Privacy Policy
Last updated: 25 August 2026
This Privacy Policy explains how Offboard HQ Ltd (“we”, “us”, “our”) handles personal information in connection with ISO Care, including the public website at https://www.isocare.uk, the ISO Care software service (SaaS) and the ISO Care mobile application.
About this Privacy Policy
ISO Care is a care operations platform for UK domiciliary and home-care providers. Authorised users may use the web platform to plan and manage care work, invite staff and family members, and operate finance and reporting functions. Invited carers may use the companion mobile app for published visits and related care work. This policy covers those services and this website.
It does not replace a care organisation’s own privacy information for the people they support, nor any data-processing agreement between Offboard HQ Ltd and a customer organisation.
Who we are
The ISO Care product is provided by Offboard HQ Ltd.
Company number: 17015641
Registered office: 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Privacy and support: support@isocare.uk
Sales: sales@isocare.uk
When we act as controller and processor
Offboard HQ Ltd is not always only a controller, and not always only a processor. The role depends on the purpose of the processing.
Where we act as a controller. We determine the purposes and means of processing for our own activities. These typically include:
- trial and enquiry requests submitted on this website (for example organisation name, contact name, work email, phone number, staff-size estimate and any message);
- customer and account administration;
- authentication and access to the ISO Care service;
- customer support;
- service security, abuse prevention and platform administration;
- service communications (for example transactional emails); and
- administration of organisation subscriptions where that functionality is used.
Submitting a trial request does not by itself create an ISO Care account, organisation or trial. Access starts if we approve an application and provision an organisation.
Where we act as a processor. Care organisations generally decide why client, staff, family and care information is processed through ISO Care (for example to plan visits, keep care records, invite families or raise invoices). Offboard HQ Ltd provides the software and infrastructure and processes that information on the organisation’s behalf, in accordance with the organisation’s instructions and applicable law.
Some processing can involve both roles. For example, authentication identifiers are used so we can operate the service, and so a customer organisation can authorise its users. Transactional emails we send may contain information that a customer organisation has asked us to deliver.
Personal information we process
The categories below reflect information the ISO Care service is designed to hold. What is actually stored for a given person depends on what a user or care organisation enters, and on which features they use.
- Identity and contact details: names, email addresses, phone numbers and postal addresses.
- Dates of birth (for example for clients or staff records).
- Account and profile information, including language preference and profile photo where provided.
- Organisation membership, roles, branch assignment and permissions.
- Staff and employment-related information (for example job title, employee reference, invitation status, qualifications, rota and shift information, holiday requests, and payroll-related records where the organisation uses those features).
- Client and service-user information (including preferred name, address, contact details and care-related fields described below).
- Family and guardian information, relationships and invitation details.
- Legal authority / power of attorney records recorded against a family or guardian link (type, status and notes as entered).
- Trial-request details, including an identifier derived from the requester’s IP address used to help limit duplicate or abusive submissions.
- Billing and invoice information for care-organisation invoicing of payers (for example payer contact details, invoice lines, recipient email and PDF copies). This is separate from any future ISO Care subscription billing.
- Care plans and related tasks or instructions.
- Care notes and observations.
- Medication and eMAR records.
- Documents, forms and signature records.
- Visit records and rota information.
- Staff sickness and absence information, including cover records.
- Audit logs (including actions taken in the service and, in some cases, related record snapshots).
- Device and session identifiers (for example authentication sessions, a mobile device identifier used for offline sync, and similar technical identifiers).
- Precise check-in and check-out location evidence, as described in the GPS section.
- In-app notifications and related preferences.
Special-category and care information
Care organisations may enter special-category and other sensitive information into ISO Care in order to provide and manage care. This may include:
- health and care needs;
- allergies;
- medical conditions;
- medication information;
- NHS number;
- DNR / end-of-life information;
- mobility and communication needs;
- sickness and absence information relating to staff; and
- other health-related information entered into notes, alerts, documents, forms or care records.
Offboard HQ Ltd does not decide the clinical or care purposes for this information where the customer organisation is the controller. The care organisation remains responsible for deciding what to record and for identifying the appropriate conditions for its processing under UK data-protection law, including any Article 9 conditions that apply to special-category data.
ISO Care is not aimed at collecting this information from members of the public as consumers. It is recorded because a care organisation (or an authorised user acting for that organisation) uses the service.
