Data protection

Clear responsibilities, one control centre.

CoreCare publishes one set of customer-facing documents for the suite. The Owner Platform coordinates privacy cases and breach records, while each product keeps the operational evidence relevant to that service.

Compliance library reviewed 5 August 2026

01

Privacy notice

How CoreCare uses personal information when it acts as controller or processor.

Open resource
02

Data processing agreement

The UK GDPR Article 28 terms and processing schedule for customer product data.

Open resource
03

Customer terms

The service terms that apply when they are incorporated into a customer order.

Open resource
04

Retention policy

Default review periods, deletion approach, legal holds and customer-controlled retention.

Open resource
05

Your data rights

The tracked route for access, correction, erasure and other privacy requests.

Open resource
06

Security

Current technical and organisational safeguards and responsible disclosure.

Open resource
07

Cookie notice

The essential cookies and service events used by the website and products.

Open resource
08

Subprocessors

The suppliers used to deliver and protect CoreCare services.

Open resource

Controller and processor roles

The role follows the data.

CoreCare is controller for its own website, sales, account, security and business administration information. A subscribing organisation is normally controller for the records it enters into a CoreCare product, and CoreCare acts as its processor under the data processing agreement.

Questions and evidence

Ask for what you need.

Customers can request the current control statement, processing schedule, subprocessor information and assistance with a rights request or data incident from privacy@corecaresystems.co.uk.