Version: 1.0
Effective date: 10 October 2026
Last reviewed: 10 October 2026
Applies to: All MyCare websites, applications, platforms, products and associated digital services.
1. Introduction
The MyCare brand (“MyCare”, “we”, “us” or “our”) is committed to protecting personal information, maintaining confidentiality and processing personal data lawfully, fairly, securely and transparently.
This Privacy Policy explains how personal information is collected, used, stored, shared, retained and protected when individuals access or use our websites, applications, digital platforms, subscription services and related products.
Our services include, without limitation:
- MyCareCompliance — compliance management, auditing, quality assurance and governance.
- MyCareManager — care management, operational oversight and workforce coordination.
- MyCarePolicies — policies, procedures, templates and document management.
- MyCareClients — client-related services and functionality made available under that product.
- Any additional products, applications, integrations, websites, software or services introduced under the MyCare brand.
These are collectively referred to as the “MyCare Services”.
This policy applies to website visitors, prospective customers, subscribers, account holders, authorised users, employees of subscribing organisations, and individuals whose personal data is processed through our services.
Some MyCare Services may require additional product-specific privacy notices where their functionality or data-processing arrangements differ.
2. Who We Are
The MyCare brand is operated by:
Legal entity: AJG Advisory Services Limited
Company number: 17183813 (registered in England and Wales)
Registered address: 9 West Street, Wilton, Salisbury, SP2 0NT
Privacy contact: info@ajgadvisory.co.uk
Website: https://www.ajgadvisory.co.uk
The legal entity identified above is responsible for personal information processed for its own business purposes, including account administration, billing, marketing, customer enquiries and website operation.
Where MyCare processes personal information on behalf of subscribing care providers or other organisations, those organisations will generally act as data controllers and MyCare will act as their data processor.
The appropriate role will depend on the actual processing activity and applicable contractual arrangements.
3. Applicable Data Protection Legislation
We aim to comply with applicable UK data protection and privacy legislation, including:
- UK General Data Protection Regulation (UK GDPR).
- Data Protection Act 2018, as amended.
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), as amended.
- Data (Use and Access) Act 2025, where applicable and in force.
- Other applicable data protection, confidentiality and information security requirements.
Where our services are supplied internationally, additional local data protection laws may apply.
4. Information We May Collect
Depending on the MyCare Service used, we may process the following categories of personal information.
4.1 Account and identity information
Names, business contact details, email addresses, telephone numbers, organisation names, job titles, account identifiers, user roles, authentication information and account preferences.
4.2 Business and subscription information
Company details, subscription plans, billing information, transaction references, payment status, invoices, contractual records and communications.
Payment card information may be processed directly by an authorised third-party payment provider rather than stored by MyCare.
4.3 Workforce information
Where uploaded or entered by subscribing organisations, information may include:
- Employment and recruitment records.
- Training and competency records.
- Supervision, appraisal and performance information.
- Right-to-work and identity verification records.
- DBS-related information where lawfully processed.
- Staff schedules, attendance and working arrangements.
- Professional qualifications and employment documentation.
- Safeguarding and incident records involving staff.
4.4 Care-related information
Where the relevant MyCare Service provides such functionality, customer organisations may upload or manage:
- Service user names, contact details and identifiers.
- Care assessments, care plans and risk assessments.
- Medication information and associated records.
- Health conditions, disabilities and support requirements.
- Incident, accident and safeguarding information.
- Daily care records and visit documentation.
- Family, representative and emergency contact details.
- Consent, mental capacity and best-interest documentation.
- Complaints, concerns and quality assurance records.
Such information may include special category personal data and other highly confidential information.
4.5 Technical information
We may collect device information, IP addresses, browser information, operating systems, authentication events, error logs, security logs, access times and information about how our services are used.
4.6 Communications
We may retain enquiries, support requests, feedback, complaints, correspondence and other communications relating to our services.
5. How We Obtain Information
Personal information may be obtained directly from individuals, from subscribing organisations, through authorised users, from third-party integrations, through payment and authentication providers, or automatically through technical systems.
Organisations using MyCare are responsible for ensuring they have an appropriate lawful basis for collecting and uploading personal information and that individuals receive appropriate privacy information.
6. Why We Process Personal Information
We process personal information where necessary to:
1. Establish and manage customer accounts.
2. Provide subscribed services and platform functionality.
3. Authenticate users and manage access permissions.
4. Process payments and maintain financial records.
5. Provide customer support and technical assistance.
6. Maintain platform security and investigate misuse.
7. Meet applicable legal and regulatory obligations.
8. Manage contractual relationships.
9. Improve performance, reliability and accessibility.
10. Respond to complaints, requests and enquiries.
11. Communicate relevant service updates.
12. Conduct lawful marketing activities.
13. Process customer-controlled information under documented instructions.
We will not use personal information for purposes incompatible with those for which it was lawfully collected unless another lawful basis or legal requirement permits the processing.
