
SEA Support Services - Privacy Policy
Controller identity and contact details
SEA Support Services Ltd is the data controller for the personal information described in this policy. We are responsible for deciding how personal information is used and for ensuring that it is managed lawfully, fairly, and transparently. Individuals can contact the Data Protection Officer using the contact details in section 6 of this policy.
Full individual Rights
Individuals may have the right to be informed, access their personal information, request correction, request erasure, restrict processing, object to processing, request data portability, withdraw consent where consent is used, and challenge automated decision-making or profiling where applicable. Some rights may be limited where we are required to keep information by law, for safeguarding, for legal claims, or for health/social care records.
1. What information do we collect about you
STAFF DATA
We process personal information only where we have a lawful basis under Article 6 of the UK GDPR. Depending on the purpose, this may include processing necessary for a contract, compliance with a legal obligation, legitimate interests, vital interests, or the provision of health or social care services. Where we rely on consent, this will be specific, informed, freely given and capable of being withdrawn.
Information we collect
We collect information for the purposes of recruiting staff to take on assignments at client premises. We start to collect this data at point of application.
The information we need for this are, for example:
· Application Form - Name and address, date of birth, telephone numbers and email address.
· Qualifications for the role applied for
· Next of Kin contact information to include telephone numbers and email address.
· Two references
· Bank account details
· Health Questionnaire
· Proof of address
· National Insurance number
· Photographic ID
· Work permit (if applicable)
· DBS details if issued with one.
· Driving Licence and proof of Insurance (business used) and MOT for vehicle.
· Details of any driving convictions.
· Photograph for ID purposes
· Equal Opportunities monitoring which includes hearing status, gender, religion and nationality.
Special category data and criminal offence data
Some information we process is special category data, including health information, disability-related information, religious beliefs, equality monitoring information, medication information, safeguarding information and information about care needs. We will only process this information where we have both a lawful basis under Article 6 of the UK GDPR and a special category condition under Article 9 of the UK GDPR, such as employment obligations, health or social care provision, safeguarding, vital interests, substantial public interest, or explicit consent where appropriate.
Where we process DBS information, criminal conviction information or driving conviction information, we will do so only where permitted by UK data protection law and where necessary for safer recruitment, legal/regulatory compliance, safeguarding, insurance, or suitability checks.
Once in employment with SEA Support Services, we also collect information on, for example;
· Training undertaken
· Video/photo consent
· Health updates and sick notes
· Risk assessments
· Disciplinary and Capability proceedings
· Supervision sessions
· Sickness and Annual Leave taken
· Lateness
· Emergency leave and other absence
· Accident Reporting
Processing purposes and lawful basis table
Data / activity | Purpose | Lawful basis / Condition |
Recruitment and employment records | Recruitment, contracts, payroll, supervision, training and workforce management | Contract, legal obligation, legitimate interests; Article 9 employment condition where health/equality data is used |
DBS and conviction information | Safer recruitment, safeguarding and suitability checks | Legal obligation, legitimate interests or substantial public interests; criminal offence data condition to be specified |
Client care and support records | Assessment, care planning, risk management, service delivery, safeguarding and reviews | Contract, legitimate interests, vital interests and/or health or social care provision; Article 9 health or social care condition |
Emergency contact / next of kin data | Contacting appropriate people in an emergency or where necessary for care/support | Vital interests, legitimate interests or contract depending on circumstance |
Photos and videos | ID, care records, training or promotional use where applicable | Consent where optional; contract/legal obligation only where genuinely necessary for ID or records |
Financial and invoicing records | Payroll, invoicing, accounting, audit and tax compliance | Contract and legal obligation |
Why we need information about staff
We collect your personal information for several reasons; to ensure that you are suitable to provide services to our clients, to ensure your own safety and that of the clients and to monitor work performance and training needs. We also process information in relation to your pay and holiday entitlement to meet with statutory requirements.
How we store this data
All data collected will be stored digitally on secure computers and paper files will be stored in locked cabinets.
Limited data such as name, address, e-mail, telephone number and next of kin contact details will be shared with other staff and stored on the works mobile phone.
What rights candidates have to access their data
Candidate information is held in a transparent and lawful manner and can be accessed on request at any time in writing. You will receive this information within one month of SEA Support Services receiving your request.
You have the right to object if you feel that information has been recorded incorrectly. This will be reviewed by a Senior Manager within SEA Support Services.
The right to erasure (staff and candidates)
Individuals have the right to request the deletion of their personal data in certain circumstances. This right is not absolute.
Where a staff member or candidate leaves SEA Support Services Ltd, we will securely delete or anonymise personal information that is no longer required. However, we may retain information where this is necessary to comply with legal, regulatory or contractual obligations, including employment law, payroll and tax requirements, safeguarding, insurance, complaints, audits or the establishment, exercise or defence of legal claims.
