CQCReadiness

Privacy Notice

cqcreadiness.com and the readyCQC platform. Effective 11 August 2026.

1. Who we are and what this notice covers

CQC Readiness Ltd (company number 17270258, registered in England and Wales, registered office 13 The Rise, Sevenoaks, England, TN13 1RG) operates the website at cqcreadiness.com, the readyCQC platform for domiciliary care agencies, and the pages published under the trading name The Modern Agency. In this notice, "we", "us" and "our" mean CQC Readiness Ltd.

This notice explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and the rights you have. It covers visitors to cqcreadiness.com (including the public directory pages and the page at cqcreadiness.com/themodernagency), people who send us an enquiry or book a demonstration, people who hold a readyCQC account, and the personal information held inside the readyCQC application on behalf of our customer agencies, where a different set of rules applies (section 2).

2. The two roles we play

Data protection law distinguishes between a controller, who decides why and how personal information is used, and a processor, who handles it on someone else's instructions. We act in both roles, for different information.

We are the controller for information about visitors to our website, enquiries and demonstration bookings, account and billing information for our customers, the public directory (section 3.5), and our own business records.

We are a processor for the information a care agency puts into readyCQC, such as records about the agency's clients, staff, rotas, medication audits, incidents and invoices. The agency is the controller of that information; we handle it only under the data processing agreement in our customer terms. If you are a client, family member or care worker of an agency that uses readyCQC and you have a question about your information, the agency is the right first point of contact. We support agencies in meeting their obligations, including responding to rights requests, but the decisions about that information are the agency's to make.

3. Information we collect and why

3.1 Website visitors

Our website does not use analytics or advertising trackers. When you browse cqcreadiness.com we process technical request data (your IP address, browser type and pages requested) in our hosting provider's server logs, used to run the site securely and investigate abuse, and we hold your IP address briefly in memory to rate-limit abusive traffic to our public forms. It is not written to a database for that purpose. Lawful basis: legitimate interests (running a secure, reliable website).

3.2 Enquiries and demonstration bookings

If you submit the enquiry form on our Modern Agency page, we collect your name, email address, agency name and mobile number. This is sent by email to our team inbox so we can respond to you; it is not stored in the readyCQC product database. If the automated send fails, the form instead opens your own email application so you can send the enquiry directly. If you book a demonstration through Calendly, your booking details are processed by Calendly LLC under its own privacy notice, and we receive the booking. If you email us directly, we hold the correspondence in our business email. Lawful bases: legitimate interests (responding to enquiries from prospective customers) and steps taken at your request prior to entering into a contract.

3.3 Account holders and billing

When an agency subscribes to readyCQC we collect, about the individuals who use it: account details (name, work email address, mobile number used for SMS sign-in codes where enabled, role and organisation), with authentication provided by Clerk, our sign-in provider; billing details, processed by Stripe (we do not hold full card numbers); and support and service communications, including transactional emails we send through Amazon SES from mail.cqcreadiness.com. Lawful bases: performance of our contract with the agency, legal obligation (accounting and tax records), and legitimate interests (service administration and security).

3.4 Information inside the readyCQC application

Agencies use readyCQC to run their services, and the records they create there can include personal information about their clients and staff: care records, medication audit uploads, evidence documents, staff training and certification records, rotas, incident records, messages, invoices, and lone-worker alert records (including logs of the calls and text messages the platform places through Twilio when an alert is raised). Some of this is special category data, for example health information in care and medication records. We process it only as a processor, on the agency's documented instructions, under the data processing agreement in place with each customer. We apply strict tenancy separation between agencies, and our operational logging is designed to be free of personal information: our transactional email and telephony logs record counts, purposes and identifiers, never names, message content or email addresses.

3.5 The public directory

Our public directory and dashboard pages republish information about registered care providers in England drawn from public sources: the Care Quality Commission's published datasets and reports (used under the Open Government Licence) and Companies House filings. This includes some personal information that those sources publish, principally the names of registered managers and company officers. Lawful basis: legitimate interests (making public regulatory information easier to find and compare, for families choosing care and for providers benchmarking themselves). We refresh CQC data on a weekly cycle, so corrections made at source flow through to us. If you are a registered manager or officer and believe information about you on our site is inaccurate or should not appear, contact us (section 13); you also have the right to object (section 9). The fastest permanent fix for factual errors is usually a correction at the source register, which we then reflect.

4. Artificial intelligence features

Some readyCQC features use an AI model provider (Anthropic's Claude API) to analyse information an agency asks us to process, for example checking uploaded medication administration records for errors and preparing inspection-readiness analysis. Where a feature's design allows, the data sent is minimised first: those features send only aggregate figures and category codes, never names or free text. Where records are analysed in their uploaded form, for example medication audit checking, they are sent only to produce the analysis the agency requested. Our AI provider processes this data under a data processing agreement and does not use it to train its models. AI outputs inside readyCQC are decision support for trained professionals; they do not make automated decisions with legal or similarly significant effects about individuals.

