Current Vacancies Menu

Privacy Policy

collection of happy clients

Iris Care is an independent social care, healthcare, and specialist education provider. We employ over 1,700 employees and cover a range of expertise and specialisms in England and Wales.

In Wales we provide care, support and expertise through Beechwood College, Ocean Community Services, ALP, Awelon and in three hospitals – Heatherwood Court Hospital, St Peters Hospital and Pinetree Court Hospital. In England, our offering includes Supported Living services and Specialist Nursing Care at Pirton Grange.

This privacy notice applies to Iris Care and its subsidiary services.

What is a Privacy Notice?

A Privacy Notice is a statement by Iris Care that advises how we collect, use, retain and disclose the personal information which we hold. This privacy notice is part of our commitment to ensure that we process personal information/data fairly and lawfully.

Why issue a Privacy Notice?

Iris Care recognise the importance of protecting personal and confidential information in all that we do, and take care to meet our legal and regulatory duties. This notice is one of the ways we can demonstrate our commitment to being transparent.

This notice also explains what rights you have to control how we use your information.

How is information retained and kept safe?

To make sure your personal information is protected, we have a series of technical and administrative measures in place. Access is limited to only those who need access to it to provide services to you.

Information is retained in secure electronic and paper records and access is restricted to only those who need to know.

All members of staff are required to undertake annual data protection and confidentiality training, and our privacy and security guidelines are communicated to all employees.

It is important that information is kept safe and secure, to protect your confidentiality. Our guiding principle is that we are holding your information in strict confidence.

Accuracy and retention of personal information

Iris Care make it easy for you to keep your personal information accurate, complete, and up to date. If any of your information changes, please let us know so that we can update our records.

All records are destroyed in accordance with the Iris Care Schedule, which sets out the appropriate length of time each type of record is retained.

Can I access my information?

You are entitled to request access to your information, with some exemptions. For more information on how to access the information we hold about you, please contact us at the address below.

National Data Opt-Out

Iris Care review all our data processing on an annual basis to assess if the National DataOpt-Out applies. This is recorded in our Record of Processing Activities. All new processing is assessed to see if the National Data Opt-Out applies.

If any data processing falls within scope of the National Data Opt-Out, we use MESH to check if any of people using our service have opted out of their data being used for this purpose.

Privacy questions

If you have any questions or concerns about this Privacy Notice, or how we process your information, or if you would like to make a complaint about a possible data breach, please contact us:

Data Protection Officer (DataProtectionOfficer@iriscaregroup.co.uk)

Iris Care Group

Unit 1, Castleton Court, St Mellons, Cardiff CF3 0LT dpo@iriscaregroup.co.uk

We take data security extremely seriously and all such communications are examined, and replies issued where appropriate as soon as possible. If you are unsatisfied with the reply you receive, you may refer your complaint to the Information Commissioner’s Office (ico.org.uk)

Why and how we collect information about the people we support

We may ask for or hold personal confidential information which will be used to support delivery of appropriate care and treatment. This is to support the provision of high-quality care.

These records may include:

  • Personal information (such as name, address, date of birth, NHS number, NI number, next of kin).
  • Characteristics (such as ethnicity, language, nationality, country of birth).
  • Personal sensitive information (such as sexuality, religion, or beliefs, and whether you have a disability, allergies, or health conditions).
  • Safeguarding information.
  • Contact we have had (such as appointments and home visits).
  • Details of diagnosis, treatment, and care (including notes and reports about your health and well-being).
  • Information from people who care for you and know you well (such as health professionals and relatives).
  • CCTV footage.
  • For students in our education settings, we also hold attendance information (such as sessions attended, number of absences and absence reasons).

This information assists staff involved to deliver and provide improved care and appropriate treatment plans to fully meet your needs. If you are subject to detention under the Mental Health Act or subject to a Mental Capacity Act order, we are legally required to hold this information.

Information is collected in several ways: referral from your commissioning team, from the service you may currently be using, and details from your GP, a relative or directly given by you.

How we use your information

  • To help inform decisions that we make about your treatment, care and or/education.
  • To ensure that your treatment is safe and effective.
  • To work effectively with other organisations, family, friends and carers who may be involved in your care.
  • To ensure our services can meet future needs.
  • To review care provided to ensure it is of the highest standard possible.
  • To ensure you are kept safe.

Additionally, for our students we use this data:

  • To support learning.
  • To monitor and report on progress.
  • To provide appropriate pastoral care.

Where an individual we are supporting is under the age of 18, the majority of information provided to us is mandatory, some of it can be provided to us on a voluntary basis. In order to comply with the law, we will inform you whether you are required to provide certain information to us or if you have a choice in this.

