Find a CareRight job.

Browse All

PRIVACY POLICY

Last updated: 12 June 2026

We use your personal and health information to provide safe and effective care.

This includes sharing information with professionals involved in your care and, where appropriate, securely accessing relevant GP record information using NHS systems such as GP Connect.

We only use information where necessary, keep it secure, and you have the right to ask questions or object to certain types of data sharing.

This privacy notice explains how CareRight Homecare Limited trading as CareRight (“CareRight”, “we”, “us”, “our”) collects, uses, stores and shares personal information when we provide home care and related services, operate our website, communicate with service users and families, and use digital care systems to help deliver safe and effective care. This notice is intended to meet our obligations under the UK GDPR, Data Protection Act 2018, the Common Law Duty of Confidentiality, the NHS GP Connect National Data Sharing Arrangement, and relevant adult social care requirements.

We are committed to handling personal information fairly, lawfully, securely and transparently. As an adult social care provider, we may process both personal information and special category data, including health and care information, where this is necessary to provide care, meet legal and regulatory obligations, safeguard people, and operate our services safely. Health and care providers must have a valid lawful basis under Article 6 and a valid condition under Article 9 of the UK GDPR when processing health data, and must also meet confidentiality requirements.

If you have any questions about this privacy notice or how we use your information, please contact us using the details in the Contact us section below. If you are receiving care from us, we can also explain this notice in a way that is easier to understand or provide support to help you make informed decisions, in line with CQC expectations around consent and communication.


1) Who we are

CareRight is a home care provider operating in Devon. Our website states that we provide in-home care services and use digital care systems, including CareLineLive, to help keep information up to date and visible to families where appropriate. Our website also lists the following contact locations: Newton Abbot, Bovey Tracey and Plymouth.

Data controller: CareRight Homecare Limited (trading as CareRight)
Reg No: 07250448
Registered office: Unit 1, Templer House Scott Close, Newton Abbot, Devon, TQ12 1GJ
Main contact email: hello@careright.co.uk
Data Protection Lead (DPL): Justin Huntington - justin.huntington@careright.co.uk


2) Whose information we use

We may process personal information about:

Where we provide regulated care, our handling of personal information is also relevant to our responsibilities under the Health and Social Care Act framework and CQC requirements, including the need to ensure people are informed and that care and treatment are provided with appropriate consent or lawful authority.


3) What information we collect

Depending on the service and your relationship with us, we may collect and use:

Where necessary, we may also process information about a person’s capacity to make decisions, whether there is a Health and Welfare Lasting Power of Attorney, Court-appointed Deputy, or other lawful representative, and who should be involved in best interests decision-making. CQC guidance makes clear that where a person lacks capacity, providers must act in accordance with the Mental Capacity Act 2005 and involve attorneys, deputies or other relevant people where appropriate.


4) Where we get information from

We collect most personal information directly from the person receiving care, from their family or representative, or through normal service delivery. We may also receive information from third parties where this is necessary and appropriate, including:

5) How we use personal information

We use personal information to:

Where we ask for consent in the course of care, we will give information in a way the person can understand and will seek consent lawfully. However, not all processing is based on consent. In health and social care, consent is not always the appropriate UK GDPR lawful basis for using information, and NHS guidance specifically warns against relying on GDPR consent as the primary legal basis for routine care processing by public authorities and care providers.


6) Our lawful bases for processing

Under the UK GDPR, we must have a lawful basis for processing personal data and an additional condition for processing health data. Depending on the purpose, we may rely on one or more of the following:

Article 6 lawful bases

Article 9 special category conditions

For health and care information, we may rely on:

We do not rely on consent as the main legal basis for routine direct care processing simply because someone is receiving care from us. This is particularly important for GP Connect and other direct care functions. NHS guidance states that for confidential patient information, the Common Law Duty of Confidentiality must also be met, and the NDSA specifically states for GP Connect that implied consent with opt out applies for direct care.


7) GP Connect and access to GP records

Where appropriate and where our systems and organisational approvals permit, we may access relevant information from a person’s GP record using NHS GP Connect to support their direct care. GP Connect is a secure NHS service that allows authorised health and social care professionals to view appropriate information from GP records through approved systems, subject to national data sharing requirements, role-based access controls and audit arrangements. Organisations using GP Connect must comply with the National Data Sharing Arrangement (NDSA) and update their transparency notices accordingly.

For social care providers, GP Connect is intended to support direct care only. Guidance for the adult social care sector explains that CQC-registered providers using assured digital care systems can access GP patient records where this is necessary, proportionate and governed properly. For non-clinical staff, access is generally limited to information such as allergies, medications, immunisations and the last three GP interactions, while clinical staff such as nurses may have broader access where appropriate for their role.

