Legal
Privacy Policy
How CareOptix collects, uses and protects personal data — and which of the two roles we are playing when we do.
Version 1.0 · Last updated 23 September 2026
1. Who we are
CareOptix is operated by Optix Compliance, a business operating in England and Wales ("we", "us", "our").
This policy covers careoptix.co.uk and the CareOptix application.
Contact for data protection matters: privacy@optixgroup.co.uk
2. The two roles we play
This is the most important thing to understand about how we handle data, and it determines which parts of this policy apply to you.
When we are the controller
We decide how and why data is used when we handle:
- data about visitors to our websites
- data about prospective customers and enquiries
- data about the individuals who administer a customer account with us
- billing and account data
- support correspondence
Sections 3 to 10 of this policy apply to that data.
When we are the processor
Our customers upload records about their own staff, workers, clients, tenants, candidates and service users into our software. For that data, our customer is the controller — they decide what is collected, why, and how long it is kept — and we are the processor, handling it only on their documented instructions.
If you are an employee, worker, candidate, tenant, resident or service user of one of our customers, and you want to exercise your rights over your data, you should contact that organisation rather than us. They are responsible for responding. We will assist them, and if you contact us we will point you to the right organisation where we can.
Our obligations as a processor are set out in our Data Processing Agreement, which forms part of our contract with every customer. Section 11 summarises it.
3. Personal data we collect as controller
| Category | Examples | Where we get it |
|---|---|---|
| Identity data | Name, job title, employer | You, directly |
| Contact data | Email address, phone number, business address | You, directly |
| Account data | Username, hashed password, account preferences | You, directly |
| Billing data | Billing contact, billing address, VAT number, subscription and invoice history, card type and last four digits | You, via Stripe |
| Usage data | Pages viewed, features used, login times | Automatically |
| Technical data | IP address, browser type and version, device type, operating system | Automatically |
| Support data | The content of emails and any attachments you send us | You, directly |
We do not collect or store your full payment card details. Card payments are processed directly by Stripe; we receive only a payment reference and limited card metadata.
4. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Creating and administering your account | Performance of a contract |
| Providing the software you subscribe to | Performance of a contract |
| Taking payment and issuing invoices | Performance of a contract |
| Providing customer support | Performance of a contract |
| Sending service messages — security alerts, password resets, changes to terms, maintenance and renewal notices | Performance of a contract, and our legitimate interest in operating the service securely |
| Keeping the service secure, and detecting and preventing fraud and abuse | Our legitimate interest in protecting our service and our customers |
| Understanding how the service is used so we can improve it | Our legitimate interest in developing our products |
| Responding to enquiries from prospective customers | Our legitimate interest in responding to enquiries, and steps taken at your request before entering a contract |
| Keeping accounting and tax records | Legal obligation |
| Establishing, exercising or defending legal claims | Our legitimate interest in protecting our legal position |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights and freedoms. You can ask us for details of that assessment at privacy@optixgroup.co.uk, and you have the right to object — see section 8.
Service messages are not marketing. You cannot opt out of security alerts, billing notices or notifications about changes to the service while you hold an account with us.
5. Marketing
We do not currently send marketing emails, and we operate no mailing list. If you complete an enquiry or demo request form, we use your details to respond to that enquiry.
Should we begin sending marketing in future, we will do so only where we have your consent or may rely on the soft opt-in, every message will carry an unsubscribe link, and this policy will be updated before we start. You can tell us at any time that you do not wish to be contacted, by emailing privacy@optixgroup.co.uk.
We do not sell your data, and we do not share it with third parties for their own marketing.
6. Who we share data with
We share personal data with the following providers. This is our full list, not a category summary.
| Provider | Purpose | What they receive | Region |
|---|---|---|---|
| Vercel Inc. | Application hosting and content delivery | All Customer Personal Data in transit; technical request data | UK / EEA |
| Nile (Niledatabase, Inc.) | Database hosting, uploaded files and backups | All Customer Personal Data | EEA (Frankfurt) |
| Stripe Payments Europe, Ltd. | Payment processing | Billing contact and card metadata only — no Customer Personal Data | EEA, with onward transfer to the United States under the UK IDTA |
| Vercel Inc. (Web Analytics) | Aggregate visitor measurement on our marketing sites | Technical request data only — no cookie, no device identifier | UK / EEA |
We also share data with our professional advisers — accountants, solicitors and insurers — where necessary; with authorities, regulators and law enforcement where required by law; and with an acquirer or successor if we sell or restructure the business.
