Find a CareRight job.
Browse AllWe use your personal and health information to provide safe and effective care.
This includes sharing information with professionals involved in your care and, where appropriate, securely accessing relevant GP record information using NHS systems such as GP Connect.
We only use information where necessary, keep it secure, and you have the right to ask questions or object to certain types of data sharing.
This privacy notice explains how CareRight Homecare Limited trading as CareRight (“CareRight”, “we”, “us”, “our”) collects, uses, stores and shares personal information when we provide home care and related services, operate our website, communicate with service users and families, and use digital care systems to help deliver safe and effective care. This notice is intended to meet our obligations under the UK GDPR, Data Protection Act 2018, the Common Law Duty of Confidentiality, the NHS GP Connect National Data Sharing Arrangement, and relevant adult social care requirements.
We are committed to handling personal information fairly, lawfully, securely and transparently. As an adult social care provider, we may process both personal information and special category data, including health and care information, where this is necessary to provide care, meet legal and regulatory obligations, safeguard people, and operate our services safely. Health and care providers must have a valid lawful basis under Article 6 and a valid condition under Article 9 of the UK GDPR when processing health data, and must also meet confidentiality requirements.
If you have any questions about this privacy notice or how we use your information, please contact us using the details in the Contact us section below. If you are receiving care from us, we can also explain this notice in a way that is easier to understand or provide support to help you make informed decisions, in line with CQC expectations around consent and communication.
1) Who we are
CareRight is a home care provider operating in Devon. Our website states that we provide in-home care services and use digital care systems, including CareLineLive, to help keep information up to date and visible to families where appropriate. Our website also lists the following contact locations: Newton Abbot, Bovey Tracey and Plymouth.
Data controller: CareRight Homecare Limited (trading as CareRight)
Reg No: 07250448
Registered office: Unit 1, Templer House Scott Close, Newton Abbot, Devon, TQ12 1GJ
Main contact email: hello@careright.co.uk
Data Protection Lead (DPL): Justin Huntington - justin.huntington@careright.co.uk
2) Whose information we use
We may process personal information about:
Where we provide regulated care, our handling of personal information is also relevant to our responsibilities under the Health and Social Care Act framework and CQC requirements, including the need to ensure people are informed and that care and treatment are provided with appropriate consent or lawful authority.
3) What information we collect
Depending on the service and your relationship with us, we may collect and use:
Where necessary, we may also process information about a person’s capacity to make decisions, whether there is a Health and Welfare Lasting Power of Attorney, Court-appointed Deputy, or other lawful representative, and who should be involved in best interests decision-making. CQC guidance makes clear that where a person lacks capacity, providers must act in accordance with the Mental Capacity Act 2005 and involve attorneys, deputies or other relevant people where appropriate.
4) Where we get information from
We collect most personal information directly from the person receiving care, from their family or representative, or through normal service delivery. We may also receive information from third parties where this is necessary and appropriate, including:
5) How we use personal information
We use personal information to:
Where we ask for consent in the course of care, we will give information in a way the person can understand and will seek consent lawfully. However, not all processing is based on consent. In health and social care, consent is not always the appropriate UK GDPR lawful basis for using information, and NHS guidance specifically warns against relying on GDPR consent as the primary legal basis for routine care processing by public authorities and care providers.
6) Our lawful bases for processing
Under the UK GDPR, we must have a lawful basis for processing personal data and an additional condition for processing health data. Depending on the purpose, we may rely on one or more of the following:
Article 6 lawful bases
Article 9 special category conditions
For health and care information, we may rely on:
We do not rely on consent as the main legal basis for routine direct care processing simply because someone is receiving care from us. This is particularly important for GP Connect and other direct care functions. NHS guidance states that for confidential patient information, the Common Law Duty of Confidentiality must also be met, and the NDSA specifically states for GP Connect that implied consent with opt out applies for direct care.
