Privacy notice
Last updated 7 August 2026
1. Controller and contact
CareProNet is the data controller for the personal data described here. Contact our data protection team at privacy@carepronet.org. We are registered with the Information Commissioner’s Office (ICO registration number pending publication).
2. What we collect
- Account data: first and last name, email address, member type, password (stored only as a hash), and the consents you gave at sign-up.
- Profile data: role, professional registration details, employer, location, skills, languages, qualifications, references and anything else you choose to add.
- Verification data: DBS details, right-to-work evidence, registration certificates and, for organisations, regulator registration and rating information.
- Activity data: posts, comments, reactions, connections, messages, applications, referral interest and event attendance.
- Technical data: device and browser information, IP address, and aggregated product analytics.
3. Why we use it and our lawful basis
- Contract: to create your account, run your profile, deliver connections, messaging, referrals and paid subscriptions.
- Legitimate interests: to verify members, keep the network safe, moderate content, prevent fraud and improve the product.
- Consent: to send optional product and sector updates, and to set non-essential analytics cookies. You can withdraw consent at any time.
- Legal obligation: to meet tax, accounting and safeguarding requirements.
Verification documents can include criminal-record information. We handle that under the safeguarding and employment-suitability conditions in UK data protection law, restrict access to trained reviewers, and store documents in private storage reachable only through short-lived signed links.
4. What other people can see
Your name, headline, role, location and verification badge appear on your public profile. Contact details, documents, DBS and right-to-work information, messages and application history are never shown publicly. You control which optional fields are published.
5. Sharing
We share data with processors who run the service on our behalf: hosting and database providers, email delivery, payment processing and product analytics. They act on our instructions under written terms. Where data leaves the UK we rely on adequacy regulations or the International Data Transfer Addendum. We never sell personal data.
6. How long we keep it
- Account and profile data: while your account is open.
- Closed accounts: 30 days, then deleted or anonymised.
- Verification documents: up to 12 months after a decision, then deleted.
- Billing records: 7 years, to meet tax law.
- Moderation and audit records: up to 3 years.
7. Your rights
You can access, correct, delete, restrict or object to our use of your data, ask for portability, and withdraw consent. Export your data or close your account from Settings, or email us. You can complain to the ICO at ico.org.uk, though we would like the chance to put things right first.
8. Cookies
We set essential cookies to keep you signed in and to protect the service — these cannot be switched off. Analytics cookies help us understand which features are used, and only load after you accept them in the cookie banner. Declining leaves all functionality intact.
9. Security
Data is encrypted in transit and at rest. Access to member data is scoped by row-level database policies, privileged actions are logged to an audit trail, and we run automated security scans against every release.