Last updated: August 2026

Privacy Policy

Anoeba Limited (company no. 16045545, "HomeCareConnection", "we", "us") trading as HomeCareConnection is committed to protecting your privacy and ensuring your personal data is handled securely and responsibly. This Privacy Policy outlines the types of data we collect, how we use and share it, and your rights under applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014.

Anoeba Limited is the data controller for the personal data described in this policy. We are registered with the Information Commissioner's Office (ICO).

We take particular care with health and social care data, recognising that our users may be vulnerable adults seeking essential support services.

Who this policy applies to

This policy applies to two groups of users:

  • Care seekers: individuals or their representatives (family members, social workers, healthcare professionals) seeking home care services who submit their details through our service.
  • Care providers: CQC-regulated (or equivalent UK regulator) home care providers who register on our service to receive care seeker introductions.

What data we collect

Care seeker data (collected during the survey and matching process)

Personal information:

  • Name, email address, phone number, age, location (postcode and region)
  • Family situation and key contacts
  • Relationship to the person requiring care (if data subject is a representative)

Health and care needs data:

  • Type of care required (support services, personal care, complex/specialist care, live-in or visiting)
  • Specific health conditions or care needs (e.g., dementia, Parkinson's, end-of-life care, mobility support, continence support)
  • Cognitive and mental health needs
  • Medication support requirements
  • Care urgency and timeframe for starting care
  • Current care arrangements
  • Dietary requirements and restrictions

Other data:

  • Other data elected to be shared by survey respondents

Care provider data (collected during registration and portal use)

Business information:

  • Organisation name, legal structure, and registration details
  • CQC registration number (England), Care Inspectorate number (Scotland), CIW number (Wales), or RQIA number (Northern Ireland)
  • CQC inspection ratings and reports
  • Types of care provided
  • Coverage area and postcodes served
  • Office address and contact details

Contact personnel:

  • Name, email address, phone number of registered contact(s)
  • Senior management and registered manager details

Technical data: (collected automatically for both care seekers and providers)

  • IP address and device information
  • Browser type and version
  • Authentication session data
  • Cookies necessary for portal functionality and security
  • Enquiry and communication history

Lawful basis for processing

We process personal data on the following legal bases:

  • Contract: to provide our matching and lead-generation service to both care seekers and care providers, including arranging introductions and managing the service.
  • Legitimate interests: to operate, secure and improve the portal; prevent fraud; administer provider accounts; monitor quality and safety; retain records of introductions to evidence consent and defend potential claims; conduct due diligence on providers.
  • Consent: to share care seeker details with care providers they have requested to be introduced to, and for marketing communications where applicable.
  • Legal obligation: to comply with tax and company law record-keeping obligations; to meet CQC/regulator requirements for safeguarding and quality monitoring; to comply with health and social care legislation.
  • Vital interests: where processing is necessary to protect the vital interests of vulnerable adults (safeguarding), particularly in emergency situations.
  • Public task: to fulfil our role in supporting vulnerable adults to access regulated care services.

How we use your data

For care seekers

  • Matching with providers: to identify and connect care seekers with CQC-regulated home care providers suited to their specific needs, location, and care preferences.
  • Communication: to contact care seekers via email or phone regarding enquiries, provider introductions, and service updates.
  • Quality assurance: to follow up on care arrangements, gather feedback on the matching service and provider quality, and improve our service.
  • Safeguarding: to monitor for safeguarding concerns and report to relevant authorities if vulnerable adult welfare issues are identified.
  • Portal operation: to provide customer support and manage enquiries.
  • Security: to protect accounts and detect fraud.
  • Legal compliance: to maintain records for 6 years to evidence the care matching transaction and defend any claims.
  • Marketing (with consent): to send newsletters, updates, or information about our service.

For care providers

  • Lead provision: to share matched care seeker enquiries with providers who have purchased access to leads in their coverage area.
  • Communication: to send care seekers' details, enquiry summaries, and transactional notifications.
  • Account management: to manage provider registrations, payments, service agreements, and portal access.
  • Quality monitoring: to review provider ratings, inspection reports, and gather feedback from care seekers.
  • Compliance: to maintain records of provider due diligence, DBS checks, and CQC/regulator status.
  • Marketing (with consent): to send updates and relevant service information.

