Health Automated

Privacy Policy

Health Automated Ltd

Privacy Policy

Website, Architecture platform and mobile applications

Organisation: Health Automated Ltd

Effective date: 19 July 2026

Version: 1.0

Privacy contact: hello@healthautomated.online

This notice explains how Health Automated Ltd uses and protects
personal data in connection with healthautomated.online, the
Architecture care-management platform, and related mobile applications.
It is intended for website visitors, prospective and current customers,
authorised platform users, employees and workers of customer
organisations, service users, their representatives, and other people
whose information is entered into Architecture.

Important: where a care provider or other customer
decides why and how personal data is used in Architecture, that
organisation is the controller and Health Automated acts as its
processor. In that situation, the customer’s privacy notice is the
primary notice and requests about the care record should normally be
directed to that customer. Health Automated will assist the customer to
respond.

1. Who we are and how to
contact us

Health Automated Ltd (company number 15289766) is registered in
England and Wales. Its registered office is C/O Andrew Smith Bookkeeping
Services Limited, Kingsley House, 106 Milton Street, Northampton,
Northamptonshire, United Kingdom, NN2 7JF.

For questions, objections or rights requests, email
hello@healthautomated.online, telephone 0330 175 5775, or write to the
registered office marked “Privacy”. Where the request concerns
information held for a care provider, please identify that provider and,
if possible, contact it directly.

2. When we are
controller and when we are processor

ContextHealth Automated’s roleWho decides the purposes
Website enquiries, demonstrations, contracts, billing, supplier
relations, security and our own business administration
ControllerHealth Automated Ltd
Customer account administration and direct support contactsController for limited account, contact, support and security
records
Health Automated Ltd
Care records, service-user data, workforce records, rosters,
medication records, messages and operational records entered by a
customer
ProcessorThe customer care provider or other customer
Product telemetry that is genuinely anonymous and cannot identify a
person
Outside data-protection law; otherwise controller for limited
telemetry
Health Automated Ltd

3. Information we may handle

  • Identity and contact information, such as names, work roles,
    organisations, email addresses, telephone numbers and postal
    addresses.

  • Account and authentication information, such as usernames, user
    IDs, roles, access permissions, login history and security events.
    Passwords are stored only in protected form.

  • Commercial and support information, including enquiries,
    demonstration requests, contracts, invoices, communications, support
    tickets and troubleshooting records.

  • Device and technical information, including IP address, device
    type, operating system, app version, timestamps, diagnostic events and
    cookie or consent preferences.

  • Customer-controlled platform content, which may include care
    plans, health and disability information, medication data, risk
    assessments, daily notes, attendance, rostering, workforce records,
    emergency alerts, communications and information about relatives or
    representatives.

  • Special-category data, including health data and, where entered
    by a customer, information revealing racial or ethnic origin, religion,
    trade-union membership, sex life or sexual orientation. Platform content
    may also include criminal-offence information and data about children or
    adults at risk.

  • AI-assisted outputs and alerts produced within Architecture from
    customer-controlled data, together with relevant audit
    information.

We ask customers and users not to place personal data—especially
names, contact details, care notes, medication data or other free
text—into crash-reporting fields or diagnostic descriptions.

4. How we obtain information

We obtain information directly from website visitors, customer
representatives, authorised users and business contacts; from customer
organisations that upload or create platform records; automatically from
the website, platform, apps and devices; and from public business
sources where necessary for business-to-business administration. If a
customer supplies data about another person, that customer is
responsible for providing appropriate privacy information and having a
lawful basis.

5. Why we use
information and our lawful bases

PurposeTypical dataUK GDPR lawful basis
Respond to enquiries, arrange demonstrations and take steps toward a
contract
Contact and enquiry dataArticle 6(1)(b); or legitimate interests, Article 6(1)(f)
Provide customer accounts, service, support, billing and contract
management
Account, commercial and support dataContract, Article 6(1)(b); legitimate interests, Article 6(1)(f);
legal obligation, Article 6(1)(c)
Operate, secure, troubleshoot and improve our servicesTechnical, audit, security and limited diagnostic dataLegitimate interests, Article 6(1)(f); legal obligation where
applicable
Send requested updates or business marketingContact details and preferencesConsent, Article 6(1)(a), or legitimate interests, Article 6(1)(f),
subject to PECR; consent can be withdrawn
Meet legal, regulatory, tax, accounting, safeguarding and claims
obligations
Relevant business and evidential recordsLegal obligation, Article 6(1)(c); legitimate interests, Article
6(1)(f)
Process customer-controlled platform contentCare, workforce and operational dataThe customer selects its Article 6 basis; Health Automated processes
on documented instructions under Article 28

For special-category and criminal-offence data in customer-controlled
content, the customer must identify and document the relevant Article 9
condition and any Data Protection Act 2018 Schedule 1 condition.
Depending on the service and context, a customer may rely on health or
social care under Article 9(2)(h), substantial public interest under
Article 9(2)(g), employment and social-protection law under Article
9(2)(b), or another applicable condition. Health Automated does not
choose that condition for the customer.

6. Architecture, AI
and automated processing

Architecture uses automation and AI-assisted functions, including the
virtual deputy known as Jack, to organise information, assist workflows,
identify events, generate alerts and support administrative tasks.
Outputs are intended to support authorised human users and should be
reviewed in context. Health Automated does not use customer care data to
train general-purpose AI models or for advertising.

Health Automated does not intend Architecture to make a solely
automated decision about a person that produces legal or similarly
significant effects without appropriate human involvement. A customer
must assess its own use, provide any required explanation, complete a
data protection impact assessment where required, and offer safeguards
such as human review and a way to challenge a decision. Contact the
relevant customer if you want an explanation or human review of an
AI-assisted outcome involving you.