5. Who we share information with

We do not sell personal information, and we do not share it with advertisers. We use a small number of service providers to run the platform:

ProviderWhat they do for usWhere
VercelWebsite and application hosting; file storage for uploaded documents (Vercel Blob)Hosting in London (lhr1); Vercel Inc is US headquartered
NeonOur application database (Postgres)London (AWS eu-west-2)
ClerkSign-in and account security, including SMS sign-in codesUS headquartered
StripeSubscription billing and paymentsUS headquartered; UK entity for UK payments
Amazon Web Services (SES)Sending transactional email from mail.cqcreadiness.comUS headquartered
TwilioAutomated phone calls and SMS for lone-worker alertsUS headquartered
AnthropicAI analysis features (see section 4)US headquartered
CalendlyDemonstration scheduling, where you choose to bookUS headquartered
Google WorkspaceOur business email and internal documentsGoogle Ireland for UK customers

We may also disclose information where the law requires it (for example to regulators or law enforcement with proper authority), and in a business transfer such as a merger or acquisition, in which case this notice would continue to apply to the transferred information.

6. Where data is stored and international transfers

The platform's primary data stores are in the United Kingdom: application hosting in London and the application database in the London region (AWS eu-west-2). Some of our providers are headquartered in the United States or operate globally, so limited personal information can be transferred outside the UK in the course of providing their service. Where that happens, we rely on the safeguards UK law provides, as implemented in each provider's data processing terms: the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses and, where applicable, the UK Extension to the EU-US Data Privacy Framework.

7. How long we keep information

InformationRetention
Enquiries and demonstration correspondence24 months from our last contact with you, then deleted
Account recordsThe life of the subscription, plus 12 months after closure
Billing and tax records6 years plus the current financial year, as UK tax law requires
Agency application data (processor role)Held while the agency's agreement is active; returned or deleted at contract end on the agency's instruction, subject to a 30-day wind-down
Server and security logsTransient, per our hosting provider's defaults
Public directory dataUpdated weekly from the source registers; entries are removed on our periodic full refresh when removed at source, and sooner where an objection is upheld

Automated retention jobs enforce time limits inside the application, for example scheduled sweeps that delete or reduce records when their retention period ends.

8. How we protect information

We use encryption in transit for all traffic and encryption at rest in our database and file storage; strict tenancy isolation between agencies, enforced in the application's data access layer and covered by automated tests; role-based access control inside the application, so agency staff see only what their role allows; rate limiting and abuse controls on public endpoints; operational logs designed to carry no personal information; and production access restricted to the small number of people who operate the platform. No system is perfectly secure: if we become aware of a personal data breach that risks your rights, we will notify the Information Commissioner's Office and affected controllers or individuals as UK GDPR requires.

9. Your rights

Where we are the controller, you have the right to access your personal information; to have inaccurate information corrected; to have information erased in certain circumstances; to restrict or object to processing, including a right to object to our legitimate-interests processing such as the public directory; to data portability in certain circumstances; and to withdraw consent where consent is the basis (we do not currently rely on consent for any core processing).

To exercise a right, contact us using the details in section 13. We respond within one month and may need to verify your identity. If the information sits inside an agency's readyCQC records, we will refer the request to the agency, which as controller is responsible for answering it, and we will support them in doing so.

You also have the right to complain to the Information Commissioner's Office: ico.org.uk, or 0303 123 1113. We would appreciate the chance to resolve a concern first, but you can go to the ICO at any time.

10. Cookies

We use only strictly necessary cookies: the session cookies our sign-in provider (Clerk) sets to keep account holders signed in securely, and a first-party cookie our lone-worker alert surface sets on its own subdomain to recognise an enrolled carer device. We do not use analytics, advertising or tracking cookies, and there is no third-party tracking on the site. Because strictly necessary cookies are exempt from consent requirements, the site does not show a cookie banner. If we ever introduce non-essential cookies, we will update this notice and seek consent first.

11. Children

Our website and platform are business tools for care providers and are not directed at children. We do not knowingly collect information from anyone under 18 as a controller. Records inside readyCQC about the people an agency cares for are the agency's controlled data (section 2).

12. Changes to this notice

We will update this notice when our processing changes, and new features that process personal information in new ways will not launch quietly: material changes will be reflected here before they take effect, with the effective date above updated. Significant changes affecting account holders will be notified in the application or by email.

13. How to contact us

CQC Readiness Ltd, 13 The Rise, Sevenoaks, England, TN13 1RG. Email: yvonne@cqcreadiness.com. We have not appointed a statutory Data Protection Officer; data protection queries are handled by the company's directors.