Legal

Data Processing Agreement

Last updated: 15 August 2026 · Version 1.0

This agreement sets out the terms required by Article 28 of the UK GDPR for our processing of personal data on behalf of our customers. It applies automatically to every Carelo customer contract and forms part of our Terms of Service — no separate signature is required, although we will provide a countersigned copy on request. How we handle data for which we are ourselves the controller is described in our Privacy Policy.

1. Definitions

Terms defined in our Terms of Service have the same meaning here. In addition:

"Data Protection Law"
The UK General Data Protection Regulation as it forms part of the law of England and Wales by virtue of the European Union (Withdrawal) Act 2018, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any other data protection or privacy legislation applicable in the United Kingdom, in each case as amended or replaced.
"Controller", "Processor", "Data Subject", "Personal Data", "Special Category Data", "Personal Data Breach", "Processing"
Have the meanings given to them in Data Protection Law.
"Customer Personal Data"
All Personal Data that we process on the Customer's behalf in the course of providing Carelo, as described in Annex I.
"Sub-Processor"
Any processor engaged by us to process Customer Personal Data on our behalf, as listed in Annex III.
"Restricted Transfer"
A transfer of Customer Personal Data to a country or international organisation outside the United Kingdom that is not covered by UK adequacy regulations.
"IDTA"
The International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018, or the UK Addendum to the European Commission's Standard Contractual Clauses, as applicable.

2. Roles of the Parties

The Customer is the Controller of Customer Personal Data. Myfinity Ltd is the Processor. This means the Customer decides what personal data is recorded in Carelo, why, on what lawful basis, and for how long — and we process it only to provide the service the Customer has bought.

The Customer confirms that it has a lawful basis for the processing it instructs, that it has satisfied the additional conditions applying to health and other Special Category Data, that it has provided the required privacy information to service users, family contacts and staff, and that the instructions it gives us comply with Data Protection Law.

Where we process personal data for our own purposes — running our business, administering accounts, taking payment, providing support, marketing to care providers and keeping our platform secure — we act as a Controller in our own right. That processing is governed by our Privacy Policy and is outside the scope of this agreement.

Nothing in this agreement makes us a joint controller with the Customer, and we do not determine the purposes of processing Customer Personal Data.

3. Scope, Subject Matter and Duration

This agreement applies to all processing of Customer Personal Data carried out by us in providing Carelo, including any migration of the Customer's data from a previous system and any support work carried out at the Customer's request.

The subject matter, duration, nature and purpose of the processing, the categories of Data Subject and the types of Personal Data are set out in Annex I.

This agreement takes effect when the Customer's Carelo account is activated and continues for as long as we process Customer Personal Data, including through any post-termination export or deletion window described in section 12.

If any conflict arises between this agreement and the Terms of Service in relation to the processing of Customer Personal Data, this agreement prevails.

4. Processing on Documented Instructions

We will process Customer Personal Data only on the Customer's documented instructions, including in relation to transfers outside the United Kingdom, unless we are required to process it by law — in which case we will inform the Customer of that legal requirement before processing, unless the law prohibits us from doing so on important grounds of public interest.

The Customer's documented instructions consist of:

  1. this agreement and the Terms of Service;
  2. the Customer's use and configuration of the Carelo platform and its mobile applications, including the permissions it sets, the family access it grants and the exports it runs;
  3. any additional written instruction the Customer gives us — for example a support request, a migration instruction or a request for an export or deletion.

We will tell the Customer if, in our opinion, an instruction infringes Data Protection Law. We may decline to act on such an instruction until it is resolved.

We do not use Customer Personal Data for our own purposes. Specifically, we do not sell it, do not use it for advertising, do not use it for product analytics in identifiable form, and do not use it — or permit any Sub-Processor to use it — to train artificial intelligence or machine learning models.

5. Confidentiality of Personnel

We ensure that every person authorised to process Customer Personal Data is bound by an appropriate duty of confidentiality, whether by contract of employment, contract for services or statutory obligation, and that the duty survives the end of their engagement.

Access to Customer Personal Data is limited to those personnel who genuinely need it to provide, support or secure the service, and only for as long as they need it.

6. Security of Processing

Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks to the rights and freedoms of the people whose data this is, we implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk.

Those measures are set out in Annex II. We may update them from time to time, provided the level of protection is not reduced.

The Customer is responsible for the security measures within its own control — configuring roles and permissions correctly, giving each person their own named login, removing access promptly when staff leave or change role, securing its own devices, and choosing appropriately who may see a service user's record.

We hold no external security certification at the date of this agreement and we make no claim to any. We are registered with the Information Commissioner's Office (registered 25 August 2026, application reference C2015753).

7. Sub-Processors

The Customer gives general written authorisation for us to engage the Sub-Processors listed in Annex III, and any replacement or additional Sub-Processor notified in accordance with this section.

