Trust

Data Protection and Security

CareBeacon is designed to help care providers manage facilities, inspections, assets, maintenance and compliance evidence securely.

This page summarises our approach to data protection and platform security. Specific contractual commitments are contained in the customer agreement and data-processing terms.

Our role

Care providers using CareBeacon will generally determine:

  • what information is entered into the platform;
  • why that information is processed;
  • which users may access it;
  • how long it should be retained; and
  • how it is used within their organisation.

The care provider will therefore generally act as controller.

CareBeacon will generally act as processor when hosting and processing that information on the provider's behalf.

For information we process for our own business purposes, such as customer contacts, billing, sales and account management, we act as controller.

Data minimisation

CareBeacon is primarily an operational and facilities-management platform.

Customers should record only information that is:

  • relevant to the inspection, task, asset or work order;
  • necessary for the relevant operational purpose;
  • accurate and appropriate; and
  • permitted under their own policies and lawful basis.

The platform should not be used as a substitute for a resident care-planning or clinical-record system.

Customers should not upload special-category information, detailed medical records or unnecessary resident information unless the use has been expressly agreed and lawfully assessed.

Access controls

CareBeacon supports role-based access so customers can control what users can view and do.

Depending on the agreed configuration, controls may include:

  • organisation and site-level access;
  • administrator, manager, supervisor and staff roles;
  • permissions for installers or contractors;
  • individual user accounts;
  • account suspension and removal;
  • activity and audit records; and
  • restricted access to particular homes or areas.

Customers are responsible for maintaining accurate user lists and promptly removing access where it is no longer required.

Platform security

Our security approach may include:

  • encrypted connections;
  • secure hosting;
  • authentication controls;
  • role-based permissions;
  • logging and monitoring;
  • backups;
  • vulnerability management;
  • restricted administrative access;
  • software-update procedures;
  • incident response; and
  • supplier and subprocessor review.

Data hosting and subprocessors

CareBeacon uses selected service providers to host and support the platform.

A current list of subprocessors can be requested from:

privacy@carebeacon.co.uk

Where a supplier processes information outside the UK, an appropriate transfer safeguard will be used where required.

Data-processing agreements

Customer contracts will include appropriate provisions governing:

  • processing instructions;
  • confidentiality;
  • security;
  • subprocessors;
  • assistance with data-subject rights;
  • security incidents;
  • deletion and return of data;
  • audit information; and
  • international transfers.

The ICO identifies controller-processor contracts, documentation, data protection by design, impact assessments and governance as central parts of accountability.

Retention and deletion

Customers control their operational retention requirements, subject to platform functionality and the customer agreement.

Following termination, customer information will be returned, exported or deleted in accordance with the agreed contractual process, subject to lawful backups and retention requirements.

Security incidents

We maintain procedures for identifying, investigating and responding to suspected personal-data or security incidents.

Where CareBeacon acts as processor, we will notify the relevant customer without undue delay after becoming aware of a personal-data breach affecting that customer's information, in accordance with the customer agreement.

Customer responsibilities

CareBeacon provides tools, but customers remain responsible for:

  • choosing lawful and proportionate uses of the platform;
  • informing staff and other individuals how their information is used;
  • establishing appropriate lawful bases;
  • configuring access correctly;
  • protecting user credentials;
  • training staff;
  • reviewing uploaded photographs and notes;
  • maintaining appropriate retention policies; and
  • completing any required data-protection impact assessment.

Data-protection enquiries

Email: privacy@carebeacon.co.uk