Privacy Policy
Last updated: 7 September 2026
1. Who We Are
This platform is operated by Babiha Care Solutions Limited("Babiha", "we", "us", or "our"), a company registered in England and Wales under company number 17081576, with its registered office at 8b Kelvin House, Kelvin Way, Crawley, RH10 9WE, United Kingdom.
We provide care management software to UK domiciliary care agencies. This Privacy Policy explains how we handle personal data and, importantly, when we are responsible for that data (as a "controller") and when we are simply handling it on a care agency's behalf (as a "processor"). Section 2 explains the difference, because it determines who you should contact about your data.
- Registered with the Information Commissioner's Office (ICO): ZC132791
- Data protection enquiries: dpo@babiha.care (our Data Protection Lead)
- General privacy enquiries: privacy@babiha.care
2. Our Two Roles: Controller and Processor
Under UK data protection law, a controller decides why and how personal data is processed, and a processor only acts on the controller's instructions. Babiha acts in both roles depending on the data:
- Where we are the controller: the account and authentication data of the agency staff who use our platform, people who visit our website or contact us, billing contacts, and the account and login data of family members who use the Family Portal. This Privacy Policy governs that data.
- Where we are the processor: the care records of service users (clients) — including health information, care plans, medication records and visit logs — as well as staff employment records and care-related family messages that an agency manages in the platform. For that data, the care agency is the controller and we process it only on the agency's documented instructions under our Data Processing Agreement.
If you are a service user or a family member and want to access, correct or delete care records, the organisation responsible is your care agency, not Babiha. Please contact them; we will support them in responding to you.
3. Information We Handle
Agency and staff account data
- Name, work email address, and phone number
- Job title and role within the agency
- Agency details and CQC registration information
- Login credentials and authentication data (including two-factor authentication)
- Usage, device and log data needed to operate and secure the platform
Babiha Carer mobile app data and permissions
The Babiha Carer mobile app asks for device permissions only when they are needed for a feature. You can deny or later withdraw a permission in your device settings, although the related feature may then be unavailable.
- Location: your current location may be collected when you check in to or check out of a visit, including when a completed action is waiting to sync. The app does not request background location access or continuously track you.
- Camera and photos: used only when you choose to take or select a photo for visit documentation, an incident, or your profile.
- Microphone and speech recognition: used when you choose voice-to-text to dictate a note. Your device's speech-recognition service turns speech into text, and the resulting text is handled like any other note you submit.
- Push notifications: a device notification token and basic device details are used to deliver alerts you are permitted to receive. You can disable notifications in your device settings.
- Biometric authentication: if you enable Face ID, fingerprint or another supported biometric, the check is performed by your device. Babiha receives only whether authentication succeeded and does not receive your biometric template.
Visit locations, care notes, photographs and other care content are Customer Data. We process them for your care agency as described in Section 2. Limited account, device, security and diagnostic data is handled by Babiha as controller so we can operate and protect the app. Some Customer Data may be held temporarily in encrypted app storage so authorised care work can continue when the device is offline and sync later.
Family Portal account data
- The name, email address and login credentials of family members we register
- Care-related messages exchanged with the care team, processed for your agency
Website visitors and enquiries
- Information you provide when you contact us or request a demonstration
- Limited technical data via cookies (see our Cookie Policy)
We do not seek to collect special category (health) data in our role as controller. Any health data about service users is processed on the agency's behalf as described in Section 2.
4. Legal Bases for Processing
For the personal data we control, we rely on the following lawful bases under Article 6 of the UK GDPR:
- Contract: to create and manage accounts, provide the platform, and handle billing where our contract is with you as an individual (Article 6(1)(b)). For staff and representatives of an agency customer, we rely on our legitimate interests in administering the agency relationship.
- Legitimate interests: to secure, maintain and improve the platform, prevent fraud and misuse, and communicate with our customers (Article 6(1)(f)).
- Legal obligation: to meet our own legal, tax and regulatory duties (Article 6(1)(c)).
- Consent: for optional analytics cookies and any marketing emails, which you can withdraw at any time (Article 6(1)(a)).
When we process service user care data as a processor, the agency determines the lawful basis and, for health data, the Article 9 condition — typically the provision of health or social care (Article 9(2)(h)).
