Legal

Privacy Policy

Last updated: 15 August 2026 · Version 1.0

This policy explains how Myfinity Ltd, the company behind Carelo, handles personal data. It covers our website, our marketing, and the accounts our customers hold with us. Where we handle the care records our customers keep inside Carelo, we do so as their processor, on their instructions — those arrangements are set out in our Data Processing Agreement. Our commercial terms are in our Terms of Service.

1. Who We Are

Carelo is a care management platform for UK domiciliary and community care providers. It is operated by Myfinity Ltd, a company registered in England and Wales.

  • Company: Myfinity Ltd
  • Company number: [Company No. — to be inserted]
  • Registered office: [Registered office address — to be inserted]
  • Contact for all privacy matters: support@carelo.co.uk

We are registered with the Information Commissioner's Office (registered 25 August 2026, application reference C2015753; new entries appear on the ICO's public register once processed). We hold no external security or quality certifications at the date of this policy and we make no claim to any; where that changes, we will say so on this page rather than imply it elsewhere.

2. When We Are a Controller and When We Are a Processor

This distinction matters, because it decides who you should approach about your data.

We Are the Controller For

  • information submitted through our website — demo requests, walkthrough requests, onboarding enquiries and migration enquiries;
  • the account and billing information of our customers, and the contact details of the people who administer those accounts;
  • emails and support conversations you have with us;
  • technical logs generated when you visit our website or use our platform;
  • our marketing to care providers.

We Are a Processor For

The care records held inside a customer's Carelo environment — service user records, care plans, visit records, case notes, medication records, incidents, body maps, staff records and messages. For all of that data, the care provider is the controller and we act only on its documented instructions.

If you are a service user, a family member or a member of care staff and you want to know what is held about you, or you want it corrected or erased, please contact the care provider that supports you. They decide what is recorded and what happens to it. If you contact us instead, we will pass your request to that provider and tell you we have done so; we cannot act on care records without their instruction.

The terms on which we process care records — including our security measures, our sub-processors and what happens when a contract ends — are set out in full in our Data Processing Agreement.

3. The Information We Collect

Information You Give Us Through the Website

Our website has forms for booking a demo, requesting a walkthrough, starting onboarding and asking about migration. Through those forms we typically collect your name, your role, your organisation's name, your email address, your telephone number, the approximate size of your care team, and whatever you choose to tell us in a free-text message.

Account Information

When your organisation becomes a customer we hold the details needed to run the account: the organisation's name and address, the named administrator and billing contact, the email addresses of office users, your chosen plan and band, your active-carer count for billing, whether the Carelo AI add-on is enabled, and your invoice history.

Payment details are handled by Stripe. We do not hold full card numbers or bank details on our own systems; we hold a payment reference, the outcome of each payment, and the last four digits of a card where Stripe provides it.

Support Correspondence

When you email us we keep the message, our reply, and any attachments, so that we have a record of what was asked and what we did about it.

Technical Information

Our hosting and infrastructure providers generate server logs when the website and platform are used. These typically include an IP address, the time of the request, the page or endpoint requested, the browser and device type, and error information. We use them to keep the service running, to investigate faults and to detect abuse.

Information We Do Not Collect

We do not buy personal data from data brokers, we do not build advertising profiles, and we do not run behavioural tracking on our marketing site.

4. Why We Use It, and Our Lawful Bases

What we doInformation usedLawful basis
Respond to a demo, walkthrough, onboarding or migration enquiryForm details, correspondenceLegitimate interests — replying to a business enquiry you have made; steps at your request prior to entering a contract
Provide and administer the Carelo platform to a customerAccount and user details, technical logsPerformance of a contract
Take payment and issue invoicesBilling contact, plan, band, payment referencesPerformance of a contract; legal obligation for accounting records
Provide support and fix faultsCorrespondence, technical logs, account detailsPerformance of a contract; legitimate interests in supporting our customers well
Keep the service secure, prevent abuse and investigate incidentsTechnical logs, account activityLegitimate interests in protecting our customers and our platform; legal obligation for personal data security
Send service messages — renewal reminders, billing notices, changes to terms, security noticesAccount contact detailsPerformance of a contract; legal obligation
Send marketing about Carelo to care providersBusiness contact detailsConsent, or legitimate interests in marketing to an existing business customer — with an unsubscribe link in every message
Improve the product using aggregated, non-identifying usage informationAggregated counts and error ratesLegitimate interests in improving the service
Establish, exercise or defend legal claimsWhatever is relevant to the claimLegitimate interests; legal obligation

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and freedoms, and we have concluded it is not. You may object to that processing at any time — see section 10.

