CareOS Privacy Policy

Data Controller: Byte River Ltd, a company registered in England and Wales (company number 14472223) with its registered office at Henleaze House Business Centre, 13 Harbury Road, Bristol, England, BS9 4PN. 

Product: CareOS (software-as-a-service) 

Version: 2.0 Last updated: 1 April 2026 

Data Protection Officer: Felix Thottumkal, hello@careos.uk, 020 4621 3024 

General privacy contact: legal@careos.uk


1. About this Privacy Policy

1.1 This Privacy Policy explains how Byte River Ltd ("Byte River", "we", "us", "our") collects, uses, stores and protects personal data in connection with the CareOS software-as-a-service platform ("CareOS") and our website at careos.uk (the "Website").

1.2 We are committed to protecting personal data and to handling it in accordance with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 ("PECR"), and guidance issued by the Information Commissioner's Office ("ICO").

1.3 This Policy is written for three audiences:

(a) visitors to our Website and prospective customers who interact with us before becoming a Customer; (b) our business customers (care providers and similar organisations that subscribe to CareOS) and their nominated contacts; and (c) end users of CareOS, including the employees, workers and contractors of our business customers ("Authorised Users"), and, where relevant, individuals whose personal data is recorded within CareOS by those customers ("Service Users").

1.4 Our role. The nature of our role under the UK GDPR depends on whose data we are processing and for what purpose:

(a) We act as data controller for personal data that we collect and use for our own business purposes, such as website analytics, marketing, sales, customer onboarding, billing, account administration, and support communications.

(b) We act as data processor on behalf of our business customers in respect of personal data that those customers (or their Authorised Users) upload to, or generate within, CareOS about their own staff and about Service Users. Our processing of that data on behalf of customers is governed by the Data Processing Addendum incorporated into our Terms and Conditions (Annex A) and not by this Privacy Policy. If you are a Service User and you wish to exercise your data protection rights in relation to information held in CareOS by a care provider, you should contact that care provider directly, as they are the controller of that data.

1.5 This Policy therefore focuses on personal data for which we are the controller, with the exception of section 5 (Cookies) and section 10 (Security), which describe technical measures applicable across the whole CareOS platform.


2. Who we are and how to contact us

2.1 Data controller. Byte River Ltd is the data controller in respect of the personal data described in this Policy.

2.2 ICO registration. We are registered with the Information Commissioner's Office as a data controller, in accordance with the Data Protection (Charges and Information) Regulations 2018. Our ICO registration reference is available on request from hello@careos.uk.

2.3 Data Protection Officer. We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection compliance. You can contact the DPO directly using the details below:

  • Name: Felix Thottumkal

  • Email: hello@careos.uk

  • Telephone: 020 4621 3024

  • Post: Data Protection Officer, Byte River Ltd, Henleaze House Business Centre, 13 Harbury Road, Bristol, England, BS9 4PN

2.4 General privacy queries. For routine privacy queries, subject access requests, or any other data protection matter, you may also contact us at privacy@careos.uk.


3. Personal data we collect

We collect and process the following categories of personal data as a controller:

3.1 Enquiry and demo data. When you contact us to request information, book a demo, or request a quote, we collect your name, job title, organisation name, business email address, business telephone number, and any information you choose to include in your enquiry.

3.2 Sales and onboarding data. During the sales and sign-up process, we collect the name, email address and role of the individual accepting our Terms and Conditions on behalf of your organisation, together with the timestamp of acceptance, the IP address from which acceptance was given, the version of the Terms accepted, and the package details displayed at sign-up. This information is retained as evidence of contract formation.

3.3 Customer account and billing data. Once you become a customer, we collect and maintain the contact details of your nominated administrators, finance contacts and support contacts, together with billing information, payment history, and records of communications between us.

3.4 Payment data. Card payments are processed by Stripe, our appointed payment processor. We do not store full card details on our own systems. We receive and retain only a Stripe customer identifier, a payment token, the last four digits of the card, the card type and the expiry date, together with a transaction reference, for reconciliation and dispute-handling purposes.

3.5 Authorised User account data. When your Authorised Users log in to CareOS, we process their name, work email address, assigned role and permissions, authentication credentials (stored only in hashed form), and records of their log-in events and session activity, in order to provide and secure the service.

