cera-logo.png
About Cera
About CeraInvestors
Care Services
Care ServicesHome CareLive-in Care ServicesExtra CareNurse led & Complex CareSupported LivingLearning Disabilities & Autism
Commissioning Care
Commissioning CareHome Care Extra CareSupported LivingLearning Disabilities and AutismReablementBridging Services
Where we are
Working in Care
Why CeraWorking in careWorking in Complex CareCareer DevelopmentNew To Care
Articles
JobsCera HQ

Privacy Policy

zero.png

1. Introduction

We are committed to protecting the privacy and security of personal data in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable laws. This Privacy Notice explains how the Cera Care Group, comprising the companies listed below, collects, uses, stores and shares personal data when we act as:

  • a Data Controller – when we determine the purpose and means of processing personal data, such as when we provide direct services to individuals;
  • a Joint Data Controller – when we, together with another party, determine the purpose and means of processing personal data; where we act as a joint controller, the essence of the arrangement (including each party's responsibilities and a contact point for exercising your rights) is available on request from our Data Protection Officer, in accordance with Article 26 UK GDPR; and
  • a Data Processor – when we process personal data on behalf of, and under the instructions of, another organisation (such as the NHS, local authorities or care commissioning groups).

Cera Care Limited is registered with the Information Commissioner's Office, and each group company that acts as a controller maintains its own registration. Our ICO registration reference(s) are available on request and via the ICO's public register. To confirm which group company is the controller for your data, please contact our Data Protection Officer using the details in Section 17.

The Cera Care Group comprises: Allied Health Support Limited, Alpenbest Limited, Apex Prime Care East Ltd, Apex Prime Care Holdings Ltd, Apex Prime Care (IOW) Ltd, Apex Prime Care Ltd, Apex Prime Care Group Ltd, Apex Prime Care North Limited, Apex Prime Care West Ltd, Beech Tree Total Care Limited, BruDi Homecare GmbH & Co KG, BruDi Homecare Management GmbH, Cardiff Homecare Services Ltd, Care 1st Limited, Care at Home Services (South East) Limited, Care Quality Services Limited, Cera Care Carers Limited, Cera Care Central Limited, Cera Care Germany GmbH, Cera Care Limited, Cera Care Operations (Scotland) Limited, Cera Care Operations Holdings Limited, Cera Care Operations Limited, Cera Care Service Limited, Cera Care Technology Limited, Cera Homecare Limited, Domus Extra Care Limited, Domus Live-In Care Limited, First City Nursing Services Ltd, Gemcare South West Limited, Hire Ami Limited, Homecare4U Limited, Mediline Home Care Limited, My Care (Holdings) Limited, My Care (Grampian) Limited, My Care (Tayside) Limited, Premier Care Limited, Velvet Glove Care Limited, and Westminster Homecare Limited.

2. What Personal Data We Collect and Process

Depending on our role as a controller or processor, we may process the following types of personal data. a) When Acting as a Data Controller / Joint Data Controller We process personal data to provide health and social care services; manage care and patient records; recruit healthcare professionals; and meet legal obligations. This may include: Personal identifiers: name, date of birth, gender, address, contact details, photographs, account/user information, NHS number.

  • Health and medical information: diagnosis, treatment history, prescriptions, weight, height, blood pressure, resting heart rate, care plans, test results and similar clinical data.
  • Social care data: support plans, safeguarding information, social worker reports.
  • Next of kin and emergency contact details.
  • Financial information: billing details, funding arrangements.
  • Criminal offence data: where we recruit care and healthcare workers we process criminal records information (for example, DBS/Disclosure Scotland checks) in accordance with Article 10 UK GDPR and Schedule 1 to the Data Protection Act 2018. Recruitment processing is described in full in our Candidate Privacy Policy.

Children's data: some of our services (including learning disabilities, autism and supported living services) may involve people under 18. Where we process children's data we apply additional safeguards, collect only what is necessary, and rely on an appropriate lawful basis and, where relevant, the consent of a person with parental responsibility.

b) When Acting as a Data Processor We process personal data on behalf of third-party organisations (such as NHS Trusts, local authorities or care providers) under a formal data processing agreement. In these cases we process data, including diversity and inclusion data, strictly according to their instructions and do not determine the purpose of processing. Purpose of processing: we do not determine why or how the data is collected or used; we only carry out processing activities as directed by the controller.

