top of page

Asisters Care app - privacy notice
Effective date: 9 September 2026.
Who we are
Asisters Ltd, a company registered in the United Kingdom under number 10729228, registered office 1 Bottom Pond Cottage, Morestead, Winchester, Hampshire SO21 1AJ.
Office: 51-53 The Main Rd, Colden Common, Winchester SO21 1RP Email: support@asisters.co.uk | Telephone: 01962 777 055
What this notice covers
The Asisters Care app on your phone or tablet, and the information that moves between the app and our systems when you use it. It does not cover our website, which has its own policy and cookie policy, and it does not cover your employment records generally except where the app shows them.
What the app collects, and when
Your account and profile. Your name, work email address and telephone number, so we can identify you and contact you about work. You may optionally choose a photo from your device as a profile picture  -  the app asks for photo access only at that point, and only for a photo you pick. It never opens the camera.
Your work schedule and visits. The visits assigned to you, when and where they are, and the records you make about them.
Pay and drawdown requests. The app shows your recorded earnings and drawdown history. If you ask the office for an advance against your pay, we record the amount, the status of the request and the office’s decision. We use these records to administer your pay and any agreed deductions.
Care records about the people you visit. The app shows care information about the people you visit and records the visit notes and other care information you submit. These records can contain health information. Access is limited to your authorised work and the office staff responsible for the service. Use these records only for providing and recording care.
When you clock in and out. The time you tap to start and end a visit.
Your location  -  at clock-in and at clock-out. When you clock in, and again when you clock out, the app asks your device for its position and sends it with that arrival or departure. We use it to record where the clock-in or clock-out happened and how far that was from the address of the visit. Your position is therefore recorded twice per visit.
This is worth being precise about, because "a care app that requests precise location" sounds worse than what actually happens:
- It is captured only at those two taps, never continuously and never in the background. The app holds no background location permission. - It gives up after 8 seconds. If your device cannot get a position quickly  -  no signal, permission declined, airplane mode  -  the clock-in or clock-out proceeds without any location. It is never blocked and you are never warned. - Declining the location permission does not stop you working. The record is made from the time you tapped; the position is additional evidence, not the evidence itself. - The app also uses your position while it is open to show you on the visit map and estimate travel time. That happens on your device while you are looking at the map.
Your contact details and date of birth. During onboarding you give your home address, town, county, postcode, mobile number and date of birth.
Tax and insurance details. You submit your Unique Taxpayer Reference, and your insurance cover type, provider, confirmation reference and expiry date. The app does not collect your bank account number or your National Insurance number.
Documents you upload. You can attach PDF, PNG or JPEG files up to 10 MB from your device  -  for example certificates, insurance documents or identity evidence. Uploads are held aside and scanned for malware before they become available. The app requests no file permission: your device's file picker hands over only the file you choose.
Training and compliance. Your training records, certificates and expiry dates, where the app shows them.
What the app does not do
Stated because a generic privacy notice would claim otherwise, and none of it is true here:
- No advertising and no tracking. Nothing in the app is used for advertising, profiling or building a picture of you, and nothing is sold or shared for those purposes. - No background location. See above. - No bank details. The app never asks for a bank account number or a National Insurance number. - No session recording. We do not record or replay your screen. - No cookies in the app.
Diagnostics when something breaks
We use Sentry (Functional Software, Inc.), on servers in the European Union (Germany), to monitor errors, crashes and app performance, including app starts, screen navigation and interaction timings. This helps us find and fix technical problems. We do not use these records for advertising or marketing analytics. We do not record or replay your screen. These diagnostic records can be linked to your internal account reference.
What is deliberately not in them: your name, your email address, or your IP address. The app replaces the IP with 0.0.0.0 before an event leaves your device, and turns off Sentry's "default personal information" collection. Screen recording and session replay are off. The report is labelled with your internal account reference  -  an opaque identifier, not your name  -  and the name of your organisation, so repeated failures affecting one person can be traced and fixed.
One honest caveat. If the app crashes at the deepest level  -  a native crash rather than an in-app error  -  the report is assembled by the operating-system-level crash handler and is not filtered by the checks described above. Such a report can contain fragments of whatever the app held in memory at that moment. We keep native crash reporting switched on because a crash that cannot report itself is a crash we cannot fix, but it is a real trade-off and you should know it.
