1. Who we are (controller)
For the purposes of the EU General Data Protection Regulation (GDPR) and applicable Dutch/EU privacy law, the data controller for Care Circles is expected to be:
- Legal entity: [Legal entity name — TODO: Applify / SentraCare operating entity]
- Registered address: [Registered address — TODO]
- Chamber of commerce / KvK: [Registration number — TODO]
- Privacy contact: [Contact email — TODO]
- Data Protection Officer (if appointed): [DPO contact — TODO]
Care Circles is a family care-coordination product built on the SentraCare platform. Where professional care organizations use SentraCare under a separate agreement, that organization may act as controller (or joint controller) for data they determine the purposes of. Those roles will be clarified in the production agreement and this policy.
2. Scope
This draft describes personal data processing in connection with the Care Circles web application (marketing site, account registration, circle membership, care coordination features, and related support). It does not cover clinical electronic health records or medical treatment decisions. Device telemetry and alarm pipelines operated by SentraCare may be described further in platform-level notices once product and legal scopes are aligned.
3. Categories of personal data we process
Depending on how you use Care Circles, we may process:
- Account & identity data: name, email address, password (stored hashed by the identity provider when live), role within a circle (e.g. Main caregiver, Caregiver, Client).
- Circle & coordination data: circle name, membership, invites, care tasks, routines, calendar items, comments, and Group messages you choose to post.
- Client profile data: display name, preferred name, home address details you enter, preferences, emergency contact details, and free-text notes you choose to store for coordination (not clinical records).
- Device / wellbeing signals (when connected): non-clinical sensor summaries and alert/status information made available through SentraCare integrations, as configured for your circle.
- Technical & usage data: IP address, device / browser type, session identifiers, security logs, and approximate usage analytics needed to operate and secure the service.
- Support communications: messages you send to support or privacy contacts.
Please do not enter unnecessary special-category data (e.g. detailed medical diagnoses) into free-text fields unless a future, counsel-approved clinical module expressly allows it.
4. Purposes and lawful bases
We process personal data only where a lawful basis under GDPR Article 6 applies. Typical mappings for this product (to be confirmed by counsel):
- Contract / pre-contract (Art. 6(1)(b)): create and manage your account, provision a care circle, enable invites, deliver core coordination features you request.
- Legitimate interests (Art. 6(1)(f)): secure the service, prevent abuse, improve reliability, and communicate service-related notices — balanced against your rights.
- Consent (Art. 6(1)(a)): where required for optional processing (e.g. certain care-data sharing within a circle, non-essential cookies/analytics, or marketing). Consent is withdrawable at any time without affecting processing based on other grounds.
- Legal obligation (Art. 6(1)(c)): where we must retain or disclose data to comply with applicable law.
If we process special-category data in a future release, we will identify an additional condition under GDPR Article 9 and update this policy before enabling that processing.
5. Sharing within a Care Circle
Care Circles is designed so members of the same circle can see coordination information needed to support the patient. When you join a circle or enable care-data sharing, other members (according to their role) may see relevant profile, task, schedule, message, and wellbeing summary information. You should only invite people you trust. Role-based visibility will be documented in product help and refined before production.
6. Processors and recipients
We may engage processors who process personal data on our instructions, for example:
- [Hosting / cloud infrastructure provider — TODO]
- [Email / transactional messaging provider — TODO]
- [Error monitoring / security tooling — TODO]
- SentraCare platform components operated by [Legal entity name — TODO] under internal data-processing arrangements
We may also disclose data to professional advisers, or to competent authorities where required by law. We do not sell personal data.
7. International transfers
If personal data is transferred outside the European Economic Area (EEA), we will implement an appropriate transfer mechanism (e.g. EU Standard Contractual Clauses, adequacy decision, or other lawful safeguard) and document the destinations in this section before production. [Transfer destinations & safeguards — TODO]
8. Retention
We retain personal data only as long as needed for the purposes described, including:
- Account & circle data: for the life of the account / circle, then deleted or anonymized within [retention period — TODO] after closure, unless longer retention is required by law.
- Security & audit logs: [log retention period — TODO]
- Support tickets: [support retention period — TODO]
Local mock / demo builds may reset data on server restart and are not a production retention environment.
9. Security
We apply appropriate technical and organizational measures intended to protect personal data against unauthorized access, loss, or alteration (access controls, encryption in transit, least-privilege administration, and logging). No method of transmission or storage is completely secure; residual risk remains.
10. Your rights
Subject to applicable law, you may have the right to access, rectify, erase, restrict, or object to certain processing, and the right to data portability. Where processing is based on consent, you may withdraw consent at any time. To exercise rights, contact [Contact email — TODO] (or [DPO contact — TODO]). We may need to verify your identity before fulfilling a request.
You also have the right to lodge a complaint with a supervisory authority. For the Netherlands, this is typically the Autoriteit Persoonsgegevens (AP). If you live elsewhere in the EU/EEA, you may contact your local authority.
11. Children
Care Circles is intended for adults coordinating care. It is not directed at children under 16 (or the digital-consent age in your Member State). If you believe we have collected a child’s data in error, contact [Contact email — TODO].
12. Changes
We may update this policy. Material changes will be highlighted in product notices or by requesting renewed acknowledgement where required. The “Last updated” date will change when a reviewed version is published.
13. Contact
Privacy questions: [Contact email — TODO]
DPO (if appointed): [DPO contact — TODO]
Postal: [Registered address — TODO]