Privacy Policy

Your data, handled with care.

How FlexiEle collects, uses, stores and protects personal data — for the care homes we serve, their staff and residents, and visitors to this website.

Last updated:

FlexiEle (“FlexiEle”, “we”, “us”) provides a Care Management System and HR & workforce platform to UK care providers. We are committed to protecting personal data and to processing it lawfully, fairly and transparently under the UK GDPR, the Data Protection Act 2018 and, where relevant, the EU GDPR. This policy explains what we do with personal data and the rights available to you.

Who is responsible for your data

The role we play depends on the data. It matters because it determines who you contact to exercise your rights.

Data inside the platform — we are the processor

For the resident care records and staff records held inside the FlexiEle platform (care plans, daily notes, clinical observations, incidents, rotas, HR and payroll data), the care provider is the data controller and FlexiEle is the data processor. We act only on the provider’s documented instructions under a Data Processing Agreement (DPA). If you are a resident, a relative or a member of care-home staff, direct data requests to the care home in the first instance; we support them in responding.

Website & enquiry data — we are the controller

For data you submit through this website (contact forms, demo bookings, pricing enquiries), FlexiEle is the data controller. This policy governs how we handle that data directly.

The data we collect

Depending on your relationship with us, we may process the following categories:

  • Resident care data (special category): care plans, “About Me” details, daily notes, NEWS2/RESTORE2 observations, incidents, allergies, conditions and NHS number — health and social-care data processed on the care home’s behalf.
  • Staff & workforce data: name, contact details, role, rota and attendance, right-to-work and DBS status, training and qualification records, and (where the HR/payroll modules are used) salary, bank and tax details.
  • Account & login credentials: usernames and securely hashed passwords, and audit metadata (who did what, and when) used for Reg 17 governance.
  • Website & enquiry data: name, work email, telephone, organisation and the message or interests you submit when you contact us or book a demo.
  • Technical data: IP address, device and browser metadata, and essential cookies needed to run the site securely (see our cookie settings in the footer).

How we use it

Personal data is processed for these purposes:

  • Providing and operating the Care Management System and HR platform for the care provider
  • Delivering point-of-care records, clinical monitoring, handover, rota and compliance features
  • Producing audit trails and governance evidence (including CQC Reg 17 records)
  • Responding to website enquiries, arranging and confirming demos, and providing quotes
  • Sending service and security notifications about the platform
  • Meeting our legal, regulatory and statutory obligations
  • Marketing communications where you have submitted an enquiry, requested a demo or otherwise opted in

Our lawful basis

Platform data (as processor): the care provider, as controller, determines the lawful basis. This is typically the performance of a contract for staff data, and, for resident health data, the provision of health or social care under UK GDPR Article 9(2)(h), together with legal obligations for statutory reporting. We process it only on the provider’s instructions.

Website & marketing data (as controller): we rely on our legitimate interest in responding to your enquiry and running our business, or on your consent where you have explicitly given it. You can withdraw consent at any time using the details below.

Where your data is held

Hosted in the UK — data never leaves the UK

All FlexiEle production data is stored in AWS eu-west-2 (London). Care records and staff data do not cross regions in the normal course of operation. Voice notes captured at the point of care are transcribed on our own UK infrastructure — audio is not sent to any third-party transcription service.

Website and enquiry data (contact-form submissions, demo bookings) is held on managed PostgreSQL infrastructure in the United Kingdom (London, AWS eu-west-2). Emails to and from our team are processed via Microsoft 365. Where a supplier operates outside the UK, any transfer is governed by the UK International Data Transfer Agreement or Standard Contractual Clauses with applicable safeguards. The current list of suppliers is published on our sub-processors page.

Sharing & sub-processors

We do not sell, trade or rent personal data.

We share data only with vetted sub-processors that help us run the service, and only where necessary. Every sub-processor is bound by a data-processing agreement with security, confidentiality and breach-notification obligations consistent with UK/EU GDPR. The full list, with each supplier’s purpose and processing region, is at /sub-processors.

We may also disclose data where required to comply with a legal obligation, a court order or a lawful request from a regulator such as the CQC or the ICO.

Advertising & conversion measurement

We advertise this website using Google Ads. To understand whether that advertising works, we use Google’s conversion-measurement tags on this site, including Google’s “enhanced conversions” feature: when you book a demo or send us an enquiry, the email address you provide may be hashed (using SHA-256, so Google never receives the address itself) and sent to Google to match the enquiry to an ad interaction. Google processes this data in accordance with its Ads Data Processing Terms and may process it outside the UK.

None of this happens without your consent: advertising cookies and this measurement are controlled by the cookie banner (Google Consent Mode). If you decline marketing cookies, no advertising identifiers or hashed contact data are sent — you can change your choice at any time via the cookie settings link in the footer.

How we protect it

We apply technical and organisational measures appropriate to the sensitivity of care data:

Technical safeguards

  • TLS 1.2+ in transit; AES-256 at rest
  • Encrypted, region-resident backups
  • Continuous vulnerability scanning
  • Annual third-party penetration testing

Access controls

  • Role-based, least-privilege access
  • Multi-factor authentication for admins
  • Full audit logging (Reg 17)
  • Scoped, reviewed staff production access

For the full picture, see our Trust & Security overview.

How long we keep it

  • Resident & staff platform data: retained for as long as the care provider instructs, in line with the statutory retention periods for adult social-care and employment records. On termination we provide export assistance and then securely delete or return the data.
  • Website & marketing leads: retained for up to 24 months from last meaningful contact, then deleted or anonymised unless you have become a customer.
  • Server & access logs: retained for 90 days for security and incident-response purposes.

Following a verified deletion request, we delete or anonymise personal data within 30 days, subject to any legal obligation to retain specific records.

Your rights

Under UK/EU GDPR you have the right to:

Access the data we hold about you
Have inaccurate data corrected
Request erasure of your data
Restrict or object to processing
Data portability
Withdraw consent at any time

Where FlexiEle is the processor (platform data), please raise requests with your care provider, who is the controller; we will support them promptly. Where FlexiEle is the controller (website data), contact us using the details below.

Contact & complaints

To exercise your rights, or for any question about this policy, contact our Data Protection Officer:

Data Protection Officer: dpo@flexiele.com

General enquiries: info@flexiele.co.uk

FlexiEle Technologies Private Limited (Company No. 15317667, registered in England & Wales)
71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom

You also have the right to complain to the UK regulator, the Information Commissioner’s Office (ICO), though we would welcome the chance to resolve your concern first.

We may update this policy from time to time. Material changes will be notified through the platform or by email, and the “last updated” date above will change.