3.6 Support and correspondence data. When you contact our support team, we retain the content of your correspondence and any associated diagnostic information (such as screenshots or log extracts you provide) for the purposes of responding to your request and improving our service.

3.7 Device and diagnostic data. When you use CareOS or visit our Website, we automatically collect certain technical information, including your IP address, device type, browser type and version, operating system, referring URL, pages visited, date and time of access, and error and performance diagnostics. This data is collected through server logs, our authentication cookies (see section 5), and our error monitoring provider (Sentry), which is configured to avoid capturing personally identifying content wherever possible.

3.8 Location data. Where the CareOS mobile application is used for visit check-in, route planning, or live-location mapping, we process location data provided by the device with the user's consent. Location data is processed on behalf of our business customers and is primarily governed by the Data Processing Addendum rather than this Policy.

3.9 Marketing data. Where you have opted in, or where we rely on the "soft opt-in" permitted under PECR in respect of existing customers, we process your contact details and marketing preferences in order to send you updates, newsletters and product information.

3.10 Special category data. We do not knowingly collect special category personal data (such as health data) about you in your capacity as a prospective or actual customer contact. Special category data relating to Service Users may be processed within CareOS itself, but only on behalf of, and on the instructions of, our business customers, under the Data Processing Addendum.


4. How we use personal data and our lawful bases

Under the UK GDPR, we must have a lawful basis for each purpose for which we use personal data. The table below sets out the main purposes for which we process personal data as a controller, and the lawful basis we rely on for each.

Purpose

Categories of data

Lawful basis

Responding to enquiries, arranging and conducting product demos

Enquiry and demo data

Legitimate interests (responding to a request made by you or your organisation); steps taken at your request prior to entering into a contract

Negotiating and forming a contract with you

Sales and onboarding data

Performance of a contract; legitimate interests (evidencing contract formation)

Providing CareOS, administering your account and processing payments

Customer account data, payment data, Authorised User account data

Performance of a contract; legitimate interests (business administration)

Providing customer support

Support and correspondence data

Performance of a contract; legitimate interests (service improvement)

Securing CareOS, detecting and preventing fraud and misuse, and monitoring for errors and outages

Authorised User account data, device and diagnostic data

Legitimate interests (securing our systems and protecting our users); legal obligation (where applicable)

Sending push notifications and service alerts to Authorised Users

Authorised User account data, device tokens

Performance of a contract; legitimate interests

Complying with legal, regulatory and accounting obligations

All relevant categories

Legal obligation

Sending service and administrative communications (e.g. outage notices, renewal reminders, changes to terms)

Customer account data

Performance of a contract; legitimate interests

Sending marketing communications to existing customers about similar products

Marketing data

Legitimate interests, subject to your right to opt out (soft opt-in under PECR)

Sending marketing communications to prospects

Marketing data

Consent

Improving CareOS, developing new features and conducting analytics on anonymised usage

Device and diagnostic data, aggregated usage data

Legitimate interests

Handling disputes, enforcing our contracts and establishing or defending legal claims

All relevant categories

Legitimate interests; establishment, exercise or defence of legal claims

4.1 Legitimate interests assessment. Where we rely on legitimate interests, we have considered whether those interests are overridden by your own interests, rights and freedoms. We have concluded that our processing is necessary, proportionate and consistent with your reasonable expectations. You have the right to object to processing based on legitimate interests, as described in section 9 below.

4.2 Consent. Where we rely on consent, you are free to withdraw that consent at any time by contacting privacy@careos.uk or by using any unsubscribe link included in our communications. Withdrawing consent does not affect the lawfulness of any processing we carried out before you withdrew it.


5. Cookies and similar technologies

5.1 Our approach. CareOS takes a minimal approach to cookies. We set only the cookies that are strictly necessary to operate the service securely, and we do not set any advertising, cross-site tracking, or third-party analytics cookies within the CareOS application itself.

