Privacy Policy
Your data, handled with care.
How FlexiEle collects, uses, stores and protects personal data — for the care homes we serve, their staff and residents, and visitors to this website.
Last updated:
FlexiEle (“FlexiEle”, “we”, “us”) provides a Care Management System and HR & workforce platform to UK care providers. We are committed to protecting personal data and to processing it lawfully, fairly and transparently under the UK GDPR, the Data Protection Act 2018 and, where relevant, the EU GDPR. This policy explains what we do with personal data and the rights available to you.
Who is responsible for your data
The role we play depends on the data. It matters because it determines who you contact to exercise your rights.
Data inside the platform — we are the processor
For the resident care records and staff records held inside the FlexiEle platform (care plans, daily notes, clinical observations, incidents, rotas, HR and payroll data), the care provider is the data controller and FlexiEle is the data processor. We act only on the provider’s documented instructions under a Data Processing Agreement (DPA). If you are a resident, a relative or a member of care-home staff, direct data requests to the care home in the first instance; we support them in responding.
Website & enquiry data — we are the controller
For data you submit through this website (contact forms, demo bookings, pricing enquiries), FlexiEle is the data controller. This policy governs how we handle that data directly.
The data we collect
Depending on your relationship with us, we may process the following categories:
- Resident care data (special category): care plans, “About Me” details, daily notes, NEWS2/RESTORE2 observations, incidents, allergies, conditions and NHS number — health and social-care data processed on the care home’s behalf.
- Staff & workforce data: name, contact details, role, rota and attendance, right-to-work and DBS status, training and qualification records, and (where the HR/payroll modules are used) salary, bank and tax details.
- Account & login credentials: usernames and securely hashed passwords, and audit metadata (who did what, and when) used for Reg 17 governance.
- Website & enquiry data: name, work email, telephone, organisation and the message or interests you submit when you contact us or book a demo.
- Technical data: IP address, device and browser metadata, and essential cookies needed to run the site securely (see our cookie settings in the footer).
How we use it
Personal data is processed for these purposes:
- Providing and operating the Care Management System and HR platform for the care provider
- Delivering point-of-care records, clinical monitoring, handover, rota and compliance features
- Producing audit trails and governance evidence (including CQC Reg 17 records)
- Responding to website enquiries, arranging and confirming demos, and providing quotes
- Sending service and security notifications about the platform
- Meeting our legal, regulatory and statutory obligations
- Marketing communications where you have submitted an enquiry, requested a demo or otherwise opted in
Our lawful basis
Platform data (as processor): the care provider, as controller, determines the lawful basis. This is typically the performance of a contract for staff data, and, for resident health data, the provision of health or social care under UK GDPR Article 9(2)(h), together with legal obligations for statutory reporting. We process it only on the provider’s instructions.
Website & marketing data (as controller): we rely on our legitimate interest in responding to your enquiry and running our business, or on your consent where you have explicitly given it. You can withdraw consent at any time using the details below.
Where your data is held
Hosted in the UK — data never leaves the UK
All FlexiEle production data is stored in AWS eu-west-2 (London). Care records and staff data do not cross regions in the normal course of operation. Voice notes captured at the point of care are transcribed on our own UK infrastructure — audio is not sent to any third-party transcription service.
Website and enquiry data (contact-form submissions, demo bookings) is held on managed PostgreSQL infrastructure in the United Kingdom (London, AWS eu-west-2). Emails to and from our team are processed via Microsoft 365. Where a supplier operates outside the UK, any transfer is governed by the UK International Data Transfer Agreement or Standard Contractual Clauses with applicable safeguards. The current list of suppliers is published on our sub-processors page.
Advertising & conversion measurement
We advertise this website using Google Ads. To understand whether that advertising works, we use Google’s conversion-measurement tags on this site, including Google’s “enhanced conversions” feature: when you book a demo or send us an enquiry, the email address you provide may be hashed (using SHA-256, so Google never receives the address itself) and sent to Google to match the enquiry to an ad interaction. Google processes this data in accordance with its Ads Data Processing Terms and may process it outside the UK.
None of this happens without your consent: advertising cookies and this measurement are controlled by the cookie banner (Google Consent Mode). If you decline marketing cookies, no advertising identifiers or hashed contact data are sent — you can change your choice at any time via the cookie settings link in the footer.
How we protect it
We apply technical and organisational measures appropriate to the sensitivity of care data:
Technical safeguards
- TLS 1.2+ in transit; AES-256 at rest
- Encrypted, region-resident backups
- Continuous vulnerability scanning
- Annual third-party penetration testing
Access controls
- Role-based, least-privilege access
- Multi-factor authentication for admins
- Full audit logging (Reg 17)
- Scoped, reviewed staff production access
For the full picture, see our Trust & Security overview.
How long we keep it
- Resident & staff platform data: retained for as long as the care provider instructs, in line with the statutory retention periods for adult social-care and employment records. On termination we provide export assistance and then securely delete or return the data.
- Website & marketing leads: retained for up to 24 months from last meaningful contact, then deleted or anonymised unless you have become a customer.
- Server & access logs: retained for 90 days for security and incident-response purposes.
Following a verified deletion request, we delete or anonymise personal data within 30 days, subject to any legal obligation to retain specific records.
Your rights
Under UK/EU GDPR you have the right to:
Where FlexiEle is the processor (platform data), please raise requests with your care provider, who is the controller; we will support them promptly. Where FlexiEle is the controller (website data), contact us using the details below.
Contact & complaints
To exercise your rights, or for any question about this policy, contact our Data Protection Officer:
Data Protection Officer: dpo@flexiele.com
General enquiries: info@flexiele.co.uk
FlexiEle Technologies Private Limited (Company No. 15317667, registered in England & Wales)
71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
You also have the right to complain to the UK regulator, the Information Commissioner’s Office (ICO), though we would welcome the chance to resolve your concern first.
We may update this policy from time to time. Material changes will be notified through the platform or by email, and the “last updated” date above will change.