Privacy Policy

Last updated: 9 July 2026

CareOps ("we", "us", "our"), operated by FORGEAI STUDIO LTD (trading as NovaStack), is committed to protecting the privacy of all users of our technology platform that connects independent carers, recruitment agencies and care providers.

1. Who we are

CareOps is a SaaS product provided by FORGEAI STUDIO LTD (trading as NovaStack), a company registered in England and Wales. We act as a data processor on behalf of our customers (agencies, recruiters and care providers) for personal data they upload, and as a data controller for account/billing data.

2. Information we collect

  • Account data: name, email, phone, role, employer.
  • Operational data: shift and opportunity postings, offers, availability, allocations, and in-platform messages.
  • Compliance data: DBS check details, professional registrations (e.g. NMC/HCPC where applicable), right-to-work documents, training certificates.
  • Photographs: profile photos.
  • Technical data: IP address, browser type, device info, log files.

3. How we use your information

  • To provide and maintain the service.
  • To record and surface identity, DBS/professional registration and right-to-work information provided by users — see our Terms & Conditions for who is responsible for verification.
  • To process platform subscription billing and generate invoices for platform usage.
  • To send service notifications and compliance reminders.
  • To meet legal and regulatory obligations.

4. Lawful basis (UK GDPR)

We rely on: (a) contract — to deliver the service; (b) legal obligation — to retain care-compliance and regulatory records; (c) legitimate interests — to operate, secure and improve the platform; (d) consent — for optional marketing.

5. Sharing

We share data only with: the agency, recruiter or provider you're connected to on the platform (the tenant); our sub-processors under contract — Supabase (hosting/database), Stripe (payments), Lovable (hosting/email) and Cloudflare (CDN), as listed in our UK GDPR Statement; and authorities where legally required (CQC, police). We never sell personal data.

6. Retention

Operational records are retained for the lifetime of your account plus a reasonable period thereafter to meet contractual and regulatory recordkeeping obligations. Compliance documents are retained per CQC and applicable regulatory guidance.

7. Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, and to lodge a complaint with the ICO (ico.org.uk).

8. Security

Data is encrypted in transit (TLS 1.2+) and at rest. Access is role-based and audit-logged. We use row-level security to ensure tenants can only access their own data.

9. Contact

Data Protection Officer: support@careopsuk.com