Privacy Policy
Circadacare Privacy Policy
Updated: 24 August 2026
Introduction
We've created this Privacy Policy to explain how we manage, collect, process, and use personal information. This Privacy Policy applies to our business subscription service, including our associated monitoring solutions and mobile applications. Please read this Privacy Policy carefully. By using our services, your organisation agrees to the collection and use of information in accordance with this policy.
About Our Service
We provide monitoring solutions that can be deployed in various environments including homes and care facilities. Our technology tracks wellness and environmental factors, providing access to data and alerts to authorised customers through our web applications and smartphone apps.
While our services may be deployed in residential settings or care facilities, all our transactions and contractual relationships are on a business-to-business (B2B) basis.
We are based in the United Kingdom and comply with UK data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We may review and update this Privacy Policy from time to time. Any changes will appear here. If we make significant changes, we'll notify your organisation's administrator before they take effect either through our website or by sending a notification through our application.
Data Controller
The data controller responsible for your personal information is Circadian Lighting Ltd (trading as Circadacare), a company incorporated and registered in England and Wales with company number 12850554, whose registered office is at Tanfield Business Centre, Tanfield Lea Industrial Estate North, Tanfield Lea, Stanley, England, DH9 9DB. We are registered with the Information Commissioner's Office (ICO).
Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this Privacy Policy. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our DPO using the details set out in the Contact Us section below.
What Personal Information We Collect
Personal Information
This refers to any information about an individual that can be used to identify them, either directly or indirectly, including name, email address, phone number, and other details.
Information We Collect About Your Organisation
Account Details: We collect organisational information including business name, address, contact details, and administrator information. If someone purchases our services on behalf of your organisation, they must confirm they have the authority to provide this information. We verify this authorisation before processing your data.
Payment Details: We collect financial details to process payment for our services.
Authorised User Information: We collect information about individuals authorised to use our platform, including their name, business email, role within the organisation, and access permissions.
Information About End Users
When our monitoring solutions are deployed in homes or care facilities, we may collect:
End User Information: Information about the individuals being monitored, which may include name, location details, profile information, and relevant health or wellness indicators.
Care Provider Information: Information about individuals providing care or oversight, including their relationship to the end user and contact details.
Children's Data
Our services may be deployed to support individuals under the age of 18, for example where monitoring is provided for children or young people with autism or other support needs. In these circumstances, personal data relating to a child will be processed under the terms of the service agreement with the contracting organisation (such as a local authority, care provider, or educational institution). We do not collect personal data directly from children.
Where we process children's data, we apply additional safeguards in accordance with our Children's Data Processing Procedure. These include enhanced access controls, restricted data sharing, age-appropriate retention periods, and additional oversight by the contracting organisation. The contracting organisation is responsible for ensuring that appropriate consent or other lawful basis is in place for the processing of a child's personal data, including any necessary parental or guardian consent.
Special Category Data
Some of the information we collect may constitute special category data under UK GDPR, including data concerning health and wellbeing. This includes sleep patterns, movement data used to infer wellness indicators, and audio recordings processed to detect signs of distress or changes in daily living patterns. We process this data on the basis that it is necessary for the provision of health or social care (Article 9(2)(h) UK GDPR), or where the contracting organisation has obtained explicit consent from the data subject or their representative (Article 9(2)(a) UK GDPR). We implement appropriate safeguards to protect the rights and freedoms of data subjects when processing special category data, including the use of pseudonymisation to reduce the risk of identifying individuals from the data we hold.
Monitoring Data
Sensor Information: Our systems collect data that may include:
-
Movement within monitored spaces (using PIR binary movement sensors)
-
Environmental conditions (temperature, humidity, light levels)
-
Audio recordings for behavioural and wellness classification
-
Other metrics relevant to the deployment scenario
Audio Data: Where implemented, we record audio that is processed to detect various sounds and events including, but not limited to:
-
Indications of distress or wellness concerns
-
Daily living activities
-
Environmental anomalies
-
Other sounds relevant to the specific monitoring purpose
Location Information: We collect basic information about the monitored environment layout and configuration as needed to properly set up our monitoring systems.
