A2Z CareHub Privacy Policy
1. About this policy
This Privacy Policy explains how A2Z IT Limited ("A2Z IT", "we", "us", "our") handles personal data in connection with the A2Z CareHub platform (also marketed under the formal commercial name A2Z CareSuite, together "the Platform").
A2Z IT Limited is a company registered in England and Wales, operating as a Microsoft and Google Partner managed services provider. Our registered trading address is in Rainham, Essex, United Kingdom. We are registered with the Information Commissioner's Office under registration reference ZB996270. Our website is a2zit.ai and the Platform is accessible at a2zcarehub.co.uk.
We take your privacy seriously. This policy is written to be specific about what we do and do not do — we believe specificity is more useful than vague reassurance.
If you have questions about this policy or how we handle your personal data, please contact us at privacy@a2zit.ai.
2. Our role: when we are controller and when we are processor
A2Z IT plays two distinct roles in the Platform, and the rules that apply depend on which role we are in for a given category of data.
We are the data controller for:
- Account and access data of users we provide direct access to the Platform, including names, work email addresses, organisation, role, and authentication metadata
- Audit logs of platform activity, including who accessed which features and when
- Billing, contract, and financial records relating to our customers
- Sales and prospect contact data, where you have engaged with us about our services
- Support communications between you and us
- Platform telemetry collected for security, performance, and service-improvement purposes
We are a data processor acting on behalf of our customer organisations (the care providers who licence the Platform) for:
- Care content processed through AI agents (for example, care notes submitted to A2Z CareNotes or conversations with A2Z CareIQ agents)
- Governance event data entered through A2Z CareTrack (such as accidents, incidents, complaints, and safeguarding referrals)
- Policy acknowledgements and training compliance records held in A2Z CareComply
- Audit responses and evidence captured in A2Z CareAudit
- Survey responses captured through A2Z CareVoice, where those responses are identifiable
In our processor role, the customer organisation that licenses the Platform is the data controller and is responsible for the lawful basis and any special-category-data condition for the data they place into the Platform. We process such data only on documented instructions from the customer organisation, under a separate Data Processing Agreement.
This Privacy Policy primarily describes the data we control. Where data subjects' rights apply against the customer organisation rather than against us, we explain how to exercise those rights in section 9.
3. Who this policy is for
This policy is written for three groups of people:
Platform users — care professionals (carers, registered managers, nominated individuals, back-office staff, administrators) who use the Platform on behalf of a care provider organisation. We are the controller for your account and access data.
Customers and prospects — care provider organisations that licence the Platform from us, and individuals at those organisations who engage with us during sales, onboarding, and ongoing account management. We are the controller for your contact, contract, and communication data.
Survey respondents — service users, family members, and care workers who respond to surveys distributed through A2Z CareVoice. We are a processor for your survey responses; the care provider organisation conducting the survey is the controller. To exercise your data rights, please contact the organisation that invited you to the survey.
4. The data we collect
For platform users, we collect the following personal data:
- Identity data — name, work email address (UPN), organisation, job role, and the access entitlements assigned to you
- Authentication metadata — sign-in events, multi-factor authentication status, IP address at sign-in, and session activity, recorded by Microsoft Entra External ID or by your organisation's identity provider where federation is in use
- Activity data — records of which features and AI agents you accessed, when, and the outcome (success, error), recorded in our audit log
- Communication content — the content of support emails, comments, and other communications you send to us
- Device and browser metadata — collected through Microsoft Application Insights, including browser type, operating system, approximate geographic region, and performance telemetry
For customers and prospects, we collect contact details, contract and billing records, and the content of communications between us.
5. What we deliberately do not collect
We are explicit about what we do not collect because we believe this matters in a care sector context:
- We do not store the content of care notes after a CareNotes or CareIQ session ends. Submissions are processed in memory, feedback is returned, and the session content is discarded by us
- We do not store identifiers for the service users described in care content
- We do not collect biometric data
- We do not track your physical location beyond the approximate geographic region implied by your IP address
- We do not use the Platform to deliver advertising and we do not sell or share personal data with advertisers
- Survey responses captured through A2Z CareVoice are anonymous end-to-end where the survey is configured as anonymous; no identifier links a response to a respondent
The transient processing of care content through Microsoft's Azure OpenAI service is described in section 7 (sub-processors).
