PRIVACY NOTICE

Mutima Care
HeartReach Group Ltd trading as Mutima Care

Document Ref: MC-PRIV-01
Version: 2.0
Effective date: 11 August 2026
Review date: August 2027, or earlier if our processing or applicable law changes

ABOUT THIS NOTICE

HeartReach Group Ltd, trading as Mutima Care (“Mutima Care”, “we”, “us” or “our”), respects your privacy and is responsible for the personal information we process as a data controller.

This notice explains how we collect, use, share, protect and retain personal information relating to people who use or enquire about our services, representatives and family members, professional referrers, job applicants, website visitors and other people who contact us.

We process personal information in accordance with the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and, where relevant, the Privacy and Electronic Communications Regulations 2003.

Mutima Care is an adult domiciliary care service registered with the Care Quality Commission for the regulated activity of Personal Care.

WHO WE ARE

Data controller:
HeartReach Group Ltd trading as Mutima Care

Address:
Office 2:18, Greenside House
50 Station Road
Wood Green
London
N22 7DE

Telephone:
020 3951 4660

Email:
mailbox@mutimacare.co.uk

If we publish our ICO registration number, it will only be added once the correct current number has been verified.

INFORMATION WE MAY COLLECT

Depending on your relationship with Mutima Care, we may process:

  • identity and contact information, including name, address, telephone number, email address and date of birth;
  • details of relatives, representatives, emergency contacts, attorneys or other authorised people;
  • referral, assessment and care-planning information;
  • information about physical or mental health, disability, medication, communication needs, mobility, nutrition, continence, risks and safeguarding;
  • information required to deliver, monitor and review Personal Care safely;
  • information about professional referrers, commissioners and organisations involved in a person’s care;
  • financial, contractual and funding information required to arrange or administer services;
  • recruitment information including employment history, references, Right to Work information and, where legally permitted and appropriate, DBS or other criminal-record information;
  • occupational-health or other special-category information where necessary for employment purposes;
  • complaints, compliments, incidents, safeguarding information and correspondence;
  • technical information associated with use of our website, such as IP address, browser or device information and cookie or similar technology information; and
  • access, audit or care-system records created when our services are provided.

We only collect information that is relevant to the purpose for which it is required.

HOW WE RECEIVE INFORMATION

We may receive information:

  • directly from you;
  • from a family member, representative or person acting with appropriate authority;
  • from Local Authorities, NHS organisations, hospital discharge teams, GPs or other health and social care professionals;
  • from commissioners, case managers or other authorised referrers;
  • through our website enquiry, referral or recruitment routes;
  • during assessment and delivery of care; and
  • through systems and service providers we use to operate our care, administration, recruitment and governance functions.

WHY WE USE PERSONAL INFORMATION

We may use personal information to:

  • respond to enquiries and referrals;
  • assess whether we can safely meet a person’s needs;
  • plan, provide, monitor and review Personal Care;
  • protect people from abuse, neglect or other harm;
  • support safe medicines-related care within our registered scope;
  • communicate with people involved in a person’s care where appropriate;
  • manage contracts, funding, invoicing and service administration;
  • recruit, vet, employ and support staff;
  • manage complaints, incidents, safeguarding concerns and quality assurance;
  • comply with legal, regulatory and contractual requirements;
  • maintain the security and integrity of our systems;
  • establish, exercise or defend legal claims; and
  • understand and improve our website and services where the law permits us to do so.

OUR LAWFUL BASES

The lawful basis we use depends on why we are processing the information.

For ordinary personal information, our bases may include:

  • Article 6(1)(b), where processing is necessary to take steps at your request before entering into a contract or to perform a contract;
  • Article 6(1)(c), where processing is necessary to meet a legal obligation;
  • Article 6(1)(f), where processing is necessary for our legitimate interests and those interests are not overridden by your rights;
  • Article 6(1)(d), where processing is necessary to protect vital interests in an appropriate emergency; and
  • Article 6(1)(a), consent, where consent is the appropriate basis for an optional activity.

Health and care information is special-category personal information. Where we process this information for health or social care purposes, we may rely on Article 9(2)(h) of the UK GDPR together with the applicable provisions of the Data Protection Act 2018.

Different legal conditions may apply to employment, safeguarding, legal claims, substantial-public-interest processing or other specific circumstances.

We do not rely on consent simply because information is sensitive. Where consent is the lawful basis, you may withdraw it at any time without affecting processing that was lawful before withdrawal.

CRIMINAL-OFFENCE INFORMATION

Criminal-offence information, including DBS information, is treated separately from ordinary and special-category data. We process it only where the law permits and where it is necessary and proportionate for the relevant role or safeguarding purpose.