How we share your data

With care providers: care seeker data (including health/care needs data) is shared with CQC-regulated care providers through the secure portal after the care seeker has requested an introduction. Providers access care seeker details directly through the portal and can download enquiry summaries. Care providers use this information solely to assess suitability and contact the care seeker for a no-obligation consultation.

With third-party representatives: if a care seeker consents, we may share details with family members, social workers, healthcare professionals, or local authority care assessors to support the care matching process.

With sub-processors: we use the following third-party services to operate the portal. Each processes data on our behalf under appropriate data processing agreements:

  • Database and authentication: Supabase (servers in EU)
  • Payment processing: [INSERT PAYMENT PROCESSOR]
  • Email delivery: Postmark or equivalent
  • Application hosting: Vercel or equivalent
  • Customer relationship management: [INSERT CRM PROVIDER]
  • Analytics: [INSERT ANALYTICS PROVIDER - if applicable]

With regulators and safeguarding bodies: in certain circumstances, we may be required or choose to share care seeker data with:

  • Care quality regulators (CQC, Care Inspectorate, CIW, RQIA) for compliance and quality monitoring.
  • Local authority safeguarding teams if vulnerable adult concerns are identified.
  • Health and social care professionals with the care seeker's consent or in emergency situations.
  • Law enforcement, if required by law.

For legal obligations: we may disclose personal data if required by law, court order, or valid regulatory demand.

We do not sell your data to any third party. Data is only shared as described above and is never distributed to unauthorised third-party providers or for commercial purposes outside the care matching service.

International data transfers

Some of our sub-processors are based outside the UK. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by the ICO.

All international sub-processors operate under Data Processing Agreements incorporating Standard Contractual Clauses and the UK International Data Transfer Addendum. A Transfer Risk Assessment covering these transfers is maintained and reviewed annually.

Data retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in this policy:

  • Care seeker enquiry data: retained for up to 6 years from the date of the enquiry, reflecting the six-year limitation period for claims and to evidence consent for care provider introductions.
  • Care provider data (registrations, DBS, compliance records): retained for the duration of the registration and for up to 6 years after termination for tax, regulatory, and safeguarding compliance.
  • Communications and enquiry records: retained for 6 years for audit and safeguarding purposes.
  • Transaction and billing records: retained for 6 years in line with HMRC and regulatory requirements.
  • Technical logs and IP addresses: retained for up to 12 months for security and debugging purposes.
  • Safeguarding records: retained in accordance with health and social care regulations and legal advice.

After the retention period, data is securely deleted or anonymised. Anonymised data may be retained longer for service improvement and statistical purposes.

Your rights

Under the UK GDPR, you have the following rights:

  • Right to access: you can request a copy of the personal data we hold about you in a structured, commonly used format.
  • Right to rectification: you may request corrections to incomplete or inaccurate data.
  • Right to erasure (the "right to be forgotten"): you have the right to request the deletion of your personal data, subject to our legal retention obligations and safeguarding responsibilities.
  • Right to restrict processing: you can ask us to limit how we use your data in certain circumstances.
  • Right to data portability: you can request your data in a structured, commonly used format for transfer to another service.
  • Right to object: you can object to the processing of your data where we rely on legitimate interests, except where we have a compelling legal or safeguarding reason to continue processing.
  • Right to withdraw consent: where processing is based on consent, you may withdraw it at any time (this does not affect processing before withdrawal).
  • Rights related to automated decision-making: you have the right not to be subject to automated decision-making that produces legal or similarly significant effects.

Important: Your rights may be limited where we have a legal obligation to retain or process your data, particularly for safeguarding vulnerable adults.

To exercise any of these rights, please contact us using the details in the Contact Information section below. We will respond within one calendar month. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk).

Cookies

The portal uses cookies to ensure security and functionality. These include:

  • Essential cookies: session cookies, authentication tokens, and security cookies strictly necessary for portal operation and user authentication.
  • Security cookies: two-factor authentication tokens and fraud prevention.
  • Analytical cookies: to understand how the portal is used and identify improvements (anonymised where possible).

By using the portal, you agree to the use of essential and security cookies. You can manage analytical cookie preferences through our cookie banner or browser settings. We do not set marketing or third-party advertising cookies without explicit consent.