5.2 Cookies set by CareOS. The CareOS application sets the following cookies:

Cookie name

Purpose

Type

HttpOnly

Secure

SameSite

Duration

access_token

Short-lived authentication token that keeps you logged in during your session

Strictly necessary

Yes

Yes (in production)

Lax

8 hours

refresh_token

Long-lived token used to renew your session without requiring you to log in again

Strictly necessary

Yes

Yes (in production)

Lax

30 days

Both cookies are first-party cookies, are marked as HttpOnly (meaning they cannot be read by JavaScript running in the browser, which protects against cross-site scripting attacks), are scoped to the specific CareOS portal on which you log in (and are not shared across other subdomains), and are required for the CareOS application to function. If you block or delete these cookies, you will not be able to log in to CareOS.

5.3 No tracking cookies. We do not use cookies for behavioural advertising, cross-site tracking, or third-party marketing analytics within the CareOS application.

5.4 Cookies on the careos.uk marketing website. Our marketing website may use a limited number of additional cookies, including cookies set by Google Analytics where you have given consent through our cookie banner. Full details are set out in our Cookie Notice at careos.uk/cookies. You can manage or withdraw your consent to non-essential cookies at any time by clicking the "Cookie Settings" link in the footer of our marketing website.

5.5 Similar technologies. We also use certain similar technologies to provide and secure CareOS, including browser local storage (to cache user preferences and improve performance) and push notification tokens issued by Firebase Cloud Messaging (to deliver in-app alerts to Authorised Users who have opted in to notifications). These technologies do not set cookies, but they are governed by the same principles of data minimisation described in this Policy.


6. How we share personal data and our service providers

6.1 We do not sell personal data to third parties.

6.2 We share personal data only where necessary, and only with parties who are bound by appropriate confidentiality and data protection obligations. The categories of recipient are:

(a) Service providers acting as our processors or sub-processors (listed in clause 6.3); (b) Regulators, law enforcement, courts and other public authorities, where we are required to disclose personal data by law, regulation, or a valid legal process, or where disclosure is necessary to protect our rights, property or safety, or those of others; (c) Professional advisers, including our accountants, auditors, insurers and legal advisers, where necessary for the proper running of our business; and (d) Prospective or actual purchasers of all or part of our business, in the event of a merger, acquisition, reorganisation or sale of assets. In any such case, personal data will be shared under appropriate confidentiality arrangements and any new controller will be bound by data protection law.

6.3 Our service providers and sub-processors. The following third parties help us to provide CareOS and our business operations. Each operates under a written contract containing the obligations required by Article 28 of the UK GDPR where they act as our processor or sub-processor.

Provider

Purpose

Categories of data involved

Processing location

Amazon Web Services (AWS)

Cloud hosting, database storage, file storage (S3), email delivery (SES), and DNS management (Route53) for CareOS

All categories of Customer Data and controller data hosted on our infrastructure

United Kingdom (primary); other AWS regions may be used for resilience, subject to UK GDPR transfer safeguards

Stripe Payments Europe, Ltd

Processing of subscription payments and management of the customer billing portal

Payment data, customer contact details, billing history

Ireland and the United States (under appropriate transfer safeguards)

Cloudflare

DNS management, content delivery, DDoS mitigation, and network security for careos.uk and tenant subdomains

IP addresses, request metadata, device and diagnostic data

Global edge network, with UK and EU points of presence

Google LLC — Google Maps Platform

Map display, geocoding and route planning in the CareOS mobile and web applications

Location data, IP addresses

United States (under appropriate transfer safeguards)

Google LLC — Google Analytics

Website analytics on the careos.uk marketing website (set only with your consent via the cookie banner)

Pseudonymous identifiers, IP addresses (truncated), page views

United States (under appropriate transfer safeguards)

Google LLC — Firebase Cloud Messaging

Delivery of push notifications to the CareOS mobile and web applications

Device tokens, notification payloads (not message content where avoidable)

United States (under appropriate transfer safeguards)

OpenAI Ireland Ltd / OpenAI, L.L.C.

AI features within CareOS, including embeddings, summarisation and drafting assistance

Text content submitted to the AI feature; no training on customer data (see clause 4 and the DPA)

Ireland and the United States (under appropriate transfer safeguards)

Anthropic PBC

AI features within CareOS, including summarisation, drafting and retrieval assistance

Text content submitted to the AI feature; no training on customer data

United States (under appropriate transfer safeguards)

Sentry (Functional Software, Inc.)

