Last updated: 24/04/2026

Cheltenham and Cotswold Care (“we”, “us”, “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store and protect personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This policy applies to clients, family members, website visitors, employees, contractors and anyone else whose personal data we process.



1. Who We Are

Cheltenham and Cotswold Care is a UK‑based care provider delivering services in Cheltenham and the Cotswolds.

Data Controller: Cheltenham and Cotswold Care
Registered address: 6-8 St Georges Road, Cheltenham, Gloucestershire, GL50 1PH
Email: info@cheltcots.co.uk
Telephone: 01242 386662



2. The Personal Data We Collect

We may collect and process the following types of personal data:

a) Client & Family Information

  • Name, address, date of birth

  • Contact details (phone, email)

  • Health and medical information

  • Care needs assessments and care plans

  • Next of kin and emergency contacts

  • Financial or billing information

b) Staff & Recruitment Information

  • Employment history and qualifications

  • Right to work documentation

  • DBS check information

  • Payroll and bank details

  • Health information relevant to employment

c) Website & Communication Data

  • Enquiries submitted via our website or email

  • IP address and basic website usage data

  • Cookies (see Section 9)



3. Special Category (Sensitive) Data

As a care provider, we process special category data, including health and medical information. We only collect and use this data where it is strictly necessary for:

  • Delivering safe and appropriate care

  • Meeting legal and regulatory obligations

  • Safeguarding individuals

  • Employment and occupational health purposes



4. How We Use Personal Data

We use personal data to:

  • Provide and manage care services

  • Communicate with clients, families and professionals

  • Maintain accurate care records

  • Process payments and invoices

  • Recruit, employ and support staff

  • Meet legal, regulatory and safeguarding responsibilities

  • Improve our services

We will never sell your personal data.



5. Lawful Bases for Processing

Under UK GDPR, we rely on the following lawful bases:

  • Performance of a contract – delivering care services

  • Legal obligation – complying with CQC, HMRC, employment and safeguarding laws

  • Legitimate interests – running our business responsibly

  • Vital interests – protecting health and safety

  • Consent – where required (e.g. marketing communications)

  • Health and social care provision – for special category data



6. Who We Share Personal Data With

We may share personal data with:

  • Health and social care professionals (GPs, nurses, local authorities)

  • Regulatory bodies (such as the Care Quality Commission)

  • Payroll, accounting and IT service providers

  • DBS and recruitment screening services

  • Emergency services where necessary

All third parties are required to keep your information secure and use it only for agreed purposes.



7. Data Security

We take data security seriously and use appropriate technical and organisational measures to protect personal data, including:

  • Secure digital systems and password protection

  • Access controls on sensitive records

  • Staff training on data protection

  • Secure storage of paper records



8. Data Retention

We keep personal data only for as long as necessary, including:

  • In line with care and medical record retention requirements

  • To meet legal, regulatory and insurance obligations

  • Employment law requirements

Once data is no longer required, it is securely deleted or destroyed.



9. Cookies and Website Data

Our website may use cookies to improve functionality and user experience. Cookies do not identify you personally.

You can control cookie preferences through your browser settings.



10. Your Data Protection Rights

Under UK GDPR, you have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request erasure of your data (where applicable)

  • Restrict or object to processing

  • Data portability

  • Withdraw consent (where processing is based on consent)

  • Lodge a complaint with the Information Commissioner’s Office (ICO)

ICO website: https://www.ico.org.uk



11. How to Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact:

Cheltenham and Cotswold Care
Email: info@cheltcots.co.uk
Telephone: 01242 386662



12. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on our website with an updated revision date.