Privacy Policy
Privacy and Data Protection Policy
Health Automated Ltd
Privacy Policy
Website, Architecture platform and mobile applications
Organisation: Health Automated Ltd
Effective date: 19 July 2026
Version: 1.0
Privacy contact: hello@healthautomated.online
This notice explains how Health Automated Ltd uses and protects personal data in connection with healthautomated.online, the Architecture care-management platform, and related mobile applications. It is intended for website visitors, prospective and current customers, authorised platform users, employees and workers of customer organisations, service users, their representatives, and other people whose information is entered into Architecture.
Important: where a care provider or other customer decides why and how personal data is used in Architecture, that organisation is the controller and Health Automated acts as its processor. In that situation, the customer’s privacy notice is the primary notice and requests about the care record should normally be directed to that customer. Health Automated will assist the customer to respond.
1. Who we are and how to contact us
Health Automated Ltd (company number 15289766) is registered in England and Wales. Its registered office is C/O Andrew Smith Bookkeeping Services Limited, Kingsley House, 106 Milton Street, Northampton, Northamptonshire, United Kingdom, NN2 7JF.
For questions, objections or rights requests, email hello@healthautomated.online, telephone 0330 175 5775, or write to the registered office marked “Privacy”. Where the request concerns information held for a care provider, please identify that provider and, if possible, contact it directly.
2. When we are controller and when we are processor
| Context | Health Automated’s role | Who decides the purposes |
|---|---|---|
| Website enquiries, demonstrations, contracts, billing, supplier relations, security and our own business administration | Controller | Health Automated Ltd |
| Customer account administration and direct support contacts | Controller for limited account, contact, support and security records | Health Automated Ltd |
| Care records, service-user data, workforce records, rosters, medication records, messages and operational records entered by a customer | Processor | The customer care provider or other customer |
| Product telemetry that is genuinely anonymous and cannot identify a person | Outside data-protection law; otherwise controller for limited telemetry | Health Automated Ltd |
3. Information we may handle
Identity and contact information, such as names, work roles, organisations, email addresses, telephone numbers and postal addresses.
Account and authentication information, such as usernames, user IDs, roles, access permissions, login history and security events. Passwords are stored only in protected form.
Commercial and support information, including enquiries, demonstration requests, contracts, invoices, communications, support tickets and troubleshooting records.
Device and technical information, including IP address, device type, operating system, app version, timestamps, diagnostic events and cookie or consent preferences.
Customer-controlled platform content, which may include care plans, health and disability information, medication data, risk assessments, daily notes, attendance, rostering, workforce records, emergency alerts, communications and information about relatives or representatives.
Special-category data, including health data and, where entered by a customer, information revealing racial or ethnic origin, religion, trade-union membership, sex life or sexual orientation. Platform content may also include criminal-offence information and data about children or adults at risk.
AI-assisted outputs and alerts produced within Architecture from customer-controlled data, together with relevant audit information.
We ask customers and users not to place personal data—especially names, contact details, care notes, medication data or other free text—into crash-reporting fields or diagnostic descriptions.
4. How we obtain information
We obtain information directly from website visitors, customer representatives, authorised users and business contacts; from customer organisations that upload or create platform records; automatically from the website, platform, apps and devices; and from public business sources where necessary for business-to-business administration. If a customer supplies data about another person, that customer is responsible for providing appropriate privacy information and having a lawful basis.
