Privacy Policy
This policy explains how we use personal data when you use Care Notes.
Who we are
Care Notes is a web application for logging and coordinating care-related notes, time logs, and bookings.
This service is owned and operated by Drofmada Ltd. For care records you upload or create in an account, the account owner is typically the data controller and Drofmada Ltd acts as a data processor on their instructions.
What data we handle
Depending on how you use the service, we may handle:
- Account data: email address and password (stored as a hash), and your name fields (if provided).
- Care data: care people (name and optional notes), care events (note text and optional start/end times), and bookings (start/end times and optional assigned carer).
- Team data: account membership and roles; invite links created for joining an account.
- Billing contact data (optional): billing name, billing email, and billing address.
Special category data (health / care information)
Care Notes is designed for care records. Content you enter may include information about health or other sensitive details about the person receiving care. Please only enter information you have the right to record and share with your care team.
How we use data
- Provide the service: create and manage accounts, care records, bookings, and teams.
- Authentication and security: sign-in, session management, and protecting the service from abuse.
- Service communications: account verification and other operational emails required for the service.
Lawful bases (UK GDPR)
- Contract: to provide the service you sign up for.
- Legitimate interests: to run and secure the service.
- Legal obligations: where we must keep or share information to comply with law.
- Consent (analytics cookies): for Google Analytics.
Special category data (UK GDPR Article 9)
Where care records include health or other special category data, processing is carried out:
- for the provision of health or social care services, or
- based on the explicit consent of the account owner or care provider.
Cookies
Care Notes uses cookies needed for the site to work, including:
- Session cookies to keep you signed in.
- Security cookies (including CSRF protection).
We also use Google Analytics (optional analytics cookies).
Google Analytics
We use Google Analytics to collect high-level usage metrics (for example, page views and general usage patterns). We do not send the content of your care notes, care person notes, or bookings to Google Analytics.
- No ads features: we do not use Google Analytics for advertising features.
- Google’s policy: Google Privacy Policy.
Who can access your data
- You and your care team: people who are members of your account can access data in that account.
- Service operators: authorised administrators may access data only where necessary to operate, secure, or support the service. All access is restricted and logged.
Who we share data with
We use service providers to run Care Notes and deliver service emails. Our infrastructure is hosted in the EU. We use Amazon Web Services (SES) to send operational emails (for example, account verification and password reset). We do not transfer care record data outside the EU.
How long we keep data
We keep personal data for as long as needed to provide the service and manage your account. Care record retention is controlled by the account owner, subject to plan limits (up to 5 years).
Your rights (UK GDPR)
You have rights over your personal data, including:
- Access (a copy of your data)
- Rectification (correction)
- Erasure (deletion)
- Restriction and objection
- Portability (where applicable)
You can also complain to the UK Information Commissioner’s Office (ICO). See the ICO website at ico.org.uk.
Changes to this policy
Last updated: January 2026
Contact
For privacy queries, contact us at privacy@drofmada.co.uk.
No card required · Cancel anytime