Privacy Policy
CALMH UK Ltd – Privacy Notice
1 October 2026
Privacy at a glance
CALMH UK Ltd provides supported living and residential care for adults with learning disabilities, autism and complex mental health needs. To do that safely, we need to hold personal information, some of it very sensitive. This notice explains how we handle it.
- We only collect what we need to provide care, answer enquiries, recruit staff and run our business.
- We never sell your information.
- We share information only where we need to, for example with your social worker, the NHS or the local authority that funds your care, or where the law requires it.
- Our website uses cookies. Analytics and advertising cookies are only set if you agree to them.
- You have rights over your information, including the right to see it, correct it and complain. A family member, advocate or legal representative can help you use these rights.
- Questions? Contact our Data Protection Lead at [email protected].
An Easy Read version of this notice is available on request.
1. Who we are
CALMH UK Ltd ("CALMH UK", "we", "us", "our") is the data controller for the personal information described in this notice. This means we decide how and why your information is used, and we are responsible for looking after it.
| Company name | CALMH UK Ltd |
| Registered in | England and Wales |
| Company number | 11651220 |
| Registered address | Unit 6, St. James House, Webberley Lane, Longton, Stoke-on-Trent, ST3 1RJ |
| ICO registration number | ZB592407 |
| Regulated by | Care Quality Commission (CQC) |
| Website | www.calmhuk.com |
CALMH UK Ltd was previously known as Ignite Nursing Ltd. If you received care or contacted us under that name, this notice applies to your information too.
Contacting our Data Protection Lead
Our Data Protection Lead oversees how we handle personal information and is your first point of contact for any privacy question or request.
- Email: [email protected] (please put "Data Protection" in the subject line)
- Post: Data Protection Lead, CALMH UK Ltd, Unit 6, St. James House, Webberley Lane, Longton, Stoke-on-Trent, ST3 1RJ
We follow the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025, the Privacy and Electronic Communications Regulations 2003 (PECR), and the health and social care laws that apply to us.
2. Who this notice covers
This notice applies to anyone whose personal information we handle, including:
- People we support: current, former and prospective residents and tenants of our residential and supported living services.
- Families and representatives: next of kin, advocates, and people with legal authority to act for someone, such as an attorney under a Lasting Power of Attorney or a Court of Protection deputy.
- Professionals who refer to us: social workers, care coordinators, brokerage officers, and NHS and hospital staff.
- Commissioners and partners: local authority and NHS commissioners, and other organisations we work with.
- Job applicants: people who apply for a role through our careers page or contact us about working with us.
- Property partners: landlords, investors and housing providers who contact us about property.
- Website visitors: anyone who uses our website or fills in one of its forms.
- Anyone else who contacts us by phone, email, social media or in person.
Our current employees have a separate staff privacy notice, available on request.
3. What information we collect
What we collect depends on your relationship with us. Information marked † is "special category" or criminal offence data, which the law treats as more sensitive (see section 6).
| Who | Information we may collect |
|---|---|
| People we support | Name, date of birth, address, contact details, NHS number, GP and next of kin details. Care and support plans, risk assessments, daily care records and observations, and medication records†. Physical and mental health information, diagnoses, discharge summaries and reasonable adjustment needs†. Mental Capacity Act assessments, best interests decisions, Deprivation of Liberty Safeguards (DoLS) or Liberty Protection Safeguards authorisations, Court of Protection and other court orders. Safeguarding information†. Forensic history, offending-related risk information and Mental Health Act or MAPPA information, where relevant to safe placement†. Ethnicity, religion, sexual orientation and gender identity, where you choose to share them or where needed for your care†. Funding, invoicing and payment details. |
| Families and representatives | Name, relationship to the person we support, contact details, and evidence of legal authority (for example a Lasting Power of Attorney or deputyship order). |
| Referrers, commissioners and professionals | Name, job title, organisation, work contact details, and records of our communications. Through a referral, you also give us information about the person being referred (see the first row). |
| Job applicants | Name, contact details, CV, employment history, qualifications and training, references, right-to-work documents, driving licence (where the role needs it), and interview notes. Information about health and reasonable adjustments†. Equality monitoring information, which is optional†. Disclosure and Barring Service (DBS) check results, for successful applicants†. |
| Property partners | Name, email address, telephone number and the area you want to invest in or provide property in. |
| Website visitors | IP address, device and browser type, pages visited, time on site and how you reached us. This is collected through cookies and similar technologies (see section 7). Anything you enter into our contact, callback, referral or careers forms. |
| Anyone who contacts us | Your messages, emails, social media messages, complaints and feedback. Recordings of calls to our main phone lines (see section 8). |
4. Where we get your information
Most information comes directly from you. We may also receive it from:
- your family, advocate or legal representative;
- local authorities, commissioners and brokerage teams that refer or fund your care;
- NHS bodies, hospitals, Assessment and Treatment Units, GPs, community mental health teams and other professionals involved in your care;
- courts, the Court of Protection, the police, probation services and MAPPA, where relevant and lawful;
- previous care providers, when your care moves to us;
- referees, previous employers and the Disclosure and Barring Service (for job applicants);
- our website, through forms and cookies; and
- social media platforms (Facebook, LinkedIn, X and TikTok), when you interact with our pages.