5. Why we use information and our lawful bases
| Purpose | Typical data | UK GDPR lawful basis |
|---|---|---|
| Respond to enquiries, arrange demonstrations and take steps toward a contract | Contact and enquiry data | Article 6(1)(b); or legitimate interests, Article 6(1)(f) |
| Provide customer accounts, service, support, billing and contract management | Account, commercial and support data | Contract, Article 6(1)(b); legitimate interests, Article 6(1)(f); legal obligation, Article 6(1)(c) |
| Operate, secure, troubleshoot and improve our services | Technical, audit, security and limited diagnostic data | Legitimate interests, Article 6(1)(f); legal obligation where applicable |
| Send requested updates or business marketing | Contact details and preferences | Consent, Article 6(1)(a), or legitimate interests, Article 6(1)(f), subject to PECR; consent can be withdrawn |
| Meet legal, regulatory, tax, accounting, safeguarding and claims obligations | Relevant business and evidential records | Legal obligation, Article 6(1)(c); legitimate interests, Article 6(1)(f) |
| Process customer-controlled platform content | Care, workforce and operational data | The customer selects its Article 6 basis; Health Automated processes on documented instructions under Article 28 |
For special-category and criminal-offence data in customer-controlled content, the customer must identify and document the relevant Article 9 condition and any Data Protection Act 2018 Schedule 1 condition. Depending on the service and context, a customer may rely on health or social care under Article 9(2)(h), substantial public interest under Article 9(2)(g), employment and social-protection law under Article 9(2)(b), or another applicable condition. Health Automated does not choose that condition for the customer.
6. Architecture, AI and automated processing
Architecture uses automation and AI-assisted functions, including the virtual deputy known as Jack, to organise information, assist workflows, identify events, generate alerts and support administrative tasks. Outputs are intended to support authorised human users and should be reviewed in context. Health Automated does not use customer care data to train general-purpose AI models or for advertising.
Health Automated does not intend Architecture to make a solely automated decision about a person that produces legal or similarly significant effects without appropriate human involvement. A customer must assess its own use, provide any required explanation, complete a data protection impact assessment where required, and offer safeguards such as human review and a way to challenge a decision. Contact the relevant customer if you want an explanation or human review of an AI-assisted outcome involving you.
7. Sharing and disclosures
We restrict personal data to authorised staff and contractors who need it for their work and who are bound by confidentiality and access controls. We do not sell personal data and do not share customer care records for advertising.
The only external application telemetry described in this notice is Google-provided crash reporting and app analytics. It is configured to receive anonymous or aggregated statistics used to understand stability and app usage. We do not intentionally send Google names, email addresses, care records, message content, medication information, precise care notes or customer-entered free text. Device or online identifiers and diagnostic data may nevertheless be personal data if they can identify or single out a user; where that occurs, Google acts as a service provider under contractual data-protection terms.
We may also disclose information where required by law, court order or a competent regulator; to protect vital interests or address security, fraud or safeguarding concerns; or in connection with a corporate transaction, subject to appropriate confidentiality and legal safeguards.
8. International transfers
Our core platform data is kept within systems controlled by Health Automated and is not intentionally transferred outside the United Kingdom. Google telemetry may be processed in countries outside the UK. Where that telemetry is personal data, we rely on an applicable UK adequacy regulation or approved contractual safeguards, such as the UK International Data Transfer Agreement or UK Addendum, together with a transfer risk assessment where required. You may request information about the relevant safeguard.
9. Cookies and similar technologies
The website and apps use strictly necessary storage for functions such as security, sign-in, session management and remembering privacy choices. Non-essential analytics or similar technologies are used only where valid consent is required and obtained. Users can reject or withdraw consent through the cookie/settings control without losing access to core functions. More detailed cookie information, including names, purposes and lifetimes, should be provided in the cookie panel or a linked cookie notice.
10. Retention and deletion
We keep personal data only for as long as needed for the stated purpose, legal obligations, security and the establishment or defence of claims. The schedule below applies unless a longer or shorter period is legally required, agreed in the customer contract, or documented in the customer’s instructions.