Who will the information be shared with?

We will only share your personal information with third parties where you have given your consent.

Where there are issues or concerns like the health and safety of yourself or others, we may be legally required to share your information with statutory organisations such as the Police and the Courts.

We will normally share information about you with other health and social care professionals so that you may receive the best quality care:

  • NHS Trusts, hospitals, and other bodies involved in your care.
  • General Practitioners (GPs).

You may be receiving (or receive in the future) care from other people, for example Social Care Services. We may need to share some information about you with them so we can all work together for your benefit, if they have a genuine need for it, or we have your permission.

Therefore, we may also share your information with:

  • Your GP and NHS organisations.
  • Social care services.
  • Education services.
  • Local authorities.
  • External regulators (including Care Quality Commission, Care inspectorate Wales, Healthcare Inspectorate Wales, and Estyn).
  • Safeguarding teams.
  • Voluntary and private sector providers working with Iris Care Group.
  • Services, families, friends or carers that may provide you with support after you leave us.

Where information is shared with non-care professionals, such as families or friends, this will only be done after a review to ensure all statutory guidelines have been followed to ensure that the data sharing is essential to your future care.

Personal information may also need to be shared with third parties to make arrangements for the funding and/or payment of services received.

Our education settings also share data with the Department for Education (DfE) and Estyn on a statutory basis. This data sharing underpins funding and educational attainment policy and monitoring.

Why and how we collect personal information about staff.

You may be asked to provide your personal information at any time. We may combine it with other information to provide and improve our services as an employer. You are not required to provide the personal information that we may request, but, if you chose not to do so, in many cases we will not be able to provide you with a job.

Why and how we collect information.

Here are some examples of the types of personal information we may collect and how we may use it:

  • Personal information (such as name, address, date of birth, next of kin).
  • Contact information (such as telephone number, email address).
  • Characteristics (such as ethnicity, language, nationality, country of birth).
  • Personal sensitive information (such as sexuality, religion or beliefs, trade union membership, and whether you have a disability, allergies, or health conditions).
  • Disclosure and Barring Service Information (including enhanced DBS details).
  • Biometric data for time and attendance (see below)
  • CCTV footage.

When you apply for a position, we will record your details including your name, postal address, telephone number, email address, educational and work history, referees, and contact preferences.

Before your appointment, all required right to work checks and a check with the Disclosure and Barring Service will be carried out. Details of these checks (or the results from them) will be retained on your HR record.

If you are successful in being appointed, and during your employment with us, we will retain your full employment record which will include your name, postal address, telephone number, email address, details of your next of kin, bank details (for the purposes of payments), educational and work history, training, appraisals, copies of any complaints, disciplinary or safeguarding matters.

Biometric data (time and attendance)

We use fingerprint recognition within our time and attendance system to confirm identity when recording working time. The system does not store full fingerprint images, only a secure template. This helps ensure accurate staffing records and supports the safe and effective delivery of care.

Use of biometric authentication is entirely optional. Staff can choose to use an alternative method, such as an ID card, without any disadvantage.

Biometric data is used only for time and attendance and is not shared outside of Iris Care.

Biometric data is deleted when you leave employment or if you opt out.

How we use your personal information

The personal information we collect and store about you allows us to facilitate the employment relationship we have with you.

Your personal information may be shared with various departments across the Group including:

  • Payroll.
  • Learning and Development.
  • Human Resources.
  • Information Technology.

Who we share your information with

We will only share your personal information with third parties where you have given your consent, or where there are issues or concerns like the health and safety of yourself or others, or where there is a legal requirement or responsibility to share the information.

Where necessary, we routinely share limited personal information with the following:

  • HMRC.
  • Pension providers.
  • External Regulators (including Care Quality Commission, Care inspectorate Wales, and Healthcare Inspectorate Wales).
  • Disclosure and Barring Service.
  • Training partners.
  • Approved suppliers of products and services for staff.

Subject Access Requests (SARs) 

Under GDPR, individuals have the right to request copies of the personal data we hold about them. This means that sometimes information that includes your name or details may be shared as part of someone else’s request.

When handling a SAR, we take steps to protect your privacy:

  • If you are a person we support, patient, or student, we will not share your personal information unless required by law. Your details will be redacted (removed) or anonymised before the records are shared.
  • If you are a staff member or visiting professional, your name may remain visible in records such as care notes or emails where it relates to your professional role. However, each request is reviewed individually, and details may be redacted if necessary.

Our Data Protection Officer (DPO) carefully assesses each request to balance the requester’s rights with your privacy.