7) GP Connect and access to GP records
Where appropriate and where our systems and organisational approvals permit, we may access relevant information from a person’s GP record using NHS GP Connect to support their direct care. GP Connect is a secure NHS service that allows authorised health and social care professionals to view appropriate information from GP records through approved systems, subject to national data sharing requirements, role-based access controls and audit arrangements. Organisations using GP Connect must comply with the National Data Sharing Arrangement (NDSA) and update their transparency notices accordingly.
For social care providers, GP Connect is intended to support direct care only. Guidance for the adult social care sector explains that CQC-registered providers using assured digital care systems can access GP patient records where this is necessary, proportionate and governed properly. For non-clinical staff, access is generally limited to information such as allergies, medications, immunisations and the last three GP interactions, while clinical staff such as nurses may have broader access where appropriate for their role.
The legal basis for GP Connect is stated in the NDSA as Article 6(1)(e) and Article 9(2)(h) of the UK GDPR, and for the Common Law Duty of Confidentiality the NDSA states that implied consent with opt out is used. This means we do not normally need separate explicit written consent to use GP Connect for direct care, but we must tell people about it, only access information where necessary for their care, and respect any objection.
If you do not want your GP record to be shared with us through GP Connect, you should tell us and also tell your GP practice, as your GP practice is responsible for recording and applying relevant GP Connect sharing choices. We will respect your wishes and explain any practical implications for your care. GP Connect guidance and social care guidance both emphasise that organisations must honour an individual’s objection and provide transparent information materials.
8) Consent, capacity and acting on someone’s behalf
Care and treatment must only be provided with the consent of the relevant person, and when a person is asked for consent, information must be provided in a way they can understand. CQC Regulation 11 requires providers to obtain consent lawfully and to act in accordance with the Mental Capacity Act 2005 where a person lacks capacity to make a specific decision.
If a person is unable to make a particular decision, we will follow the Mental Capacity Act principles. This includes assuming capacity unless it is established otherwise, taking all practicable steps to support the person to decide, and if the person lacks capacity, consulting those who should be involved in a best interests decision such as family, attorneys, deputies or others interested in the person’s welfare, where appropriate and lawful.
If someone is acting on behalf of a person receiving care, for example under a Health and Welfare Lasting Power of Attorney, we may ask to see evidence of that authority. GOV.UK guidance confirms that health and welfare attorneys can only make decisions when the person lacks capacity for the relevant decision and may need to show their authority to care staff.
9) CareLineLive and our digital care systems
Our website states that CareRight uses CareLineLive to support communication and up-to-date care information, including visibility for families where appropriate. CareLineLive also publishes information explaining that it is certified to recognised standards including ISO 27001, the NHS Data Security and Protection Toolkit, and Cyber Essentials Plus, and that it uses encryption, backups, disaster recovery and regular testing.
Where we use CareLineLive or other digital care systems to store or process information on our behalf, those providers act as our data processors or technology suppliers, unless clearly acting as separate controllers for their own purposes. We use written agreements and organisational controls to ensure personal information is handled securely and only on our instructions, as required by UK GDPR accountability and processor obligations.
We may use digital systems for care records, rotas, medication support, family communications, reporting, auditing and secure information sharing. Access is restricted to authorised users and monitored to help ensure information is only accessed where necessary and proportionate. GP Connect access, where enabled through an approved solution, is also controlled through role-based access and audit mechanisms.
10) Who we share personal information with
We only share personal information where there is a valid reason to do so. Depending on the circumstances, we may share information with:
We do not sell personal information. We do not use GP Connect for marketing, profiling or unrelated business purposes. GP Connect is for direct care only, and the NDSA and GP Connect transparency guidance are explicit on this point.
11) National Data Opt-Out
The National Data Opt-Out allows people to opt out of their confidential patient information being used for purposes beyond their individual care, such as certain planning and research uses. It does not apply to information used to support individual care, and NHS guidance makes clear that opt-out policies for planning and research are different from direct care sharing arrangements such as GP record sharing for individual care.
As a CQC-registered adult social care provider, we review our processing activities to determine whether the National Data Opt-Out applies and will apply it where required by law and policy. If a processing activity falls within scope, we will take steps to comply with the opt-out policy.
