Who is responsible for your information?
Inclusive Community Care Ltd, company number 16250366, is the data controller for information it decides how and why to use. Our operating address is 76 Burngreave Road, Sheffield, S3 9DE. Data-protection enquiries can be made through our Contact us page.
Information we may use
- Contact and enquiry details supplied by families, professionals, commissioners and partners.
- Referral, assessment, safeguarding and service-delivery information where a service relationship exists.
- Staff, applicant, contractor and supplier information.
- Account, audit and security information for authorised portal users.
Why we use it
We use personal information to respond to enquiries, assess and deliver services, safeguard people, manage staff and suppliers, meet contractual and legal duties, maintain secure records and improve quality. Depending on the circumstances, our lawful basis may be contract, legal obligation, legitimate interests, vital interests, consent or performance of a task connected to public functions. Where special-category information is necessary, an additional condition under UK data-protection law must also apply.
Sharing, storage and retention
Information is shared only where necessary and proportionate, including with the person, their representative, commissioners, safeguarding partners, regulators, professional advisers and contracted technology providers. We do not sell personal information. Records are protected through role-based access and are kept only for the applicable legal, contractual and safeguarding retention period.
Your rights
Depending on the circumstances, you may ask for access, correction, erasure, restriction, objection or transfer of your information. You may also withdraw consent where consent is the basis used. Contact us first so we can respond. You can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint.
Website contact form and portal
When you use the website contact form, we record the details you provide, your chosen contact method and a privacy confirmation so an authorised manager can review and respond. We use a daily, one-way connection identifier to limit automated spam; we do not retain the raw internet address for that purpose. Keep the first message brief and do not use the form for urgent safeguarding information. The staff portal is restricted to administrator-provisioned identities; access and record activity are logged for security and accountability. Authenticator setup secrets are encrypted, session tokens are stored only as one-way hashes, and passkeys store a public credential rather than a face or fingerprint. Biometric information stays on the staff member's device.
Job applicants
When you apply through our Careers page, we use the information you provide to administer recruitment, assess your evidence against the vacancy, carry out safer-recruitment checks, meet safeguarding and employment duties, and establish or defend legal claims where necessary. This can include contact and address history, education and work history, gaps, references, right-to-work information, suitability declarations and information needed for a role-appropriate criminal-record process.
You may attach a CV, qualification or training certificate, or other relevant evidence. Do not upload passports, share codes, DBS certificates, bank details, medical records or another person's confidential information at the application stage. Uploaded files are checked against an allowlist, their real file structure and active-content rules before a protected copy is stored. Files that fail the check are not added to the application. Evidence can be opened only by authorised management through the protected workspace.
Recruitment information and evidence are reviewed against the retention period that applies to the outcome; the initial application record is scheduled for review after 180 days. Optional equality-monitoring information is stored separately from the application and is not included in the shortlisting view. It is used only where you choose to provide it, normally in anonymised or aggregated monitoring. To ask about your application information or exercise a data-protection right, use our Contact us page.
ICCare Companion AI website guide
The guide first applies local safety checks and refuses personal, sensitive, case-specific, explicit, harmful or illegal questions before using any outside service. Approved ICCare service and policy answers are composed only from ICCare's controlled knowledge. Harmless arithmetic and several common everyday replies are handled locally. For another harmless question, the current non-identifying question and, where useful, the guide's own previous reply may be sent to Google Gemini to identify whether the question concerns ICCare or to produce a short conversational answer. Previous user messages are not sent. Gemini cannot write or change approved ICCare service facts.
The guide does not accept private names, contact details, addresses, individual health or medicine information, safeguarding cases, incidents, care or referral records, personal legal, financial or employment matters, explicit sexual content, harmful or illegal instructions, hate, extremism or requests to bypass its safety rules. Gemini requests are stateless and set store to false. Google's published Gemini API terms explain that free-tier prompts and responses may be used to improve its products, so ICCare sends only questions that have passed the local non-identifying and safety checks; it does not send earlier user messages, portal records, form data or care records. If you ask for a journey estimate and then choose to continue, only the journey postcode and ICCare's public postcode are sent to a UK postcode lookup service; route coordinates are then sent to a road-routing service. ICCare does not add public chat content to care, referral or staff records. Use our Contact or Safeguarding routes when a personal response is needed.
