Privacy Policy
Last updated: 7 July 2026
This Policy explains, in detail, how FHcare Tech Limited collects, uses, shares, protects and retains personal data across all sectors in which the FHcare platform is deployed, and sets out the rights available to individuals under the United Kingdom, European Union, South African, United States and other applicable data protection frameworks.
1. Introduction and Who We Are
Who we are
FHcare Tech Limited (referred to in this Policy as FHcare, we, our or us) is a technology company incorporated and operating in England. We design, build and operate a workforce management and compliance software platform that is currently deployed primarily within the healthcare and social care recruitment sector, supporting agencies, care providers and their candidates with compliance tracking, shift management, document verification, onboarding and related workforce administration functions.
This Policy sets out how we collect, use, store, share and protect personal data belonging to the individuals who interact with our platform, our website and our services. It is written to be read by administrators, recruiters, candidates, workers, corporate clients and members of the public who visit our online properties. We have written it in plain language wherever possible because we believe that transparency about data practices is a foundational obligation, not a formality to be dispensed with in dense legal text.
Controller and processor roles
Where you are a candidate or worker whose personal data is processed through a client agency's branded instance of the FHcare platform, that client agency is ordinarily the data controller in respect of your personal data, and FHcare acts as a data processor providing the underlying technology. In those circumstances you should also refer to the relevant client agency's own privacy notice, which will describe how that agency specifically uses your information. Nothing in this arrangement diminishes the protections described in this Policy, which apply to all processing carried out on our infrastructure regardless of which entity holds the role of controller for a particular data set.
2. Our Multi Sector Capability
Although FHcare originated within, and remains deeply rooted in, healthcare and social care recruitment, the platform has been engineered as a configurable, multi tenant compliance and workforce technology system rather than as a single purpose healthcare tool. Its underlying architecture, including document verification workflows, right to work checking, DBS and background screening integrations, shift and rota management, credential expiry tracking and communication tooling, is sector agnostic by design and can be, and in some cases already is being, tailored and licensed for deployment into adjacent regulated and unregulated sectors.
These sectors may include, without limitation, education and childcare staffing, hospitality and events staffing, transport, logistics and driving services, construction and skilled trades, retail and facilities services, and other fields in which organisations must manage a distributed or agency based workforce and demonstrate ongoing compliance with sector specific credentialing, right to work, safeguarding or licensing requirements. Because our client base and the categories of personal data we process can therefore expand beyond healthcare specific data such as clinical training records or professional registration numbers, this Policy has been written broadly enough to cover data practices across all sectors in which the FHcare platform is or may in future be deployed, while retaining the enhanced protections appropriate to health related and other special category data where that data continues to be processed.
We will update our sector specific annexes as new verticals are onboarded, and we encourage client agencies operating outside healthcare to confirm with us which categories of this Policy apply most directly to their configuration of the platform.
3. Definitions and Interpretation
In this Policy, personal data means any information relating to an identified or identifiable natural person. Special category data or sensitive personal data means personal data revealing racial or ethnic origin, health data, biometric data used for identification, or other categories afforded enhanced protection under applicable law. Processing means any operation performed on personal data, including collection, storage, use, disclosure and deletion. Data controller means the entity that determines the purposes and means of processing personal data. Data processor means an entity that processes personal data on behalf of and under the instructions of a controller. Client agency means an organisation that has licensed the FHcare platform to manage its own workforce, candidates or clients. Candidate or workermeans an individual whose data is processed through a client agency's use of the platform. Sub processor means a third party engaged by FHcare to assist in providing the Services and who processes personal data as a result.
References in this Policy to applicable law include, as relevant to the location of the individual concerned or the location of processing, the UK General Data Protection Regulation and the Data Protection Act 2018, the EU General Data Protection Regulation, the California Consumer Privacy Act as amended by the California Privacy Rights Act, the South African Protection of Personal Information Act, the Irish Data Protection Act 2018, and any other data protection or privacy law that applies to a given instance of processing carried out through the platform.