How we obtain information
We obtain personal information:
- directly from you (for example when you request a trial, create or use an account, or contact us);
- from authorised users of a customer organisation (for example when they add staff, clients, family members or care records);
- automatically from your device when you use the website, web app or mobile app (for example authentication cookies, session data and, where you permit it, location at check-in or check-out); and
- from service providers who process information on our behalf (for example authentication, hosting and transactional email).
How and why we use personal information
Our own purposes (typically as controller) include reviewing trial applications; provisioning and administering customer organisations and user access; authenticating users; providing support; protecting the security and integrity of the service; sending transactional service messages; meeting legal obligations; and administering subscriptions if and when that functionality is enabled.
On behalf of customer organisations (typically as processor) we process the information they (and their authorised users) enter so they can operate care, workforce, family access, visits, records, documents, reporting and invoicing through ISO Care.
Lawful bases
UK GDPR requires a lawful basis for processing personal data. The following describes how we approach our own controller activities.
For Offboard HQ Ltd’s own processing, we typically rely on one or more of:
- Performance of a contract, or steps at your request before entering a contract (for example considering a trial application, providing an account you have been invited to use, or providing the service to a customer organisation).
- Legitimate interests, such as securing the service, preventing abuse of the trial form, administering our business, and improving reliability of hosting. We will not rely on legitimate interests where they are overridden by your interests or fundamental rights and freedoms.
- Legal obligation, where we must retain or disclose information to comply with applicable law.
- Consent, only where we actually rely on consent (for example certain optional cookies or communications, if we introduce them and ask you). Where we rely on consent, you may withdraw it without affecting processing that took place before withdrawal.
For special-category data processed on behalf of a customer organisation, that organisation is generally responsible for identifying the appropriate Article 6 basis and Article 9 condition for its processing. Offboard HQ Ltd does not select the care organisation’s care-lawful basis for it.
GPS and location
The ISO Care mobile app may request foreground location permission at check-in and check-out. If permitted, the app may capture a one-off reading of precise latitude and longitude, and an accuracy figure, at the time of that action.
This information is used for visit and attendance verification. If location cannot be captured, or accuracy is poor, a manual exception may be recorded for later review by authorised office users. Precise coordinates may be shown on the organisation’s check-in exception tools.
ISO Care does not continuously track staff location and does not currently use background location tracking, geofencing or always-on location.
If a device is offline, location evidence may remain temporarily in the mobile offline sync queue on the device until it is uploaded to the service.
Mobile and offline processing
The mobile app is for invited users of an existing organisation. It is not a public sign-up or billing channel.
The app supports offline working. Until synchronisation, it may temporarily store operational care information locally on the device. That may include visit information, client names and alerts, care tasks, medication information, notes and forms, check-in and check-out data, and GPS evidence.
That local operational store is a device database used for offline queues and caches. This Privacy Policy does not claim that that database is encrypted. Authentication and session material is stored using the device’s secure storage facilities provided for that purpose.
Unsynchronised information can remain on the device across app restarts until it is uploaded or the offline store is cleared (for example on a clean sign-out where the app allows it).
Account closure requests
Invited users of the ISO Care mobile app can submit an in-app “Request account closure” request. That records a request for review of their login access. It does not immediately delete the login account, organisation membership, staff record, or historical care, visit, medication, note or audit information. Care organisations may need to retain those records for legal, regulatory, safeguarding or operational reasons.
This in-app request is separate from a manager ending employment on the web platform. You can also contact support@isocare.uk about personal-data rights. Erasure is not guaranteed where a lawful reason to retain information continues to apply.
Cookies, local storage and service telemetry
We use cookies and similar technologies that are needed to operate the service, including authentication and session cookies provided through our hosting and authentication platform (Supabase). We also use first-party local storage for limited interface preferences (for example remembering that a prompt was dismissed).
The website currently uses Vercel Speed Insights, which collects performance and vitals information about how pages load.
If we change how we use cookies, local storage or telemetry, we will update this Privacy Policy.
Who we share information with
We share personal information with service providers who help us operate ISO Care, only as needed for those services:
- Supabase — database, authentication and file storage.
- Vercel — website and web-application hosting, and Speed Insights.
- Resend — transactional email where that sending is enabled in the relevant environment (for example invitations, owner setup messages, trial-application alerts and invoice emails). Password-reset messages are sent using our authentication provider’s email facilities.
- Expo / EAS — mobile application tooling and build infrastructure.
