Skip to main content
VitaSync Care, connected
Platform Solutions Register a home Sign in

Legal centre

Privacy Notice

How VitaSync handles personal information across our website, home registration, platform accounts, and care-management services.

Effective 27 July 2026 United Kingdom UK GDPR & Data Protection Act 2018
On this page Our data protection roles Information we handle Purposes and lawful bases Sharing and transfers Retention and security Your rights Cookies Contact and complaints

Important role distinction. A subscribing care provider normally decides why and how resident, family, carer, medication, safeguarding, and visit information is used. That provider is the data controller. VitaSync processes that information on the provider’s documented instructions and is normally its data processor.

01

Who we are and our data protection roles

VitaSync provides a care-management platform to UK care providers. We act as a controller for personal data used to operate our website, assess home applications, administer contracts and licences, secure accounts, prevent misuse, communicate with prospective and existing customers, and meet our own legal obligations.

For personal data entered by a care provider about people receiving care, relatives, staff, visitors, complaints, safeguarding, medication, or care delivery, the care provider is normally the controller and VitaSync is its processor. Questions about those care records should normally be directed first to the relevant care provider.

02

Information we handle

  • Registration and business details: home name, registration number, care type, address, capacity, contact information, manager identity, and application status.
  • Account and security details: name, work contact details, role, permissions, password hash, authentication events, IP address, device and browser information, login history, and audit records.
  • Commercial information: licence period, contract, billing, invoice, payment, and service correspondence information.
  • Customer-controlled care data: client profiles, assessments, care plans, visits, EVV, notes, tasks, observations, medication records, family access, safeguarding, complaints, training, evidence, and related audit history.
  • Support information: messages, issue reports, diagnostic information, and records supplied when support is requested.

Care data may include health information and other special category personal data. The subscribing care provider is responsible for identifying its lawful basis and Article 9 condition, giving appropriate privacy information, and ensuring that instructions to VitaSync are lawful.

03

Why we use information and our lawful bases

PurposeTypical lawful basis
Assess registrations, provide accounts, licences, support, and contracted servicesContract, or steps requested before entering a contract
Secure the platform, prevent fraud, investigate misuse, and maintain auditabilityLegitimate interests in providing a secure and accountable service; legal obligation where applicable
Billing, taxation, corporate records, disputes, and regulatory cooperationContract and legal obligation; legitimate interests in establishing or defending legal claims
Service communications and important platform noticesContract and legitimate interests
Processing customer-controlled care dataPerformed as processor under the care provider’s documented instructions and data-processing terms

We do not use customer-controlled care records for advertising or sell them. If we introduce optional marketing or non-essential tracking, we will provide the choices and information required by UK law.

04

Sharing, processors, and international transfers

We may share relevant information with authorised personnel at the subscribing home; infrastructure, hosting, email, security, support, payment, and professional-service suppliers; regulators, courts, law enforcement, or public authorities where lawfully required; and a successor organisation during a properly controlled corporate transaction.

Suppliers receive only the information needed for their function and must be subject to appropriate confidentiality, security, and data-protection terms. Where personal data is transferred outside the UK, we use a lawful transfer mechanism and appropriate safeguards, such as UK adequacy regulations or the UK International Data Transfer Agreement/Addendum, as applicable.

05

Retention and security

We keep controller data only for as long as needed for the purposes described above, including contractual, tax, security, dispute, and legal requirements. Retention periods vary by record type.

For customer-controlled care records, the care provider determines the retention schedule. We retain or delete those records on its documented instructions, subject to law, backup cycles, security requirements, and the need to preserve records relevant to legal claims or regulatory duties. Care records must not be destroyed merely because an account is closed where the provider has a lawful or regulatory reason to retain them.

We apply role-based access, authentication controls, audit logging, tenant separation, encryption in transit, backups, monitoring, and organisational controls appropriate to the risks. No internet service can be guaranteed completely secure, so users must protect credentials and report suspected compromise promptly.

06

Your UK data protection rights

Depending on the circumstances, you may have rights to be informed, access your personal data, correct inaccurate data, erase data, restrict processing, receive portable data, object to processing, and receive safeguards concerning solely automated decisions.

These rights are not absolute. For example, erasure may not apply where information must be retained to comply with law, preserve care-record integrity, protect safeguarding interests, or establish, exercise, or defend legal claims. If your request concerns information held by a care provider, we may refer it to that provider and assist it as processor.

We normally respond to valid rights requests within one month, although UK law permits extensions for complex or numerous requests. We may request proportionate proof of identity.

07

Cookies and similar technologies

VitaSync currently uses strictly necessary technologies for security, session management, login, CSRF protection, and preferences needed to provide the service requested by the user. These cannot normally be switched off through our service.

We do not currently use advertising cookies on the public website. If non-essential analytics, advertising, or similar storage/access technologies are introduced, they will not be activated until the consent and information requirements of PECR and UK data-protection law have been met.

08

Contact us and complain

For VitaSync-controlled information or privacy questions, email privacy@vitasync.stepanite.com. For care records, contact the care provider that delivered or arranged the care. You may also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint.

We may update this notice when our services or the law change. Material changes will be communicated through the platform or other appropriate channels.

VitaSyncCare, connected

One connected care-management platform for safer delivery, clearer oversight, and accountable operations.

Privacy Notice Terms & Conditions Account & Data Deletion Register a home Secure sign in

© 2026 VitaSync. All rights reserved.

UK care operations platform.