If you refer someone to us: please only share what we need to assess the referral. Make sure you have a lawful basis to share it, and tell the person (or their representative) that you are referring them to CALMH UK, unless doing so would put them or others at risk.
5. How we use your information and our lawful basis
The law says we must have a valid reason, called a "lawful basis", for each way we use personal information. The ones we rely on are:
- Contract: we need it to deliver a contract with you, or to take steps you ask for before entering one.
- Legal obligation: the law requires it, for example the Health and Social Care Act 2008, the Care Act 2014 or the Mental Capacity Act 2005.
- Legitimate interests: it is necessary for our reasonable business interests, and we have checked that those interests are not outweighed by your rights.
- Recognised legitimate interests: specific purposes the Data (Use and Access) Act 2025 recognises, such as safeguarding vulnerable people, responding to emergencies, and helping public bodies carry out their functions.
- Vital interests: it is needed to protect someone's life.
- Consent: you have agreed. You can withdraw consent at any time.
| What we use it for | Lawful basis |
|---|---|
| Assessing referrals and planning whether we can meet someone's needs | Legitimate interests; contract (where you arrange your own care) |
| Providing care and support, including care plans, risk assessments and care records | Contract (where you fund or arrange your own care); legitimate interests (where a local authority or the NHS commissions your care); legal obligation |
| Meeting CQC requirements, reporting notifiable incidents and monitoring quality | Legal obligation |
| Complying with the Mental Capacity Act, DoLS and court orders | Legal obligation |
| Safeguarding people from abuse or neglect, and sharing information in an emergency | Legal obligation; recognised legitimate interests; vital interests |
| Speaking to relatives or friends who have no legal authority to act for you | Consent (or best interests, where you lack capacity to decide) |
| Invoicing, taking payments and keeping financial records | Contract; legal obligation |
| Answering enquiries, callback requests and messages | Legitimate interests |
| Handling complaints and feedback | Legal obligation; legitimate interests |
| Recruiting staff: shortlisting, interviews, references and right-to-work checks | Steps before entering a contract; legal obligation |
| DBS checks for roles involving regulated activity | Legal obligation |
| Equality monitoring of applicants (optional) | Legitimate interests (only in a form that cannot identify you when we report on it) |
| Responding to property partners | Legitimate interests |
| Recording calls to our main phone lines | Legitimate interests |
| Protecting our website forms from spam and abuse (reCAPTCHA) | Legitimate interests |
| Website analytics and advertising cookies | Consent |
| Sending newsletters | Consent; legitimate interests for professional contacts at organisations we work with, who can opt out at any time |
| Publishing stories and testimonials | Consent |
| Bringing or defending legal claims | Legitimate interests |
Where we rely on legitimate interests, you can ask us how we balanced our interests against yours.
6. Health, social care and criminal offence information
To provide safe care we need to use special category data, such as health information, and sometimes criminal offence data. The law sets extra conditions for this, on top of the lawful bases in section 5.
| Why we use it | Condition we rely on |
|---|---|
| Providing health and social care, and managing care services | UK GDPR Article 9(2)(h); Data Protection Act 2018, Schedule 1, paragraph 2 (health or social care purposes) |
| Safeguarding adults at risk | Article 9(2)(g); Schedule 1, paragraph 18 (safeguarding of children and individuals at risk) |
| Protecting someone's life where they cannot consent | Article 9(2)(c) (vital interests) |
| Recruitment, employment checks and reasonable adjustments | Article 9(2)(b); Schedule 1, paragraph 1 (employment and social security) |
| Equality monitoring of applicants | Article 9(2)(g); Schedule 1, paragraph 8 (equality of opportunity or treatment) |
| Publishing stories that include health information | Article 9(2)(a) (explicit consent) |
| Bringing or defending legal claims | Article 9(2)(f) |
Criminal offence data. Some placements, particularly step-down from hospital or an Assessment and Treatment Unit, need us to know about past offending, court orders or MAPPA arrangements, so we can plan care and manage risk safely. We also carry out DBS checks on staff. We use this information under UK GDPR Article 10 and Data Protection Act 2018, section 10(5), relying on Schedule 1, paragraphs 1 (employment), 2 (health or social care), 18 (safeguarding) and 33 (legal claims).
