Privacy notice
How CoreCare uses personal information when it acts as controller or processor.
Open resourceData protection
CoreCare publishes one set of customer-facing documents for the suite. The Owner Platform coordinates privacy cases and breach records, while each product keeps the operational evidence relevant to that service.
Compliance library reviewed 5 August 2026
How CoreCare uses personal information when it acts as controller or processor.
Open resourceThe UK GDPR Article 28 terms and processing schedule for customer product data.
Open resourceThe service terms that apply when they are incorporated into a customer order.
Open resourceDefault review periods, deletion approach, legal holds and customer-controlled retention.
Open resourceThe tracked route for access, correction, erasure and other privacy requests.
Open resourceCurrent technical and organisational safeguards and responsible disclosure.
Open resourceThe essential cookies and service events used by the website and products.
Open resourceThe suppliers used to deliver and protect CoreCare services.
Open resourceController and processor roles
CoreCare is controller for its own website, sales, account, security and business administration information. A subscribing organisation is normally controller for the records it enters into a CoreCare product, and CoreCare acts as its processor under the data processing agreement.
Questions and evidence
Customers can request the current control statement, processing schedule, subprocessor information and assistance with a rights request or data incident from privacy@corecaresystems.co.uk.