  • Scope of processing: the type of data, the categories of individuals and the ways it is used are all defined by the controller.
  • Limited use: we do not use the data for any purpose other than fulfilling the controller's instructions, and we do not share it with third parties except on the controller's instructions.
  • Retention and deletion: we retain data only for as long as required by the controller's instructions and delete or return it on request or at the end of our agreement, save where we must retain it to meet our own legal obligations. To find out who your data controller is, please contact our Data Protection Officer at dpo@ceracare.co.uk

3. Lawful Basis for Processing

We process personal data under one or more of the following lawful bases, depending on our role.

a) When Acting as a Data Controller/Joint Data Controller Article 6(1)(c) (Legal Obligation): where required to comply with legal or regulatory obligations.

  • Article 6(1)(b) (Contract): where providing care or recruitment services under a contract, or taking steps prior to entering a contract.
  • Article 6(1)(e) (Public Task): where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, including when we access NHS England direct-care services such as GP Connect and the Personal Demographics Service to deliver your care.
  • Article 6(1)(f) (Legitimate Interests): where necessary for our legitimate interests, namely the safe and efficient delivery and administration of care, eligibility assessment for research purposes, service improvement and quality assurance, recruitment and workforce management, network and information security and fraud prevention, and the management of our corporate group. We balance these interests against your rights and only rely on this basis where appropriate; you may obtain details of the relevant legitimate interests assessment on request.
  • Article 6(1)(a) (Consent): where you have given consent for one or more specific purposes.
  • Article 9(2)(a) (Explicit Consent): where you have given explicit consent for one or more specified purposes involving special category data.
  • Article 9(2)(h) (Health and Social Care): for the management of healthcare and social care services.
  • Article 9(2)(j) (Research/Statistics): where necessary for scientific or historical research or statistical purposes, carried out in accordance with the safeguards in Article 89(1) UK GDPR and Schedule 1 to the Data Protection Act 2018.

Where we process special category data and criminal offence data under the conditions in Schedule 1 to the Data Protection Act 2018, we maintain an Appropriate Policy Document explaining our compliance and retention arrangements, which is available on request.

b) When Acting as a Data Processor We process data on the lawful basis provided by the controller and under their instructions. We do not determine the purpose or legal basis for processing in this capacity; this information can be found in the controller's privacy notice. If you need help locating it, please contact dpo@ceracare.co.uk.

4. How We Use Personal Data

We use personal data for the following purposes:

  • delivering healthcare and social care services;
  • managing patient and service user records;
  • coordinating care with other health and social care providers;
  • processing referrals and funding requests;
  • carrying out continuous reviews, such as service reviews, surveys and feedback;
  • conducting service improvement studies, data analysis, research and clinical trials;
  • meeting legal and regulatory requirements; and
  • investigating complaints or safeguarding concerns.

5. Automated Decision-Making and Profiling

We use technology, including software developed within our group, to support and improve care. This can involve profiling – for example, analysing care and health data to help identify changes in a person's condition, to flag potential risks to our care teams, and to plan and improve services.

These tools support decisions made by our trained staff; we do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement. Where any such solely automated decision-making is introduced, we will only carry it out where permitted by law, will tell you, and will provide meaningful information about the logic involved and the significance and likely consequences for you. You may request human review of, express your point of view on, or contest a decision by contacting our Data Protection Officer.

6. Where We Obtain Your Personal Data

We collect personal data directly from you and, where you are unable to provide it yourself, from those acting on your behalf. We also receive personal data about you from other sources, including:

  • NHS Trusts, GPs and other healthcare providers;
  • local authorities, social workers and care commissioners;
  • your next of kin, family members, advocates and emergency contacts;
  • organisations that engage us as a processor; and
  • for recruitment, referees, recruitment agencies and DBS/Disclosure Scotland.

The categories of data obtained from these sources are those described in Section 2. Where we receive your data from a source other than you, we provide this information in satisfaction of Article 14 UK GDPR.

7. How the NHS and Care Services Use Your Information

We are one of many organisations working in the health and care system to improve care for patients and the public. Whenever you use a health or care service, important information about you is collected in a record for that service, which helps to ensure you receive the best possible care.

Information collected about you can also be used and shared with other organisations for purposes beyond your individual care, for instance to help with improving the quality and standards of care, research into new treatments, preventing illness, monitoring safety and planning services. This only takes place where there is a clear legal basis. Most of the time anonymised data is used for research and planning, so that you cannot be identified.

You have a choice about whether your confidential patient information is used in this way (the national data opt-out). If you are happy with this use you do not need to do anything; if you opt out, your confidential patient information will still be used to support your individual care. To find out more or to register your choice, please visit www.nhs.uk/your-nhs-data-matters. You can change your mind at any time. Data used or shared for purposes beyond individual care is not shared with insurance companies or used for marketing unless you specifically agree.

