This agreement sets out the terms required by Article 28 of the UK GDPR for our processing of personal data on behalf of our customers. It applies automatically to every Carelo customer contract and forms part of our Terms of Service — no separate signature is required, although we will provide a countersigned copy on request. How we handle data for which we are ourselves the controller is described in our Privacy Policy.
Terms defined in our Terms of Service have the same meaning here. In addition:
The Customer is the Controller of Customer Personal Data. Myfinity Ltd is the Processor. This means the Customer decides what personal data is recorded in Carelo, why, on what lawful basis, and for how long — and we process it only to provide the service the Customer has bought.
The Customer confirms that it has a lawful basis for the processing it instructs, that it has satisfied the additional conditions applying to health and other Special Category Data, that it has provided the required privacy information to service users, family contacts and staff, and that the instructions it gives us comply with Data Protection Law.
Where we process personal data for our own purposes — running our business, administering accounts, taking payment, providing support, marketing to care providers and keeping our platform secure — we act as a Controller in our own right. That processing is governed by our Privacy Policy and is outside the scope of this agreement.
Nothing in this agreement makes us a joint controller with the Customer, and we do not determine the purposes of processing Customer Personal Data.
This agreement applies to all processing of Customer Personal Data carried out by us in providing Carelo, including any migration of the Customer's data from a previous system and any support work carried out at the Customer's request.
The subject matter, duration, nature and purpose of the processing, the categories of Data Subject and the types of Personal Data are set out in Annex I.
This agreement takes effect when the Customer's Carelo account is activated and continues for as long as we process Customer Personal Data, including through any post-termination export or deletion window described in section 12.
If any conflict arises between this agreement and the Terms of Service in relation to the processing of Customer Personal Data, this agreement prevails.
We will process Customer Personal Data only on the Customer's documented instructions, including in relation to transfers outside the United Kingdom, unless we are required to process it by law — in which case we will inform the Customer of that legal requirement before processing, unless the law prohibits us from doing so on important grounds of public interest.
The Customer's documented instructions consist of:
We will tell the Customer if, in our opinion, an instruction infringes Data Protection Law. We may decline to act on such an instruction until it is resolved.
We do not use Customer Personal Data for our own purposes. Specifically, we do not sell it, do not use it for advertising, do not use it for product analytics in identifiable form, and do not use it — or permit any Sub-Processor to use it — to train artificial intelligence or machine learning models.
We ensure that every person authorised to process Customer Personal Data is bound by an appropriate duty of confidentiality, whether by contract of employment, contract for services or statutory obligation, and that the duty survives the end of their engagement.
Access to Customer Personal Data is limited to those personnel who genuinely need it to provide, support or secure the service, and only for as long as they need it.
Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks to the rights and freedoms of the people whose data this is, we implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk.
Those measures are set out in Annex II. We may update them from time to time, provided the level of protection is not reduced.
The Customer is responsible for the security measures within its own control — configuring roles and permissions correctly, giving each person their own named login, removing access promptly when staff leave or change role, securing its own devices, and choosing appropriately who may see a service user's record.
We hold no external security certification at the date of this agreement and we make no claim to any. We are registered with the Information Commissioner's Office (registered 25 August 2026, application reference C2015753).
The Customer gives general written authorisation for us to engage the Sub-Processors listed in Annex III, and any replacement or additional Sub-Processor notified in accordance with this section.
Where we engage a Sub-Processor, we impose on it by written contract data protection obligations that are no less protective than those set out in this agreement. We remain fully liable to the Customer for the performance of each Sub-Processor's obligations.
We will give the Customer notice before adding or replacing any Sub-Processor, by email to the Customer's account contact or by notice inside Carelo, describing the new provider and what it will do. The Customer may object on reasonable grounds relating to data protection within 30 days of the notice.
If the Customer objects, we will work in good faith to find a solution — for example by offering an alternative provider or a configuration that avoids the new Sub-Processor. If no reasonable solution can be found, the Customer may terminate the affected part of the service, and we will refund any prepaid fees covering the period after termination.