The legal basis for GP Connect is stated in the NDSA as Article 6(1)(e) and Article 9(2)(h) of the UK GDPR, and for the Common Law Duty of Confidentiality the NDSA states that implied consent with opt out is used. This means we do not normally need separate explicit written consent to use GP Connect for direct care, but we must tell people about it, only access information where necessary for their care, and respect any objection.

If you do not want your GP record to be shared with us through GP Connect, you should tell us and also tell your GP practice, as your GP practice is responsible for recording and applying relevant GP Connect sharing choices. We will respect your wishes and explain any practical implications for your care. GP Connect guidance and social care guidance both emphasise that organisations must honour an individual’s objection and provide transparent information materials.


8) Consent, capacity and acting on someone’s behalf

Care and treatment must only be provided with the consent of the relevant person, and when a person is asked for consent, information must be provided in a way they can understand. CQC Regulation 11 requires providers to obtain consent lawfully and to act in accordance with the Mental Capacity Act 2005 where a person lacks capacity to make a specific decision.

If a person is unable to make a particular decision, we will follow the Mental Capacity Act principles. This includes assuming capacity unless it is established otherwise, taking all practicable steps to support the person to decide, and if the person lacks capacity, consulting those who should be involved in a best interests decision such as family, attorneys, deputies or others interested in the person’s welfare, where appropriate and lawful.

If someone is acting on behalf of a person receiving care, for example under a Health and Welfare Lasting Power of Attorney, we may ask to see evidence of that authority. GOV.UK guidance confirms that health and welfare attorneys can only make decisions when the person lacks capacity for the relevant decision and may need to show their authority to care staff.


9) CareLineLive and our digital care systems

Our website states that CareRight uses CareLineLive to support communication and up-to-date care information, including visibility for families where appropriate. CareLineLive also publishes information explaining that it is certified to recognised standards including ISO 27001, the NHS Data Security and Protection Toolkit, and Cyber Essentials Plus, and that it uses encryption, backups, disaster recovery and regular testing.

Where we use CareLineLive or other digital care systems to store or process information on our behalf, those providers act as our data processors or technology suppliers, unless clearly acting as separate controllers for their own purposes. We use written agreements and organisational controls to ensure personal information is handled securely and only on our instructions, as required by UK GDPR accountability and processor obligations.

We may use digital systems for care records, rotas, medication support, family communications, reporting, auditing and secure information sharing. Access is restricted to authorised users and monitored to help ensure information is only accessed where necessary and proportionate. GP Connect access, where enabled through an approved solution, is also controlled through role-based access and audit mechanisms.


10) Who we share personal information with

We only share personal information where there is a valid reason to do so. Depending on the circumstances, we may share information with:

We do not sell personal information. We do not use GP Connect for marketing, profiling or unrelated business purposes. GP Connect is for direct care only, and the NDSA and GP Connect transparency guidance are explicit on this point.


11) National Data Opt-Out

The National Data Opt-Out allows people to opt out of their confidential patient information being used for purposes beyond their individual care, such as certain planning and research uses. It does not apply to information used to support individual care, and NHS guidance makes clear that opt-out policies for planning and research are different from direct care sharing arrangements such as GP record sharing for individual care.

As a CQC-registered adult social care provider, we review our processing activities to determine whether the National Data Opt-Out applies and will apply it where required by law and policy. If a processing activity falls within scope, we will take steps to comply with the opt-out policy.


12) How long we keep information

We keep personal information only for as long as necessary for the purposes we collected it for, including to provide care, meet legal and regulatory requirements, resolve complaints, defend legal claims, and maintain appropriate records. Different categories of information may be retained for different periods in line with legal requirements, NHS or social care records management guidance, contractual requirements and our internal retention schedule.

When information is no longer required, we will securely delete, destroy or anonymise it. Where deletion is not immediately possible, for example because records are held in secure backups, we will protect the information and limit any further use until deletion becomes possible.


13) How we keep information safe

We use appropriate technical and organisational security measures to protect personal information against accidental or unlawful loss, access, misuse, alteration or disclosure. This includes access controls, role-based permissions, staff training, device and account security, secure systems, backups, audit logs, and policies and procedures designed to handle personal information correctly. UK data protection guidance and NHS data security guidance both require organisations to apply appropriate safeguards and accountability controls.

The Data Security and Protection Toolkit (DSPT) is the NHS’s self-assessment tool against the National Data Guardian’s ten data security standards, and it applies to organisations that access NHS patient data and systems. Digital Care Hub also explains that the DSPT is the official self-assessment tool for the adult social care sector and is recognised by the CQC, local authorities and the NHS.

Where we use suppliers such as CareLineLive, we expect them to maintain appropriate security standards and controls. CareLineLive states that it is certified to ISO 27001, the NHS DSPT and Cyber Essentials Plus, and that it uses encryption, backups, failover, vulnerability scanning and disaster recovery measures.

