top of page

Privacy Policy

 

 

Introduction

TP Care at Homes Ltd ("TP Care", "we", "us") is committed to protecting the privacy, dignity and personal data of our clients, their families, our staff and other stakeholders, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Human Rights Act 1998, and the guidance issued by the Information Commissioner's Office (ICO), the UK's independent regulator for data protection and information rights.

Privacy and dignity, not just data

Beyond data protection law, every client has a fundamental right to privacy, dignity and freedom from unwarranted intrusion in their own home — a right reinforced by Regulation 10 (Dignity and Respect) of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014. This extends to how we handle personal information: information about a client is only shared with their consent, or — where a client lacks the mental capacity to consent — where sharing is judged to be in their best interests in line with the Mental Capacity Act 2005.

What personal data we collect

We collect personal data necessary to respond to enquiries and, for clients, to plan and deliver safe, person-centred care. This may include contact details and next-of-kin information, and, with consent, special category data such as health information (as defined under Article 9 UK GDPR), which we handle with additional safeguards given its sensitivity.

Our lawful basis for processing

We process personal data on one or more lawful bases under Article 6 UK GDPR: consent; performance of a contract, in delivering the care service you have engaged us for; compliance with a legal obligation, such as our duties as a CQC-regulated provider; and legitimate interests, exercised in a way that does not override your rights and freedoms. Where we process special category (health) data, we rely on Article 9(2)(h) — the provision of health or social care — subject to duties of confidentiality equivalent to those in professional codes of conduct.

How we share information

Information is shared only where necessary for safe care delivery or where legally required — for example with GPs, district nurses or other professionals directly involved in your care, or with the Care Quality Commission, local authorities or NHS bodies where we have a legal or contractual duty to do so. We do not sell personal data, and staff handling client information are trained in confidentiality as part of induction and ongoing supervision.

How we keep information secure

Our information governance is built around the NHS Digital Data Security and Protection Toolkit (DSPT), the sector framework used to verify that a health or social care provider's data handling meets NHS-approved standards; TP Care at Homes currently holds Standards Met, the toolkit's highest self-assessment tier. Any suspected breach of privacy is treated as a serious event, fully investigated, and, where required, reported to the appropriate regulatory body without undue delay, in line with our obligations under UK GDPR.

How long we keep it

We retain personal data only for as long as necessary to provide care, meet our regulatory obligations as a CQC-registered provider, and satisfy statutory retention periods that apply to health and social care records, after which it is securely destroyed.

Your rights

Under UK GDPR, you have the right to: request access to the personal data we hold about you; request that inaccurate data be corrected; request erasure of your data, subject to our overriding legal and regulatory retention obligations; restrict or object to certain processing; and request data portability where technically applicable. To exercise any of these rights, please contact us using the details on our Contact page.

Raising a concern

If you have a concern about how your information has been handled, please contact us directly in the first instance. If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk), the UK's supervisory authority for data protection.

bottom of page