8. Accessing Your GP Record and NHS Demographic Data

To support your direct care, we access certain national NHS England digital services. Access is limited to authorised staff who are involved in your care, and every access is recorded and auditable.

GP Connect
We use a facility called GP Connect to support your direct care. GP Connect makes patient information available to appropriate clinicians and care professionals when and where they need it, to support direct care, leading to improvements in both care and outcomes. GP Connect is only used for the purpose of direct care.

Authorised clinicians and care professionals – such as GPs, NHS 111 clinicians, care home and care staff treating you, secondary care trusts and social care clinicians – are able to access the GP records of the patients they are treating through this secure NHS England service. Where relevant, appointments may also be booked at GP practices and other local services.

Legal basis. The legal bases for direct care via GP Connect are the same as those for the care you would receive from your own GP or another healthcare provider: Article 6(1)(e) UK GDPR (a task carried out in the public interest or in the exercise of official authority) for personal data, and Article 9(2)(h) UK GDPR (the provision of health or social care or treatment, or the management of health or social care systems and services) for special category data, including your medical information.

Controllers. Your GP practice remains the controller of the GP record. NHS England operates the GP Connect service and is a controller for the secure, accurate transmission and the audit of the messages that pass through its infrastructure; it does not collect or store the content of those messages. We are the controller for our use of the information we access to provide your care.

Your rights. Because the legal bases are the same as in other direct care situations, the rights you have over this data (set out in Section 14) are the same. You can ask us how your information has been accessed and shared through GP Connect. We maintain a Data Protection Impact Assessment covering our use of GP Connect.

Personal Demographics Service (PDS)
We use the NHS Personal Demographics Service (PDS), the national electronic database of NHS patient details, to confirm your identity and keep your demographic details accurate. PDS holds information such as your name, address, date of birth, related people, registered GP and your NHS number.

When we provide your care, we may send basic details such as your name, date of birth and address to PDS in order to find or confirm your NHS number and to retrieve up-to-date demographic information. This helps us match you correctly to your records, reduces the amount of personal data we need to hold locally, and supports the safe sharing of information with other health and care organisations involved in your care. We access PDS through the PDS FHIR API, in line with NHS England's onboarding and access requirements.

Legal basis. We process this information for your direct care under Article 6(1)(e) UK GDPR (public task) and, where special category data is involved, Article 9(2)(h) UK GDPR. NHS England is the controller for the Personal Demographics Service itself; we are the controller for our use of the demographic data we obtain from it.

9. How We Keep Data Secure

We take appropriate technical and organisational measures to protect personal data, including:

  • access controls: limiting access to authorised personnel only;
  • encryption: protecting data in storage and transmission;
  • regular security audits: monitoring and improving our protections;
  • data minimisation: collecting only the information necessary for the purpose;
  • secure disposal: ensuring data is safely destroyed when no longer needed.

10. Who We Share Data With

We may share personal data where necessary for the provision of care, legal compliance or safeguarding. This may include:

  • NHS Trusts, GPs and healthcare providers (to ensure continuity of care);
  • local authorities and social care services (for care assessments and safeguarding);
  • third-party research organisations;
  • regulatory bodies (such as the Care Quality Commission and NHS England/NHS Digital);
  • other providers and suppliers that support our services;
  • commissioning bodies (for funding and service management);
  • IT and cloud service providers (for secure data storage and management); and
  • business partners, suppliers and contractors, for the performance of any contract we enter into with them or you.

We may also share personal data between entities within our corporate group for legitimate reasons, including service delivery and operational efficiency (administration, HR, IT, finance, customer service); regulatory compliance and risk management; security and fraud prevention; and research and analytics using aggregated or pseudonymised data.

To ensure intra-group sharing is lawful, transparent and secure we use data sharing agreements defining purpose, scope and legal basis; share only where there is a valid legal basis; apply purpose limitation; enforce role-based access controls; and, for cross-border transfers, apply the safeguards described in Section 12. Any third party that processes data on our behalf must comply with strict data protection requirements under a written contract.

11. Marketing and Website Analytics

Where we send you marketing communications about our services, we do so on the basis of your consent or our legitimate interests, as permitted by the Privacy and Electronic Communications Regulations (PECR). You can opt out of marketing at any time using the unsubscribe link in any message or by contacting us, and we will stop. You have an absolute right to object to the use of your data for direct marketing (see Section 14).

Our website uses cookies and similar technologies, including analytics and advertising tools, which are only set in line with your cookie choices. Full details are set out in our Cookie Policy.