5. How We Use Your Information
- Provide, maintain, secure and improve the platform
- Set up and administer accounts and process subscription payments
- Provide customer support and respond to enquiries
- Send service and administrative messages
- Detect, prevent and investigate security incidents and misuse
- Comply with our legal and regulatory obligations
6. Who We Share Data With
We use a small number of carefully selected service providers ("sub-processors") to run the platform — for example for hosting, email and error monitoring. Our processor contracts must limit how those providers use personal data. Some providers also act as independent controllers for their own legal and security purposes. We publish our provider list and the recorded status of the relevant agreements and safeguards, including what each provider does and where it is located, on our Sub-processors page.
We may also share data where necessary with professional advisers, or where required by law or to protect our legal rights. We do not sell personal data.
7. Where Your Data Is Stored and International Transfers
Our primary database and file storage are hosted in the United Kingdom (London region). UK storage does not mean that every processing operation stays in the UK: application hosting, support access and the providers listed below may involve other countries.
Some providers are headquartered outside the UK, and their data-hosting location can differ from their headquarters. A restricted transfer requires a recognised mechanism, such as applicable UK adequacy regulations or an appropriate safeguard such as the UK International Data Transfer Agreement or UK Addendum to EU Standard Contractual Clauses. The UK Extension to the EU–US Data Privacy Framework can apply only where the recipient and transfer meet its conditions. The recorded status for each provider is on our Sub-processors page; a status awaiting verification is not a confirmation that a safeguard has been completed. Contact our Data Protection Lead for information about the safeguards applicable to your data and how to obtain a copy.
8. Data Security
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit, encryption at rest by our hosting provider, application-layer encryption of the most sensitive fields, strict role-based access controls, database-level tenant access policies, and audit logging. You can read more on our Security page.
9. How Long We Keep Data
We keep personal data only for as long as necessary. Where we are the controller, we retain account data for the life of the account and for a reasonable period afterwards to meet legal and operational needs. Where we are a processor, care records are retained on the agency's instructions and applicable requirements. The periods below are our standard retention review thresholds; they are not a universal statutory schedule or a promise of automatic deletion. Care, staff, financial and communications records require review before erasure, and audit records are protected against routine alteration or deletion:
- Service user care records: review after 8 years, subject to agency instructions and the applicable record category
- Audit logs: review after 7 years; no routine automatic deletion
- Staff and employment records: review after 6 years following employment
- Financial and billing records: review after 6 years
- Communications logs (email/SMS): review after 2 years
For account and enquiry data, we consider whether the relationship remains active, whether an enquiry has been resolved, and whether a legal obligation or claim requires continued retention. Agency instructions and record-specific legal duties determine the final retention decision for Customer Data.
10. Your Rights
Your rights depend on the circumstances and lawful basis. They include the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data (subject to legal retention requirements)
- Restrict or object to certain processing
- Data portability — receive your data in a portable format
- Withdraw consent at any time where we rely on consent
We respond to rights requests without undue delay and normally within one calendar month of receipt. We may need proportionate identity information; any extension or pause will follow the law and be explained to you. To exercise rights over data we control, contact privacy@babiha.care. For care records, please contact your care agency as the controller (see Section 2).
To close your Babiha or Babiha Carer account, follow our public delete your account instructions. Account data is deleted or anonymised where applicable, subject to legal retention requirements and the care agency's responsibilities as controller for care records.
11. Automated Decision-Making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, and we do not carry out profiling of that kind.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and change the "Last updated" date, and notify you of material changes where appropriate.
13. Complaints
You can raise a data protection complaint by emailing privacy@babiha.care or writing to the address below. Please explain your concern without including care records or passwords. We will acknowledge your complaint within 30 days, investigate without undue delay, keep you informed and explain the outcome. You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator:
- Website: ico.org.uk
- Helpline: 0303 123 1113
14. Contact Us
- General privacy enquiries: privacy@babiha.care
- Data Protection Lead: dpo@babiha.care
- Post: Data Protection, Babiha Care Solutions Limited, 8b Kelvin House, Kelvin Way, Crawley, RH10 9WE