WHO WE MAY SHARE INFORMATION WITH

Where necessary and lawful, information may be shared with:

  • GPs, district or community nurses and other health professionals;
  • Local Authorities, social workers and safeguarding services;
  • NHS organisations, Integrated Care Boards, commissioners and Continuing Healthcare teams;
  • emergency services;
  • the Care Quality Commission and other regulators where we are legally required to provide information or notifications;
  • professional advisers, insurers, auditors or legal representatives;
  • organisations providing secure care-management, hosting, email, communications, payroll, recruitment or other business systems on our behalf; and
  • law-enforcement agencies or other organisations where disclosure is required or permitted by law.

Our service providers are required to handle personal information securely and only for authorised purposes.

CARE MANAGEMENT AND DIGITAL SYSTEMS

We use digital systems to support safe care, records, communication, administration and governance. This may include our digital care-management platform and other approved systems.

Access is restricted according to role and need. We use appropriate technical and organisational safeguards and maintain audit and access controls where the relevant system supports them.

We do not routinely use cameras or microphones in service users’ homes.

Where assistive technology, sensors, digital access records or similar technology are considered as part of a person’s care, we assess the purpose, necessity, proportionality, lawful basis, privacy implications and appropriate safeguards before use.

COOKIES AND WEBSITE TECHNOLOGIES

Our website uses technologies necessary for it to operate and may use other storage or access technologies for purposes such as preferences, security or analytics.

CookieYes is used to provide cookie information and preference controls.

Where consent is required, non-essential technology will be used in accordance with the choices made through our cookie controls. Where a legal exception applies, we will still provide appropriate information and any required means of objection.

You can revisit your cookie preferences using the cookie controls available on our website.

INTERNATIONAL DATA TRANSFERS

Some technology or service providers may process information outside the United Kingdom.

Where personal information is transferred internationally, we require an appropriate lawful transfer mechanism, such as UK adequacy regulations or appropriate contractual safeguards, unless another lawful exception applies.

Information about relevant safeguards can be requested from us.

DATA PROTECTION BY DESIGN AND SECURITY

We apply data-protection-by-design and data-minimisation principles when designing or changing processes.

Where processing is likely to result in a high risk to people’s rights and freedoms, we carry out a Data Protection Impact Assessment where required.

We maintain proportionate technical and organisational security measures. Depending on the system and risk, these may include role-based access, multi-factor authentication, secure hosting, audit logging, encryption, controlled physical access and staff confidentiality requirements.

No organisation can guarantee that information is completely free from risk, but we take reasonable steps to protect the confidentiality, integrity and availability of information entrusted to us.

HOW LONG WE KEEP INFORMATION

We keep personal information only for as long as necessary for the purpose for which it is held, taking account of legal, regulatory, contractual, safeguarding, insurance and legitimate operational requirements.

Our internal retention schedule sets retention periods for different record types.

Adult social care records, including care plans, are normally retained for eight years and are then reviewed and securely destroyed where they are no longer required.

Unsuccessful recruitment information is normally retained for six months unless there is a documented lawful reason to retain it for longer or you have agreed to an appropriate longer retention arrangement.

Employment, payroll, financial, safeguarding, incident, complaint and other records are retained in accordance with the applicable legal requirements and our documented retention schedule.

At the end of the relevant retention period, information is securely deleted, destroyed or anonymised unless there is a justified reason to retain it.

YOUR DATA PROTECTION RIGHTS

Depending on the circumstances and the lawful basis we rely upon, you may have the right to:

  • ask for access to your personal information;
  • ask us to correct inaccurate or incomplete information;
  • ask for information to be erased in certain circumstances;
  • ask us to restrict processing in certain circumstances;
  • object to certain processing, particularly where we rely on legitimate interests;
  • receive or transfer certain information in a portable form;
  • withdraw consent where consent is the lawful basis; and
  • raise concerns about how your information is used.

These rights are not absolute and may be limited where the law requires or permits us to continue processing information.

SUBJECT ACCESS REQUESTS

You may ask us for a copy of personal information we hold about you.

We normally respond without undue delay and within one month of the applicable start date.

Where legally permitted, the period may be extended for complex or multiple requests. We may also request proportionate proof of identity or clarification where reasonably necessary.

We will carry out a reasonable and proportionate search for information falling within the scope of your request.

AUTOMATED DECISION-MAKING

We do not currently make decisions about service users or applicants that produce legal or similarly significant effects solely by automated decision-making.

If this changes, we will provide the information and safeguards required by law.

DATA PROTECTION COMPLAINTS

If you are concerned about how Mutima Care has used or protected your personal information, please contact us first.

Email:
mailbox@mutimacare.co.uk

Telephone:
020 3951 4660

Address:
Office 2:18, Greenside House
50 Station Road
Wood Green
London
N22 7DE

We provide a clear route for data protection complaints. We will acknowledge a data protection complaint within 30 days, investigate it appropriately, keep you informed where necessary and communicate the outcome without undue delay.

You also have the right to complain to the Information Commissioner’s Office.

Information Commissioner’s Office:
https://ico.org.uk/

CHANGES TO THIS NOTICE

We review this notice periodically and sooner where our services, technology, processing activities or legal obligations change.

The current version will be published on this page.

Scroll to Top