Privacy notice
How we use your information.
This notice explains what CoreCare collects, why it is used, who receives it, how long it is kept and how to exercise your rights.
Version 2.0 · 5 August 2026
Who we are
Christopher Anthony Warman, trading as CoreCare Systems (“CoreCare”, “we”, “us”) is the controller for personal information used to run this website, answer enquiries, manage trials, administer customers, protect accounts and operate the business. Our trading address is Red Lion, Fen Road, East Kirkby, Spilsby, PE23 4DB, United Kingdom. Contact privacy@corecaresystems.co.uk or telephone 07983 408588. CoreCare has no company number and is not VAT registered. An ICO registration application has been submitted under application reference C1999522; the public register entry is awaiting publication.
When a customer is the controller
For personal information a subscribing organisation enters into a CoreCare product, that organisation will normally be controller and CoreCare will act as processor under the customer DPA. The customer decides why the records are used, who can access them and how long they are required. A request about those records should normally go first to that organisation; CoreCare will assist it.
Information we collect
- Enquiries and trials: name, work email, organisation, optional telephone number, team size, selected product, message and setup status.
- Accounts and customer administration: identity, contact, role, permissions, organisation, subscription, billing administration, support and service communications.
- Privacy and security requests: contact details, relationship, request scope, verification status, actions, decisions and communications. Identity evidence is requested separately only where proportionate.
- Technical and security information: request time, network address or a protective hash, browser or device information, requested route, form outcome, authentication and audit events.
- Customer product information: the records, attachments and activity needed to provide the selected service under the customer’s instructions.
Purposes and lawful bases
| Purpose | Lawful basis |
|---|---|
| Answer an enquiry, prepare a trial or enter a customer agreement. | Steps at your request before a contract and legitimate interests in responding to genuine business enquiries. |
| Provide, secure and support a purchased service. | Performance of a contract and legitimate interests in reliable service administration. |
| Prevent misuse, investigate faults and protect accounts and services. | Legitimate interests in security, fraud prevention and service integrity; legal obligation where applicable. |
| Handle privacy requests, incidents, tax, accounting and legal claims. | Legal obligation and legitimate interests in accountability and establishing or defending claims. |
Where we rely on legitimate interests, we assess the purpose, necessity and effect on people. We do not use these website forms for direct marketing enrolment. If that changes, a clear choice and lawful unsubscribe route will be provided.
Required information and sensitive records
Required form fields let us identify the service, reply safely and prevent misuse. Optional fields are marked. Public forms are not intended for passwords, payment-card details, health or care records, identity documents or children’s information. Do not put those records in a general enquiry. Special-category product data is processed only where the ordered product, customer instructions and lawful safeguards require it.
Recipients and subprocessors
Access is limited to authorised CoreCare personnel and suppliers that need the information to host, protect or support the enabled service. Cloudflare provides network, security, application hosting, database and object-storage services. If you actively open live subscription checkout, Stripe receives the billing and payment information needed to provide regulated payment services; Stripe may act as processor for some activities and independent controller for others. The current supplier and subprocessor list explains these roles. We do not sell personal information.
International processing
Cloudflare operates an international network, so limited service information may be processed outside the UK. Where a restricted transfer applies, CoreCare relies on the provider’s applicable contractual transfer mechanism and supplementary measures. Contact us for information about the safeguard relevant to your service. We do not claim a UK-only storage location unless the customer order expressly confirms it.
Retention
We keep information only while its purpose, a customer instruction, a security need or a legal duty justifies it. The published retention policy sets baseline periods and explains legal holds, product-specific instructions and end-of-service deletion. Where a fixed period is not appropriate, we document the review criteria and action.
Automated processing
Security checks, rate limits, subscription status and account routing use automated rules. CoreCare does not use public-website information to make a solely automated decision with legal or similarly significant effects. A trial request is not automatic approval for production use.
Your rights
Depending on the information and lawful basis, you may have rights of access, correction, erasure, restriction, portability and objection. These rights are not absolute. You may object to processing based on legitimate interests and to direct marketing at any time. Use the privacy request form, email privacy@corecaresystems.co.uk or contact us by post. Requests may be verbal or written. We normally respond without undue delay and within one calendar month, subject to lawful clarification, identity checks or an explained extension.
Complaints and changes
Tell us first if you would like us to investigate. You may also complain to the UK Information Commissioner’s Office through ico.org.uk/make-a-complaint. We review this notice when our products, providers or legal obligations change and publish the new date and version here.