Anthropic processes Customer Personal Data only where the Customer has enabled the optional Carelo AI add-on. A Customer that has not enabled the add-on has no data processed by Anthropic at all.
Our production database and file storage are located in an EU region. Some Sub-Processors are established outside the United Kingdom or may process Customer Personal Data outside it.
We will not make a Restricted Transfer of Customer Personal Data unless an appropriate safeguard recognised by Data Protection Law is in place. In practice this means that the transfer is covered by UK adequacy regulations, or is made under the IDTA, or under the UK Addendum to the European Commission's Standard Contractual Clauses, supported by a transfer risk assessment where one is required.
The Customer authorises us to enter into such transfer mechanisms with Sub-Processors on its behalf as its agent, where that is necessary to give effect to this section. We will provide details of the safeguards applying to a particular transfer on written request.
Carelo is built so that the Customer can meet most requests itself. Every module exports to Word, Excel and PDF, records can be searched and viewed on screen, and the Customer can correct, restrict or remove information subject to the record-integrity rules described in section 12.
Taking into account the nature of the processing, we will assist the Customer by appropriate technical and organisational measures, so far as is possible, in fulfilling its obligation to respond to requests to exercise rights of access, rectification, erasure, restriction, portability and objection.
If we receive a request directly from a Data Subject relating to Customer Personal Data, we will not respond to it substantively. We will confirm receipt, forward the request to the Customer without undue delay, and tell the Data Subject that we have done so and that the Customer is the Controller.
Assistance under this section is provided at no charge unless a request requires significant bespoke engineering effort, in which case we will agree a reasonable charge with the Customer in advance.
Taking into account the nature of the processing and the information available to us, we will provide the Customer with reasonable assistance in complying with its obligations under Articles 32 to 36 of the UK GDPR — security of processing, breach notification to the Information Commissioner and to Data Subjects, data protection impact assessments, and prior consultation with the Commissioner.
In practice this means we will supply, on reasonable request, a description of our security measures, the information in these annexes, details of our Sub-Processors and transfer safeguards, and a written response to a reasonable security or DPIA questionnaire.
We will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification will be sent to the Customer's account contact by email.
Our notification will describe, so far as we know it at the time:
Where we cannot provide all of that information at once, we will provide it in phases as it becomes available, without further undue delay. We will cooperate with the Customer and take the reasonable steps it directs to assist in its investigation and remediation.
It is the Customer, as Controller, who decides whether a breach must be reported to the Information Commissioner or communicated to Data Subjects, and who makes that report. We will not make such a report on the Customer's behalf unless the Customer asks us to in writing.
At the Customer's choice, we will delete or return all Customer Personal Data at the end of the provision of services, and delete existing copies, unless we are required by law to keep it.
In practice:
The Customer should be aware that delivered care records are locked once a check-in exists. This is a deliberate integrity measure: it prevents evidence of care that has actually been delivered from being silently altered or removed. It does not prevent lawful erasure at the end of the relationship, or erasure that the Customer instructs as Controller; it means corrections during the life of the contract are recorded as additions with an audit trail rather than as overwrites.
We will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations in Article 28 of the UK GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
Because Carelo is a shared multi-tenant platform, audits are subject to the following reasonable conditions:
Each party bears its own costs, except that we may charge a reasonable fee for an on-site audit that requires significant time from our team.
Liability under this agreement is subject to, and counts towards, the exclusions and limitations set out in section 18 of our Terms of Service. The limits there apply to the parties' aggregate liability under the Terms of Service and this agreement taken together, and are not cumulative.
Nothing in this section limits or excludes either party's liability where it cannot lawfully be limited or excluded, or affects any right of a Data Subject under Article 82 of the UK GDPR.
This agreement applies automatically to every Carelo customer contract and requires no separate signature. A customer who needs a countersigned copy for its own records may request one at support@carelo.co.uk.