7. Lawful Bases for Processing
Depending on the circumstances, we may rely upon:
Contract: Processing necessary to perform a contract with an individual or take requested pre-contractual steps.
Legal obligation: Processing required to comply with applicable law.
Legitimate interests: Processing necessary for legitimate business interests, including security, service administration, fraud prevention and appropriate service improvement, provided those interests are not overridden by individuals’ rights and freedoms.
Consent: Processing based on valid consent, where consent is required or selected as the appropriate lawful basis.
Vital interests: Processing necessary to protect life in circumstances permitted by law.
Where a subscribing organisation controls the data, that organisation is responsible for identifying and documenting the lawful basis for its processing.
8. Special Category and Sensitive Information
Some MyCare Services may process health information, disability information, safeguarding information and other special category personal data.
Such information requires an appropriate Article 6 lawful basis and a separate Article 9 condition under the UK GDPR.
Where applicable, additional conditions under the Data Protection Act 2018 and appropriate policy documentation may also be required.
MyCare will process this information only where a valid legal basis and relevant processing arrangements exist.
We do not assume that an individual’s use of a care service automatically constitutes consent to all related data processing.
Criminal offence data, including relevant DBS information, must only be processed where the requirements of Article 10 UK GDPR and applicable domestic law are satisfied.
9. Our Role as a Data Processor
Where MyCare provides software to a care provider or another organisation that determines the purposes and essential means of processing personal information:
- The subscribing organisation will generally be the data controller.
- MyCare will generally act as the data processor.
- Processing will be governed by appropriate contractual terms and a Data Processing Agreement.
- MyCare will process personal information only on documented instructions, except where otherwise required by applicable law.
- Access to customer-controlled information will be restricted to authorised purposes.
- Appropriate confidentiality and security measures will apply.
- Sub-processors will be engaged in accordance with the relevant contractual arrangements.
- MyCare will provide reasonable assistance with applicable data protection obligations.
Individuals wishing to exercise rights relating to care records or employment records should normally contact the organisation responsible for those records.
MyCare will support the relevant controller in responding to lawful requests.
10. Confidentiality and Access Controls
We recognise that information processed through care-sector platforms can be highly sensitive.
We will implement appropriate technical and organisational measures proportionate to the risks, which may include:
- Role-based access controls.
- Secure authentication.
- Encryption in transit and, where appropriate, at rest.
- Access logging and monitoring.
- Secure backup and recovery arrangements.
- Security updates and vulnerability management.
- Restricted administrative access.
- Confidentiality obligations for authorised personnel.
- Incident response procedures.
- Appropriate supplier due diligence.
Specific security measures will depend on the service and its technical architecture.
No internet-based system can guarantee absolute security.
11. Sharing Personal Information
We may disclose personal information to authorised recipients where necessary and lawful, including:
- Hosting and infrastructure providers.
- Payment processing providers.
- Authentication and identity management providers.
- Email and communication service providers.
- Technical support providers.
- Professional advisers.
- Authorised sub-processors.
- Regulators, courts, law enforcement and other competent authorities where legally required.
- Other recipients expressly authorised by the relevant data controller.
We do not sell personal information to third parties.
Personal information will not be disclosed to unrelated third parties for their independent marketing purposes without an appropriate lawful basis.
A current list of relevant sub-processors will be made available where required by applicable law or contractual arrangements.
12. International Data Transfers
Where personal information is transferred outside the United Kingdom, we will ensure that applicable international transfer requirements are met.
Depending on the circumstances, this may involve UK adequacy regulations, an approved International Data Transfer Agreement, the UK Addendum to approved contractual clauses, or another lawful transfer mechanism.
Where required, we will assess transfer risks and implement appropriate supplementary safeguards.
Customers should consult their relevant Data Processing Agreement for product-specific transfer arrangements.
13. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, subject to legal, regulatory, contractual and legitimate operational requirements.
Retention periods depend on the type of information, the relevant service and the applicable legal obligations.
Examples include:
- Account information: while the account remains active and for an appropriate period afterwards.
- Billing and accounting records: in accordance with applicable financial and tax recordkeeping requirements.
- Support communications: for an appropriate period to resolve issues, manage disputes and maintain service records.