We never use customer care records for our own marketing, product analytics or model training.

5. Cookies and Local Storage

We will be straightforward about this, because most privacy policies are not.

Our marketing website sets no advertising cookies and no analytics cookies. There is no Google Analytics, no advertising pixel, no social media tracker and no third-party profiling script on the pages you are reading. That is why you have not been shown a consent banner: there is nothing to consent to.

The only browser storage involved in the marketing site is essential or functional — for example, remembering a preference you have set on a page during your visit. Fonts are loaded from Google Fonts, which means your browser makes a request to Google's font servers and Google receives your IP address as part of that request.

Inside the Carelo application itself, essential cookies and browser storage are used to keep you signed in, to keep your session secure, and to remember interface preferences such as filters. These are strictly necessary for the service to work and cannot be switched off while you are using it.

If we ever introduce analytics or any non-essential cookie, we will ask for your consent first and update this section before doing so.

6. Who We Share Information With

We do not sell personal data and we do not share it for anyone else's marketing. We use a small number of carefully chosen service providers to run Carelo. Each one is bound by a written contract, may act only on our instructions, and is subject to appropriate confidentiality and security obligations.

ProviderWhat it does for us
SupabaseDatabase and file storage for the platform, hosted on Amazon Web Services infrastructure in an EU region
VercelHosting and delivery of the Carelo web application and this website
StripePayment processing and subscription billing
ResendDelivery of transactional email — account invitations, password resets, billing and service notices
AnthropicAI processing, only for customers who have enabled the optional Carelo AI add-on. Data sent for AI processing is not used to train models. Customers who do not enable the add-on have no data processed by Anthropic at all
GeoapifyAddress lookup, geocoding and travel-time calculation for scheduling and route planning
MapboxMap display on the Care Map
ExpoDelivery of push notifications to the Carelo mobile app
Apple App Store and Google PlayDistribution of the Carelo mobile app to iOS and Android devices

We may also disclose information to our professional advisers, to a purchaser or successor of our business, and to a regulator, court or law enforcement body where we are legally required to do so. Where a legal disclosure concerns a customer's care records, we will notify that customer unless the law forbids it.

The same list operates as our authorised sub-processor list for customer care records. We will give notice before adding or replacing a sub-processor, and customers may object on reasonable grounds — see the DPA.

7. International Transfers

Our database and file storage sit in an EU region. Some of the providers listed above are established outside the United Kingdom, or may process data outside it — for example for support, monitoring or content delivery.

Where personal data is transferred outside the UK, we make sure that one of the safeguards recognised by UK data protection law is in place. In practice that means the destination is covered by UK adequacy regulations, or the transfer is made under the International Data Transfer Agreement, or under the UK Addendum to the European Commission's Standard Contractual Clauses, supported by a transfer risk assessment where one is required.

You may ask us for information about the safeguards that apply to a particular transfer by writing to support@carelo.co.uk.

8. How Long We Keep Information

InformationRetention
Website enquiries that do not become customersUp to 24 months from the last contact, then deleted
Customer account and user recordsFor the life of the contract, then deleted or returned within 30 days of termination
Care records held on a customer's behalfOn the customer's instructions; deleted or returned within 30 days of termination, as set out in the DPA
Invoices, payment records and accounting dataSix years after the end of the financial year they relate to, to meet UK tax and company law requirements
Support correspondenceUp to 24 months after the matter is closed
Technical and security logsTypically up to 12 months, longer only where an investigation requires it
Marketing contactsUntil you unsubscribe or object, and then only a minimal suppression record so that we do not contact you again

Where we are required to keep information for a longer period by law, or need it to establish or defend a legal claim, we keep only what is necessary for that purpose and nothing more.