4. Scope and Application of This Policy
This Policy applies to all users of the FHcare platform, our corporate website, our mobile applications and any other digital property operated by FHcare, regardless of the sector in which the client agency operates. It applies whether you are an administrator configuring the platform on behalf of an agency, a recruiter using the platform day to day, a candidate or worker whose compliance and shift data is held within it, or a visitor to our marketing website.
This Policy does not apply to the separate privacy practices of client agencies themselves, which are addressed in their own privacy notices, nor does it apply to third party websites or services that may be linked from our platform but which we do not control. Where a client agency has requested a bespoke or sector specific configuration of the platform, we may issue a supplementary annex to this Policy describing any additional categories of data collected or any sector specific legal basis relied upon, and that annex should be read together with this Policy.
5. Information We Collect
Information you provide directly
When you or your organisation create an account, configure the platform, use its features or contact our support team, we may collect your name, email address, telephone number, job title, employer or agency name and business address, login credentials, which are stored using a salted bcrypt hash and never in plain text, and any content you choose to upload, including compliance documents, profile photographs, certificates, references and correspondence.
Collected on behalf of client agencies
Where the platform is used to manage candidates or workers, additional categories of data may be collected depending on the sector configuration in use. In healthcare and social care deployments this typically includes professional registration numbers, right to work documentation, Disclosure and Barring Service or equivalent background check outcomes, training and clinical competency certificates, immunisation and occupational health records where relevant, and shift availability and placement history. In non healthcare deployments this may instead or additionally include driving licence and vehicle insurance details, food hygiene certification, safeguarding and enhanced criminal record checks relevant to work with children or vulnerable adults, trade qualifications, health and safety training records, and other credentials specific to the sector concerned.
Automatically collected data
When you use the platform or visit our website we automatically collect technical information including your IP address and approximate geographic location derived from it, device type, browser and operating system, pages visited and features used within the platform, log data including access times, session duration and error reports, and cookie and similar tracking identifiers as described in Section 13.
Information from third parties
We may receive information from identity verification providers, background and criminal record check providers engaged where permitted by law and instructed by a client agency, single sign on and authentication providers, payment processors where subscription billing is involved, and, in some sector configurations, professional or regulatory bodies that confirm registration status.
We do not knowingly collect more data than is necessary for the purposes described in this Policy, and where a client agency requests collection of a data field that appears disproportionate to its stated purpose we reserve the right to query that configuration before enabling it.
6. How We Use Your Information
We use personal data to provide and operate the platform, including processing recruitment and onboarding applications, managing compliance workflows and credential expiry alerts, enabling shift booking and rota management, and delivering the sector specific features that a client agency has licensed.
We use personal data for account management, including creating and maintaining user accounts, authenticating logins, enforcing role based access controls and sending account related notifications. We use it for customer support, to respond to queries and resolve technical issues raised by administrators, recruiters or candidates. We use it for security and fraud prevention, including monitoring for suspicious login activity, detecting attempted credential compromise and protecting the platform and its users from misuse.
We use personal data, in aggregated or pseudonymised form wherever practicable, for analytics and product improvement, so that we can understand how features are used across our client base and prioritise development accordingly. We use personal data as necessary to comply with applicable law, including responding to lawful requests from courts, regulators or law enforcement authorities. Where you have given consent, we use contact details for marketing communications such as product updates, case studies and platform news, and you may withdraw that consent at any time without affecting any other use of your data.
We do not use candidate or worker compliance data for marketing purposes, and we do not permit client agencies to repurpose data collected for compliance verification into unrelated marketing activity without an independent lawful basis of their own.
7. Legal Basis for Processing
UK GDPR / EU GDPR
Where the UK GDPR or EU GDPR applies to our processing, we rely on the following legal bases. Consent, where you have given explicit, freely given, specific and informed agreement, for example to receive marketing communications or to permit non essential cookies, and which you may withdraw at any time without affecting the lawfulness of processing carried out before withdrawal. Contract, where processing is necessary to perform a contract with you or your organisation or to take steps at your request before entering into a contract, for example to provision access to the platform under a subscription agreement. Legitimate interests, where processing is necessary for our legitimate interests or those of a client agency and is not overridden by your rights and freedoms, for example platform security monitoring, service analytics and fraud prevention, and where such reliance is supported by a documented balancing assessment. Legal obligation, where processing is required to comply with a legal duty, for example retaining financial records or responding to a lawful regulatory request. Vital interests and substantial public interest, in the limited circumstances where processing of health data is necessary to protect someone's life or is otherwise justified under conditions set out in applicable law, for example where safeguarding concerns require urgent information sharing.
