Policies · Privacy
Privacy Notice
Effective: 2026-04-22 · Last updated: 2026-04-22 · Version 1.0
This notice explains how Care Airo Ltd ("Care Airo", "we", "us") handles personal data collected through the CareAiro platform, mobile application, and marketing website at careairo.com.
1. Who we are
Care Airo Ltd is the controller of the personal data we collect through this platform.
| Registered office | 61 Cranbrook House, Cranbrook Road, Ilford, Essex IG1 4PG, United Kingdom |
|---|---|
| Privacy contact | privacy@careairo.com |
2. What personal data we collect
Through the mobile application
When care workers use the CareAiro mobile app, we collect:
- GPS location (only during visit check-in and check-out for verification)
- Camera access (to scan QR codes for secure check-in and upload incident photos)
- Microphone access (for optional speech-to-text visit note dictation)
- Photos from library (to attach images to incident reports)
- Visit notes, tasks, and care records entered by the care worker
- Device push notification token (for shift and visit alerts)
Through the web platform
- Name, email address, and role for account management
- Activity logs and audit trails for compliance purposes
- Standard server log entries (IP address retained 30 days)
3. Why we process your data and our lawful basis
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| GPS check-in verification for care visits | Legitimate interests — ensuring care workers attend scheduled visits |
| QR code scan for secure check-in | Legitimate interests — verifying visit attendance |
| Speech-to-text for visit notes | Consent — only when care worker activates the feature |
| Incident photo upload | Legal obligation — safeguarding and CQC compliance |
| Push notifications for shifts and visits | Legitimate interests — operational communication |
| Audit logging for CQC compliance | Legal obligation — Care Quality Commission requirements |
4. How long we keep your data
| Data | Retention |
|---|---|
| Care records and visit notes | 8 years (CQC requirement) |
| Staff records | 6 years post-employment |
| Audit logs | Indefinite (regulatory compliance) |
| Incident photos | 8 years (CQC) or 90 days (GDPR — failed verifications) |
| GPS location data | Retained with visit record (8 years) |
| Server IP logs | 30 days |
| Push notification tokens | Until device deregistration |
6. Your rights
Under UK GDPR you have the right to:
- Access — ask for a copy of the personal data we hold about you
- Rectification — ask us to correct data that is wrong
- Erasure — ask us to delete data in certain circumstances
- Restriction — ask us to limit how we use your data
- Portability — receive your data in a structured format
- Object — object to processing based on legitimate interests
To exercise any rights, email privacy@careairo.com. We will respond within one calendar month.
You may also complain to the Information Commissioner's Office: ico.org.uk · 0303 123 1113
7. Automated decision-making
The CareAiro platform uses AI to assist care managers with scheduling suggestions and care summaries. These are advisory tools only — no automated decisions that produce legal or similarly significant effects are made without human review.
9. Security
We protect personal data using encryption in transit (TLS 1.2+), encryption at rest, role-based access controls, and immutable audit logs. Our infrastructure is hosted exclusively in the United Kingdom (Google Cloud Platform, london region).
10. Mobile application permissions
| Permission | Why it is needed |
|---|---|
| Location (when in use) | GPS check-in at service user address to verify attendance |
| Camera | Scan QR codes for secure check-in; upload photos for incident reports |
| Microphone | Speech-to-text dictation for visit notes (activated by care worker only) |
| Photo library | Attach images to incident and safeguarding reports |
| Notifications | Shift reminders, visit alerts, and urgent care messages |
11. Changes to this notice
We may update this notice from time to time. The "Last updated" date at the top shows when it was last revised. Material changes will be communicated to registered users.
12. Contact
| Privacy enquiries & subject access requests | privacy@careairo.com |
|---|---|
| Postal | Data Protection, Care Airo Ltd, 61 Cranbrook House, Cranbrook Road, Ilford, Essex IG1 4PG |
Change log
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026-04-22 | Initial version |
| 1.1 | 2026-05-09 | Added mobile app permissions section |