9. How We Protect Information

We take security seriously because the data our customers hold is among the most sensitive there is. Our measures include:

  • encryption of data in transit using industry-standard TLS across the website, the platform and the mobile apps;
  • encryption of stored data at the infrastructure layer by our hosting and database providers;
  • passwords stored only as salted hashes — we never hold them in a readable form and cannot tell you what yours is;
  • role-scoped access, so that each user sees only what their role requires;
  • row-level security in the database, so that a company's records are isolated from every other company's at the data layer rather than only in the interface — carers see only their own visits, and a family member sees only the one person they are connected to;
  • private file storage with time-limited signed links rather than publicly readable files;
  • least-privilege service credentials, kept out of client applications;
  • audit trails on care records, with delivered-care records locked once a check-in exists so that evidence cannot be quietly rewritten;
  • regular managed backups of the production database;
  • a small team, with access to production limited to those who need it.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to people's rights and freedoms, we will notify the ICO within 72 hours where we are the controller, and we will notify affected customers without undue delay where we are the processor, so that they can meet their own obligations.

10. Your Rights

Where we are the controller of your personal data, you have the right to:

  • be told how your data is used — which is what this policy is for;
  • ask for a copy of the personal data we hold about you;
  • have inaccurate data corrected, and incomplete data completed;
  • ask for your data to be deleted, where we have no continuing lawful reason to keep it;
  • ask us to restrict how we use your data while a question about it is resolved;
  • object to processing we carry out on the basis of legitimate interests, and to object at any time to direct marketing;
  • receive certain data in a portable, machine-readable format, or ask us to transmit it to another provider;
  • withdraw consent at any time, where we relied on consent — this does not affect anything done before you withdrew it.

To exercise any of these rights, email support@carelo.co.uk. We will respond within one month. If a request is particularly complex we may extend that by up to two further months, and we will tell you if that happens and why. We may need to verify your identity before we act, so that we do not disclose someone's data to the wrong person. There is no charge unless a request is manifestly unfounded or excessive.

If your request concerns care records held by a care provider using Carelo, please see section 2 — that provider is the controller, and we will forward your request to them.

11. Complaining to the ICO

If you are unhappy with how we have handled your personal data, please tell us first at support@carelo.co.uk. We would rather hear about it and put it right.

You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, at any time. You can reach the ICO at ico.org.uk, by telephone on 0303 123 1113, or by post at Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

12. Children's and Vulnerable Adults' Data

Carelo is a business tool sold to care organisations. It is not directed at children, and we do not knowingly collect children's personal data through our website or our marketing.

Care records held inside Carelo will, by their nature, include personal data about vulnerable adults and may include health data and other special category data. All of that data is processed strictly as a processor, on the documented instructions of the care provider who is the controller, under the terms of our Data Processing Agreement. We do not use it for any purpose of our own, we do not use it for analytics or product development, and we do not use it to train AI models.

Where a care provider chooses to give a family member access to a service user's record, that access is granted, configured and withdrawn by the care provider. Family access is scoped to a single service user.

13. Changes to This Policy

We will update this policy when our practices change, when we add or replace a service provider, or when the law requires it. The date and version at the top of the page will always tell you which version you are reading.

Where a change materially affects how we use personal data, we will give notice to our customers by email or inside Carelo before it takes effect. Changes to our sub-processor list are notified in advance in accordance with the DPA.

14. How to Contact Us

For any question about this policy, about the data we hold, or to exercise a right described in section 10:

  • Email: support@carelo.co.uk
  • Company: Myfinity Ltd, registered in England and Wales
  • Company number: [Company No. — to be inserted]
  • Registered office: [Registered office address — to be inserted]

We do not currently have a statutory obligation to appoint a Data Protection Officer. Privacy questions are handled directly by the company at the address above.