Your right to erasure matters, but it is not absolute. UK GDPR Article 17 applies in specified circumstances. Care providers may still need to preserve accurate care, medication, safeguarding, employment, financial, or audit records to comply with law, protect people, and establish or defend legal claims.
Account closure and data erasure are different
Account closure disables access and ends the user’s ability to sign in. It does not automatically delete records of actions already taken, because removing those records could damage the integrity of the care provider’s audit trail.
Erasure is a data-protection request to delete qualifying personal data. It is assessed against the purposes, lawful bases, controller instructions, exemptions, and retention duties that apply to each record.
How to make a request
For resident, relative, carer, visit, medication, safeguarding, or care records, contact the care provider that collected the information. For VitaSync registration or service-account data, contact us.
Provide your name, work email, home or organisation, relationship to the data, and what you want closed or erased. Do not email sensitive care information unless necessary.
We or the care provider may request information needed to verify identity and authority before changing or disclosing records.
Requests concerning care records
The care provider is normally controller for care records and decides the request. VitaSync will assist the provider as processor. We will not independently delete a provider’s care records merely because an individual user account is closed.
Where erasure would undermine an accurate and contemporaneous record of care, medication, safeguarding, consent, complaints, staff activity, or management decisions, the provider may need to retain the record and instead restrict access, correct inaccuracies, record an objection, or apply another lawful safeguard.
What happens after a valid request
- We identify whether VitaSync or a care provider is the controller for the information.
- We acknowledge the request and may ask focused questions or request proof of identity.
- We search relevant live systems and assess lawful retention grounds and exemptions.
- We erase qualifying data, anonymise it where appropriate, or explain what cannot be erased and why.
- Where required and reasonably possible, relevant recipients are informed of the erasure.
- Deletion from encrypted backups occurs through controlled backup-rotation cycles unless restoration is required for disaster recovery, in which case deletion controls are reapplied.
Valid requests are normally answered within one month. Complex or numerous requests may take longer where UK law permits, and the requester will be informed.
Information that may still be retained
Depending on the circumstances, limited information may be retained for legal obligations, CQC and care-record governance, medication safety, safeguarding, taxation and accounting, fraud and security prevention, contract enforcement, complaints, insurance, or legal claims.
Access will remain limited and the information will not be used for unrelated purposes. If you disagree with the outcome, you may ask for reconsideration or complain to the Information Commissioner’s Office.