade Google Workspace environment featuring AES-256 bit encryption in transit and at rest.
* Access Security: Systems are protected by strict access controls and Mandatory Multi-Factor Authentication (2FA).
* Physical Protection: Handwritten consultation notes are securely digitized and disposed of using confidential destruction methods.
----------------------------------------------------------------------
7. DATA RETENTION & POST-BEREAVEMENT "LOCK & KEY" STANDARD
* General Client Records: Retained for up to 7 years following the end of our service agreement to satisfy UK statutory business, legal, and accounting standards.
* Post-Bereavement Protection (7.1): We treat the privacy and memory of every individual with deep respect following their passing. Upon notification of a client’s death:
 - Records are immediately archived into a restricted, encrypted "Vault" accessible only by authorized co-founders.
 - Confidentiality is strictly maintained; data is only disclosed if requested by a legally recognized Executor of the Estate or as required by law.
 - Following the statutory 7-year retention period, all associated records are permanently erased using digital destruction procedures.
----------------------------------------------------------------------
8. EMAIL CAMPAIGNS & NEWSLETTERS
We send regular educational emails, care guides, and advisory updates (2–3 times per week) to subscribers who have explicitly opted in.Â
* You can easily unsubscribe at any time by clicking the "Unsubscribe" link at the bottom of any campaign email or by contacting kimberley@thecarelens.co.uk.
----------------------------------------------------------------------
9. YOUR INDIVIDUAL RIGHTS
Under UK GDPR, you have the right to request access to your data, request corrections, request erasure ("Right to be Forgotten"), or withdraw your consent for health data processing at any time.
For any data queries, email Kimberley at kimberley@thecarelens.co.uk. You also have the right to lodge a concern with the Information Commissioner's Office (ICO) at www.ico.org.uk.
Â