We require every provider that handles personal data on our behalf to be bound by a written contract meeting the requirements of Article 28 UK GDPR.
7. International transfers
We host customer data in the United Kingdom or the European Economic Area.
Stripe processes billing data in the EEA with onward transfer to the United States. Where a transfer leaves the UK without an adequacy decision, we rely on the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.
You can ask us for details of the safeguards applying to a specific transfer at privacy@optixgroup.co.uk.
8. Your rights
Under UK GDPR you have the right to:
- be informed about how we use your data — this policy
- access your personal data and receive a copy
- rectification of inaccurate or incomplete data
- erasure, in certain circumstances
- restrict processing, in certain circumstances
- data portability for data you provided, where processing is by consent or contract and carried out by automated means
- object to processing based on legitimate interests, and to direct marketing at any time
- not be subject to solely automated decision-making producing legal or similarly significant effects
- withdraw consent at any time where we rely on it, without affecting the lawfulness of processing before withdrawal
To exercise a right, email privacy@optixgroup.co.uk. We will respond within one month. We may extend that by up to two further months for complex requests and will tell you if we do. We may ask you to verify your identity. There is no charge unless a request is manifestly unfounded or excessive.
If your data is held in our software by one of our customers, contact that organisation instead — see section 2.
We would like the chance to resolve any concern first, but you have the right to complain to the Information Commissioner's Office at any time: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · 0303 123 1113 · ico.org.uk
9. How long we keep it
| Data | Retention |
|---|---|
| Account data | For the life of the account, then 12 months |
| Customer data held in the software | See section 11 and the Data Processing Agreement |
| Billing, invoices and accounting records | 6 years from the end of the financial year, as required by tax law |
| Support correspondence | 3 years from the end of the matter |
| Enquiries that did not become customers | 12 months |
| Website analytics | Aggregate counts only, retained by our analytics provider; no individual record is created |
Where we need to keep data to establish, exercise or defend legal claims, we may retain it for the relevant limitation period.
10. Security
Our technical and organisational measures are published in full in Schedule 3 of our Data Processing Agreement, including the measures we have not yet built. We would rather state the gap than imply a control we do not have.
No system is completely secure, and we cannot guarantee the security of data transmitted to us over the internet.
Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and notify affected individuals without undue delay where the risk is high. Where we are a processor, we will notify the relevant customer without undue delay so they can meet their own obligations.
11. Data held in our software
As processor, we process the personal data that customer organisations choose to upload to CareOptix. For this product that includes: name, date of birth, contact details, photographs, care records, daily logs, placement plans, risk assessments, education records, incident and accident records, missing-from-home records, contact arrangements, complaints, staff records, rotas, training records and supervision records.
CareOptix may hold special category data: health and medical information; mental health information; disability; ethnicity; religion; sexual orientation; and genetic or biometric data where uploaded. It may also hold criminal offence data: dBS check records for staff; youth offending information, police involvement, cautions and convictions relating to young people; and allegations against staff. Customer organisations are responsible for holding a valid condition under Article 9 and, where applicable, Article 10 UK GDPR.
For that data:
- our customer determines what is collected and why
- we process it only on their documented instructions
- we do not use it for our own purposes
- we do not use it to train, fine-tune or evaluate any artificial intelligence or machine learning model
- we do not sell or disclose it, except to the providers listed in section 6 under contract, or where legally required
- we delete or return it on termination, as set out in the Data Processing Agreement
If you believe an organisation using our software holds data about you, contact that organisation. If you do not know which organisation to contact, email privacy@optixgroup.co.uk and we will help where we are able to without breaching our confidentiality obligations to our customers.
12. Children
Our websites and products are business tools and are not directed at children. We do not knowingly collect personal data directly from children through our websites.
CareOptix contains records about children and young people. That data is uploaded by care providers acting as controller. We process it strictly as a processor under section 11 and under the Data Processing Agreement, and never for our own purposes.
13. Cookies
Our marketing sites set no cookies at all, and our visitor measurement is cookieless. Our applications set only the cookies strictly necessary to keep you signed in. Our Cookie Policy explains this in full.
14. Changes to this policy
We may update this policy. We will post the updated version here with a revised date. Where changes are material, we will notify account holders by email at least 30 days before they take effect.