This Privacy Policy explains how MCARE SOLUTIONS LTD (company number 07049570) handles personal data through mcaresolutions.co.uk, the MCare Solutions mobile application, and the connected workforce-management platform (together, the “Services”). It applies to business customers, administrators, workers and other authorised users, website visitors, prospects and support contacts.
1. Who we are and our roles
MCARE SOLUTIONS LTD, of 12 McGrath Road, London, E15 4JP, United Kingdom, is responsible for this policy. Contact: salman.mir@mcaresolutions.co.uk; 0751 5508 466.
For account administration, subscriptions, billing, support, security, website operation and our own service analytics, we normally act as a controller and decide why and how personal data is used.
For timesheets, attendance, site assignments, audits, employee records, budgets, stock records, window-cleaning schedules, work evidence, signatures, payroll-related records and similar information uploaded or generated by a business customer, we normally act as that customer’s processor. The customer is the controller and decides the purpose, lawful basis, access rights and retention period. Workers should first direct questions about those records to their employer or the organisation that provided their account. We will assist that organisation as required by data-protection law.
2. Personal data we collect
Account and identity data: names, usernames, employer or organisation, job title, employee or personnel identifiers, authentication details and account permissions.
Contact data: work or personal email address, telephone number, postal address and emergency or other contact details where a customer chooses to record them.
Workforce and operational data: work sites and assignments; rosters; clock-in and clock-out times; hours, breaks, overtime, leave and absence records; tasks; notes; site audits; inspection results; incidents; budgets; stock movements; window-cleaning schedules; and related reports.
Location and device data: GPS or other device location at the time a location-enabled function is used; site check-in information; IP address; device type; operating system; app version; identifiers; diagnostic, security and activity logs. The app should not collect location when the relevant feature is off or permission has not been granted.
Evidence and content: photographs, signatures, audit evidence, documents, comments and other files submitted through the Services. Images may contain people, locations or other personal information.
Financial and payroll-related data: pay rates, payroll inputs, cost and budget information and payment or invoice records. Unless expressly enabled and agreed, the Services are not intended to store full payment-card details; card processors handle those details under their own notices.
Communications and marketing data: enquiries, support messages, feedback, preferences and records of communications.
We do not intentionally require special-category data (such as health, biometric, racial or trade-union data) or criminal-offence data as a standard feature. A customer that chooses to enter such data must have a lawful basis and, where required, an additional UK GDPR condition and safeguards.
3. Where the data comes from
We receive data directly from users; from the business customer or its administrators; from workers’ devices when permissions are enabled; automatically from use of the Services; and from service providers or integrations selected by the customer. A customer may create an employee account or upload workforce records before that employee first logs in.
4. Why we use data and our lawful bases
Contract: to create and administer business accounts, provide the Services, authenticate users, process subscriptions, provide support and communicate about the service.
Legitimate interests: to secure, troubleshoot and improve the Services; prevent fraud and misuse; keep appropriate business records; respond to enquiries; and understand service performance. We balance these interests against users’ rights.
Legal obligation: to comply with tax, accounting, regulatory, law-enforcement and data-protection obligations and to establish, exercise or defend legal claims.
Consent: where required for non-essential cookies, device permissions or electronic marketing. Consent may be withdrawn without affecting earlier lawful processing.
Customer instructions: when we act as processor, we process customer-controlled data only to provide and secure the Services, on documented instructions, and as permitted by the customer agreement and law. The customer determines its own lawful basis, including for worker monitoring and GPS data.
5. GPS, monitoring and mobile permissions
Location information can be intrusive. Business customers must use location features only for a clear, necessary and proportionate work purpose; tell workers what is collected, when and why; avoid covert or unjustified out-of-hours monitoring; restrict access; set suitable retention; and complete a data-protection impact assessment where the proposed monitoring is likely to create a high risk.
The app will request device permission before accessing protected functions such as location or camera. Users can change permissions in device settings, but some features may then be unavailable. Customers must not use photographs, signatures or location data for unrelated purposes without an appropriate lawful basis and notice.
6. Sharing personal data
We may share data with the relevant customer and its authorised users; hosting, cloud infrastructure, database, backup, authentication, communications, customer-support, analytics, security and payment providers; professional advisers, insurers and auditors; regulators, courts and law-enforcement bodies where required; and a buyer or successor in a genuine corporate transaction.
Service providers may use data only for the contracted service and must protect it. We do not sell personal data. We do not share personal data for third-party behavioural advertising unless this policy and the relevant consent choices are updated first.
7. International transfers
Some suppliers may process data outside the United Kingdom. Where UK data-protection law requires a transfer safeguard, we will use an adequacy regulation, the UK International Data Transfer Agreement or UK Addendum, or another lawful mechanism, and carry out any required transfer risk assessment. Contact us for information about safeguards relevant to your data.
8. Retention
Customer-controlled workforce and operational data is retained for the subscription term and then deleted or returned in accordance with the customer agreement, documented instructions, applicable law and the technical backup cycle. Unless an order form states otherwise, production customer data should be scheduled for deletion within 90 days after termination, with residual encrypted backups expiring within a further 90 days.
Controller records are generally kept as follows: account and support records for the account term plus up to two years; security and diagnostic logs for up to 12 months; unsuccessful sales enquiries for up to two years; marketing records until opt-out, with a minimal suppression record retained to respect the opt-out; and contracts, invoices and tax records for six years after the relevant financial period. We may retain specific records longer where reasonably necessary for a legal claim, fraud prevention or a legal obligation.
9. Security
We use proportionate technical and organisational measures intended to protect personal data, including access controls, role-based permissions, authentication, encryption in transit, backups, logging, supplier controls and incident-management procedures. No service can guarantee absolute security. Customers are responsible for configuring roles, promptly removing leavers, protecting credentials and devices, and notifying us of suspected compromise.
10. Your rights
Depending on the circumstances, individuals may have rights to be informed; access personal data; correct inaccurate data; erase data; restrict processing; object to processing; receive portable data; and not be subject to a decision based solely on automated processing that has legal or similarly significant effects. They may also withdraw consent where consent is used.
For customer-controlled employment or workforce records, contact the relevant employer or customer first. We will support the customer in responding. For data we control, contact us using the details below. We may verify identity and applicable exemptions before acting.
11. Accounts and deletion
Users may initiate account deletion using the deletion control provided in the app or connected web account. Deletion of a user login does not automatically erase records that the business customer must retain or controls for employment, payroll, audit, contractual or legal purposes. In that case, we will notify or act on the instructions of the relevant customer and explain any retention that applies. Subscription cancellation and account deletion are separate actions.
12. Cookies and analytics
The website and connected service may use strictly necessary cookies or similar storage for authentication, security and core functions. Non-essential analytics, preference or marketing technologies will be used only after any consent required by law. A separate cookie notice or consent tool should identify each non-essential technology, provider, purpose and duration.
13. Children
The Services are intended for businesses and authorised working users, not children. We do not knowingly offer accounts directly to children under 16. A customer must not create an account for a child unless lawful, necessary for a legitimate employment arrangement, and supported by all required notices and safeguards.
14. Changes to this policy
We may update this policy to reflect changes to the Services, suppliers or law. We will post the updated version and change the “Last updated” date. We will give additional notice where a change materially affects users’ rights or our use of personal data.
15. Contact and complaints
Privacy enquiries: salman.mir@mcaresolutions.co.uk; telephone 0751 5508 466; post: MCARE SOLUTIONS LTD, 12 McGrath Road, London, E15 4JP, United Kingdom.
You may complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk or by telephone on 0303 123 1113. We would appreciate the opportunity to address your concern first.