Information From Other Sources
We may collect information from other sources such as business directories, credit agencies, or other third parties when relevant to providing our services.
How We Use Information
We only use information when the law allows us to and when we have proper authorisation. We use this information with clear purpose to provide monitoring and wellness services. We use information in these circumstances:
-
To perform the contract we've entered into with your organisation
-
Where necessary for our legitimate interests (or those of a third party) and rights don't override those interests
-
To comply with legal obligations
-
With appropriate consent to process specific data or send communications
Your organisation has the right to withdraw consent at any time by contacting us, though this won't affect the lawfulness of any processing based on consent before withdrawal.
Why We Use Information
We use information for these purposes:
-
To set up and configure our services for your specific deployment scenarios
-
To combine data from our systems with settings and learned patterns to generate appropriate alerts
-
To communicate with authorised users about changes that may affect our services
-
To customise our services to meet the specific needs of your implementation
-
To develop and improve our services through data analytics
-
To respond to questions and provide support
-
To provide promotional information about our services (with consent)
-
To comply with laws and regulations
Improving Our Services
We may process the data we collect to improve our monitoring capabilities and develop new features. This includes:
-
Training artificial intelligence models to better identify important events in various deployment scenarios
-
Analysing patterns to improve our ability to detect potential issues or concerns
-
Creating better metrics and alerts that help optimise monitoring effectiveness
When using data for these purposes, we take steps to remove or disguise personally identifying information whenever possible, including through the use of pseudonymisation and de-identification techniques. Where we retain data for the purpose of training or improving our AI models, this is done using pseudonymised or de-identified datasets. We do not use identifiable personal data for general model training without the explicit agreement of the contracting organisation. Data retained for AI training purposes is held separately from operational data and is subject to the same security controls described in this policy.
Who We Share Information With
We don't sell, rent, or share information with third parties except as described in this Privacy Policy. We may share information with:
-
Business partners who help us process information when providing our services
-
Our payment processing provider to provide secure payment services
-
Potential buyers or sellers if we sell or buy assets or businesses
-
Regulatory bodies if we're legally required to disclose information
-
Between authorised users as determined by your organisation's administrator
-
Research partners to improve our service (using anonymised data only)
-
Technical support staff who may need access to data to solve problems
All third parties must respect the security of information and treat it according to the law. We don't allow our third-party service providers to use information for their own purposes and only permit them to process information for specific purposes according to our instructions.
International Data Transfers
Our services use cloud infrastructure provided by Google Cloud Platform, which may involve the transfer and processing of personal data in data centres located outside the United Kingdom. Where personal data is transferred internationally, we ensure that appropriate safeguards are in place in accordance with UK data protection law. These safeguards include the use of Standard Contractual Clauses approved by the UK authorities, transfer risk assessments, and confirmation that the receiving country provides an adequate level of data protection or that other suitable measures are in place. A copy of our transfer risk assessment is available on request.
Third-Party Integrations
Our platform may provide API integration capabilities allowing your organisation to connect with third-party systems, including care management systems, electronic health records, and telecare platforms. Where your organisation enables such integrations, your organisation is responsible for ensuring that appropriate data sharing agreements are in place with the third party and that a lawful basis exists for any transfer of personal data. We provide the technical integration capability only and do not control the processing undertaken by third-party systems.