South Africa (POPIA)
Where the South African Protection of Personal Information Act applies, for example where a client agency or candidate is located in South Africa, we process personal information only where one of the conditions recognised under that Act is met, including consent of the data subject, necessity for a contract to which the data subject is party, compliance with a legal obligation, protection of a legitimate interest of the data subject, and pursuit of our legitimate interests or those of the client agency, always subject to the eight conditions for lawful processing set out in that Act, namely accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation.
California (CCPA/CPRA)
Where the California Consumer Privacy Act as amended by the California Privacy Rights Act applies, we process personal information for the disclosed business and commercial purposes described in this Policy and do not sell or share personal information for cross context behavioural advertising.
Special category data
Where processing involves special category or sensitive personal data, such as health information, criminal record check outcomes or, in limited configurations, information from which racial or ethnic origin might be inferred, we apply an additional condition permitting that processing, most commonly explicit consent, a legal obligation relating to employment, social security or social protection law, or a substantial public interest condition relevant to safeguarding or regulated care provision, and we apply enhanced technical and organisational safeguards to that data as described in Section 14.
8. Automated Decision Making and Artificial Intelligence
Certain features of the platform use automated logic to support compliance and workforce management, including automated flagging of expiring credentials, automated matching of candidate availability against open shifts, and automated document verification checks that compare uploaded credentials against expected formats and expiry rules. These features are designed to assist human decision makers within a client agency rather than to make final decisions about an individual's employment, engagement or access to work without human involvement.
Where a feature does involve a decision that produces legal or similarly significant effects on an individual, we ensure that a human reviewer within the relevant client agency retains the ability to review, challenge and override the automated output before it is acted upon, consistent with the requirements of applicable law concerning automated decision making and profiling. We do not use candidate or worker data to train general purpose machine learning models outside the context of the specific platform features described to client agencies, and where any model training does occur on platform usage data, we apply pseudonymisation and minimisation techniques and maintain a record of the lawful basis, source jurisdiction and purpose of that training data.
If you believe an automated feature within the platform has produced an inaccurate or unfair outcome affecting you, you should raise this in the first instance with the client agency responsible for your record, who as data controller is best placed to review and correct the outcome, and you may also contact us directly using the details in Section 24.
10. Sub Processors and Third Party Vendors
We maintain a current list of sub processors engaged in the operation of the platform, which is available on request and, where feasible, published within the platform's administrative settings for client agency review. Our principal sub processors include Amazon Web Services for cloud infrastructure hosting, Firebase for push notification delivery, and reputable SMTP providers for transactional email delivery. Where a client agency has integrated a third party background screening, identity verification or payroll provider into their instance of the platform, that provider acts as a further sub processor or, in some cases, as an independent controller in its own right, and its own privacy terms will apply to the specific checks it performs.
Before engaging any new sub processor that will have access to personal data, we conduct a due diligence review of its security posture, data protection commitments and, where the sub processor is located outside the United Kingdom or European Economic Area, the transfer mechanism that will govern the export of data to it. We require all sub processors to enter into data processing terms consistent with applicable law, including obligations of confidentiality, security, breach notification and cooperation with data subject rights requests, and we notify client agencies of any material change to our sub processor list with a reasonable opportunity to object.
11. Data Retention
We retain personal data for as long as the relevant account remains active or as needed to provide the Services. When an account is closed or a subscription ends, we retain associated data for ninety days to allow for account recovery and to meet short term legal and operational obligations, after which it is securely deleted or irreversibly anonymised unless a longer period is required by law or by the client agency's own retention instructions.
