1. Who We Are
Otas Supported Living (“we”, “our”, “us”) is a CQC-registered care provider based at 21 St. Helens Road, Sheerness, ME12 2QY. We are committed to protecting and respecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data Controller: Otas Supported Living
Contact: info@otassupportedliving.com | 01795 394 942
2. Information We Collect
We may collect and process the following personal data:
- Identity Data: Full name, date of birth, gender
- Contact Data: Address, email address, telephone numbers
- Health & Care Data: Medical history, care needs assessments, care plans, and medication records (for service users)
- Employment Data: CV, qualifications, references, DBS check results (for job applicants and employees)
- Enquiry Data: Information you provide when contacting us via our website forms, email, or telephone
- Technical Data: IP address, browser type, and usage data collected through cookies when you visit our website
3. How We Use Your Information
We use your personal data for the following purposes:
- To provide, manage, and improve our care services
- To respond to enquiries and arrange care assessments
- To process job applications and manage employment
- To comply with legal and regulatory obligations, including CQC requirements
- To communicate with families, health professionals, and local authorities involved in a service user's care
- To send you newsletters or updates where you have opted in
- To maintain the safety and security of our services
4. Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: Where you have given us clear consent to process your data (e.g., newsletter subscriptions, enquiry forms)
- Contract: Where processing is necessary for the performance of a contract with you (e.g., care service agreements, employment contracts)
- Legal Obligation: Where we are required by law to process your data (e.g., CQC regulatory requirements, safeguarding)
- Vital Interests: Where processing is necessary to protect someone's life (e.g., emergency health situations)
- Legitimate Interests: Where we have a legitimate business interest that does not override your rights
5. Who We Share Your Data With
We may share your personal data with:
- NHS bodies, GPs, district nurses, and other healthcare professionals involved in your care
- Local authority social care teams and commissioners
- The Care Quality Commission (CQC) as required by regulation
- Safeguarding authorities where there is a concern about abuse or neglect
- Our employees and carers on a need-to-know basis to deliver your care
- DBS checking services (for employment purposes)
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Care records: Retained for a minimum of 8 years after the last entry, in line with CQC guidance
- Job applications (unsuccessful): Retained for up to 6 months, then securely destroyed
- Employee records: Retained for 6 years after employment ends
- Enquiry data: Retained for up to 12 months unless you become a service user
- Newsletter subscriptions: Retained until you unsubscribe
7. Your Rights
Under UK GDPR, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your data where there is no compelling reason for its continued processing
- Right to Restrict Processing: Request that we limit how we use your data
- Right to Data Portability: Request transfer of your data to another organisation
- Right to Object: Object to processing based on legitimate interests or direct marketing
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
To exercise any of these rights, please contact us at info@otassupportedliving.com or call 01795 394 942.
8. Data Security
We take the security of your personal data seriously. We have implemented appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or destruction. These include:
- Secure, password-protected electronic systems
- Locked storage for paper records
- Staff training on data protection and confidentiality
- Access controls limiting data access to authorised personnel only
- Regular review of data protection practices
9. Cookies
Our website uses cookies to improve your browsing experience. Cookies are small text files stored on your device. We use:
- Essential cookies: Required for the website to function correctly
- Analytics cookies: Help us understand how visitors use our website so we can improve it
You can manage your cookie preferences through your browser settings. Disabling cookies may affect the functionality of our website.
10. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
We would appreciate the opportunity to address your concerns before you contact the ICO. Please reach out to us first at info@otassupportedliving.com.
11. Contact Us
If you have any questions about this privacy policy or how we handle your personal data, please contact us:
Otas Supported Living
21 St. Helens Road, Sheerness, ME12 2QY
01795 394 942 | 07882 710 854
info@otassupportedliving.com