Access to this information is limited to staff who need it for their role. Where we rely on a Schedule 1 condition that requires one, we keep an Appropriate Policy Document explaining how we protect this data.
7. Our website and cookies
We build and host our own website. Like most websites, our servers automatically record basic technical information when you visit, such as your IP address, browser type and the pages you request. We use this to keep the site secure and working.
Website forms
Our contact, callback, referral and careers forms send the information you enter to a secure CALMH UK email inbox. Only authorised staff can access it. Referral forms can contain health information, so please share only what is needed for an initial assessment. We will ask for more detail securely if the referral moves forward.
What cookies are
Cookies are small text files that a website saves on your device. Some are essential for the site to work. Others help us understand how the site is used, or let us measure our advertising.
How we ask for your consent
When you first visit our website, a cookie banner lets you accept or reject non-essential cookies. Analytics and advertising cookies are only set if you choose to accept them. You can change your choice at any time using the "Cookie settings" link at the bottom of every page.
Cookies we use
| Cookie | Provider | Type | Purpose | How long it lasts |
|---|---|---|---|---|
| Cookie consent cookie | CALMH UK (cookie banner tool) | Strictly necessary | Remembers your cookie choices | 12 months |
| _GRECAPTCHA | Google reCAPTCHA | Strictly necessary (security) | Protects our forms from spam and automated abuse | 6 months |
| _ga | Google Analytics | Analytics (consent) | Distinguishes visitors so we can count visits | 2 years |
| ga[ID] | Google Analytics | Analytics (consent) | Keeps track of your visit session | 2 years |
| _fbp | Meta (Facebook) Pixel | Advertising (consent) | Measures how well our Facebook and Instagram adverts work, and shows our adverts to people who have visited our site | 3 months |
| _fbc | Meta (Facebook) Pixel | Advertising (consent) | Records that you arrived from one of our Meta adverts | 3 months |
Google Analytics tells us how many people visit our site, which pages they view and how they found us. We have set it up so that Google does not use the data for its own advertising.
Google reCAPTCHA checks that forms are being filled in by a person, not an automated program. To do this, it sends information about your device and how you use the page to Google. Google's use of this information is covered by the Google Privacy Policy and Terms of Service.
Meta Pixel lets us measure our adverts on Facebook and Instagram and show them to people who have visited our website. Meta may combine this with information it already holds about you, under the Meta Privacy Policy.
Managing cookies
You can also block or delete cookies in your browser settings. Blocking strictly necessary cookies may stop parts of our website, such as the forms, from working. You can opt out of Google Analytics on all websites with the Google Analytics opt-out add-on.
Links to other websites
Our website may link to other websites, including our social media pages. We are not responsible for how those sites handle your information, so please read their privacy notices.
8. Call recording
We record calls to and from our main phone lines. A recorded message tells you this at the start of the call. We use recordings to:
- keep an accurate record of referrals, concerns and instructions;
- support safeguarding and investigate incidents or complaints;
- train staff and check the quality of our service; and
- protect our staff and the people we support.
Only authorised staff can listen to recordings. We keep them for 6 months, unless we need one for longer to deal with a safeguarding concern, complaint, incident or legal claim. If you would prefer not to be recorded, tell us at the start of the call and we can arrange another way to talk, such as email.
9. Newsletters and marketing
We send newsletters and service updates by email to families, people we support, commissioners and professional partners.
- Individuals and families only receive newsletters if they have signed up or agreed to them.
- Professional contacts at local authorities, the NHS and other organisations may receive updates relevant to their role. Every email lets you unsubscribe.
We use Mailchimp (operated by Intuit Inc.) to send newsletters. Mailchimp tells us whether an email was opened and which links were clicked, so we can improve what we send. Mailchimp stores data in the United States (see section 12).
You can unsubscribe at any time using the link in any email, or by emailing [email protected]. When you unsubscribe, we keep your email address on a "do not contact" list so we don't email you again by mistake. Unsubscribing does not affect messages we need to send you about your care or an ongoing enquiry.
We never sell or rent your details to other organisations for their marketing.
