CRIS (“the App”) is a professional workforce and record-keeping application provided by CRIS Care Technologies Ltd (“CRIS”, “we”, “us”, “our”) for use by the staff of children’s residential care providers. This policy explains what personal data the App handles, why, and the rights available to individuals under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who is responsible for your data (controller and processor)
CRIS is supplied to children’s residential care organisations under a contract. In most cases:
- Your employing care organisation (the children’s home or care provider that issued your account) is the data controller. It decides what records are kept about staff and about the children in its care.
- CRIS Care Technologies Ltd acts as a data processor, providing and hosting the software and processing data only on the documented instructions of the controller.
Where CRIS Care Technologies Ltd determines the purposes of processing (for example, managing your app account and securing the service), we act as a controller for that limited processing.
If you have questions about how your care organisation uses your data, contact that organisation. For questions about the App itself, contact us using the details in section 11.
2. Personal data we handle
Depending on your role, the App may process:
- Account and identity data — your name, email address, job role, and the home(s)/organisation you belong to.
- Authentication data — securely stored access tokens and, where enabled, multi-factor authentication details. We do not store your password in plain text.
- Location data — when a staff member clocks in, the App may capture device location to verify attendance against the home’s permitted clock-in area. Location is used for attendance verification only and is not tracked in the background.
- Photographs and images — photos you attach to messages or upload as expense/petty-cash receipts, taken with the camera or chosen from your device.
- Care and operational records you enter — including daily reports, keywork and contact notes, significant events, incidents, medication rounds, shifts, tasks, calendar events, finance/petty-cash entries, and messages. Some of these records contain sensitive personal data about children in care, including health and safeguarding information (special category data).
- Communications — messages you send and receive within the App.
- Device and technical data — device identifiers, push-notification tokens, app version, and diagnostic/log data used to operate and secure the service.
3. Why we process it and our legal bases
| Purpose | Typical legal basis (UK GDPR) |
|---|---|
| Providing your account and the App’s core functions | Contract; legitimate interests |
| Attendance verification via clock-in location | Legitimate interests (accurate, safe staffing) |
| Keeping care, safeguarding, medication and incident records | Legal obligation and public task of the care provider; substantial public interest |
| Sending operational and safety notifications | Legitimate interests |
| Securing the service, MFA, and preventing misuse | Legitimate interests; legal obligation |
Where the App processes special category data (such as health or safeguarding information about children), the controller relies on conditions in Article 9 UK GDPR and Schedule 1 of the Data Protection Act 2018 — in particular safeguarding of children and individuals at risk, and substantial public interest. CRIS Care Technologies Ltd processes this data only on the controller’s instructions.
We do not use your data for advertising, and we do not sell personal data.
4. Where your data is stored and who processes it
App data is transmitted to and stored on secured servers operated for CRIS (accessed via api.criscare.uk), hosted with reputable cloud infrastructure providers. We use a limited number of sub-processors (for example, cloud hosting and push-notification delivery) under contracts that require appropriate safeguards. Data is stored within the UK/EEA, or with equivalent safeguards where any transfer outside the UK/EEA is necessary.
5. Push notifications
If you enable notifications, we register a push token for your device so the service can deliver operational alerts (for example, new tasks, messages, or shift reminders). You can disable notifications at any time in your device settings.
6. Data sharing
We share personal data only:
- with your employing care organisation and other authorised users, according to role-based permissions within the App;
- with our sub-processors who host and operate the service on our behalf;
- where required to comply with a legal obligation, or to protect the vital interests, safety, or safeguarding of a child or other individual.
We do not share personal data with third parties for their own marketing.
7. Data retention
Records are retained for as long as required by your care organisation and by the regulations that apply to children’s residential care, after which they are deleted or anonymised. Because the controller sets retention periods, requests to delete care records should be directed to your employing organisation.
8. Security
We use technical and organisational measures to protect your data, including encryption in transit, secure storage of authentication tokens on your device, role-based access controls, and support for multi-factor authentication. No system is completely secure, but we work to protect data appropriately given its sensitivity.
9. Your rights
Under UK data protection law you have rights to access, rectify, erase, restrict, or object to the processing of your personal data, and to data portability, subject to legal exemptions. Because your employing care organisation is usually the controller, please exercise these rights through that organisation in the first instance; we will assist the controller in responding. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
10. Children’s data
The App is a professional record-keeping tool used by authorised adult staff. It is not intended for use by children and is not directed at children. Some records within the App concern children in care; access to those records is restricted to authorised users under role-based permissions and the controller’s safeguarding policies.
11. Contact us
12. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top shows when it was last revised. Material changes will be communicated through the App or by your care organisation.