Version 1.0 · Effective 21 May 2026 · Operated by Salstead Ltd
Salstead Privacy Policy
1. Who we are
Salstead is operated by Salstead Ltd (“Salstead”, “we”, “us”), registered in England and Wales, registered office 33 Midworth Street, Mansfield, NG18 1AT. Salstead is the data controller for personal data we collect about our customers, prospects and website visitors, and a data processor for personal data we handle on behalf of our care home customers. Contact us at dpo@salstead.com regarding any aspect of this policy or your personal data.
2. Scope
This policy explains what personal data we collect, how we use it, who we share it with, how long we keep it and what rights you have. It applies to the Salstead service at app.salstead.com and related marketing sites. Where Salstead processes personal data on behalf of a care home, the care home is the data controller and our Data Processing Agreement governs the relationship.
3. Personal data we collect
3.1 Care home staff (workers)
- Identification: name, date of birth, photograph, National Insurance number.
- Contact: postal address, email, phone, next of kin.
- Employment: role, hours, hourly rate, bank account details for payroll.
- Regulatory: DBS check status, right-to-work documents, NMC / Social Care Wales / SSSC registration where relevant, training certificates.
- Activity: shifts worked, timesheets, in-app messages, audit logs.
3.2 Care home customer users
- Name, work email, role, organisation, account activity, audit logs.
3.3 Residents and family members (only where modules are enabled)
- Limited personal data such as name, room number, care notes and family contact details, processed strictly on the care home’s instructions as data processor under our DPA.
3.4 Website visitors and prospects
- IP address, browser type, pages viewed, marketing form submissions, email correspondence.
4. Why we use your personal data and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Providing the Salstead service to care home customers | Contract (Article 6(1)(b)); legitimate interests for non-contracting individuals. |
| Processing staff payroll under PAYE | Legal obligation (Article 6(1)(c)) and contract. |
| Verifying right to work and DBS status | Legal obligation; legitimate interests in workforce compliance. |
| Special category data (occupational health) | Article 9(2)(b) employment, social security and social protection law. |
| Sending operational emails and alerts | Contract; legitimate interests. |
| Marketing to prospects | Consent (where required) or legitimate interests, with a clear opt-out. |
| Security, fraud prevention and audit logging | Legitimate interests and legal obligation. |
5. Who we share it with
We share personal data with carefully selected sub-processors that help us deliver the service. The current list of sub-processors is in Schedule 3 of our DPA. Examples include:
- Supabase / AWS (eu-west-2): hosting and database.
- Vercel: application hosting and CDN.
- Stripe and GoCardless: payment processing.
- SendGrid: transactional email.
- Twilio: SMS notifications.
- Sentry: error reporting.
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
6. International transfers
Primary processing takes place in the United Kingdom or European Economic Area. Where a sub-processor processes data outside the UK or EEA, we rely on an appropriate transfer mechanism, including the UK International Data Transfer Addendum (IDTA), the EU Standard Contractual Clauses, adequacy decisions, or equivalent safeguards.
7. How long we keep it
- Worker employment records: 7 years after end of employment (HMRC requirement).
- Payroll and tax records: 7 years (HMRC requirement).
- DBS check status: retained for the period required by the care home customer and applicable regulation.
- Audit logs: 24 months.
- Marketing contacts: until you unsubscribe or 24 months after last engagement, whichever is sooner.
- Customer data on customer instruction: per the DPA and the customer’s documented retention rules.
8. Your rights
Under UK GDPR you have the right to: access your data; request rectification; request erasure; restrict or object to processing; request data portability; and not be subject to solely automated decisions with legal effect. You can exercise most of these rights in-app at Settings → My data, or by emailing dpo@salstead.com. We will respond within 30 days.
If you are dissatisfied with our response you may complain to the UK Information Commissioner’s Office at ico.org.uk.
9. Security
We use industry-standard technical and organisational measures: TLS 1.2+ in transit, AES-256 at rest, role-based access control with Supabase row-level security, application-layer encryption for sensitive identifiers (NI numbers, bank details), audit logging, vulnerability management and an incident response plan.
10. Children
Salstead is not intended for use by children under 18. We do not knowingly collect personal data from children.
11. Changes
We may update this policy from time to time. The version and effective date appear at the top. Where changes materially affect you we will notify the account owner by email at least 30 days before the change takes effect.
12. Contact
Data Protection contact: dpo@salstead.com. Postal: Data Protection Officer, Salstead Ltd, 33 Midworth Street, Mansfield, NG18 1AT.