Compliance documents and candidate records processed on behalf of client agencies are retained in accordance with that agency's instructions and applicable employment, immigration and healthcare regulation, which in the United Kingdom and Ireland typically requires retention of certain right to work and training records for a period of up to seven years following the end of the working relationship. Where a sector configuration outside healthcare imposes a different statutory retention period, for example driver licensing records or safeguarding checks in education settings, we apply the retention schedule appropriate to that sector as instructed by the client agency.
You may request deletion of your personal data at any time, subject to our legal retention obligations and those of the relevant client agency, by contacting us using the details in Section 24 or by contacting the client agency directly where they hold controller responsibility for your record.
12. Your Rights
United Kingdom and European Union
If you are located in the United Kingdom or the European Economic Area, you have the right of access to obtain a copy of the personal data we hold about you, the right to rectification of inaccurate or incomplete data, the right to erasure of personal data where there is no continuing lawful basis for processing it, the right to restriction of processing in defined circumstances, the right to data portability to receive your data in a structured, commonly used and machine readable format, the right to object to processing based on legitimate interests or carried out for direct marketing, and the right to withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with the Information Commissioner's Office in the United Kingdom or with your national supervisory authority within the European Economic Area.
South Africa
If you are located in South Africa, the Protection of Personal Information Act gives you the right to be notified that personal information is being collected, the right to access personal information held about you, the right to request correction, destruction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, the right to object to processing on reasonable grounds, and the right to lodge a complaint with the Information Regulator of South Africa.
California and other US states
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the right to know what personal information we collect and how it is used, the right to request deletion of your personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information, which we confirm we do not engage in, the right to limit the use of sensitive personal information, and the right to non discrimination for exercising any of these rights. Residents of other United States states with comprehensive privacy laws, including Virginia, Colorado and others, are afforded materially equivalent rights of access, correction, deletion, portability and opt out, which we will honour on the same basis.
Ireland and other jurisdictions
Candidates and client agencies located in the Republic of Ireland enjoy the same rights described above under the EU GDPR heading and may lodge complaints with the Data Protection Commission. Where you are located in a jurisdiction not specifically listed here, we will nonetheless endeavour to honour requests consistent with the highest applicable standard described in this Policy, in keeping with our general approach of building our compliance programme to the strictest relevant standard and applying it consistently rather than offering different levels of protection depending on location.
To exercise any of these rights, please contact us using the details in Section 24. We will verify your identity before actioning a request, and we will respond within thirty days or such shorter period as applicable law requires, extending that period where permitted and where the complexity of the request requires it, in which case we will explain the reason for the extension.
14. Data Security Measures
We implement technical and organisational measures appropriate to the sensitivity of the data we hold, calibrated to reflect that some client agencies process health, criminal record and safeguarding data requiring the highest level of protection, while others process less sensitive workforce data. Measures include encryption of data in transit using TLS 1.2 or higher and encryption of sensitive data at rest, per client agency data isolation achieved through separate database partitioning or dedicated clusters depending on the client tier, role based access controls that restrict data access to authorised personnel on a need to know basis, mandatory multi factor authentication for administrative accounts, regular automated backups stored in encrypted storage, and continuous monitoring and alerting for suspicious or anomalous activity.
We conduct periodic security reviews and, where appropriate to the scale of a deployment, independent penetration testing, and we maintain an incident response plan that is tested and updated at least annually. Access to special category data within the platform is further restricted through granular permission settings that allow a client agency to limit visibility of health, criminal record or safeguarding information to specifically authorised roles within their own organisation.
No system can guarantee absolute security, and we cannot warrant that unauthorised access, hardware failure or other harm will never occur. We commit to acting promptly and transparently in the event of any incident, as described in Section 17.
15. International Data Transfers, Data Localisation and Cross Border Processing
Our primary infrastructure is hosted on Amazon Web Services in the European Union, in the eu west 1 Ireland region, and in the United Kingdom, in the eu west 2 London region. As our client base and sector footprint expand, personal data may in some configurations be processed, stored or accessed from additional locations, including where a client agency operates internationally, where a sub processor maintains infrastructure outside the United Kingdom or European Economic Area, or where support and development functions are carried out from a jurisdiction other than the location of the data subject.
