Privacy

How Be Care Compliant handles personal information. Written in plain English, because the people who read it are the people who have to answer for it.

Last updated 29 July 2026

The two different sets of information

There are two very different kinds of personal information around Be Care Compliant, and the difference matters, because we do not hold the same role for each.

The first is information about you as a visitor to this website, for example when you ask for a trial. For that information we decide what happens to it, so we are the data controller.

The second is the information inside the platform, meaning your staff records and the records of the people your service supports. That belongs to your care company. Your company decides what goes in it and what it is used for, so your company is the controller and we are only the processor acting on your instructions. We do not use it for anything of our own, and we never sell it.

What this website collects

If you ask for a trial we collect your company name, your name, your email address and, if you choose to give them, your phone number, the size of your team, the plan you are interested in and anything you tell us in the message box.

We use it to reply to you, to set your trial up and to talk to you about it. We do not sell it and we do not pass it to anyone for their own marketing.

We keep a trial request for as long as we are talking to you about it, and for up to two years afterwards so we know who we have already spoken to. Ask us and we will delete it sooner.

The website sets no advertising cookies and no analytics cookies. Once you sign in, the application uses cookies that are strictly necessary to keep you signed in and to keep your session secure.

What sits inside the platform

The platform holds records about your staff, such as supervisions, spot checks, training, DBS and right to work checks, absence and holiday, and records about the people you support, such as care plan reviews, risk assessments and medication audits. Some of that is health information, which the law treats as a special category and which we treat as the most sensitive data we hold.

Every company's data is separated from every other company's at the database level rather than by a filter in the application, so one company cannot see another's records even if something goes wrong in the interface.

Access inside a company is limited by role. A carer sees their own record. A supervisor sees their caseload. Views and changes are written to an audit trail that cannot be edited.

Files and completed forms are stored privately. They are never public, and they are handed out only through links that expire after five minutes, with each download recorded.

Where it is kept

The database, the files and the backups are held in the United Kingdom, in a London region.

One exception is worth stating plainly. Where you choose to use an AI feature, the text of that request is sent to our AI supplier for processing and comes straight back. That supplier operates outside the United Kingdom and Europe, so that particular transfer relies on the standard contractual safeguards. AI features are optional and metered, and nothing is sent to them unless someone in your company asks for it.

Who else is involved

We use a small number of suppliers to run the service, and each of them only sees what they need to do their part.

Hosting and the application itself run on Vercel. The database, the file storage and authentication are provided by Supabase, in a London region. Email is sent through Resend. Text messages, where your plan includes them, are sent through Twilio. Payments are handled by Stripe, which means card details never reach our servers. AI features are processed by our AI supplier as described above.

We do not add new suppliers who touch your data without telling the companies who use the platform.

How long we keep it

Compliance evidence is kept for at least eight years from the end of a person's care, which reflects what a care provider is expected to be able to produce for a regulator. When that period is up we anonymise it automatically: the record that a check happened stays, and the personal detail inside it is removed. A care company can hold particular records back for longer where they have to, for example while a tribunal or an investigation is running.

If your company stops using Be Care Compliant, your records are not deleted the moment a subscription ends. Tell us and we will export them for you or delete them, whichever you ask for.

Your rights

You can ask what we hold about you, ask for it to be corrected, ask for it to be deleted, ask us to limit what we do with it, or object to it.

If your request is about records inside the platform, the right person to ask first is the care company that holds them, because they are the controller. We will always help them answer you.

If you are not happy with how we have handled something, you can complain to the Information Commissioner's Office at ico.org.uk.

Contact

Email hello@becarecompliant.com and a person will read it.

Questions about any of this? hello@becarecompliant.com, or ask for a trial.

Privacy · Be Care Compliant