We may also share information with professional advisers, or if required by law, a regulator or a competent authority, or in connection with a reorganisation of our business.
Authorised users within a customer organisation can see information according to that organisation’s roles, permissions and branch settings. Invited family members see only the family-safe information the organisation has configured for them.
International transfers
Some of our service providers may process personal information outside the United Kingdom. ISO Care’s production Supabase database is hosted in West EU (Ireland) (AWS region eu-west-1). Web hosting compute for ISO Care is configured in Dublin. Providers such as Resend and Expo/EAS may involve processing outside the UK. This policy does not claim that all personal data, or all processing by our service providers, remains in the United Kingdom or the European Economic Area.
Where personal data is transferred outside the UK, Offboard HQ Ltd will use appropriate safeguards required by applicable UK data-protection law (for example the UK’s international data-transfer mechanisms, or other safeguards permitted at the time).
Retention
We do not apply a single universal retention period to all personal information. Information is retained according to:
- the purpose for which it was collected;
- customer instructions where Offboard HQ Ltd acts as processor;
- applicable legal, regulatory and accountability obligations;
- contractual requirements; and
- the need to establish, exercise or defend legal claims where applicable.
Certain financial, care, security and audit records may need to be retained despite an erasure request where there is a lawful reason to do so.
Trial applications are retained so we can review, approve or reject them and keep a record of that process.
Security
We implement technical and organisational measures appropriate to the nature of the service. These include organisation (tenant) isolation, database row-level security, role and section permissions, branch-scoped access for office users, authenticated access, audit logging of relevant actions, and server-side handling of privileged credentials. Communication with the hosted service is designed to use encryption in transit.
No method of transmission or storage is completely secure. We do not promise absolute security. Offboard HQ Ltd does not claim ISO 27001, SOC 2, Cyber Essentials, HIPAA or “GDPR certification” in this policy.
Data-protection rights
Depending on the circumstances, UK GDPR may give you the following rights:
- Access — to obtain a copy of personal information we hold about you.
- Correction — to have inaccurate personal information corrected.
- Erasure — to request that personal information is deleted.
- Restriction — to request that we limit how we use personal information in certain circumstances.
- Objection — to object, where applicable, to processing based on legitimate interests (including profiling related to that processing) or to processing for direct marketing. If you object, we will stop that processing unless we have a compelling legitimate ground that overrides your interests, rights and freedoms, or the processing is needed for legal claims.
- Portability — to receive personal information you provided to us, in a structured, commonly used and machine-readable format, and to transmit it to another controller, where that right applies.
- Withdrawal of consent — where processing is based on consent, to withdraw that consent at any time.
These rights are not absolute. For example, we or a care organisation may need to retain information to comply with the law or to establish, exercise or defend legal claims, or because another lawful ground continues to apply.
For processing that Offboard HQ Ltd carries out as controller (for example a trial request you submitted to us), contact support@isocare.uk. We will consider valid rights requests, including access, erasure and portability requests made through that address.
For care, staff or family information controlled by a care organisation, you should normally contact that organisation first. Offboard HQ Ltd will assist customer organisations with rights requests where required in our role as processor.
Care-organisation-controlled information
If you are a client, family member or member of staff of a care organisation that uses ISO Care, that organisation generally decides what is recorded about you and who in their team can see it. Their own privacy notice, and your relationship with them, will usually be the starting point for questions about that information.
You can still contact us at support@isocare.uk if you need help identifying the organisation or raising a request. We will not treat a request about another organisation’s care records as a request we can decide in their place.
Vulnerable people
ISO Care is a business service for care providers. It is not aimed directly at children or vulnerable adults as consumers, and we do not seek to collect their information through the public website.
Care organisations may enter personal information about the people they support, including children or vulnerable adults, because that is necessary to provide and manage care. Responsibility for the lawfulness of that recording, and for informing those individuals or their representatives as required, sits primarily with the care organisation as controller of that information.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example if we change how the service works, add a payment provider, or need to reflect legal or operational developments. The “Last updated” date at the top of this page will change when we do. Please review this page periodically.
Contacting us
For privacy questions about Offboard HQ Ltd’s own processing, email support@isocare.uk. Sales enquiries: sales@isocare.uk. You may also use our Contact page.
Complaints
You have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection. The ICO’s website is https://ico.org.uk/. We would welcome the chance to address your concern first at support@isocare.uk.