Skip to main content

Privacy Policy

How we collect, use, and protect your personal information.

Last updated: February 2026

1. Introduction

Hearthstone Supported Living Ltd ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data Controller: Hearthstone Supported Living Ltd, Company Number 17028948, registered at 49 Noakes Avenue, Chelmsford, CM2 8EN.

Data Protection Contact: Contact us through our contact page

2. Information We Collect

We may collect and process the following categories of personal data:

2.1 Service Users and Prospective Service Users

2.2 Referrers and Professionals

2.3 Job Applicants and Employees

2.4 Website Visitors

3. How We Use Your Information

We use personal data for the following purposes:

PurposeLegal Basis (UK GDPR)
Providing care and support servicesContract performance; Vital interests; Legal obligation
Processing referrals and assessmentsLegitimate interests; Consent
Medication management and health monitoringVital interests; Legal obligation
Safeguarding and duty of careLegal obligation; Vital interests; Public interest
Regulatory compliance (CQC, local authority)Legal obligation
Recruitment and employmentContract performance; Legal obligation
Responding to enquiriesLegitimate interests; Consent
Quality improvement and auditLegitimate interests
Complaints handlingLegal obligation; Legitimate interests

4. Special Category Data

As a care provider, we process special category data including health information, which requires additional safeguards. We process this data on the basis of:

5. Who We Share Data With

We may share personal data with:

We will never sell your personal data to third parties. We do not transfer personal data outside the UK without appropriate safeguards.

6. Data Retention

We retain personal data only for as long as necessary:

7. Data Security

We implement appropriate technical and organisational measures to protect personal data, including:

8. Your Rights

Under UK GDPR, you have the following rights:

To exercise any of these rights, please contact us through our contact page. We will respond within one month.

9. Complaints

If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO):

We would appreciate the opportunity to resolve any concerns directly first. Please contact us before raising a complaint with the ICO.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "last updated" date. We encourage you to review this page periodically.

11. Contact Us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us:

Hearthstone Supported Living Ltd
49 Noakes Avenue, Chelmsford, CM2 8EN
Contact us through our contact page