Data Security
We take the security of information seriously:
-
Information is collected through our application and transferred using secure connections
-
All recordings are stored securely in encrypted form in the cloud
-
All data transfers between our devices and our systems are fully encrypted
-
We use artificial intelligence to analyse relevant data
-
Access to data is limited to authorised users through authentication systems
-
Each user can only access information they're authorised to see
-
We apply data minimisation and pseudonymisation techniques to reduce the identifiability of personal data wherever this is compatible with the effective operation of our services
-
We maintain Cyber Essentials certification and follow industry best practices for information security management
-
We conduct regular security assessments and penetration testing of our systems
Automated Decision-Making and Profiling
Our services use artificial intelligence and machine learning to analyse sensor and audio data in order to detect events, generate alerts, and identify patterns relevant to the wellbeing of end users. This processing may constitute profiling as defined under UK GDPR, as it involves the automated analysis of personal data to evaluate certain aspects relating to an individual's health, behaviour, or daily living patterns.
Alerts generated by our system are provided to authorised users within the contracting organisation for review and action. Our automated processing does not produce decisions that have legal effects or similarly significant effects on individuals without human oversight. Authorised users are responsible for reviewing alerts and determining what action, if any, to take. If you have concerns about automated processing of your data, you may contact us to request human review of any automated output.
Cookies and Similar Technologies
Our web applications and website use cookies and similar technologies to enable functionality, maintain your session, and improve your experience. We use strictly necessary cookies that are essential for the operation of our platform, and performance cookies that help us understand how our services are used. We do not use cookies for advertising purposes. On our website, cookies that are not strictly necessary are switched off unless you choose to enable them. You can accept them, decline them all, or set your preferences individually using the cookie banner, and you can change your choice at any time using the Cookie settings link on any page. You can also control cookies through your browser preferences, although disabling certain cookies may affect the functionality of our services.
How Long We Keep Information
We keep information only as long as necessary to provide our services and meet legal requirements. Information is stored while your organisation is an active customer and will be securely deleted within 30 days after service termination. Audio recordings with no positive classification are automatically deleted after 30 days, and recordings with a positive classification, or selected for quality assurance, after 180 days; these periods cannot be extended manually under any circumstances. A limited sample of audio may be kept in pseudonymised form for the purpose of improving and training our AI systems, as described in the Improving Our Services section above. Where a legal hold, an active investigation or a regulatory request applies, deletion is suspended for the affected records only, until the hold is lifted, and the reason is recorded by our Data Protection Officer. Business records and correspondence, which may contain personal data such as names and contact details, are retained separately under our Information Classification and Handling Policy for up to 7 years. Upon expiry of any retention period, personal data is securely deleted using methods appropriate to the storage medium.
Rights Under UK Data Protection Law
As we are based in the UK, data subjects have the following rights under UK data protection law:
-
Request access to personal information
-
Ask us to correct personal information
-
Request deletion of personal information
-
Object to the processing of personal information
-
Request restriction of processing personal information
-
Request transfer of personal information
-
Withdraw consent for processing personal information
-
Right not to be subject to decisions based solely on automated processing, including profiling
To exercise any of these rights, please contact us through your organisation's administrator. Your organisation won't have to pay a fee to access information, but we may charge a reasonable fee for clearly unfounded, repetitive, or excessive requests.
We may need specific information to confirm authorisation before providing access to information. We aim to respond to all legitimate requests within one month, as required by UK law, though it may take longer for complex requests.
Complaints
If you are unsatisfied and wish to raise a complaint, please contact us at hello@circadacare.com and we will endeavour to resolve your concerns. If after investigating your complaint, you remain dissatisfied, your organisation and individual data subjects have the right to file a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (https://ico.org.uk/make-a-complaint/).
Contact Us
If you have questions about our Privacy Policy or how we handle information, please contact us.
Email: hello@circadacare.com
Data Protection Officer: dpo@circadacare.com
Correspondence address: Circadian Lighting Ltd (trading as Circadacare), The Catalyst, 3 Science Square, Newcastle Helix, Newcastle upon Tyne, NE4 5TG
Phone: 0191 535 9598
Registered office: Tanfield Business Centre, Tanfield Lea Industrial Estate North, Tanfield Lea, Stanley, England, DH9 9DB
Company Number: 12850554