If a personal data breach occurs, we will investigate it, take steps to contain and remediate it, and report it where required. NHS DSPT guidance explains that reportable incidents must be notified through the reporting tool and that notifiable personal data breaches must also be reported to the ICO without undue delay and, where applicable, within 72 hours.


14) Website, cookies and analytics

When you visit our website, we may automatically collect technical information such as IP address, browser type, device information, pages visited and similar usage information to help us operate, secure and improve the website. We may also use cookies and similar technologies. Information about this should be explained in a separate cookie notice or cookie policy.

You can usually control cookies through your browser settings. If you disable or block some cookies, certain website features may not work properly. For more detail, refer to our cookie policy.


15) Children and young people

If we provide services to children or young people, we may process their personal information where necessary to provide care and support, comply with safeguarding and legal duties, and communicate with those who have parental responsibility or another lawful role in the child’s care. We will handle children’s information with particular care and in line with data protection law and professional obligations. UK guidance recognises that children’s information requires appropriate protection and transparency.


16) Your rights

Under UK data protection law, you may have the right to:

These rights are not absolute and may be limited in some situations, for example where we must keep records for legal, regulatory or safeguarding reasons. If we are relying on consent for a specific optional purpose, you also have the right to withdraw that consent at any time, but this does not affect processing already carried out lawfully before the withdrawal. NHS guidance also makes clear that consent should not usually be the main UK GDPR lawful basis for routine health and care processing by public authorities or health and care providers.

If you want to exercise your rights, please contact us using the details below. We may need to ask you for proof of identity before responding.


17) Contact us

If you have any questions about this privacy notice, want to exercise your rights, or wish to raise a concern, please contact:

CareRight Homecare Limited
Email: hello@careright.co.uk
Address: Unit 1, Templer House, Scott Close, Newton Abbot, Devon, TQ12 1GJ

Data Protection Lead (DPL):

You also have the right to complain to the Information Commissioner’s Office (ICO). ICO contact details are available on the ICO and GOV.UK websites.


18) Changes to this privacy notice

We may update this notice from time to time to reflect changes in the law, our services, our systems, or the way we process personal information. We encourage people to review the notice periodically. Where changes are significant, we will take reasonable steps to bring them to the attention of service users and others affected. Transparency is a core requirement of UK data protection law.

Careline Live Care portal

CareRights Care Circle Family Portal

  • Real-time updates for families
  • Emergency access for health professionals
  • Comprehensive information
  • Enhanced communication

Family get visibility on, tasks completed and care notes, so they can see how their loved ones are doing. CareRight uses CarelineLive to keep family in the loop Making up-to-date information accessible.

Peace of mind about loved ones’ care

Find out more

We value your privacy

We use essential cookies to make our site work. With your consent, we may also use non-essential cookies to improve user experience, personalize advertisements, and analyze web traffic. For these reasons, we may share your site usage data with our advertising and analytics partners. By clicking “Accept,” you agree to our website's cookie use as described in our Cookie Policy.