- Security logs: for a proportionate period determined by security requirements.
- Customer-controlled care and workforce records: in accordance with the controller’s documented instructions, contractual arrangements and applicable retention requirements.
Termination of an account does not necessarily result in immediate deletion of every record.
Information may be retained where legally required, necessary to establish or defend legal claims, or temporarily held in secure backup systems subject to documented deletion arrangements.
A detailed retention schedule will be maintained and reviewed as appropriate.
14. Account Closure, Data Export and Deletion
Following termination or expiry of a subscription, customers may request the return or deletion of customer-controlled information in accordance with their agreement and applicable law.
Data export formats, access periods, deletion timescales and backup arrangements will be specified in the applicable service agreement or Data Processing Agreement.
MyCare may retain information where required by law or where another lawful basis justifies continued retention.
Customers are responsible for ensuring that necessary records are exported and retained in accordance with their own regulatory and legal obligations.
15. Data Breaches and Security Incidents
We maintain procedures for identifying, investigating, containing and responding to suspected or confirmed personal data breaches.
Where MyCare acts as a processor, we will notify the relevant controller without undue delay after becoming aware of a personal data breach, in accordance with applicable contractual and legal requirements.
Where MyCare acts as a controller, we will assess whether notification to the Information Commissioner’s Office or affected individuals is required.
Where legally applicable, reportable breaches will be notified to the ICO within 72 hours of awareness, where feasible.
16. Individual Data Protection Rights
Subject to applicable law, individuals may have rights to:
- Access their personal information.
- Request correction of inaccurate information.
- Request erasure in qualifying circumstances.
- Request restriction of processing.
- Object to certain processing.
- Request data portability where applicable.
- Withdraw consent where processing relies on consent.
- Receive protections concerning qualifying solely automated decisions.
Rights are not absolute and may be subject to legal exemptions.
Requests can be submitted to info@ajgadvisory.co.uk.
Where the request concerns information controlled by a subscribing organisation, we may refer the request to that organisation or assist it in responding.
We will respond to requests for which we are responsible within applicable statutory timescales, normally one month, subject to permitted extensions.
17. Marketing Communications
We may send relevant product updates, service announcements and marketing communications where permitted by applicable law.
Where consent is required, we will obtain it before sending marketing communications.
Where the law permits marketing without consent, we will comply with the applicable conditions, including relevant opt-out requirements.
Recipients may unsubscribe from marketing communications at any time.
Essential service, contractual and security communications may continue where necessary and lawful.
18. Cookies and Tracking Technologies
Our websites and applications may use cookies, local storage, session technologies and similar mechanisms.
These may support authentication, security, preferences, functionality, analytics and other disclosed purposes.
Our separate Cookie Policy explains the technologies used and how individuals can manage their preferences.
Where consent is required, we will obtain it before using the relevant technologies.
19. Automated Processing and Artificial Intelligence
Certain MyCare Services may offer automated reporting, document generation, alerts, recommendations, analytics or AI-assisted functionality.
Where such functionality is available, we will explain relevant data processing, applicable safeguards and any material limitations.
Customer-controlled personal information will not be used to train general-purpose AI models unless a lawful basis exists, appropriate contractual arrangements permit that use, and any necessary notices and safeguards are in place.
Automated outputs must be appropriately reviewed before being relied upon for decisions affecting care, safeguarding, employment or individual rights.
Where legally applicable, additional protections will apply to significant solely automated decisions.
20. Children’s Information
The MyCare Services are primarily intended for professional and organisational use.
Where a product is designed for adult social care, its intended use does not automatically authorise the processing of children’s information.
Any processing of children’s personal information must be lawful, necessary and appropriate to the relevant service.
21. Third-Party Websites and Integrations
Our services may link to third-party websites or integrate with external software.
External providers may operate under their own privacy notices and contractual terms.
We are not responsible for independent processing carried out by third parties outside our control.
22. Changes to This Privacy Policy
We may update this policy to reflect changes in legislation, business operations, technology, products or data-processing activities.
Material changes will be communicated through appropriate channels where required.
The latest version will be made available through our websites and applications.
23. Complaints and Contact Information
Questions, concerns and privacy requests should be directed to:
MyCare Privacy Team Email: info@ajgadvisory.co.uk
Individuals may also raise concerns with the Information Commissioner’s Office.
Information Commissioner’s Office
Website: https://ico.org.uk
Telephone: 0303 123 1113
We encourage individuals to contact us first so that we have an opportunity to address their concerns, without limiting their right to contact the ICO.
⸻
End of MyCare Master Privacy Policy