Where we engage a Sub-Processor, we impose on it by written contract data protection obligations that are no less protective than those set out in this agreement. We remain fully liable to the Customer for the performance of each Sub-Processor's obligations.

We will give the Customer notice before adding or replacing any Sub-Processor, by email to the Customer's account contact or by notice inside Carelo, describing the new provider and what it will do. The Customer may object on reasonable grounds relating to data protection within 30 days of the notice.

If the Customer objects, we will work in good faith to find a solution — for example by offering an alternative provider or a configuration that avoids the new Sub-Processor. If no reasonable solution can be found, the Customer may terminate the affected part of the service, and we will refund any prepaid fees covering the period after termination.

Anthropic processes Customer Personal Data only where the Customer has enabled the optional Carelo AI add-on. A Customer that has not enabled the add-on has no data processed by Anthropic at all.

8. International Transfers

Our production database and file storage are located in an EU region. Some Sub-Processors are established outside the United Kingdom or may process Customer Personal Data outside it.

We will not make a Restricted Transfer of Customer Personal Data unless an appropriate safeguard recognised by Data Protection Law is in place. In practice this means that the transfer is covered by UK adequacy regulations, or is made under the IDTA, or under the UK Addendum to the European Commission's Standard Contractual Clauses, supported by a transfer risk assessment where one is required.

The Customer authorises us to enter into such transfer mechanisms with Sub-Processors on its behalf as its agent, where that is necessary to give effect to this section. We will provide details of the safeguards applying to a particular transfer on written request.

9. Assistance With Data Subject Rights

Carelo is built so that the Customer can meet most requests itself. Every module exports to Word, Excel and PDF, records can be searched and viewed on screen, and the Customer can correct, restrict or remove information subject to the record-integrity rules described in section 12.

Taking into account the nature of the processing, we will assist the Customer by appropriate technical and organisational measures, so far as is possible, in fulfilling its obligation to respond to requests to exercise rights of access, rectification, erasure, restriction, portability and objection.

If we receive a request directly from a Data Subject relating to Customer Personal Data, we will not respond to it substantively. We will confirm receipt, forward the request to the Customer without undue delay, and tell the Data Subject that we have done so and that the Customer is the Controller.

Assistance under this section is provided at no charge unless a request requires significant bespoke engineering effort, in which case we will agree a reasonable charge with the Customer in advance.

10. Assistance With DPIAs and Security Obligations

Taking into account the nature of the processing and the information available to us, we will provide the Customer with reasonable assistance in complying with its obligations under Articles 32 to 36 of the UK GDPR — security of processing, breach notification to the Information Commissioner and to Data Subjects, data protection impact assessments, and prior consultation with the Commissioner.

In practice this means we will supply, on reasonable request, a description of our security measures, the information in these annexes, details of our Sub-Processors and transfer safeguards, and a written response to a reasonable security or DPIA questionnaire.

11. Personal Data Breaches

We will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification will be sent to the Customer's account contact by email.

Our notification will describe, so far as we know it at the time:

  • the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned;
  • the likely consequences of the breach;
  • the measures we have taken or propose to take to address it and to mitigate its effects;
  • a point of contact for further information.

Where we cannot provide all of that information at once, we will provide it in phases as it becomes available, without further undue delay. We will cooperate with the Customer and take the reasonable steps it directs to assist in its investigation and remediation.

It is the Customer, as Controller, who decides whether a breach must be reported to the Information Commissioner or communicated to Data Subjects, and who makes that report. We will not make such a report on the Customer's behalf unless the Customer asks us to in writing.

12. Deletion or Return of Personal Data

At the Customer's choice, we will delete or return all Customer Personal Data at the end of the provision of services, and delete existing copies, unless we are required by law to keep it.

In practice:

  1. The Customer's data remains available for export for 30 days after the agreement ends, so the Customer can take a complete copy using the platform's own exports.
  2. On written request within that window, we will provide a structured export in a commonly used machine-readable format at no charge.
  3. At the end of the 30-day window, or earlier if the Customer instructs us to delete immediately, we delete Customer Personal Data from our production systems.
  4. Encrypted backups are held on a rolling cycle and are overwritten in the ordinary course. Data persisting only in backups is not used for any purpose and is deleted as those backups expire.
  5. Where the law requires us to retain particular records — for example billing records for tax purposes — we retain only what is necessary, for no longer than required, and continue to protect it under this agreement.

The Customer should be aware that delivered care records are locked once a check-in exists. This is a deliberate integrity measure: it prevents evidence of care that has actually been delivered from being silently altered or removed. It does not prevent lawful erasure at the end of the relationship, or erasure that the Customer instructs as Controller; it means corrections during the life of the contract are recorded as additions with an audit trail rather than as overwrites.

13. Audits and Information

We will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations in Article 28 of the UK GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.