6. Our lawful basis for processing
Where we are the controller, we rely on the following lawful bases under the UK GDPR for processing personal data:
| Data category | Lawful basis |
|---|---|
| Platform user account, access, and activity data | Performance of a contract (Article 6(1)(b)) — necessary to provide the Platform under our contract with your organisation |
| Audit logs and platform security telemetry | Legitimate interests (Article 6(1)(f)) — securing and maintaining the integrity of the Platform |
| Billing, financial, and statutory accounting records | Legal obligation (Article 6(1)(c)) — UK Companies Act, HMRC retention requirements |
| Customer and prospect contact data, sales communications | Legitimate interests (Article 6(1)(f)) — managing existing and prospective business relationships |
| Service-improvement analytics | Legitimate interests (Article 6(1)(f)) — improving the Platform |
Where we rely on legitimate interests, we have considered whether your interests, rights, and freedoms override our interests, and have concluded they do not in the contexts described. You have the right to object to processing based on legitimate interests; see section 9.
We do not rely on consent for any of the controller-side processing described above. Where any future processing requires consent, we will request it separately and explicitly.
7. Sub-processors and how data flows
We use a small number of carefully selected sub-processors to deliver the Platform. The current list is maintained at a2zcarehub.co.uk/sub-processors and is updated when sub-processors are added, changed, or removed.
Our principal sub-processors are:
Microsoft Corporation and Microsoft Ireland Operations Limited — provide the underlying Azure infrastructure (hosting, database, storage, AI inference, authentication, communications, monitoring) on which the Platform runs. All primary processing takes place in Microsoft's UK South region. Where Microsoft escalates support engineering to teams outside the United Kingdom, transfers are governed by the UK Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement, supplemented by the UK-US Data Bridge where applicable.
Microsoft Azure OpenAI Service — provides the AI inference capability that powers the Platform's AI agents. Care content submitted to AI agents is processed by Microsoft's Azure OpenAI service. Our Azure OpenAI resource is hosted in the UK South region and data stored at rest remains in the United Kingdom; however, because the Platform uses Microsoft's global deployment model, individual AI requests may be processed for inference in Microsoft Azure regions outside the United Kingdom, under the transfer safeguards described in section 8. Under Microsoft's default configuration, Azure OpenAI may retain submitted prompts and the AI's responses for up to 30 days for abuse-monitoring purposes, and a small number of authorised Microsoft personnel may review such content where Microsoft's automated systems flag a potential policy violation. We are working with Microsoft to apply for a zero-data-retention configuration that disables this retention and review for the Platform; we will update this policy and notify customers when that configuration is in place.
Cloudflare, Inc. — provides DNS, edge proxying, and TLS termination for our domains. Cloudflare's network operates globally; transfers are governed by the UK International Data Transfer Agreement and the UK-US Data Bridge.
Google LLC — for customer organisations that use Google Workspace, Google acts as an identity provider integrated into Microsoft Entra External ID. Transfers to Google are governed by the UK International Data Transfer Agreement and the UK-US Data Bridge.
Microsoft Clarity: provides visitor analytics on our public marketing pages only (the home, features, free trial, contact, security, accessibility and vision pages). It is never loaded inside the Platform, on sign-in pages, on invitation pages or on survey pages. See section 13.
We do not use sub-processors for advertising, and we do not track anyone across other websites.
8. International transfers
The Platform is hosted in the United Kingdom (Microsoft Azure UK South) and personal data is stored at rest in the United Kingdom. Routine processing takes place within the United Kingdom, with one exception: AI inference requests may be processed in Microsoft Azure regions outside the United Kingdom, as described in section 7.
Where personal data is transferred outside the United Kingdom — for example, AI inference processing on Microsoft's global Azure OpenAI infrastructure, or where Microsoft or Cloudflare engineering or support functions are performed by colleagues in other jurisdictions — we rely on the following safeguards:
- The UK Addendum to the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Agreement, in our contracts with sub-processors
- The UK Extension to the EU-US Data Privacy Framework (the UK-US Data Bridge) for transfers to participating United States organisations, which currently includes Microsoft and Cloudflare
We do not transfer personal data to any third country without an appropriate safeguard in place.
9. Your rights
Under the UK GDPR, you have the following rights in relation to personal data we hold about you as controller:
- The right to be informed about how we process your data (this policy is part of how we meet that right)
- The right of access — to obtain a copy of the personal data we hold about you
- The right to rectification — to have inaccurate data corrected
- The right to erasure ("the right to be forgotten"), subject to the limits described below
- The right to restrict processing in certain circumstances
- The right to data portability for data we process by automated means under contract or consent
- The right to object to processing based on legitimate interests
- Rights related to automated decision-making and profiling — see section 10
To exercise any of these rights, please contact us at privacy@a2zit.ai. We will respond within one calendar month and may extend this by up to two further months for complex requests, in line with the UK GDPR.