Where personal data is transferred outside the United Kingdom or European Economic Area, we ensure that an appropriate safeguard is in place before the transfer occurs. This may include reliance on an adequacy decision made by the UK government or European Commission in respect of the receiving jurisdiction, the use of Standard Contractual Clauses approved by the European Commission together with the UK International Data Transfer Addendum where relevant, the use of the South African Protection of Personal Information Act's own cross border transfer conditions where data moves to or from South Africa, or other lawful transfer mechanisms recognised under applicable law from time to time. We conduct a transfer impact assessment before relying on Standard Contractual Clauses to confirm that the receiving jurisdiction offers a level of protection that is not undermined by local law or practice, and we implement supplementary technical measures such as encryption and pseudonymisation where warranted by that assessment.
Because the FHcare platform is built as a multi tenant system that may in future serve client agencies located in, or with candidates or workers located in, multiple jurisdictions simultaneously, personal data belonging to individuals in different countries may in some cases be logically aggregated within shared infrastructure for the purposes of system administration, analytics conducted on anonymised or pseudonymised data, and platform wide security monitoring, even where that data is not accessible to client agencies outside their own tenant environment. We refer to this operational reality, and the protections we apply to it, in Section 16.
16. Limitation of Liability and Indemnification for Cross Border and Multi Jurisdictional Processing
This section addresses the specific operational reality that FHcare operates a single, centrally administered technology platform that is licensed to client agencies across multiple jurisdictions, and that infrastructure level administration, security monitoring, backup and disaster recovery functions may necessarily involve the collocation or logical aggregation of data originating from different countries within shared, tenant isolated infrastructure, even though client data remains logically segregated and is not commingled between client agencies at the application layer.
FHcare processes personal data strictly on the documented instructions of the relevant client agency acting as data controller, or, in respect of our own website and account administration data, as an independent controller subject to the terms of this Policy. Where a client agency instructs us to collect, process or store personal data in a manner that does not comply with the data protection law applicable to that client agency's own jurisdiction or to the jurisdiction of the individuals whose data is concerned, responsibility for that instruction and its compliance with local law rests with the instructing client agency, and FHcare's role is limited to executing that instruction through the technical means made available on the platform, together with flagging any instruction that appears on its face to be unlawful.
To the fullest extent permitted by applicable law, FHcare shall not be liable for any loss, damage, regulatory penalty or third party claim arising from the collocation, aggregation or cross border transfer of personal data within our shared infrastructure where that collocation, aggregation or transfer occurs as a necessary consequence of operating a centrally administered, multi tenant platform in accordance with the security architecture described in Section 14 and the transfer safeguards described in Section 15, and where FHcare has not acted outside the documented instructions of the relevant controller or in breach of its own obligations as processor under applicable data processing terms. Each client agency using the platform agrees, as a condition of its licence to use the Services, to indemnify FHcare against claims, penalties or losses arising from that client agency's own instructions, its own determination of the lawful basis for processing, its own compliance with sector specific or jurisdiction specific law, or its own failure to notify FHcare of a jurisdiction specific requirement that would materially affect how data belonging to its candidates or workers should be collected, stored or transferred.
This limitation of liability does not exclude or limit liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be excluded or limited under applicable law. It is intended to reflect a fair allocation of responsibility between a technology platform provider operating shared multi jurisdictional infrastructure and the client agencies who determine the purposes and legal basis for processing personal data through that platform, consistent with the recognised division of responsibility between data controllers and data processors under the UK GDPR, EU GDPR, POPIA and comparable frameworks.
17. Data Breach Notification
We maintain an incident response process designed to detect, contain and assess any suspected personal data breach without undue delay. In the event of a personal data breach that poses a risk to the rights and freedoms of affected individuals, we will notify the relevant supervisory authority within seventy two hours of becoming aware of the breach where required by applicable law, and we will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
Where a breach affects data processed on behalf of a client agency acting as controller, we will notify that client agency promptly and provide the information reasonably necessary for them to meet their own regulatory notification obligations, recognising that in most jurisdictions the primary notification duty to affected individuals rests with the controller rather than with FHcare as processor. We will cooperate fully with any investigation carried out by a supervisory authority or by an affected client agency in connection with a breach.