Because Carelo is a shared multi-tenant platform, audits are subject to the following reasonable conditions:

  • the Customer gives at least 30 days' written notice, except where an audit follows a Personal Data Breach affecting the Customer, when a shorter period may be agreed;
  • audits take place no more than once in any twelve-month period, unless required by a regulator or following a Personal Data Breach;
  • audits are conducted during UK business hours, in a way that does not disrupt our operations or the service other customers receive;
  • the auditor is not a competitor of ours and signs a reasonable confidentiality undertaking;
  • no audit gives access to another customer's data, to any data belonging to a third party, or to our own commercially confidential information beyond what is necessary;
  • we may satisfy an audit request by providing written responses, our security documentation and these annexes, where doing so reasonably addresses the Customer's questions.

Each party bears its own costs, except that we may charge a reasonable fee for an on-site audit that requires significant time from our team.

14. Liability

Liability under this agreement is subject to, and counts towards, the exclusions and limitations set out in section 18 of our Terms of Service. The limits there apply to the parties' aggregate liability under the Terms of Service and this agreement taken together, and are not cumulative.

Nothing in this section limits or excludes either party's liability where it cannot lawfully be limited or excluded, or affects any right of a Data Subject under Article 82 of the UK GDPR.

15. General and Governing Law

This agreement applies automatically to every Carelo customer contract and requires no separate signature. A customer who needs a countersigned copy for its own records may request one at support@carelo.co.uk.

We may update this agreement to reflect a change in the law, a change in our Sub-Processors or a change in our security measures, provided the level of protection for Customer Personal Data is not reduced. Material changes will be notified to customers with at least 30 days' notice, and the version number and date at the top of this page will change.

If any provision is found to be unenforceable, the rest continues in force. This agreement, and any dispute or claim arising out of or in connection with it, is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Annex IDetails of the Processing

Parties

ControllerThe Customer — the care provider organisation subscribing to Carelo, as identified in its account records.
ProcessorMyfinity Ltd, registered in England and Wales, company number [Company No. — to be inserted], registered office [Registered office address — to be inserted]. Contact: support@carelo.co.uk

Subject Matter, Nature and Purpose

Subject matterThe provision of the Carelo care management platform and its mobile applications to the Customer.
Nature of the processingCollection, recording, organisation, structuring, storage, retrieval, consultation, use, alignment, transmission, export, restriction, erasure and destruction of Customer Personal Data by automated means, as directed by the Customer through its use of the platform.
Purpose of the processingTo enable the Customer to plan, deliver, monitor, evidence and govern the care it provides — scheduling and rota management, live call monitoring and GPS check-in, medication administration records, case notes and handovers, incident and body map reporting, timesheets, holidays and availability, supervision and compliance tracking, messaging, branded exports and reporting, family access to a single service user's record, and, where the Customer has enabled it, the optional Carelo AI assistant operating on the Customer's own records.
DurationFor the term of the Customer's subscription, plus the post-termination export and deletion window described in section 12.
FrequencyContinuous, for as long as the Customer uses the service.

Categories of Data Subject

  • Service users — the people receiving care from the Customer.
  • Family contacts and representatives — next of kin, named contacts, attorneys and deputies, and family members granted access to a service user's record.
  • Care staff — carers and support workers employed or engaged by the Customer.
  • Office staff — managers, care co-ordinators and administrators of the Customer.
  • Other individuals recorded in care records — such as GPs, district nurses, social workers, pharmacists and other professionals named in notes, incidents or care plans.

Categories of Personal Data

  • Identity and contact data — names, dates of birth, addresses, telephone numbers, email addresses, service user reference numbers, next-of-kin details.
  • Care planning data — care plans, assessments, risk assessments, preferences, capacity and consent notes, documents uploaded by the Customer.
  • Care delivery data — scheduled and delivered visits, planned and actual times, check-in and check-out records, visit outcomes, tasks completed.
  • Location data — GPS coordinates captured at carer check-in and check-out for geofence verification, service user home addresses and geocoded locations, and routed journeys shown on the Care Map.
  • Notes and reports — case notes, handovers, incident reports, body map reports, complaints and reviews.
  • Employment data of care staff — roles, availability, working hours, timesheets, holidays, sickness, training, supervision, spot checks and appraisals.
  • Account and authentication data — login email addresses, hashed passwords, roles and permissions, device tokens for push notifications, activity and audit records.
  • Communications — messages between the office and carers, and between the office and family members.

Special Category and Criminal Offence Data

The processing includes Special Category Data concerning health, which is inherent in the delivery of care: medical conditions and diagnoses, medication administration records including refusals and missed doses, mobility and continence needs, mental capacity, allergies, wounds and skin integrity recorded on body maps, and clinical observations recorded by carers. Depending on what the Customer records, it may also include data revealing racial or ethnic origin, religious or philosophical beliefs, and data concerning sex life or sexual orientation, where relevant to a person's care and preferences.