Where a request for erasure is received, we will assess it on a case‑by‑case basis and explain the outcome to the individual.
The reasons why we are storing candidate data
The reason we hold personal data on our candidates is so we can lawfully operate a Social Care and employment business for the purposes of supplying staff to clients.
We have an obligation to our clients to provide staff with the correct qualifications and experience to carry out the duties required. We are legally obliged to ensure that staff who work with vulnerable clients in the community and residential settings have an up-to-date DBS.
How long we keep this data
We will keep personal data for 7 years from the day the staff member leaves the organisation. We have to keep all payroll data for a period of 7 years from the last date the candidate worked.
Who we share this data with
By consenting to using your personal data for the purposes of employment we will share your information with SEA managers (Seniors and Team Leaders) and third parties for the purposes of work assignments only. This information will never include information such as bank account details but will include information to show your suitability for the role.
We will only give full information if requested to do so by Law Enforcement Agencies and Government bodies.
We will also share information with our payroll processor, accountant and HMRC for pay purposes.
We will never share or sell your data for marketing purposes to any third parties unless you have provided consent or asked us to do so.
Sharing is limited to what is necessary and proportionate.
CLIENT DATA
The following client information is collected
· Name, address, date of birth and contact details
· Initial Enquiry Form
· Consent forms
· Next of kin information and information about family members including their contact information and availability
· Type of service required and frequency of support
· Assessment of Need/Support Plan and any reviews that have taken place
· Outcomes reports
· Client Meeting minutes
· Risk Assessments
· Health needs including information about personal care and mental health needs.
· Medication log sheets and details of regular medication taken
· Day notes and reports of any incidents
· Client financial information and invoicing details where applicable
· Equal Opportunities monitoring which includes hearing status, gender, religion and nationality.
· Staff compatibility assessments
· Person centred training needs for staff
· Contact details for professionals involved in care
· Accident Reporting
· Photo/Video consent form
· Safeguarding reports
Why we need information about clients
We collect your personal information for several reasons; to provide you with a quote for services, to ensure that services are meet individual needs, to ensure safety and wellbeing and to make sure that we are responsive to your needs.
How we store this data
§ We will store client details and records of services including day notes, risk assessments, support plans and reviews on cloud-based software.
§ The account invoice details are stored on the computer within PASS. Paper records of account documents are stored in a locked cabinet.
§ All computer digital records are protected with several layers of software to protect from cyber-attacks and virus attacks.
§ All digital records are password protected.
§ Contact details of clients and family members/relevant others is stored on the staff mobile phone for emergency contact purposes.
If you have not used our services for five (5) years, then we will contact you and request whether you would like your information to be discarded or if you would like to remain on the database system. If we do not obtain a response, then all records will be deleted. Certain information may be retained where we are required by law to do so.
What rights clients have to access their data
Client information is held in a transparent and lawful manner and can be accessed on request at any time in writing. This information will be provided within one month of the request in writing. You have the right to object if you feel that information has been recorded incorrectly. This will be reviewed by a Senior Manager within SEA Support Services.
The right to erasure (clients)
Clients have the right to request the deletion of their personal information in certain circumstances. This right is not absolute and does not apply where we are required to retain information for lawful reasons.
In adult social care, some records must be retained to ensure safe care, safeguarding, continuity of support, regulatory compliance, inspection purposes, complaints handling, or legal obligations. Where this applies, we will not erase relevant records but will ensure they are stored securely and accessed only where necessary.
All requests for erasure will be considered on a case‑by‑case basis, and we will clearly explain our decision to the individual.
The right for client data to be transferred
A client has the right to ask for the transfer of all personal data to an alternative service provider when they stop using SEA Support Services.
The reasons why we are storing client data
The reason we hold personal data on our clients is so we can ensure that services are provided to meet individual needs, and that staff and clients are kept safe and well cared for. We are also required to keep information for inspection purposes.
How long we keep this data
We will not keep personal information for longer than necessary. Retention periods will depend on the type of record, legal/regulatory requirements, safeguarding needs, limitation periods and health/social care records guidance. Records will be reviewed at the end of the relevant retention period and securely destroyed or retained only where there is a documented lawful reason.
Who we share this data with
§ Contact details are entered on to a database and used to contact you by telephone, e-mail and post.
§ Client contact details are also stored onto a password-protected mobile phone. Staff who manage this phone will have access to this information.
§ Contact details and a pen picture are sent to all staff that are booked onto shifts with clients.
§ PASS software is used for all rotas including information about which staff have been booked.