10. Stories and testimonials
The stories on our website are about real people we support. We only publish a story when the person has given signed consent. Where it helps, we support them to make that decision, for example with Easy Read materials or an advocate. We agree with each person what is shared, including whether their real name or photograph is used.
People can withdraw consent at any time by contacting us. We will then remove their story from our website and social media as soon as possible, and within 30 days at most. We cannot recall printed materials that have already been handed out, or copies that others have made.
11. Who we share information with
We only share what is necessary for the purpose, and we never sell personal information.
Organisations involved in care, regulation and safeguarding
Where necessary and lawful, we share information with:
- local authorities, commissioners and funding bodies;
- NHS organisations, GPs, hospitals and other health professionals involved in your care;
- social workers, care coordinators and multidisciplinary teams;
- the Care Quality Commission (CQC);
- safeguarding teams and Safeguarding Adults Boards;
- the police, probation services and MAPPA, where the law requires or allows it;
- courts, tribunals and the Court of Protection;
- the Disclosure and Barring Service (for recruitment); and
- other care providers, if your care moves to them.
Suppliers who work for us
We use trusted suppliers to run our services. They can only use your information on our instructions, under a written contract, and must keep it secure. They include providers of:
- electronic care records and care management systems;
- email, document storage and office software;
- customer support and ticketing systems;
- telephone and call-recording services;
- finance, invoicing and payment collection;
- email newsletters;
- website analytics, security and cookie consent tools;
- IT support, backup and cyber security;
- administrative and operational support, including our back-office team in Kenya (see section 12); and
- professional advisers, such as lawyers, auditors, insurers and data protection consultants.
Other situations
We may also share information:
- with your consent, or with someone who has legal authority to act for you;
- to protect someone's life, health or safety;
- to bring or defend legal claims;
- where the law, a court order or a regulator requires it; or
- if our business is restructured, sold or merged, with the new owner, who must protect the information in the same way.
12. International transfers
Most of your information is stored in the UK. Some is accessed or stored in other countries. When this happens, the law requires protections that keep your information to the same standard as in the UK.
| Where | Why | How it is protected |
|---|---|---|
| Kenya | Our back-office team gives us administrative and operational support | International Data Transfer Agreement (IDTA) approved by the UK Information Commissioner. The team acts only on our documented instructions and sees only the information it needs for each task. |
| United States | Website analytics and security (Google), advertising measurement (Meta) and newsletters (Mailchimp) | The UK Extension to the EU–US Data Privacy Framework (the “UK–US data bridge”), or the UK International Data Transfer Addendum where a supplier is not certified |
| European Economic Area | Some IT and software suppliers store data there | UK adequacy regulations, which recognise that these countries protect data to UK standards |
To find out more about these protections, or to request a copy of the relevant safeguards, contact our Data Protection Lead.
13. Artificial intelligence tools
We use business AI tools to help with administrative work, such as drafting documents and summarising information. We do not use AI to make decisions about your care, a referral or a job application. A member of staff always reviews the output and makes the decision.
We only use AI tools under business agreements that stop the provider from using our data to train its models. We do not enter health or other sensitive information into an AI tool unless we have assessed the risks and put suitable safeguards in place.
14. How we keep information secure
We use technical and organisational measures to protect personal information from loss, misuse and unauthorised access, including:
- role-based access, so staff only see what they need for their job;
- multi-factor authentication and strong password controls on our systems;
- encryption of devices and of data in transit;
- secure, access-controlled electronic care records;
- data protection and confidentiality training for all staff, refreshed regularly;
- confidentiality clauses in staff and supplier contracts;
- checks on suppliers before we use them;
- secure disposal of paper and electronic records; and
- a procedure for reporting and managing data breaches, including notifying the ICO and affected people where the law requires it.
Email is not always secure. Please do not send detailed health information through our website forms or by ordinary email unless we have asked you to.
15. How long we keep information
We keep information only as long as we need it. Our retention periods follow the Records Management Code of Practice for Health and Social Care 2021 and other legal requirements. When a retention period ends, we securely delete or destroy the information, or make it fully anonymous.
