Important role distinction. A subscribing care provider normally decides why and how resident, family, carer, medication, safeguarding, and visit information is used. That provider is the data controller. VitaSync processes that information on the provider’s documented instructions and is normally its data processor.
Who we are and our data protection roles
VitaSync provides a care-management platform to UK care providers. We act as a controller for personal data used to operate our website, assess home applications, administer contracts and licences, secure accounts, prevent misuse, communicate with prospective and existing customers, and meet our own legal obligations.
For personal data entered by a care provider about people receiving care, relatives, staff, visitors, complaints, safeguarding, medication, or care delivery, the care provider is normally the controller and VitaSync is its processor. Questions about those care records should normally be directed first to the relevant care provider.
Information we handle
- Registration and business details: home name, registration number, care type, address, capacity, contact information, manager identity, and application status.
- Account and security details: name, work contact details, role, permissions, password hash, authentication events, IP address, device and browser information, login history, and audit records.
- Commercial information: licence period, contract, billing, invoice, payment, and service correspondence information.
- Customer-controlled care data: client profiles, assessments, care plans, visits, EVV, notes, tasks, observations, medication records, family access, safeguarding, complaints, training, evidence, and related audit history.
- Support information: messages, issue reports, diagnostic information, and records supplied when support is requested.
Care data may include health information and other special category personal data. The subscribing care provider is responsible for identifying its lawful basis and Article 9 condition, giving appropriate privacy information, and ensuring that instructions to VitaSync are lawful.
Why we use information and our lawful bases
| Purpose | Typical lawful basis |
|---|---|
| Assess registrations, provide accounts, licences, support, and contracted services | Contract, or steps requested before entering a contract |
| Secure the platform, prevent fraud, investigate misuse, and maintain auditability | Legitimate interests in providing a secure and accountable service; legal obligation where applicable |
| Billing, taxation, corporate records, disputes, and regulatory cooperation | Contract and legal obligation; legitimate interests in establishing or defending legal claims |
| Service communications and important platform notices | Contract and legitimate interests |
| Processing customer-controlled care data | Performed as processor under the care provider’s documented instructions and data-processing terms |
We do not use customer-controlled care records for advertising or sell them. If we introduce optional marketing or non-essential tracking, we will provide the choices and information required by UK law.
Retention and security
We keep controller data only for as long as needed for the purposes described above, including contractual, tax, security, dispute, and legal requirements. Retention periods vary by record type.
For customer-controlled care records, the care provider determines the retention schedule. We retain or delete those records on its documented instructions, subject to law, backup cycles, security requirements, and the need to preserve records relevant to legal claims or regulatory duties. Care records must not be destroyed merely because an account is closed where the provider has a lawful or regulatory reason to retain them.
We apply role-based access, authentication controls, audit logging, tenant separation, encryption in transit, backups, monitoring, and organisational controls appropriate to the risks. No internet service can be guaranteed completely secure, so users must protect credentials and report suspected compromise promptly.
Your UK data protection rights
Depending on the circumstances, you may have rights to be informed, access your personal data, correct inaccurate data, erase data, restrict processing, receive portable data, object to processing, and receive safeguards concerning solely automated decisions.
These rights are not absolute. For example, erasure may not apply where information must be retained to comply with law, preserve care-record integrity, protect safeguarding interests, or establish, exercise, or defend legal claims. If your request concerns information held by a care provider, we may refer it to that provider and assist it as processor.
We normally respond to valid rights requests within one month, although UK law permits extensions for complex or numerous requests. We may request proportionate proof of identity.
Contact us and complain
For VitaSync-controlled information or privacy questions, email privacy@vitasync.stepanite.com. For care records, contact the care provider that delivered or arranged the care. You may also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint.
We may update this notice when our services or the law change. Material changes will be communicated through the platform or other appropriate channels.