Limits on the right to erasure. We are required to retain certain records for legal, regulatory, contractual, or operational integrity reasons. In particular:
- Audit logs of platform activity are retained for the periods set out in section 11 and cannot be selectively erased, because the integrity of those logs is itself a legitimate interest of ours and a regulatory expectation in the care sector
- Billing and financial records are retained for the periods required by UK statutory accounting and tax law and cannot be erased earlier
- Where we are a processor (rather than controller) — for example, in respect of governance data, care content, or training compliance records held on behalf of your employer — your right to erasure is exercised against your employer, not against us. We will assist your employer in fulfilling such requests in line with our Data Processing Agreement with them
Right to complain. You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection authority. The ICO's contact details are at ico.org.uk. We would, however, appreciate the opportunity to address any concerns you have before you contact the ICO.
10. Automated decision-making and AI
The Platform uses AI extensively to assist care professionals in producing care notes, preparing for inspections, drafting documentation, analysing governance data, and similar tasks.
AI outputs from the Platform are advisory. All decisions affecting service users, staff, or compliance outcomes are made by qualified human professionals. The Platform does not make solely automated decisions producing legal or similarly significant effects on any individual.
You retain the right under Article 22 of the UK GDPR not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. The Platform is designed to operate consistently with that right.
11. How long we keep personal data
| Data category | Retention period |
|---|---|
| Platform user account and access data | For the duration of your organisation's contract with us, plus 12 months |
| Audit logs of platform activity | 7 years from the date of the recorded event |
| Billing and financial records | 7 years (UK statutory minimum) |
| Support communications | 3 years from the date of the most recent exchange |
| Application Insights performance telemetry | 90 days |
| Azure SQL automated database backups | 7 days (point-in-time restore) |
| Care content processed through AI agents | Not retained by us once the session ends. Microsoft's Azure OpenAI service may retain content for up to 30 days as described in section 7 |
| Anonymous A2Z CareVoice survey responses | Configured by the customer organisation; default 5 years |
When retention periods expire, we delete or anonymise the data using procedures appropriate to its sensitivity.
12. Security
We protect personal data through a combination of technical and organisational controls, including:
- Encryption of personal data in transit (TLS) and at rest
- Authentication and access control through Microsoft Entra External ID, with multi-factor authentication available and enforced where required
- Row-level security in our database to enforce per-customer data isolation
- Audit logging of access to sensitive functions
- Secrets management through Azure Key Vault with managed identity access
- Security monitoring through Microsoft Application Insights and Azure-native security tooling
- Regular review of access permissions, sub-processors, and controls
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and, where required, the Information Commissioner's Office, in line with our obligations under the UK GDPR.
13. Cookies and similar technologies
Inside the Platform we use a small number of cookies and similar technologies, all of which are strictly necessary or technical:
- Authentication cookies and tokens: set by Microsoft Entra External ID (or your organisation's federated identity provider) to keep you signed in during a session
- Cloudflare proxy cookies: set by Cloudflare to manage edge proxy functions and protect against abuse
- Application Insights cookies: set by Microsoft Application Insights to measure performance and detect errors
Our public marketing pages (the home, features, free trial, contact, security, accessibility and vision pages) also use Microsoft Clarity to help us understand how visitors use those pages, for example which sections are read and where people click. Clarity is set up so that it stores no cookies on your device: we tell it on every visit that consent has not been given, so it gives each page view a new random identifier and does not link your visits together. It does not share data with Microsoft advertising. Clarity keeps page recordings for 30 days and summary click data for up to 9 months. Clarity is never loaded inside the Platform, on sign-in pages, on invitation pages or on survey pages, so it never sees care records or anything you do after signing in.
You can stop Clarity collecting data about your visits by turning on Global Privacy Control in your browser, which Clarity honours, or by blocking scripts from clarity.ms.
We do not use cookies for advertising or to track you across other websites.
Because none of the technologies above store non-essential information on your device, we do not present a cookie consent banner. If we ever introduce a technology that needs your consent under the Privacy and Electronic Communications Regulations, we will update this policy and ask for your consent first.
14. Children's data
The Platform is a business-to-business service used by adult care professionals. It is not directed to children, and we do not knowingly collect personal data from children.
15. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this policy reflects the most recent change.
For material changes — for example, the addition of a new sub-processor that materially changes how data is processed, or a change in the lawful basis for a category of processing — we will notify customer organisations by email and through a notice on the Platform, in advance of the change taking effect where possible.
16. Contact
For privacy questions or to exercise any of the rights described in this policy:
A2Z IT LimitedPrivacy contact: privacy@a2zit.ai
Website: a2zit.ai
Platform: a2zcarehub.co.uk
Address: Rainham, Essex, United Kingdom
We have not appointed a formal Data Protection Officer because we do not meet the statutory threshold under Article 37 of the UK GDPR. The privacy contact above is the designated point of contact for all data protection matters.