| Information | How long we keep it |
|---|---|
| Care records of people we support, including care plans, risk assessments and daily notes | 8 years after care ends, or 8 years after death |
| Safeguarding records, incident records and records linked to court orders | With the care record, and longer if an investigation, inquiry or legal case needs them |
| Referrals that do not lead to a placement | 2 years from the referral decision |
| Complaints | 10 years after the complaint is closed |
| Invoices, payments and financial records | 6 years after the end of the financial year they relate to |
| Enquiries and callback requests | 2 years from our last contact |
| Unsuccessful job applications | 6 months after the recruitment decision |
| Successful applications | Moved to the staff file and kept under our staff privacy notice |
| DBS certificate information | No longer than 6 months after the recruitment decision. We keep a record of the date, certificate number and outcome on the staff file. |
| Property partner contact details | 2 years from our last contact, unless we enter into an agreement |
| Call recordings | 6 months, unless needed for a safeguarding concern, complaint, incident or legal claim |
| Newsletter subscriber details | Until you unsubscribe. After that we keep only your email address on a “do not contact” list. |
| Stories and consent forms | While the story is published, then 2 years after it is removed |
| Google Analytics data | 14 months |
| Website server logs | 90 days |
We may keep information longer if the law requires it, if a regulator or court asks us to, or if it is needed for a legal claim.
16. Your rights
You have the right to:
- be informed about how we use your information (this notice);
- access your information and get a copy of it (a “subject access request”);
- correct information that is wrong or incomplete;
- have information deleted in some circumstances. We cannot delete care records we are required by law to keep;
- restrict how we use your information in some circumstances;
- object to us using your information on the basis of legitimate interests, and to any direct marketing at any time;
- data portability: get information you gave us in a format you can pass to another organisation, where we use it on the basis of consent or contract;
- withdraw consent at any time, where we rely on consent. This does not affect anything we did before you withdrew it;
- not be subject to decisions made only by automated means that have significant effects on you (see section 17); and
- complain to us and to the Information Commissioner's Office (see section 18).
How to make a request
You can make a request in writing, by email or verbally to any member of staff. You don't need to use a form or particular words, but sending your request to [email protected] will help us deal with it quickly.
- It is free. We may only charge a reasonable fee, or refuse, if a request is clearly unfounded or excessive.
- We will reply within one month. If your request is complex, or you make several, we may extend this by up to two more months and will tell you why.
- We may need to check your identity before we release information. The one-month period starts once we have what we need.
- We will carry out reasonable and proportionate searches for your information.
- We may withhold some information where the law allows. For example, if releasing it would cause serious harm to your or someone else's physical or mental health, or would reveal information about another person without their agreement. A health professional may need to review health information first.
Making a request on someone else's behalf
Many people we support have help from family, advocates or legal representatives. Someone can make a request or use these rights for another person if they:
- have the person's written permission;
- hold a registered Lasting Power of Attorney (a Health and Welfare LPA for care records, or a Property and Financial Affairs LPA for financial records);
- are a deputy appointed by the Court of Protection with the relevant authority; or
- are acting as an Independent Mental Capacity Advocate or Relevant Person's Representative, within the limits of that role.
We will ask to see evidence of authority. If the person has capacity, we will check with them first. If they lack capacity, we will make sure the request is in their best interests under the Mental Capacity Act 2005.
Records of someone who has died. Data protection law does not cover people who have died. A personal representative, or someone with a claim arising from the death, can request access to care records under the Access to Health Records Act 1990.
17. Automated decisions and age
Automated decisions. We do not make decisions about you by automated means alone, including profiling, that have legal or similarly significant effects. Decisions about referrals, care and recruitment are always made by people. Google reCAPTCHA automatically filters suspected spam from our forms. If you have trouble submitting a form, contact us by phone or email instead.
Age. We only provide services to adults aged 18 and over. Our website is not aimed at children, and we do not knowingly collect information from anyone under 18 through it.
18. Complaints
If you are unhappy with how we have handled your personal information, please tell us first so we can try to put it right. Contact our Data Protection Lead at [email protected].
Under the Data (Use and Access) Act 2025, you have the right to complain to us directly. We will acknowledge your complaint within 30 days, look into it without undue delay, and tell you the outcome.
If you are still not satisfied, you can complain to the Information Commissioner's Office (ICO):
- Website: ico.org.uk/make-a-complaint
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Complaints about the care you receive, rather than about your information, are handled under our care complaints procedure, which is available on request.
19. Changes to this notice
We review this notice at least once a year, and sooner if the law or the way we work changes. The latest version is always on our website. If we make significant changes that affect people we support, we will tell them directly.
| Version | Date | Changes |
|---|---|---|
| 1.0 | July 2026 | First version, published as Ignite Nursing Ltd |
| 2.0 | October 2026 | Rebranded to CALMH UK Ltd. Covers all groups the website serves, and adds cookies, call recording, newsletters, stories, AI, retention periods and rights requests made on someone's behalf. |
Next review due: October 2027