Care World privacy.
The marketplace that introduces families to self-employed carers. Chronix Health Group Ltd is the controller for Care World.
Accounts, profiles and matching
Our role: controller. Chronix Health Group Ltd is the controller.
Why: Introducing families to self-employed carers; account management; messaging; showing evidence and references with the carer's consent.
Lawful basis: Contract (your account); legitimate interests with a documented assessment (matching, messaging, safety); legal obligation (right-to-work records and employment-agency records under the Conduct Regulations 2003).
Special-category data: Health or support needs a family chooses to describe — processed with explicit consent.
Who receives it: Carers and families see each other's information as the product requires. Service providers: Supabase (hosting), Vercel (hosting), Cloudflare (DNS/CDN), Resend (sending email), Google Workspace (hosting our role mailboxes — anything you email to safeguarding@, support@, privacy@ or reply@ is stored by Google, as is anything we send to them), Stripe (payments), Stripe Identity (identity checking), and a DBS umbrella body once appointed.
How long we keep it: Account data: life of the account plus 30 days. Messages: 12 months from last activity. Employment-agency records: at least 1 year from the last introduction. DBS certificate content: no more than 6 months (metadata: listing plus 1 year). Right-to-work records: the arrangement plus 2 years.
Criminal-offence data (DBS check metadata)
Our role: controller. Chronix Health Group Ltd is the controller.
Why: Recording that a DBS check exists and its dates — never certificate content.
Lawful basis: Article 10 with DPA 2018 Schedule 1 conditions, under the Appropriate Policy Document.
Who receives it: Shared only with the carer's consent while a family is actively considering them.
How long we keep it: Certificate content: no more than 6 months. Metadata: listing plus 1 year.
Visit statistics
We keep aggregate statistics about visits to our sites — the page visited, the website that referred you, and the country of the request. These records contain no cookies, no IP addresses and no identifiers, so they cannot be linked to you or to any other visit. We keep them for 12 months.
International transfers
Data is resident in the UK/EU (Supabase eu-west-2). Any US sub-processor requires an IDTA or UK Addendum plus a transfer risk assessment.
Your rights
You can ask for access to your data, correction, deletion, restriction, and a portable copy, and you can object to processing based on legitimate interests. Where we act as a processor, we pass your request to the controller (the organisation or clinician) without delay.
Complaints
Tell us first if you can — use the data complaints form (no account needed). We acknowledge every complaint when it is made and respond within a month. You can also complain to the Information Commissioner's Office (ICO), the UK regulator, at any time, and you have the right to an effective judicial remedy.


