Legal

Privacy notice

Last updated [date]

Draft for review. Items in [square brackets] must be completed by ZiosCare before publication. Nothing here has been reviewed by a lawyer.

This notice explains what ZiosCare collects when you use the website, the web portal and the mobile app, and how it is used. ZiosCare is operated by [legal entity name], [registered address], [company number].

What we collect

Account information: your name, work email, phone number and role, and the organisation you belong to.

Operational records your organisation enters: service-user records, care plans, communications, rotas, attendance, leave, training and documents. Your organisation controls this data; ZiosCare processes it on your organisation's instructions.

Billing information: subscription status and invoices. Card details are collected by Stripe on its own pages and are never stored by ZiosCare.

Technical information: sign-in times and IP addresses in the audit log, and the device token used for notifications in the mobile app.

How it is used

To provide the service to your organisation, keep records of who did what for safety and accountability, send service emails (invitations, password resets, approvals), process subscriptions and respond to your enquiries.

Contact and demo requests sent through the website are emailed to [contact inbox] and used only to reply to you.

Who we share it with

Stripe (payments), [email provider] (service emails), [hosting provider] (infrastructure). [Confirm each sub-processor and the country where data is stored.]

We do not sell personal data.

Your rights

Depending on where you are, you may have rights to access, correct, delete or restrict the use of your personal data. For data your care organisation has entered, contact that organisation first, as it is the controller of those records. For anything else contact [privacy contact email].

Retention and security

Organisation data is retained while the organisation's account is active and for [period] afterwards. Access is role-based and enforced on the server, sensitive actions are audited, and secrets are encrypted at rest. [Describe backup, breach-notification and data-transfer arrangements once confirmed.]