| Record | Standard retention / deletion rule |
|---|---|
| Website enquiries and unsuccessful sales enquiries | Up to 24 months after the last meaningful contact, then delete or anonymise. |
| Marketing preferences | Until consent is withdrawn or objection is made; suppression record retained as needed to honour the request. Review inactive contacts after 24 months. |
| Customer contracts, orders, invoices and core business records | Contract term plus 6 years, or longer where tax, accounting or claims law requires. |
| Customer administrator and authorised-user accounts | For the account lifetime; disable promptly when instructed. Delete or anonymise controller-held profile data within 90 days after contract end, subject to legal records. |
| Support tickets and support communications | 3 years after closure, unless needed for an active contract, security investigation or legal claim. |
| Authentication, access and security audit logs | 12 months from creation; security-incident evidence may be retained for 6 years after closure where necessary. |
| Customer-controlled care, workforce and operational content | For the period set by the customer. On contract end, return or make data available as agreed, then delete production copies within 30 days unless the customer instructs otherwise or law requires retention. |
| Encrypted backups containing deleted customer content | Expire through the normal backup cycle within 90 days; isolated and not restored except for continuity or disaster recovery. If restored, the deletion is re-applied. |
| Anonymous/aggregated app analytics and crash statistics | Up to 14 months, then aggregate further or delete. Any identifiable diagnostic record is kept no longer than 90 days unless required to investigate an active incident. |
| Cookie and consent records | For the lifetime shown in the cookie notice; consent evidence and preferences normally up to 24 months, then refreshed or deleted. |
| Rights requests and privacy complaints | 3 years after final response; longer if needed for an active complaint or claim. |
Deletion means secure removal from live systems so the data is no longer available for ordinary use. Backup copies are protected from routine access and expire on the cycle above. We may retain a minimal record of a deletion, objection or suppression request to demonstrate compliance. Truly anonymised information may be retained because it no longer identifies a person.
11. Security
We use proportionate technical and organisational measures designed to protect personal data, including role-based access controls, authentication controls, encryption in transit and at rest where appropriate, logging and monitoring, backup and recovery arrangements, vulnerability and incident management, staff confidentiality and training, and customer access controls. No system can be guaranteed completely secure. Users must protect their credentials, use authorised devices and report suspected compromise promptly.
12. Your data-protection rights
Depending on the circumstances, you may have the right to be informed; obtain access and a copy; correct inaccurate data; have data erased; restrict processing; receive portable data; object to processing based on legitimate interests or to direct marketing; withdraw consent at any time; and obtain safeguards relating to solely automated decisions. Rights are not absolute and legal exemptions may apply.
If Health Automated holds the data as a processor, we will refer the request to the relevant customer and assist it. We may need information to verify identity and locate the data. We normally respond without undue delay and within one month, subject to lawful extensions for complex or numerous requests.
13. Children and adults at risk
Architecture may contain information about children or adults at risk where a customer uses the service to provide care. The customer determines the purpose and lawful basis and is responsible for appropriate transparency, safeguards, permissions and access controls. Health Automated does not knowingly market directly to children and the public website is directed at organisations and adult business users.
14. Complaints
Please contact us first so that we can try to resolve the issue. You may also complain to the Information Commissioner’s Office (ICO), the UK supervisory authority, at ico.org.uk or by telephone on 0303 123 1113. If another organisation is the controller, you may complain to it directly as well.
15. Changes to this policy
We may update this policy to reflect changes in our services, technology, law or regulatory guidance. We will publish the current version on healthautomated.online and, where a change is material, provide an appropriate additional notice through the platform, app or customer contact channel. The effective date at the start shows when this version applies.
Last updated: 19 July 2026
Frequently Asked Questions
We've compiled a list of answers to common questions.
Yes! Your data is incredibly safe. We have partnered with some of the leading cyber security firms across the globe to help ensure we have the best shot at protecting your sensitive data. We cannot explain too much of the inner workings, as that in itself would be a security breach. We have applied some of the best practices available, including creating our own pioneering safety and security measures.
We can have your account setup immediately. However, we will more than likely need to schedule an onboarding session with you to demonstrate the full system spec and to help reduce further support enquiries. We strongly advise an onboarding session to ensure you understand the full scope of and can maximise the use of Architecture and our other apps to get the full benefit.
The market has been very dynamic with charges for bolt-ons and other services.
We believe you should have a core functioning application with the full usage that you should expect.
We do not charge additional fees for Medication Administration, Communication, Number of Service Users, Powers of Attorney, etc.
We are very clear on our pricing and what third party plugins you can access if you wish.
There may be additional charges for access top applications such as Social JobFindr. Speak to us to find out more.