Privacy notice
How personal information and care records are handled.
Company details and legal review are outstanding. These pages do not certify legal or clinical compliance.
Who is responsible
WealHeal is being developed for the intended company WealHeal UK Limited. Incorporation, company number, registered office and privacy contact have not yet been confirmed. This is a pre-launch draft, not a completed statutory company disclosure. The care provider normally acts as controller of service-user and staff care records; WealHeal acts as its processor. Account and commercial administration require a separate controller assessment.
Information processed
Account email and authentication details, organisation membership, service-user identity and care type, care plans, medication entries, incidents, family updates, supervision records and audit events may be processed. Care records can include health information and other special-category data. Do not add information that is unnecessary for care.
Purposes and lawful bases
Information supports account access, organisation operations, care documentation, security and agreed customer support. The provider must determine and document its Article 6 lawful basis and Article 9 condition, retention schedule and any required Appropriate Policy Document. A cookie preference is not consent to process health information. WealHeal must complete its own lawful-basis assessment for account data before commercial launch.
Hosting and international transfers
The connected database is hosted in Ireland (EU). UK adequacy arrangements can support transfers to the EEA, but do not by themselves establish compliance for every onward transfer. Application delivery, authentication, email and any future AI processing must be assessed separately. No assumption is made that every subprocesser or inference location is Ireland.
Retention and rights
Providers must set documented retention periods, legal holds and an authorised deletion process. A universal care-record deletion date or 30-day backup retention has not been verified. Individuals may ask their care provider about access, rectification, restriction, objection, portability or erasure where applicable. Rights are not absolute. Complaints may be raised with the Information Commissioner’s Office at ico.org.uk.
Automated decisions and AI
Inspection rehearsal sends approved evidence identifiers and metadata plus the user’s management response to Lovable AI. Voice transcription sends a permission-confirmed recording to Lovable AI; the app does not store the audio, and transcripts are saved only by an explicit action. Both tools are restricted to non-identifiable input while privacy and supplier assessments remain outstanding. Do not send identifiable personal or health information until lawful basis, processor terms, transfer safeguards and a DPIA are assessed. AI never makes autonomous clinical or safeguarding decisions and outputs require human review.
Advisers, benchmarking and portable declarations
Advisers receive only manager-published non-identifiable briefs through revocable, time-limited grants. Anonymous benchmarking requires organisation opt-in and a minimum of ten opted-in organisations; only evidence-domain coverage is aggregated, and disclosure-risk review remains outstanding. Passport and commissioner declarations can be shared through revocable 30-day bearer links after manager publication. Anyone holding a link can read its limited declaration until expiry or revocation. Staff passport sharing requires staff confirmation of consent; no DBS or criminal-history information should be included. These are provider-reviewed declarations, not independently verified credentials or quality certificates.