18. Children's Privacy
The FHcare platform is intended for professional use by adults aged eighteen and over, including in sector configurations outside healthcare such as education staffing, where the platform is used by adult staff members rather than by the children or young people who are ultimately supported or taught by those staff members. We do not knowingly collect personal data directly from children under eighteen through the platform.
Where a client agency operating in a sector involving work with children, such as education or childcare staffing, uses the platform to record safeguarding related information that references a child or young person incidentally, for example within a placement note, that information is treated with the same enhanced protections described in Section 14 for special category data, and access is restricted to specifically authorised roles. If we become aware that we have collected personal data directly from a child without appropriate authorisation, we will delete that data promptly. If you believe we may hold such data, please contact us using the details in Section 24.
19. Third Party Links, Integrations and Client Agency Instances
Our website and platform may contain links to third party websites, or may integrate with third party services selected by a client agency, such as payroll providers, accounting software, background screening providers or communication tools. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy notices before providing personal data to them.
Each client agency operates its own branded instance of the FHcare platform, configured according to its own sector, size and compliance requirements. While the underlying infrastructure and security architecture is common across instances, the specific data fields collected, the workflows applied and the retention periods observed may differ between client agencies. This Policy describes our practices as the platform operator across all instances, while acknowledging that a given client agency's own privacy notice may contain additional or, in narrow respects, differing detail relevant to their specific use of the platform.
20. Accessibility Statement
We are committed to making our website and platform accessible to the widest possible audience, including individuals with disabilities, consistent with recognised accessibility standards such as the Web Content Accessibility Guidelines. If you experience difficulty accessing any part of our website or platform, or if you require this Policy in an alternative format, please contact us using the details in Section 24 and we will take reasonable steps to assist you.
21. Complaints and Dispute Resolution
If you have a concern about how we have handled your personal data, we encourage you to contact us in the first instance using the details in Section 24 so that we can investigate and, wherever possible, resolve the matter directly. We aim to acknowledge complaints promptly and to provide a substantive response within thirty days.
If you remain dissatisfied following our response, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction, including the Information Commissioner's Office in the United Kingdom, the Data Protection Commission in Ireland, the Information Regulator in South Africa, or the equivalent authority in your own country of residence. Where a dispute cannot be resolved informally, and subject to any mandatory rights you hold under applicable consumer or data protection law, the parties may agree to resolve the dispute through mediation before resorting to court proceedings.
22. Governing Law and Jurisdiction
This Policy, and any dispute arising out of or in connection with it, is governed by the laws of England and Wales, without prejudice to any mandatory rights you hold under the data protection law of your own country of residence, which continue to apply and are not displaced by this clause. The courts of England and Wales have non exclusive jurisdiction over any dispute arising from this Policy, meaning that you remain free to bring proceedings in the courts of your own jurisdiction where applicable law entitles you to do so.
23. Changes to This Policy
We may update this Policy from time to time to reflect changes in our data practices, our sector footprint, applicable law or the way our business operates. Where a change is material, we will notify affected users by email or by posting a prominent notice within the platform at least thirty days before the change takes effect. The updated Policy will display a revised effective date at the top of the document. Your continued use of the Services after the effective date of an updated Policy constitutes your acceptance of that update, save that we will always seek fresh consent where applicable law requires it, for example in relation to a materially different use of special category data.
24. Contact Us
Data controller and processor details
FHcare Tech Limited acts as data controller for personal data processed through our own website, marketing activity and account administration, and as data processor for candidate and worker data processed on behalf of client agencies, except where this Policy states otherwise.
- Company: FHcare Tech Limited
- Registered address: Lombard Business Park, London, England SW19 3TZ
- Phone: +353 87 034 4882
- Email: info@fhcaretech.io
Data Protection Officer
If you have questions about how we handle personal data or wish to exercise any of the rights described in Section 12, you may contact our Data Protection Officer at support@fhcaretech.io. You also have the right to lodge a complaint with the Information Commissioner's Office in the United Kingdom at ico.org.uk, the Data Protection Commission in Ireland at www.dataprotection.ie, or the Information Regulator in South Africa, without prejudice to any other administrative or judicial remedy available to you.