Notifications
If you allow notifications, your device is issued a push token which we store so we can send you alerts about your work.
Notifications are delivered through the Expo push service (650 Industries, Inc., United States) and from there through Apple or Google's notification services, also in the United States. Carer notifications carry meaningful text  -  for example a new shift offer, or confirmation naming how many visits and when the first one is  -  so that content passes through those services. Turning notifications off in your device settings stops this.
Maps and directions
When you tap Directions for a visit, the app hands the destination to your phone's maps application  -  Apple Maps or Google Maps. That destination is the address of the person you are visiting, so their address is disclosed to whichever maps provider your phone uses, under that provider's own privacy policy.
Who processes your information
- Asisters Ltd  -  the care provider, and the organisation responsible for your information. - CleverTech B.V. (Netherlands)  -  operates the Asisters platform on our behalf, under a data processing agreement. - Sentry (EU/Germany)  -  error and crash diagnostics, as described above. - Expo, Apple and Google (United States)  -  delivery of push notifications, as described above. - Amazon Web Services (London)  -  hosting.
Where your information is held
Our systems and your records are hosted in the United Kingdom (AWS London). Backups stay in the United Kingdom. Diagnostic reports go to Germany. Push notifications pass through the United States.
How long we keep it
Different kinds of record are kept for different periods. What we can state today:
- The audit trail is permanent. Every action taken in the system is recorded once and never altered or deleted. This is deliberate  -  a care record you cannot audit is a care record you cannot trust  -  but it means a record that you did something persists even after other data about you is removed. - Records of who viewed identifying information are kept for 13 months, then deleted automatically. - Staff sign-in sessions are cleared 90 days after they end. - Care records and care documents are kept for as long as our regulatory and legal obligations require. They currently have no automatic expiry.
Your rights
You can ask us for a copy of the information we hold about you, to correct it if it is wrong, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Some of these rights are limited where we must keep records by law  -  care records in particular.
Being straight about deletion. Closing your account in the app deactivates it: you can no longer sign in, and the office can reactivate it. It does not delete your information, and the app's own wording says so. Records of care you delivered are kept because we are required to keep them. If you want your personal information erased, contact us and we will tell you what can be removed and what must be retained, and why.
To exercise any of these rights, contact support@asisters.co.uk. You can also complain to the Information Commissioner's Office at ico.org.uk.
Changes
If we change this notice we will update the date below and, where the change is significant, tell you in the app.
Still being confirmed
This notice is being finalised. The following points are being confirmed, and this page will be updated when they are:
- ICO registration number.
- Whether a Data Protection Officer is appointed and, if so, their contact details.
- Confirm Asisters Ltd is the controller for app data  -  the existing Data Protection Policy names Asisters Ltd as the company but predates the app.
- Your background check. You submit your DBS certificate number, and the app shows your DBS status and its expiry date. Information about criminal convictions and offences has its own protection under UK data protection law, separate from health information.
- Confirm the lawful basis and the Schedule 1 condition relied on for this.
- Your referees. You give the names, email addresses and roles of your referees. Those people are not users of this app and did not give us their details themselves, so please tell them you have shared them.
- Confirm how referees are informed, as UK data protection law requires.
- Confirm the lawful basis and Article 9 condition relied on.
- The microphone. The app declares a microphone permission for recording "a short message for transcription". Confirm whether that feature is switched on for carers in the live app; if it is not, the permission should be removed from the build rather than described here, because a declared permission with no live feature is both a store-review problem and a promise we do not keep. If it is on, this notice must say where recordings go and how long they are kept.
- Sentry's retention period, its server-side scrubbing rules, and who inside the organisation can read these reports. These are recorded as unverified release prerequisites.
- Whether the in-app visit map is rendered using Google's mapping service in the released build; if it is, Google must be named here as receiving that location.
- Confirm this list is complete and that each has a current processing agreement.
- Confirm the safeguards relied on for the United States transfer.
- Confirm the statutory retention periods for care records and employment records, and state them here. This section is incomplete until they are.
Last updated 9 September 2026.

bottom of page