§ Information may be shared with professionals such as health workers, social workers, commissioners and other related personnel on a need-to-know basis. Where appropriate, we will seek consent for information sharing. However, information may also be shared without consent where necessary for safeguarding, care provision, vital interests or legal/regulatory obligation, and this will be reviewed with your keyworker annually. We will not share unnecessary information.
§ From time to time, we may share your information with government bodies even if you have not consented for us to do so. This will only be in situations when your safety and wellbeing is at risk, or you place others at risk as a result of your behaviour.
§ Administrative staff within the office will have access to contact details and support package for financial invoicing purposes.
§ We will never share or sell your data for marketing purposes to any third parties unless you have provided consent or asked us to do so.
Where information comes from
We may collect personal information directly from staff, candidates, clients and their representatives. We may also receive information from family members, next of kin, referees, health professionals, social workers, commissioners, local authorities, regulators, safeguarding bodies, payroll providers, accountants and other organisations involved in recruitment, employment, care or safeguarding.
Information Security
We work hard to keep your data safe. We use an appropriate combination of technical and organisational measures to always ensure as reasonably possible the confidentiality integrity and availability of your information. If you have a security related concern, please contact us using the contact details at the end of this policy.
CQC record‑keeping requirements
In line with Care Quality Commission (CQC) Regulation 17 (Good governance), SEA Support Services Ltd securely maintains accurate, complete, detailed and contemporaneous records for each person using the service. This includes records of care and support provided, risk assessments, decisions made, reviews, incidents, safeguarding matters and communications with relevant professionals.
We also securely maintain staff employment records and records relating to the management, quality, safety and governance of the regulated activity. Records may be paper‑based or digital and will be stored, accessed, shared and disposed of securely in line with data protection law, health and social care records guidance and our internal policies.
2. Access to your information and correction
You have the right to request a copy of the information we hold about you. We will provide you with this information within one month of receiving the request and verifying your identity.
You also have the right to contact us if you believe your personal information is incorrect or if you believe we are no longer entitled to use your personal data. If you have any questions about how we use your personal information, please contact us using the details provided at the end of this policy.
3. Retaining your data
SEA Support Services and the information we collect about you are subject to various regulatory and legislative requirements. We will endeavour not to keep your personal information for longer than we have to for us to fulfil our obligations to you.
Where it is not possible for us to delete your data, we will ensure the appropriate security and organisational measures are put in place to protect the use of your data.
4. Data Breach Procedures
1. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the Information Commissioner’s Office in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification is not made to the ICO within 72 hours, it shall be accompanied by reasons for the delay.
Affected individuals will be informed without undue delay where a breach is likely to result in a high risk to their rights and freedoms. Add an internal requirement that all staff report suspected breaches immediately to the Data Protection Officer or data protection lead.
The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
The notification referred to in paragraph 1 shall at least:
· Describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned.
· Communicate the name and contact details of the Data Protection Officer or other contact point where more information can be obtained.
· Describe the likely consequences of the personal data breach.
· Describe the measures taken or proposed to be taken by the controller to address the personal data breach, including where appropriate, measures to mitigate its possible adverse effect.
· Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue delay.
· The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.
· Data breaches to be reported to ICO 0303 123 1113 Option B
Security safeguards for mobile phones and remote access
Where information is stored or accessed on mobile phones, laptops or remote systems, access must be limited to authorised staff, protected by strong passwords or biometric access, kept to the minimum necessary, and subject to secure deletion, remote wipe or access removal when no longer required. Staff must follow the BYOD, confidentiality, secure storage and cyber security policies.
5. Complaints
We work hard to ensure that your personal information is treated safely and securely. However, if you have a complaint write to us using the contact details at the end of this policy or talk to a member of the staff team. You also have the right to complain to the Information Commissioners Office, via their website ico.org.uk/make-a-complaint or contact number 0303 123 1113.
6. Who to contact in relation to processing of personal information
If you would like to discuss anything in relation to this policy or how we handle your personal information you can contact the
Data Protection Officer
SEA Support Services Ltd,
1-5 The Downs,
Altrincham,
Cheshire
WA14 2QD
Related Policies;
1. Confidentiality Policy
2. Archiving policy
3. Duty Policy
4. Computer email and internet usage policy
5. BYOD Policy
6. Secure Storage and handling policy
7. Service user’s contract
8. Staff contract
9. Cyber security
SEA Support Services Ltd is committed to complying with the UK General Data Protection Regulation, the Data Protection Act 2018 and other applicable data protection and health/social care records requirements.”
Contact Us
If you have questions or concerns about the information in this Privacy Policy, our handling of your personal information, or your choices and rights regarding such use, please do not hesitate to contact us at:
SEA Support Services Ltd
1-5 The Downs Altrincham Greater Manchester GB WA14 2QD
marketing@sea-supportservices.co.uk