Privacy Policy
Last updated: March 2026
1. Data Controller
Carew Technologies Ltd ("we", "us", or "our") is the data controller responsible for your personal data. We are registered in England and Wales.
If you have any questions about this privacy policy or how we handle your personal data, you can contact us at:
- Email: privacy@carewtechnologies.com
- Website: carewtechnologies.com/contact
2. Information We Collect
We collect personal data through the following methods:
Directly from you (via forms, emails, and meetings):
- Contact information (name, email address, phone number)
- Company information (company name, role, website)
- Project requirements and specifications you provide
- Communication records between you and our team
Automatically (via our website):
- IP address and approximate location
- Browser type and device information
- Pages visited, time spent, and navigation patterns
- Referral source (how you found our website)
We do not collect special category data (e.g. health data, racial or ethnic origin, political opinions) unless you voluntarily provide it, in which case we will obtain your explicit consent.
3. Lawful Bases for Processing
Under Article 6 of UK GDPR, we process your personal data on the following legal bases:
- Contract — To perform a contract with you or take pre-contractual steps at your request (e.g. delivering project work, responding to enquiries).
- Legitimate interests — To pursue our legitimate business interests where your rights do not override those interests (e.g. website analytics, improving our services, business development). We conduct Legitimate Interest Assessments (LIAs) where required.
- Consent — Where you have given clear consent for us to process your data for a specific purpose (e.g. marketing communications). You may withdraw consent at any time.
- Legal obligation — To comply with legal or regulatory requirements (e.g. tax records, anti-money laundering).
4. How We Use Your Information
We use your information for the following purposes:
- Providing and delivering our software development and consulting services (Contract)
- Communicating with you about projects, enquiries, and proposals (Contract / Legitimate interests)
- Sending marketing updates about our services (Consent)
- Analysing website usage to improve user experience (Legitimate interests)
- Maintaining business records and accounts (Legal obligation)
- Protecting our legal rights and preventing fraud (Legitimate interests)
5. Data Sharing
We do not sell your personal data. We may share your information with the following categories of third parties, under appropriate data processing agreements (Article 28 UK GDPR):
- Cloud hosting providers — for website and application hosting
- Analytics services — for website usage analysis
- Email service providers — for business communications
- Accounting and payment processors — for invoicing and financial records
- Professional advisors — solicitors, accountants, where required by law
We require all third-party processors to respect the security of your personal data and treat it in accordance with UK GDPR. We do not allow them to use your data for their own purposes.
6. International Data Transfers
Some of our third-party service providers are based outside the United Kingdom. Where we transfer personal data internationally, we ensure appropriate safeguards are in place, including:
- Transfers to countries with a UK adequacy decision
- International Data Transfer Agreements (IDTAs) or UK Addendum to EU Standard Contractual Clauses
- Transfer Risk Assessments conducted where required
You may request further details of the safeguards we use by contacting us.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit and at rest
- Access controls and authentication measures
- Regular security reviews and updates
- Staff training on data protection obligations
Breach notification: In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach (Article 33 UK GDPR). Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay (Article 34 UK GDPR).
8. Data Retention
We retain your personal data only for as long as necessary. Our typical retention periods are:
- Contact enquiries — 2 years from last contact
- Client project data — Duration of engagement plus 6 years (to meet legal and contractual obligations)
- Financial and tax records — 7 years (as required by HMRC)
- Marketing consent records — Until consent is withdrawn, plus 1 year
- Website analytics data — 26 months
After the retention period expires, we securely delete or anonymise your data.
9. Your Rights
Under UK GDPR, you have the following rights. We will respond to your request within one month (which may be extended by up to two months for complex requests). Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.
- Right of access — Request a copy of the personal data we hold about you (Subject Access Request)
- Right to rectification — Request correction of inaccurate or incomplete data
- Right to erasure — Request deletion of your data where there is no compelling reason to continue processing
- Right to restrict processing — Request that we limit how we use your data
- Right to data portability — Request your data in a structured, commonly used, machine-readable format
- Right to object — Object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent — Where processing is based on consent, withdraw at any time without affecting prior processing
- Rights related to automated decision-making — We do not currently carry out solely automated decision-making that produces legal effects. If this changes, we will update this policy and provide appropriate safeguards
To exercise any of these rights, please email us at privacy@carewtechnologies.com. We may need to verify your identity before processing your request.
10. Cookies
Our website uses the following types of cookies:
- Strictly necessary cookies — Required for the website to function (e.g. session management). These cannot be disabled.
- Analytics cookies — Help us understand how visitors use our website (e.g. page views, navigation patterns). We use these to improve our site.
You can control cookie settings through your browser preferences. Disabling certain cookies may affect website functionality. For more information on cookies, visit aboutcookies.org.
11. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with us first. Please contact us at privacy@carewtechnologies.com and we will acknowledge your complaint within 30 days and provide a full response without undue delay.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:
- Website: ico.org.uk
- Helpline: 0303 123 1113
12. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via email to individuals whose data we hold. Minor changes will be posted on this page with an updated revision date. We recommend reviewing this policy periodically.