MicroCare ("we", "us", "our") respects your privacy. This policy explains what data we collect, why, and how we protect it.
What we collect
- Account data — name, email, role, password (hashed)
- Care data — patient records, shifts, tasks, medications, notes
- Usage data — login times, pages visited, anonymised analytics
- Location data — only when a carer clocks in (for geofence verification)
Why we collect it
- To operate the MicroCare service
- To comply with our contract with you
- To improve the product (using anonymised data only)
- To meet our legal obligations (UK GDPR, Care Quality Commission requirements)
Who we share it with
We do not sell your data. We share it only with:
- Microsoft Azure UK — our hosting provider
- Azure Communication Services — for sending emails
- UK authorities — when legally compelled (rare)
How long we keep it
While your account is active, plus a retention period for legal/regulatory purposes:
- Care records: 8 years (UK NHS standard)
- Wage records: 6 years (HMRC requirement)
- Account data: until you delete your account, plus 30 days
Your rights
Under UK GDPR you have the right to:
- Access your data
- Correct inaccurate data
- Delete your data (subject to legal retention)
- Object to processing
- Data portability (export)
- Lodge a complaint with the ICO
To exercise these rights, email privacy@microcare.app.
Cookies
We use essential cookies for session management. We do not use tracking or advertising cookies.
Changes to this policy
We'll notify you by email of any material changes at least 30 days before they take effect.
Contact
Data Protection Officer: privacy@microcare.app