Application error monitoring, performance tracing and session replay for diagnostics

Error stack traces, technical diagnostic data, anonymised session replays with sensitive inputs masked

United States (under appropriate transfer safeguards); PII transmission is disabled and sensitive inputs are masked

6.4 Sub-processor list. An up-to-date list of our sub-processors is maintained at careos.uk/subprocessors. We notify our business customers of any material additions or changes in accordance with the Data Processing Addendum.

6.5 Changes to this list. The list in clause 6.3 reflects our arrangements as at the "Last updated" date shown at the top of this Policy and may change over time as our service evolves. The authoritative current list is always the one published at careos.uk/subprocessors.


7. International transfers

7.1 Our primary position. We primarily store and process personal data within the United Kingdom, using UK-based infrastructure wherever practicable.

7.2 Transfers by us. Some of the services described in section 6 involve the transfer of personal data outside the UK, typically to the United States or the European Economic Area. Where we transfer personal data outside the UK as a controller, we put in place appropriate safeguards to ensure that the data receives an essentially equivalent level of protection to that provided under UK data protection law. These safeguards may include:

(a) transfers to countries which the UK Government has determined provide an adequate level of protection (adequacy regulations), including the European Economic Area and, in certain circumstances, the United States under the UK Extension to the EU-US Data Privacy Framework; (b) transfers under the UK International Data Transfer Agreement (IDTA); or (c) transfers under the UK Addendum to the EU Standard Contractual Clauses.

7.3 Transfers by our service providers and sub-processors. The providers listed in clause 6.3 may themselves transfer personal data internationally in the course of delivering their services (for example, for engineering support, backup storage, or content delivery). In each case, we require them to maintain equivalent transfer safeguards under their contracts with us.

7.4 Transfers by our business customers. Our business customers decide who within their own organisations has access to Customer Data in CareOS, and from which locations that access takes place. Where a business customer, or their Authorised Users, chooses to access CareOS from outside the UK, any resulting international transfer is the responsibility of that customer as the data controller of the Customer Data concerned. CareOS provides the technical means to restrict access by location where customers wish to do so.

7.5 Further information. You may request further information about the specific safeguards applied to transfers involving your personal data by contacting hello@careos.uk.


8. How long we keep personal data

8.1 We retain personal data only for as long as is necessary for the purposes for which it was collected, including to satisfy any legal, accounting or reporting requirements.

8.2 Our general retention periods are:

Category of data

Retention period

Enquiry data from prospects who do not become customers

24 months from the last meaningful interaction

Sales and onboarding data (including contract-formation evidence)

For the duration of the contract and 6 years thereafter, to meet contractual and statutory limitation requirements

Customer account and billing data

For the duration of the contract and 6 years thereafter (in line with HMRC record-keeping requirements)

Authorised User account data

For as long as the user remains active, and deleted or anonymised within a reasonable period after account deactivation

Support and correspondence data

3 years from the date of the correspondence

Device and diagnostic data (including Sentry error data)

Typically 90 days, and in any event no longer than 12 months

Marketing data

Until you unsubscribe or withdraw your consent, reviewed periodically to ensure it remains accurate and necessary

Cookie-based data

As set out in section 5 and in our Cookie Notice

8.3 Where personal data is no longer needed, we will either securely delete it or irreversibly anonymise it so that it can no longer be associated with any identifiable individual.

8.4 Retention of personal data processed within CareOS on behalf of our business customers is governed by the Data Processing Addendum and by the retention settings configured by those customers.


9. Your data protection rights

9.1 Under the UK GDPR, you have the following rights in respect of personal data for which we are the controller:

(a) Right of access — to request a copy of the personal data we hold about you and information about how we process it; (b) Right to rectification — to ask us to correct personal data that is inaccurate or incomplete; (c) Right to erasure ("right to be forgotten") — to ask us to delete personal data in certain circumstances; (d) Right to restrict processing — to ask us to limit how we use your personal data in certain circumstances; (e) Right to data portability — to receive personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller; (f) Right to object — to object to processing based on our legitimate interests, and to object at any time to processing for direct marketing purposes; (g) Rights in relation to automated decision-making and profiling — not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you. We do not carry out any such automated decision-making in respect of your personal data as a customer contact; and (h) Right to withdraw consent — where we rely on consent, to withdraw it at any time.