7. Sharing and disclosures

We restrict personal data to authorised staff and contractors who
need it for their work and who are bound by confidentiality and access
controls. We do not sell personal data and do not share customer care
records for advertising.

The only external application telemetry described in this notice is
Google-provided crash reporting and app analytics. It is configured to
receive anonymous or aggregated statistics used to understand stability
and app usage. We do not intentionally send Google names, email
addresses, care records, message content, medication information,
precise care notes or customer-entered free text. Device or online
identifiers and diagnostic data may nevertheless be personal data if
they can identify or single out a user; where that occurs, Google acts
as a service provider under contractual data-protection terms.

We may also disclose information where required by law, court order
or a competent regulator; to protect vital interests or address
security, fraud or safeguarding concerns; or in connection with a
corporate transaction, subject to appropriate confidentiality and legal
safeguards.

8. International transfers

Our core platform data is kept within systems controlled by Health
Automated and is not intentionally transferred outside the United
Kingdom. Google telemetry may be processed in countries outside the UK.
Where that telemetry is personal data, we rely on an applicable UK
adequacy regulation or approved contractual safeguards, such as the UK
International Data Transfer Agreement or UK Addendum, together with a
transfer risk assessment where required. You may request information
about the relevant safeguard.

9. Cookies and similar
technologies

The website and apps use strictly necessary storage for functions
such as security, sign-in, session management and remembering privacy
choices. Non-essential analytics or similar technologies are used only
where valid consent is required and obtained. Users can reject or
withdraw consent through the cookie/settings control without losing
access to core functions. More detailed cookie information, including
names, purposes and lifetimes, should be provided in the cookie panel or
a linked cookie notice.

10. Retention and deletion

We keep personal data only for as long as needed for the stated
purpose, legal obligations, security and the establishment or defence of
claims. The schedule below applies unless a longer or shorter period is
legally required, agreed in the customer contract, or documented in the
customer’s instructions.

RecordStandard retention / deletion rule
Website enquiries and unsuccessful sales enquiriesUp to 24 months after the last meaningful contact, then delete or
anonymise.
Marketing preferencesUntil consent is withdrawn or objection is made; suppression record
retained as needed to honour the request. Review inactive contacts after
24 months.
Customer contracts, orders, invoices and core business recordsContract term plus 6 years, or longer where tax, accounting or
claims law requires.
Customer administrator and authorised-user accountsFor the account lifetime; disable promptly when instructed. Delete
or anonymise controller-held profile data within 90 days after contract
end, subject to legal records.
Support tickets and support communications3 years after closure, unless needed for an active contract,
security investigation or legal claim.
Authentication, access and security audit logs12 months from creation; security-incident evidence may be retained
for 6 years after closure where necessary.
Customer-controlled care, workforce and operational contentFor the period set by the customer. On contract end, return or make
data available as agreed, then delete production copies within 30 days
unless the customer instructs otherwise or law requires retention.
Encrypted backups containing deleted customer contentExpire through the normal backup cycle within 90 days; isolated and
not restored except for continuity or disaster recovery. If restored,
the deletion is re-applied.
Anonymous/aggregated app analytics and crash statisticsUp to 14 months, then aggregate further or delete. Any identifiable
diagnostic record is kept no longer than 90 days unless required to
investigate an active incident.
Cookie and consent recordsFor the lifetime shown in the cookie notice; consent evidence and
preferences normally up to 24 months, then refreshed or deleted.
Rights requests and privacy complaints3 years after final response; longer if needed for an active
complaint or claim.

Deletion means secure removal from live systems so the data is no
longer available for ordinary use. Backup copies are protected from
routine access and expire on the cycle above. We may retain a minimal
record of a deletion, objection or suppression request to demonstrate
compliance. Truly anonymised information may be retained because it no
longer identifies a person.

11. Security

We use proportionate technical and organisational measures designed
to protect personal data, including role-based access controls,
authentication controls, encryption in transit and at rest where
appropriate, logging and monitoring, backup and recovery arrangements,
vulnerability and incident management, staff confidentiality and
training, and customer access controls. No system can be guaranteed
completely secure. Users must protect their credentials, use authorised
devices and report suspected compromise promptly.

12. Your data-protection
rights

Depending on the circumstances, you may have the right to be
informed; obtain access and a copy; correct inaccurate data; have data
erased; restrict processing; receive portable data; object to processing
based on legitimate interests or to direct marketing; withdraw consent
at any time; and obtain safeguards relating to solely automated
decisions. Rights are not absolute and legal exemptions may apply.

If Health Automated holds the data as a processor, we will refer the
request to the relevant customer and assist it. We may need information
to verify identity and locate the data. We normally respond without
undue delay and within one month, subject to lawful extensions for
complex or numerous requests.

13. Children and adults at
risk

Architecture may contain information about children or adults at risk
where a customer uses the service to provide care. The customer
determines the purpose and lawful basis and is responsible for
appropriate transparency, safeguards, permissions and access controls.
Health Automated does not knowingly market directly to children and the
public website is directed at organisations and adult business
users.

14. Complaints

Please contact us first so that we can try to resolve the issue. You
may also complain to the Information Commissioner’s Office (ICO), the UK
supervisory authority, at ico.org.uk or by telephone on 0303 123 1113.
If another organisation is the controller, you may complain to it
directly as well.

15. Changes to this policy

We may update this policy to reflect changes in our services,
technology, law or regulatory guidance. We will publish the current
version on healthautomated.online and, where a change is material,
provide an appropriate additional notice through the platform, app or
customer contact channel. The effective date at the start shows when
this version applies.

Last updated: 19 July 2026

Skip to content
Health Automated
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.