Privacy Policy
Last updated: 12 July 2026
Empatha ("we", "us", "our") provides a platform that matches families and individuals with care workers and companions. This policy explains what personal data we collect, why, how we protect it, and the rights you have over it. We are committed to handling data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who this applies to
This policy applies to clients, family members and legal representatives arranging care ("clients"), care workers ("carers"), and visitors to our public website. Where a client submits information about someone in their care ("a care recipient") who is not themselves an Empatha user, this policy also governs how that information is handled.
2. What data we collect
The data we collect depends on how you use Empatha:
- Account details — name, email, phone number, password, profile photo, and postcode/address for matching purposes.
- Care request details — care recipient information, care needs, mobility and medical conditions, medication requirements, allergies, behavioural notes, companionship preferences, schedule and budget.
- Carer verification data — identity documents, right-to-work status, enhanced DBS certificate details, references, training certificates and insurance status.
- Messages — content sent through in-app messaging between clients, carers and our support team.
- Payment data — processed by our payment provider (Stripe); we store only the last four digits of a card and its expiry, never full card numbers.
- Usage data — pages visited, device and browser information, and cookies as described in our Cookie Policy.
3. Special category data
Care needs, medical conditions, and DBS/criminal-record data are classed as "special category" and "criminal offence" data under UK GDPR, and we treat them accordingly. This information is encrypted at rest, access is restricted to the people who need it to deliver or arrange your care (your matched carer, and authorised Empatha staff for verification and safeguarding purposes), and it is never used for marketing or shared with third parties for commercial purposes.
4. Why we process your data
- To provide the service — matching clients with carers, enabling bookings, messaging and payments (contractual necessity).
- To verify carers — identity, right-to-work and DBS checks before a carer can accept bookings (legal obligation and legitimate interest in platform safety).
- To keep everyone safe — safeguarding review, incident investigation, and fraud prevention (legitimate interest and, in some cases, legal obligation).
- To communicate with you — booking confirmations, match notifications, and service updates (contractual necessity), and optional marketing emails (consent, which you can withdraw at any time).
5. Who we share data with
We share data only where necessary: your matched carer sees the care request details relevant to a booking; our payment provider (Stripe) processes payments; and our hosting and email providers process data on our behalf under contract. We do not sell personal data, and we do not share care or medical details with advertisers.
6. How long we keep data
We retain account and booking data for as long as your account is active, and for a limited period afterwards to meet accounting and legal obligations (for example, payment records). Read notifications are automatically deleted after 90 days. If you delete your account, we anonymise your personal data rather than retaining it indefinitely — see Section 8.
7. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Object to or restrict certain processing, including marketing
- Request erasure of your data ("the right to be forgotten")
- Receive your data in a portable format
- Complain to the Information Commissioner's Office (ICO) if you believe we have mishandled your data
8. Exporting or deleting your data
You don't need to submit a support request for the basics — from your account settings you can download a complete export of your personal data at any time, and request account deletion directly. When you delete your account, we anonymise your personal details (name, contact information, medical and verification data) immediately. Bookings, payments and reviews are retained in anonymised form only where we have a legal obligation to keep financial records — they are no longer linked to your identity.
9. Data security
Special category data (medical details, DBS numbers) is encrypted at rest. Access to sensitive data is role-restricted and logged. We conduct regular reviews of our authorisation and data-handling practices as the platform evolves.
10. Children's data
Empatha is intended for adults arranging or providing care. We do not knowingly collect data from children under 16 as account holders.
11. Contact us
For any privacy question, or to exercise a right not covered by your account settings, contact us at privacy@empatha.example or via our contact page.