GDPR Compliance

Carionex is designed with data protection at its core. We help care agencies meet their GDPR obligations while delivering excellent care.

Our Commitment to Data Protection

As a provider of software to care agencies, we understand the sensitive nature of the data you handle. Carionex is built to support your compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

When you use our platform, you act as the data controllerfor your clients' and staff's personal data. Carionex acts as your data processor, processing data only on your behalf and according to your instructions.

We are registered with the Information Commissioner's Office (ICO) and maintain comprehensive technical and organisational measures to protect personal data.

How We Support Your Compliance

Data Processing Agreement

We provide a comprehensive DPA that outlines our responsibilities as your data processor.

Data Subject Rights

Our platform makes it easy to respond to access, rectification, and deletion requests.

Encryption & Security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256).

Access Controls

Role-based access ensures staff only see data relevant to their responsibilities.

Audit Trails

Comprehensive logging of all data access and modifications for accountability.

Data Minimisation

We only collect and process data necessary for providing our services.

UK Data Residency

All data is stored on servers located within the United Kingdom.

Regular Assessments

We conduct annual security audits and data protection impact assessments.

Your Responsibilities as Data Controller

While we provide the tools and security, as a care agency you have responsibilities under GDPR:

  • Ensure you have a lawful basis for processing personal data
  • Inform data subjects about how their data is processed
  • Respond to data subject requests within required timeframes
  • Report data breaches to the ICO within 72 hours (we will notify you immediately)
  • Keep your own records of processing activities
  • Ensure staff are trained on data protection

Data Processing Agreement

All Carionex customers receive a Data Processing Agreement (DPA) that clearly defines our obligations as your data processor. The DPA covers data security measures, sub-processors, breach notification procedures, and more.

Request DPA

Supporting Data Subject Rights

Carionex includes features to help you respond to data subject requests:

  • Right of Access: Export all data related to an individual in a portable format
  • Right to Rectification: Easily update and correct personal information
  • Right to Erasure: Delete personal data (subject to legal retention requirements for care records)
  • Right to Restrict Processing: Flag records to prevent further processing
  • Right to Data Portability: Export data in standard formats (CSV, JSON)

Questions About GDPR Compliance?

Our Data Protection Officer is available to answer your questions and help ensure your agency meets its data protection obligations.