See our separate Cookie Policy for more details.

Security measures

We take the protection of your personal data very seriously and implement robust security measures, including:

  • Authentication: two-factor authentication (email codes) on all portal accounts; optional time-based one-time passwords (TOTP) for providers.
  • Encryption: HTTPS encryption on all connections; encrypted storage of sensitive data; encrypted data transmission.
  • Access controls: role-based access control; data separation ensuring users only access data they are authorised to view; secure logging of data access.
  • Password security: bcrypt or equivalent hashing; secure session management with signed tokens.
  • Endpoint protection: rate limiting on authentication and sensitive endpoints; CSRF protection; input validation and sanitisation.
  • Data minimisation: we collect and process only data necessary for the service; health data is handled with particular care.
  • Staff training: all staff handling personal data receive data protection and safeguarding training.
  • Third-party security: sub-processors are vetted for security compliance; data processing agreements require equivalent security measures.
  • Regular audits: periodic security assessments and code reviews.

Despite these measures, no online system is completely secure. We will not be responsible for any breach arising from circumstances beyond our reasonable control.

Data breach procedures

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the Information Commissioner's Office (ICO) within 72 hours, as required by UK GDPR Article 33.
  • Inform affected individuals without undue delay, as required by UK GDPR Article 34.
  • Provide details of the breach, the likely consequences, and measures we are taking or propose to take.
  • In cases involving vulnerable adults or safeguarding concerns, we will also notify relevant social care authorities, health and social care regulators, and other agencies as appropriate.

Safeguarding and vulnerable adults

Because our service deals with vulnerable adults, we have safeguarding commitments beyond standard data protection:

  • Safeguarding reporting: we monitor for signs of abuse, exploitation, or neglect and report concerns to local authority safeguarding teams and relevant regulators.
  • Vulnerable adult assessment: care seeker data is assessed for safeguarding risks, and appropriate support or warnings may be provided.
  • Provider vetting: we conduct enhanced due diligence on care providers, including CQC/regulator checks and DBS verification where relevant.
  • Reporting obligations: we comply with Care Act 2014 and other safeguarding legislation.

Your right to erasure, rectification, or objection may be limited where we have safeguarding concerns or legal obligations regarding vulnerable adults.

Children's data

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If a child's data is shared in the context of family care arrangements (e.g., a child's contact details for a grandparent's care), we will process it only as necessary for the care service and in accordance with children's data protection principles.

Third-party links

The portal may contain links to external websites operated by care providers, regulators, or other third parties. We are not responsible for the privacy practices of third-party sites and encourage you to read their privacy policies before sharing personal data.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our service, technology, legal requirements, or other factors. Any material changes will be posted on this page with an updated effective date. We encourage you to review this policy periodically. Continued use of our service following changes constitutes your acceptance of the updated policy.

Contact information

If you have any privacy-related questions, concerns, requests, or wish to exercise your data rights, please contact us at:

Anoeba Limited
Trading as: HomeCareConnection
Email: [INSERT EMAIL ADDRESS]
Phone: [INSERT PHONE NUMBER]
Address: [INSERT BUSINESS ADDRESS]
ICO Registration: [INSERT ICO REGISTRATION NUMBER]

Data Protection Officer (if appointed):
Email: [INSERT DPO EMAIL - if applicable]

For safeguarding concerns or to report suspected abuse, please contact your local authority safeguarding team or relevant regulator immediately, or contact us urgently at [INSERT EMERGENCY CONTACT].

Governing law

This Privacy Policy is governed by and interpreted in accordance with the laws of the United Kingdom. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts of England and Wales (or the courts of Scotland, Wales, or Northern Ireland where applicable).

Additional information

ICO complaint: If you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

ICO
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Phone: 0303 123 1113
Website: ico.org.uk

Regulator contact details:

  • Care Quality Commission (CQC) – England: 03000 616161 | cqc.org.uk
  • Care Inspectorate – Scotland: 0345 600 9527 | careinspectorate.com
  • Care Inspectorate Wales (CIW): 0300 790 0126 | careinspectorate.wales
  • Regulation and Quality Improvement Authority (RQIA) – Northern Ireland: 028 9051 7500 | rqia.org.uk

Version History

VersionDateChanges
1.0August 2026Initial publication