The Customer may also record safeguarding information which could constitute criminal offence data. All such processing is carried out solely on the Customer's instructions, and it is the Customer's responsibility to identify the Article 9 condition and, where relevant, the Schedule 1 condition in the Data Protection Act 2018 on which it relies.

Annex IITechnical and Organisational Security Measures

The measures below are those we implement as Processor. They may be updated from time to time provided the level of protection is not reduced.

Encryption

  • All traffic between browsers, mobile apps and our servers is encrypted in transit using industry-standard TLS. Plain HTTP is redirected to HTTPS.
  • Data at rest is encrypted at the infrastructure layer by our database, storage and hosting providers.
  • User passwords are stored only as salted hashes. They are never stored in a readable form and cannot be recovered by us or by our staff.

Access Control

  • Role-based access control, so that each user sees only what their role in the Customer's organisation requires.
  • Row-level security enforced in the database, so that authorisation is applied at the data layer and not only in the user interface.
  • Per-company data isolation — every record is scoped to the company that owns it, and one company's users cannot reach another company's data.
  • Carer scoping — a carer using the mobile app sees only their own visits and the service users they are assigned to, never a company-wide list.
  • Family scoping — a family user sees exactly one service user's record and nothing else.
  • Named individual logins with self-service password reset by verified email; shared logins are prohibited by the Terms of Service.

Storage and Keys

  • Uploaded files are held in private storage buckets. They are never publicly readable and are served only through short-lived signed URLs issued to an authorised user.
  • Least-privilege service keys: privileged credentials are held server-side only and are never shipped in client applications or mobile bundles.
  • Secrets and credentials are stored in the hosting provider's managed environment configuration, not in source code.

Integrity and Audit

  • Audit trails on care records, recording who did what and when.
  • Delivered care is locked once a check-in exists: such records cannot be cancelled, deleted or reassigned, and bulk operations skip them and report the exceptions.
  • Corrections to delivered care are recorded as additions with attribution, rather than as silent overwrites.
  • Timestamps are recorded and displayed consistently as UK wall-clock times, so that recorded times cannot drift with time-zone conversion.

Resilience and Backup

  • Regular managed backups of the production database, held encrypted by our database provider.
  • Managed, monitored hosting with the ability to restore the service from backup.
  • Application and infrastructure logging to support fault diagnosis and security investigation.

Organisational Measures

  • Access to production data is limited to personnel who need it to provide, support or secure the service.
  • All personnel with access are bound by written confidentiality obligations that survive their engagement.
  • Written contracts with every Sub-Processor imposing data protection obligations no less protective than those in this agreement.
  • A defined process for identifying, assessing and notifying Personal Data Breaches, as described in section 11.
  • Change control through version-controlled source code and an automated test suite covering the scheduling and record-integrity rules that protect care evidence.

Measures Within the Customer's Control

  • Assigning appropriate roles and permissions, and reviewing them regularly.
  • Issuing a named login to each person and removing access promptly when someone leaves or changes role.
  • Deciding which family members may access a service user's record, and withdrawing that access when it is no longer appropriate.
  • Securing the devices on which Carelo is used, including screen locks and device encryption.

Annex IIIAuthorised Sub-Processors

The following Sub-Processors are authorised in accordance with section 7. We will give notice before adding or replacing any of them, and the Customer may object on reasonable grounds.

Sub-ProcessorProcessing activityLocation of processing
SupabaseDatabase and file storage for all platform dataHosted on Amazon Web Services infrastructure, EU region
VercelHosting and delivery of the Carelo web applicationGlobal edge infrastructure, under UK-approved transfer safeguards
StripePayment processing and subscription billingUK, EU and United States, under UK-approved transfer safeguards
ResendDelivery of transactional email — invitations, password resets, billing and service noticesUnited States, under UK-approved transfer safeguards
AnthropicAI processing for the optional Carelo AI add-on only. Engaged solely for customers who enable the add-on. No customer data is used to train modelsUnited States, under UK-approved transfer safeguards
GeoapifyAddress lookup, geocoding and travel-time calculation for scheduling and route planningEuropean Union
MapboxMap rendering for the Care MapUnited States, under UK-approved transfer safeguards
ExpoDelivery of push notifications to the Carelo mobile appUnited States, under UK-approved transfer safeguards
Apple App StoreDistribution of the Carelo mobile app to iOS devicesUnited States and global, under UK-approved transfer safeguards
Google PlayDistribution of the Carelo mobile app to Android devicesUnited States and global, under UK-approved transfer safeguards

Where a Sub-Processor is located outside the United Kingdom, the transfer is made under an appropriate safeguard as described in section 8. Details of the safeguard applying to a particular Sub-Processor are available on written request to support@carelo.co.uk.