Purposes


+Store and/or access information on a device
Vendors can:
  • Store and access information on the device such as cookies and device identifiers presented to a user.
+Select basic ads
To do basic ad selection vendors can:
  • Use real-time information about the context in which the ad will be shown, to show the ad, including information about the content and the device, such as: device type and capabilities, user agent, URL, IP address
  • Use a user’s non-precise geolocation data
  • Control the frequency of ads shown to a user.
  • Sequence the order in which ads are shown to a user.
  • Prevent an ad from serving in an unsuitable editorial (brand-unsafe) contextVendors cannot:
  • Create a personalised ads profile using this information for the selection of future ads without a separate legal basis to create a personalised ads profile.
  • N.B. Non-precise means only an approximate location involving at least a radius of 500 meters is permitted.
+Create a personalised ads profile
To create a personalised ads profile vendors can:
  • Collect information about a user, including a user's activity, interests, demographic information, or location, to create or edit a user profile for use in personalised advertising.
  • Combine this information with other information previously collected, including from across websites and apps, to create or edit a user profile for use in personalised advertising.
+Select personalised ads
To select personalised ads vendors can:
  • Select personalised ads based on a user profile or other historical user data, including a user’s prior activity, interests, visits to sites or apps, location, or demographic information.
+Create a personalised content profile
To create a personalised content profile vendors can:
  • Collect information about a user, including a user's activity, interests, visits to sites or apps, demographic information, or location, to create or edit a user profile for personalising content.
  • Combine this information with other information previously collected, including from across websites and apps, to create or edit a user profile for use in personalising content.
+Select personalised content
To select personalised content vendors can:
  • Select personalised content based on a user profile or other historical user data, including a user’s prior activity, interests, visits to sites or apps, location, or demographic information.
+Measure ad performance
To measure ad performance vendors can:
  • Measure whether and how ads were delivered to and interacted with by a user
  • Provide reporting about ads including their effectiveness and performance
  • Provide reporting about users who interacted with ads using data observed during the course of the user's interaction with that ad
  • Provide reporting to publishers about the ads displayed on their property
  • Measure whether an ad is serving in a suitable editorial environment (brand-safe) context
  • Determine the percentage of the ad that had the opportunity to be seen and the duration of that opportunity
  • Combine this information with other information previously collected, including from across websites and appsVendors cannot:
    • Apply panel- or similarly-derived audience insights data to ad measurement data without a Legal Basis to apply market research to generate audience insights (Purpose 9)
+Measure content performance
To measure ad performance vendors can: To measure content performance vendors can:
  • Measure and report on how content was delivered to and interacted with by users.
  • Provide reporting, using directly measurable or known information, about users who interacted with the content
  • Combine this information with other information previously collected, including from across websites and apps.Vendors cannot:
  • Measure whether and how ads (including native ads) were delivered to and interacted with by a user.
  • Apply panel- or similarly derived audience insights data to ad measurement data without a Legal Basis to apply market research to generate audience insights (Purpose 9)
+Apply market research to generate audience insights
To apply market research to generate audience insights vendors can:
  • Provide aggregate reporting to advertisers or their representatives about the audiences reached by their ads, through panel-based and similarly derived insights.
  • Provide aggregate reporting to publishers about the audiences that were served or interacted with content and/or ads on their property by applying panel-based and similarly derived insights.
  • Associate offline data with an online user for the purposes of market research to generate audience insights if vendors have declared to match and combine offline data sources (Feature 1)
  • Combine this information with other information previously collected including from across websites and apps. Vendors cannot:
  • Measure the performance and effectiveness of ads that a specific user was served or interacted with, without a Legal Basis to measure ad performance.
  • Measure which content a specific user was served and how they interacted with it, without a Legal Basis to measure content performance.
+Develop and improve products
To develop new products and improve products vendors can:
  • Use information to improve their existing products with new features and to develop new products
  • Create new models and algorithms through machine learningVendors cannot:
  • Conduct any other data processing operation allowed under a different purpose under this purpose

Special Purposes

+Ensure security, prevent fraud, and debug
To ensure security, prevent fraud and debug vendors can:
  • Ensure data are securely transmitted
  • Detect and prevent malicious, fraudulent, invalid, or illegal activity.
  • Ensure correct and efficient operation of systems and processes, including to monitor and enhance the performance of systems and processes engaged in permitted purposesVendors cannot:
  • Conduct any other data processing operation allowed under a different purpose under this purpose.Note: Data collected and used to ensure security, prevent fraud, and debug may include automatically-sent device characteristics for identification, precise geolocation data, and data obtained by actively scanning device characteristics for identification without separate disclosure and/or opt-in.
+Technically deliver ads or content
To deliver information and respond to technical requests vendors can:
  • Use a user’s IP address to deliver an ad over the internet
  • Respond to a user’s interaction with an ad by sending the user to a landing page
  • Use a user’s IP address to deliver content over the internet
  • Respond to a user’s interaction with content by sending the user to a landing page
  • Use information about the device type and capabilities for delivering ads or content, for example, to deliver the right size ad creative or video file in a format supported by the deviceVendors cannot:
  • Conduct any other data processing operation allowed under a different purpose under this purpose

Features

+Match and combine offline data sources
Vendors can:
  • Combine data obtained offline with data collected online in support of one or more Purposes or Special Purposes.
+Link different devices
Vendors can:
  • Deterministically determine that two or more devices belong to the same user or household
  • Probabilistically determine that two or more devices belong to the same user or household
  • Actively scan device characteristics for identification for probabilistic identification if users have allowed vendors to actively scan device characteristics for identification (Special Feature 2)
+Receive and use automatically-sent device characteristics for identification
Vendors can:
  • Create an identifier using data collected automatically from a device for specific characteristics, e.g. IP address, user-agent string.
  • Use such an identifier to attempt to re-identify a device.Vendors cannot:
  • Create an identifier using data collected via actively scanning a device for specific characteristics, e.g. installed font or screen resolution without users’ separate opt-in to actively scanning device characteristics for identification.
  • Use such an identifier to re-identify a device.

Special Features

+Use precise geolocation data
Vendors can:
  • Collect and process precise geolocation data in support of one or more purposes.N.B. Precise geolocation means that there are no restrictions on the precision of a user’s location; this can be accurate to within several meters.
+Actively scan device characteristics for identification
Vendors can:
  • Create an identifier using data collected via actively scanning a device for specific characteristics, e.g. installed fonts or screen resolution.
  • Use such an identifier to re-identify a device.
Manage