This policy explains how Smart Connect Hub handles personal information — including health and care data — when you use our platform and mobile applications.
01Who we are
Smart Connect Hub is operated by SmartTSense Connect Ltd, a company registered in England and Wales, with its registered office at 30 Larchwood Road, Hemel Hempstead, Hertfordshire, HP2 5NB, United Kingdom. Throughout this policy, "we", "us", and "our" refer to SmartTSense Connect Ltd.
We provide software that domiciliary (home) care providers use to schedule and record care visits, manage electronic medication administration records (eMAR), maintain care plans and risk assessments, and meet their regulatory and record-keeping obligations.
02Controllers and processors
Because Smart Connect Hub is a platform used by many independent care providers, responsibility for personal data is shared. It is important to understand who is responsible for what.
Care providers are the data controllers of care records
Each care provider that uses Smart Connect Hub (for example, the organisation that employs you as a carer, or that arranges your care) is the data controller for the personal and health data of the people they support and their own staff. They decide why and how that data is processed. If you are a person receiving care, or a family member, and you wish to exercise your data rights over care records, your care provider is your first point of contact.
We are the data processor for care records
When we store and process care data on behalf of a care provider, we act as their data processor. We only process that data on the provider's documented instructions and under a written data processing agreement, as required by Article 28 of the UK GDPR.
We are a controller for our own account and technical data
For information we need to run the service itself — such as your app account details, sign-in credentials, and technical logs — SmartTSense Connect Ltd is the data controller.
03Data we handle
Depending on your role, the platform may handle the following categories of information:
| Category | Examples |
|---|---|
| Account details | Name, work email address, phone number, job role, and the care organisation you belong to. |
| Authentication data | Passwords (stored only in hashed form), and — where you enable it — biometric sign-in (fingerprint or face). Biometric data stays on your device; we never receive or store it. |
| Health and care data (special category) | Care plans, medication administration records, visit notes and observations, vital signs, risk assessments, and other records about the people receiving care. This is handled on behalf of the care provider. |
| Location data | Approximate or precise location at the point of clocking in and out of a care visit, to confirm attendance. See section 4. |
| Device and usage data | Device type and operating system, app version, and technical logs used to keep the service secure and working. |
04Location data
The carer app uses your device's location to confirm that a care visit took place at the right place and time — for example, when you clock in and clock out of a visit.
- Location is captured only while you are using the app to start or end a visit. The app does not track your location continuously and does not collect location while running in the background.
- You control location access through your device settings, and can withdraw it at any time. If you turn location off, visit attendance may need to be confirmed another way by your care provider.
05Legal bases
Under the UK GDPR, we and the care providers rely on the following legal bases:
- Contract — to provide you and your organisation with the app and platform you have signed up to use.
- Legitimate interests — to keep the service secure, prevent misuse, maintain audit trails, and improve reliability, balanced against your rights.
- Legal obligation — to meet record-keeping and safeguarding duties that apply to care.
For health and care data (special category data under Article 9 of the UK GDPR), the additional condition relied on is Article 9(2)(h) — the provision of health and social care and the management of health and social care systems, supported by the corresponding condition in the UK Data Protection Act 2018. Where safeguarding is involved, the substantial-public-interest condition for safeguarding may also apply.
06How we use data
We use the information described above to:
- Let you sign in securely and use the app for your role.
- Schedule, record, and evidence care visits, including attendance and the care delivered.
- Maintain medication records, care plans, risk assessments, and observations.
- Provide AI-assisted drafting and review tools that help care staff prepare care plans and risk assessments, and highlight notes for a person to review — always subject to review and approval by a qualified member of staff (see section 7).
- Keep tamper-evident audit trails required for care governance and regulatory compliance.
- Keep the platform secure, diagnose problems, and support the people who use it.
07AI-assisted care documentation
We use artificial-intelligence (AI) tools to help our care staff prepare and review care documentation — for example, drafting sections of a care plan or risk assessment, and highlighting notes that a manager should look at more closely.
To provide these features, relevant information is sent securely to our AI provider (Anthropic PBC), which acts as our data processor under a written contract. We minimise what is sent — for example, we remove names, dates of birth and NHS numbers where they are not needed. The information is not used to train the provider's AI models, and it is held only for a strictly limited period. All AI activity is recorded in a tamper-evident audit trail.
Using AI in this way does not change your rights, and the legal bases are the same as for the underlying care records (see section 5). Information sent to our AI provider is processed in the United States under appropriate safeguards — see section 12.
09Security
We take the protection of care data seriously and apply appropriate technical and organisational measures, including:
- Encryption of data in transit (HTTPS/TLS) and encryption of data at rest.
- Role-based access controls, so people only see the data appropriate to their role and organisation.
- Tamper-evident audit logging (including cryptographic hash chains for medication records).
- Separation of each care organisation's data within the platform.
- Regular review of access, backups, and security practices.
No system can be guaranteed completely secure, but we work to protect your data and to respond promptly to any incident, including notifying the ICO and affected people where the law requires.
10Retention
How long care records are kept is decided by the care provider (the controller), in line with their legal and regulatory obligations — health and social care records are typically retained for a number of years after care ends, as set out in applicable NHS and care record retention guidance.
Account and technical data we control is kept for as long as your account is active and for a reasonable period afterwards, then deleted or anonymised. When a care provider stops using the platform, we return or delete the data we hold on their behalf in line with our agreement with them.
11Your rights
Under UK data protection law you have rights over your personal data, including the right to:
- Be informed about how your data is used (this policy).
- Access a copy of your personal data.
- Have inaccurate data corrected.
- Have data erased in certain circumstances.
- Restrict or object to certain processing.
- Data portability in certain circumstances.
Because care records are controlled by your care provider, requests about those records are usually handled by them — contact your care organisation, or contact us and we will help direct your request. For data we control (such as your app account), contact us directly using the details below.
12International transfers
Most personal data is hosted and processed within the United Kingdom and/or the European Economic Area.
Where our AI-assisted features (section 7) are used, relevant, minimised information is processed by our AI sub-processor, Anthropic PBC, in the United States. This transfer is protected by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with additional safeguards — data minimisation, a contractual commitment that the data is not used to train AI models, and a strictly limited retention period. We have completed a transfer risk assessment for this transfer.
For any other transfer outside the UK, we ensure an appropriate safeguard is in place, such as an adequacy decision or the UK International Data Transfer Agreement / Addendum, so that your data remains protected.
13Children's data
The Smart Connect Hub app is intended for use by care staff and administrators, not by children. Some care records processed on behalf of a care provider may relate to children who receive care services; that data is handled under the care provider's instructions and the legal bases described above, with the additional safeguards that apply to children's data.
14Changes
We may update this policy from time to time. When we make material changes, we will update the "last updated" date at the top and, where appropriate, notify you through the app or your care provider. The current version is always available at this page.
Version 1.1 (14 July 2026): added section 7 (AI-assisted care documentation) and updated section 12 (international transfers) to reflect the use of an AI sub-processor.
15Contact and complaints
Data protection contact
SmartTSense Connect Ltd
Email: info@smartconnects.co
Registered office: 30 Larchwood Road, Hemel Hempstead, Hertfordshire, HP2 5NB, United Kingdom
If you have a concern about how your data is handled, please contact us first so we can try to put it right. You also have the right to complain to the UK supervisory authority:
Supervisory authority
Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113