9.2 How to exercise your rights. You can exercise any of these rights by contacting our Data Protection Officer at hello@careos.uk or by emailing privacy@careos.uk. We may need to verify your identity before responding, to ensure that we do not disclose personal data to the wrong person.

9.3 Response time. We will respond to your request within one (1) month of receipt. If your request is complex, or if we have received a number of requests from you, we may extend this period by a further two (2) months and will notify you of the extension and the reasons for it.

9.4 No fee. Exercising your rights is free of charge. However, we may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive.

9.5 Right to complain to the ICO. If you are not satisfied with how we have handled your personal data or a request you have made, you have the right to lodge a complaint with the Information Commissioner's Office:

  • Website: ico.org.uk

  • Helpline: 0303 123 1113

  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would, however, appreciate the opportunity to address your concerns before you approach the ICO, so please consider contacting our DPO first.


10. How we protect personal data

10.1 We take the security of personal data seriously and have implemented appropriate technical and organisational measures designed to protect it against unauthorised or unlawful processing, accidental loss, destruction or damage, taking into account the state of the art, the costs of implementation, and the nature of the data.

10.2 Our measures include:

(a) encryption of personal data in transit (using TLS) and at rest; (b) multi-tenant isolation, with Customer Data logically separated between tenants at the database and application layers; (c) authentication via short-lived JWT tokens delivered in HttpOnly cookies, with session refresh controls and support for multi-factor authentication on administrative accounts; (d) access controls based on the principle of least privilege, with role-based permissions for both customer-side users and our own staff; (e) network and application security controls, including firewalls, DDoS mitigation (via Cloudflare), and regular vulnerability scanning; (f) secure software development practices, code review, and regular security testing; (g) vetting and training of staff who handle personal data, together with contractual confidentiality obligations; (h) logging and monitoring of access to systems containing personal data, with error and performance monitoring configured to avoid capturing personal data wherever possible (in particular, our error-monitoring provider is configured to mask sensitive input fields and not to transmit default personally identifying information); (i) secure backup and disaster recovery arrangements; and (j) written contracts with all processors and sub-processors requiring them to implement equivalent security measures.

10.3 While we take these measures seriously, no system can be guaranteed to be completely secure. If you believe that your interaction with us is no longer secure, please contact us immediately at hello@careos.uk.


11. Personal data breaches

11.1 We have procedures in place to detect, investigate and respond to suspected personal data breaches.

11.2 Where we are the controller and a breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Article 33 of the UK GDPR.

11.3 Where a breach is likely to result in a high risk to the rights and freedoms of individuals, we will also notify the affected individuals without undue delay, in accordance with Article 34 of the UK GDPR.

11.4 Where we are acting as processor on behalf of a business customer, we will notify that customer of any personal data breach affecting their Customer Data without undue delay, as set out in the Data Processing Addendum.


12. Children's data

CareOS is a business-to-business service intended for use by care providers and similar organisations. Our Website and marketing activities are not directed at children, and we do not knowingly collect personal data from children in the course of our controller activities. Personal data about children may be processed within CareOS by our business customers (for example, in the context of children's services), but such processing is carried out under the Data Processing Addendum and on the instructions of those customers as controllers.


13. Changes to this Privacy Policy

13.1 We may update this Privacy Policy from time to time to reflect changes in our practices, in the CareOS service, in our service-provider arrangements, in applicable law, or in ICO guidance.

13.2 Where we make material changes, we will notify customers by email or through CareOS, and will update the "Last updated" date at the top of this Policy. We encourage you to review this Policy periodically to stay informed about how we handle personal data.

13.3 Previous versions of this Policy are available on request from hello@careos.uk.


14. Further information

If you would like more information about your data protection rights, please visit the ICO's website at ico.org.uk. If you have any questions about this Privacy Policy or about how we handle personal data, please contact our Data Protection Officer:

Felix Thottumkal Data Protection Officer, Byte River Ltd 📧 hello@careos.uk · ☎ 020 4621 3024