HayatCMS Privacy Policy
At HayatCMS, we respect your privacy and are committed to protecting your data. This Privacy Policy outlines how HayatCMS, as a modern Care Management System, handles, processes, and protects your information in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and NHS data security standards.
Please read this policy carefully to understand our practices regarding your information.
1. Information We Collect & Special Category Data
To deliver our care management services, handle scheduling, and manage user accounts, we collect two categories of information:
Standard Personal Data: Account details such as user names, professional email addresses, system login information, and corporate business configurations.
Special Category Data (Health & Medical Records): Because HayatCMS acts as a Digital Social Care Record platform, our clients upload highly sensitive data, including patient medical histories, care plans, digital MAR charts (medication administration), clinical notes, and vulnerability risk assessments.
Lawful Basis for Processing
For Standard Data, our legal basis is the Performance of a Contract (UK GDPR Article 6(1)(b)) to provide you with the HayatCMS service.
For Special Category Data, we act strictly as a Data Processor on behalf of our clients (the Data Controllers). The legal basis relies on UK GDPR Article 9(2)(h) (Health or Social Care Provision). We process this data strictly under the written instructions of our clients via executed Data Processing Agreements (DPAs).
2. Location Usage and Shift Monitoring
The HayatCare and HayatCareClient mobile applications require background location access.
Purpose: This access is used strictly to track employee mileage, monitor lone-worker safety routes during active shifts, and verify electronic care delivery timestamps at the service user’s address.
Lawful Basis: The lawful basis is our Legitimate Interest (UK GDPR Article 6(1)(f)) in ensuring employee accountability, contract fulfillment, and workplace safety.
Control: Background location tracking occurs only during scheduled work shifts. Users can manage or toggle location permissions at any time via their mobile operating system settings. This location data is never shared with third parties.
3. Data Infrastructure, Security, and Encryption
We take your data security seriously and employ a “Privacy by Design” architecture to protect sensitive health data:
Application-Layer Encryption: All stored patient data and text records are heavily encrypted at rest using industry-standard AES-256 application-layer encryption. This ensure that even in a backup format, the data remains unreadable.
Network Security: Data is fully encrypted in transit between user devices and our servers using Secure Socket Layer (SSL/TLS) protocols.
Sovereign Infrastructure & Data Residency: HayatCMS hosts all client data on secure, ISO/IEC 27001-certified bare-metal server infrastructure located strictly within the European Union (Germany via Hetzner Online).
Client Isolation: Each client operates on a fully isolated multi-instance architecture. Your data, code instances, and databases are strictly ring-fenced and never commingled with other clients. No data is transferred to jurisdictions outside the UK/EEA without valid legal adequacy mechanisms.
4. Data Sharing and Third Parties
We do not sell, rent, or monetize your personal or clinical data under any circumstances. We only share information under the following strict conditions:
Legal Requirements: If mandated by UK law, government regulations, or valid law enforcement orders, we will disclose only the minimum data legally required.
Sub-Processors: We only use infrastructure partners (such as ISO-certified hosting providers) who have signed legally binding Data Processing Agreements (DPAs) matching our UK GDPR obligations.
5. Your Rights and Data Portability
Under the UK GDPR, system users and data subjects have comprehensive rights regarding their information:
Right to Access & Portability: You have the right to request a complete copy of the data we hold about you. Our platform provides tools to export care records into structured, machine-readable formats (such as JSON or CSV).
Right to Rectification: You can directly update or correct inaccurate profile details inside the application configuration panel.
Right to Erasure (The Right to be Forgotten): You may request the deletion of your account and related information. Please note that clinical care logs may be subject to statutory medical retention periods defined by UK health authorities, which supersede standard deletion requests.
To exercise any of these rights, please email our support team at info@hayatcms.co.uk.
6. Data Retention
We retain your information as long as your corporate client account is active. If an account is closed or terminated, data is securely securely scrubbed from live databases and purged from historical, encrypted system backups in line with our internal 30-day backup retention cycles.
7. Regulatory Contact and Complaints
If you have any questions or feel your data privacy rights have been infringed, please contact us:
Email: info@hayatcms.co.uk
Regulatory Body: You have the legal right to lodge a formal complaint at any time with the UK supervisory authority:
The Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: www.ico.org.uk