We may update this agreement to reflect a change in the law, a change in our Sub-Processors or a change in our security measures, provided the level of protection for Customer Personal Data is not reduced. Material changes will be notified to customers with at least 30 days' notice, and the version number and date at the top of this page will change.
If any provision is found to be unenforceable, the rest continues in force. This agreement, and any dispute or claim arising out of or in connection with it, is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
| Controller | The Customer — the care provider organisation subscribing to Carelo, as identified in its account records. |
| Processor | Myfinity Ltd, registered in England and Wales, company number [Company No. — to be inserted], registered office [Registered office address — to be inserted]. Contact: support@carelo.co.uk |
| Subject matter | The provision of the Carelo care management platform and its mobile applications to the Customer. |
| Nature of the processing | Collection, recording, organisation, structuring, storage, retrieval, consultation, use, alignment, transmission, export, restriction, erasure and destruction of Customer Personal Data by automated means, as directed by the Customer through its use of the platform. |
| Purpose of the processing | To enable the Customer to plan, deliver, monitor, evidence and govern the care it provides — scheduling and rota management, live call monitoring and GPS check-in, medication administration records, case notes and handovers, incident and body map reporting, timesheets, holidays and availability, supervision and compliance tracking, messaging, branded exports and reporting, family access to a single service user's record, and, where the Customer has enabled it, the optional Carelo AI assistant operating on the Customer's own records. |
| Duration | For the term of the Customer's subscription, plus the post-termination export and deletion window described in section 12. |
| Frequency | Continuous, for as long as the Customer uses the service. |
The processing includes Special Category Data concerning health, which is inherent in the delivery of care: medical conditions and diagnoses, medication administration records including refusals and missed doses, mobility and continence needs, mental capacity, allergies, wounds and skin integrity recorded on body maps, and clinical observations recorded by carers. Depending on what the Customer records, it may also include data revealing racial or ethnic origin, religious or philosophical beliefs, and data concerning sex life or sexual orientation, where relevant to a person's care and preferences.
The Customer may also record safeguarding information which could constitute criminal offence data. All such processing is carried out solely on the Customer's instructions, and it is the Customer's responsibility to identify the Article 9 condition and, where relevant, the Schedule 1 condition in the Data Protection Act 2018 on which it relies.
The measures below are those we implement as Processor. They may be updated from time to time provided the level of protection is not reduced.
The following Sub-Processors are authorised in accordance with section 7. We will give notice before adding or replacing any of them, and the Customer may object on reasonable grounds.
| Sub-Processor | Processing activity | Location of processing |
|---|---|---|
| Supabase | Database and file storage for all platform data | Hosted on Amazon Web Services infrastructure, EU region |
| Vercel | Hosting and delivery of the Carelo web application | Global edge infrastructure, under UK-approved transfer safeguards |
| Stripe | Payment processing and subscription billing | UK, EU and United States, under UK-approved transfer safeguards |
| Resend | Delivery of transactional email — invitations, password resets, billing and service notices | United States, under UK-approved transfer safeguards |
| Anthropic | AI processing for the optional Carelo AI add-on only. Engaged solely for customers who enable the add-on. No customer data is used to train models | United States, under UK-approved transfer safeguards |
| Geoapify | Address lookup, geocoding and travel-time calculation for scheduling and route planning | European Union |
| Mapbox | Map rendering for the Care Map | United States, under UK-approved transfer safeguards |
| Expo | Delivery of push notifications to the Carelo mobile app | United States, under UK-approved transfer safeguards |
| Apple App Store | Distribution of the Carelo mobile app to iOS devices | United States and global, under UK-approved transfer safeguards |
| Google Play | Distribution of the Carelo mobile app to Android devices | United States and global, under UK-approved transfer safeguards |
Where a Sub-Processor is located outside the United Kingdom, the transfer is made under an appropriate safeguard as described in section 8. Details of the safeguard applying to a particular Sub-Processor are available on written request to support@carelo.co.uk.