Last updated: July 2026
1. Who We Are
This platform is operated by Babiha Care Solutions Limited("Babiha", "we", "us", or "our"), a company registered in England and Wales under company number 17081576, with its registered office at 8b Kelvin House, Kelvin Way, Crawley, RH10 9WE, United Kingdom.
We provide care management software to UK domiciliary care agencies. This Privacy Policy explains how we handle personal data and, importantly, when we are responsible for that data (as a "controller") and when we are simply handling it on a care agency's behalf (as a "processor"). Section 2 explains the difference, because it determines who you should contact about your data.
- Registered with the Information Commissioner's Office (ICO): ZC132791
- Data protection enquiries: dpo@babiha.care (our Data Protection Lead)
- General privacy enquiries: privacy@babiha.care
2. Our Two Roles: Controller and Processor
Under UK data protection law, a controller decides why and how personal data is processed, and a processor only acts on the controller's instructions. Babiha acts in both roles depending on the data:
- Where we are the controller: the account and profile data of the agency staff who use our platform, people who visit our website or contact us, billing contacts, and the account and login data of family members who use the Family Portal. This Privacy Policy governs that data.
- Where we are the processor: the care records of service users (clients) — including health information, care plans, medication records and visit logs — that an agency enters into the platform. For that data, the care agency is the controller and we process it only on the agency's documented instructions under our Data Processing Agreement.
If you are a service user or a family member and want to access, correct or delete care records, the organisation responsible is your care agency, not Babiha. Please contact them; we will support them in responding to you.
3. Information We Collect (Where We Are the Controller)
Agency and staff account data
- Name, work email address, and phone number
- Job title and role within the agency
- Agency details and CQC registration information
- Login credentials and authentication data (including two-factor authentication)
- Usage, device and log data needed to operate and secure the platform
Family Portal account data
- The name, email address and login credentials of family members we register
- Messages exchanged with the care team through the portal
Website visitors and enquiries
- Information you provide when you contact us or request a demonstration
- Limited technical data via cookies (see our Cookie Policy)
We do not seek to collect special category (health) data in our role as controller. Any health data about service users is processed on the agency's behalf as described in Section 2.
4. Legal Bases for Processing
For the personal data we control, we rely on the following lawful bases under Article 6 of the UK GDPR:
- Contract: to create and manage accounts, provide the platform, and handle billing (Article 6(1)(b)).
- Legitimate interests: to secure, maintain and improve the platform, prevent fraud and misuse, and communicate with our customers (Article 6(1)(f)).
- Legal obligation: to meet our own legal, tax and regulatory duties (Article 6(1)(c)).
- Consent: for optional analytics cookies and any marketing emails, which you can withdraw at any time (Article 6(1)(a)).
When we process service user care data as a processor, the agency determines the lawful basis and, for health data, the Article 9 condition — typically the provision of health or social care (Article 9(2)(h)).
5. How We Use Your Information
- Provide, maintain, secure and improve the platform
- Set up and administer accounts and process subscription payments
- Provide customer support and respond to enquiries
- Send service and administrative messages
- Detect, prevent and investigate security incidents and misuse
- Comply with our legal and regulatory obligations
6. Who We Share Data With
We use a small number of carefully selected service providers ("sub-processors") to run the platform — for example for hosting, email and error monitoring. Each is bound by data protection terms and may only use the data to provide services to us. We publish the full, current list, including what each provider does and where it is located, on our Sub-processors page.
We may also share data where necessary with professional advisers, or where required by law or to protect our legal rights. We do not sell personal data.
7. Where Your Data Is Stored and International Transfers
Our primary database and file storage are hosted in the United Kingdom (London region), so the core of the personal data we handle does not leave the UK.
A small number of our sub-processors are based outside the UK (for example, our email and error-monitoring providers are in the United States). Where personal data is transferred outside the UK, we put in place a transfer mechanism recognised under UK data protection law — either the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, or we rely on the UK Extension to the EU–US Data Privacy Framework where the provider is certified. Details are on our Sub-processors page.
8. Data Security
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit, encryption at rest by our hosting provider, application-layer encryption of the most sensitive fields, strict role-based access controls, database-level tenant isolation, and immutable audit logging. You can read more on our Security page.
9. How Long We Keep Data
We keep personal data only for as long as necessary. Where we are the controller, we retain account data for the life of the account and for a reasonable period afterwards to meet legal and operational needs. Where we are a processor, care records are retained on the agency's instructions and in line with UK care-sector requirements. Our standard retention periods are:
- Service user care records: 8 years (UK adult social care standard), on agency instruction
- Audit logs: 7 years
- Staff and employment records: 6 years after the end of employment
- Financial and billing records: 6 years
- Communications logs (email/SMS): 2 years
10. Your Rights
Under UK data protection law you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data (subject to legal retention requirements)
- Restrict or object to certain processing
- Data portability — receive your data in a portable format
- Withdraw consent at any time where we rely on consent
To exercise these rights over data we control, contact privacy@babiha.care. For care records, please contact your care agency as the controller (see Section 2).
11. Automated Decision-Making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, and we do not carry out profiling of that kind.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and change the "Last updated" date, and notify you of material changes where appropriate.
13. Complaints
We hope to resolve any concern you raise with us directly. You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator:
- Website: ico.org.uk
- Helpline: 0303 123 1113
14. Contact Us
- General privacy enquiries: privacy@babiha.care
- Data Protection Lead: dpo@babiha.care
- Post: Data Protection, Babiha Care Solutions Limited, 8b Kelvin House, Kelvin Way, Crawley, RH10 9WE