12) How long we keep information
We keep personal information only for as long as necessary for the purposes we collected it for, including to provide care, meet legal and regulatory requirements, resolve complaints, defend legal claims, and maintain appropriate records. Different categories of information may be retained for different periods in line with legal requirements, NHS or social care records management guidance, contractual requirements and our internal retention schedule.
When information is no longer required, we will securely delete, destroy or anonymise it. Where deletion is not immediately possible, for example because records are held in secure backups, we will protect the information and limit any further use until deletion becomes possible.
13) How we keep information safe
We use appropriate technical and organisational security measures to protect personal information against accidental or unlawful loss, access, misuse, alteration or disclosure. This includes access controls, role-based permissions, staff training, device and account security, secure systems, backups, audit logs, and policies and procedures designed to handle personal information correctly. UK data protection guidance and NHS data security guidance both require organisations to apply appropriate safeguards and accountability controls.
The Data Security and Protection Toolkit (DSPT) is the NHS’s self-assessment tool against the National Data Guardian’s ten data security standards, and it applies to organisations that access NHS patient data and systems. Digital Care Hub also explains that the DSPT is the official self-assessment tool for the adult social care sector and is recognised by the CQC, local authorities and the NHS.
Where we use suppliers such as CareLineLive, we expect them to maintain appropriate security standards and controls. CareLineLive states that it is certified to ISO 27001, the NHS DSPT and Cyber Essentials Plus, and that it uses encryption, backups, failover, vulnerability scanning and disaster recovery measures.
If a personal data breach occurs, we will investigate it, take steps to contain and remediate it, and report it where required. NHS DSPT guidance explains that reportable incidents must be notified through the reporting tool and that notifiable personal data breaches must also be reported to the ICO without undue delay and, where applicable, within 72 hours.
14) Website, cookies and analytics
When you visit our website, we may automatically collect technical information such as IP address, browser type, device information, pages visited and similar usage information to help us operate, secure and improve the website. We may also use cookies and similar technologies. Information about this should be explained in a separate cookie notice or cookie policy.
You can usually control cookies through your browser settings. If you disable or block some cookies, certain website features may not work properly. For more detail, refer to our cookie policy.
15) Children and young people
If we provide services to children or young people, we may process their personal information where necessary to provide care and support, comply with safeguarding and legal duties, and communicate with those who have parental responsibility or another lawful role in the child’s care. We will handle children’s information with particular care and in line with data protection law and professional obligations. UK guidance recognises that children’s information requires appropriate protection and transparency.
16) Your rights
Under UK data protection law, you may have the right to:
These rights are not absolute and may be limited in some situations, for example where we must keep records for legal, regulatory or safeguarding reasons. If we are relying on consent for a specific optional purpose, you also have the right to withdraw that consent at any time, but this does not affect processing already carried out lawfully before the withdrawal. NHS guidance also makes clear that consent should not usually be the main UK GDPR lawful basis for routine health and care processing by public authorities or health and care providers.
If you want to exercise your rights, please contact us using the details below. We may need to ask you for proof of identity before responding.
17) Contact us
If you have any questions about this privacy notice, want to exercise your rights, or wish to raise a concern, please contact:
CareRight Homecare
Limited
Email: hello@careright.co.uk
Address: Unit 1, Templer House, Scott Close, Newton Abbot, Devon, TQ12 1GJ
Data Protection Lead (DPL):
You also have the right to complain to the Information Commissioner’s Office (ICO). ICO contact details are available on the ICO and GOV.UK websites.
18) Changes to this privacy notice
We may update this notice from time to time to reflect changes in the law, our services, our systems, or the way we process personal information. We encourage people to review the notice periodically. Where changes are significant, we will take reasonable steps to bring them to the attention of service users and others affected. Transparency is a core requirement of UK data protection law.
Family get visibility on, tasks completed and care notes, so they can see how their loved ones are doing. CareRight uses CarelineLive to keep family in the loop Making up-to-date information accessible.