12. International Data Transfers

We may transfer personal data to parties outside the United Kingdom. Any personal data transferred is processed only on our instructions and protected to a high standard as required by data protection law. Where data is transferred to a country without a UK adequacy decision, we put appropriate safeguards in place before the transfer, which may include:

  • the Standard Contractual Clauses together with the UK International Data Transfer Addendum;
  • the International Data Transfer Agreement (IDTA); or
  • an exception under Article 49 UK GDPR.

You can obtain a copy of the safeguards we use, or information about the countries to which your data may be transferred, by contacting our Data Protection Officer at dpo@ceracare.co.uk.

13. How Long We Keep Personal Data

We retain clinical and care records in accordance with the NHS Records Management Code of Practice and other relevant guidelines. Retention periods are determined by the type of record and the purpose for which it is held, taking into account any minimum periods set by law or regulation, our legal and contractual obligations, and whether the data is still needed for the purpose collected. By way of example, recruitment records for unsuccessful candidates are generally held for a limited period after the decision; financial and tax records are held for the periods required by HMRC; and complaint and safeguarding records are held in line with statutory and regulatory requirements.

Once retention periods expire, data is securely deleted or anonymised. Further detail on retention periods is set out in our retention schedule, which is available on request.

14. Your Data Protection Rights

Under data protection law you have rights regarding your personal data, including:

  • Right of access: you can request a copy of your personal data.
  • Right to rectification: you can ask us to correct inaccurate or incomplete data.
  • Right to erasure: you can request deletion of your data where appropriate.
  • Right to restrict processing: you can ask us to limit processing in certain circumstances.
  • Right to data portability: you can request transfer of your data to another provider.
  • Right to object: you can object to processing based on our legitimate interests. You also have an absolute right to object to the use of your data for direct marketing, and we will always stop such processing on request.
  • Right to withdraw consent: where we rely on your consent or explicit consent, you can withdraw it at any time by contacting us. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
  • Rights relating to automated decision-making: as described in Section 5.

To exercise any of these rights, contact our Data Protection Officer using the details in Section 17. We will respond within one month (which may be extended for complex requests, in which case we will tell you). There is normally no charge. We may need to verify your identity before acting on a request.

If we are acting as a data processor, you should contact the relevant controller (for example, the NHS Trust or local authority) to exercise these rights.

15. Providing Your Information

Some of the personal data we ask for is necessary to enter into or perform our contract with you, or to meet a legal or regulatory requirement (for example, information needed to deliver care safely or to carry out pre-employment checks). Where this is the case and you choose not to provide it, we may be unable to provide the relevant service or to proceed with your application or care. Where information is requested on a purely optional basis, we will make this clear.

16. Data Breaches and Incident Reporting

We have procedures in place to manage data breaches. If a breach occurs we will assess the impact and take action to contain it; where we act as a processor we will notify the controller without undue delay; and, where required, we will report the breach to the Information Commissioner's Office (ICO) and to affected individuals.

17. How to Complain and Contact Us

If you have any concerns about our use of your personal data, please contact us using the details below. If you remain unhappy after raising a complaint with us, you can also complain to the ICO at ico.org.uk/make-a-complaint.

Data Protection Officer
Cera Care, Labs Hawley Lock, 1 Water Lane, London, NW1 8NZ
Email: dpo@ceracare.co.uk
Registered address: Crown House, Stephenson Road, Severalls Industrial Park, Colchester, CO4 9QR

18. Policy Review and Amendments

We keep this Notice under regular review. This Notice was last updated on 10/06/2026. We reserve the right to update it at any time and will provide a new notice when we make substantial changes. We may also notify you in other ways from time to time about the processing of your personal data.

cera-logo.png

BECOME A CARER

  • Home
  • Our Locations
  • Why Cera
  • Our Services
  • Working in Care

CERA HQ

  • HQ Careers
  • Investors
  • Media
  • Policies
  • Group Tax Strategy
  • First Call Comms

REGISTERED ADDRESS

Crown House
Stephenson Road
Severalls Industrial Park
Colchester
CO4 9QR

    Contact us

    • phone.svg
      0330 123 9180
    • facebook.svg
      Facebook
    • linkedin.svg
      Linkedin
    • twitter.svg
      Twitter
    • instagram.svg
      Instagram
    • Privacy Policy
    • Cookie Policy
    • Legal Notices
    • Terms and Conditions
    • Modern Slavery Statement
    • Candidate Privacy Policy
    2021 - 2026 © Cera Care
    assets-partner.png
    cera-quality.png