1. Our role
For website enquiries and our own business records, ServPatch acts as data controller. For care record data that customers enter into the ServPatch platform, ServPatch acts as data processor, and the customer organisation is the data controller.
2. Lawful basis
We rely on contract, legitimate interest and legal obligation as our lawful bases, as set out in full in our Privacy Policy. Customers using the platform for care records are responsible for identifying their own lawful basis for processing service-user and staff data, typically a mix of contract, legal obligation and vital interests.
3. Data Processing Agreement
Where ServPatch processes care-record data on a customer's behalf, the applicable processor terms and security information are agreed before that processing begins. Contact [email protected] for the documents currently available for a proposed arrangement.
4. Security measures
Data is encrypted in transit. Access is restricted to authorised care team members, and carer accounts are issued by the care organisation. Contact us if your organisation needs further information about the safeguards currently implemented.
5. International transfers
Details of service providers, locations and transfer safeguards, where applicable, are provided through the contractual information relevant to the customer arrangement.
6. Data subject rights
Individuals can request access, correction, deletion, restriction or portability of their personal data. Where ServPatch is a data processor, requests about care records are usually directed to the relevant care provider as data controller; ServPatch assists as required by the customer agreement and applicable law.
7. Breach notification
Personal-data incidents are handled in line with applicable law and the relevant customer agreement, including customer notification where required.
8. Contact us
Data protection queries can be sent to [email protected].