Skip to main content

Legal & data protection

Privacy notice

How MW Integrated Care Consultancy Ltd handles personal information, and where a care provider using the platform stays responsible for its own records.

v0.9 (pre-release) · Awaiting legal review and first release — not yet in force

Pre-release document — not yet in force

MW Compliance Hub is not yet open to customers and does not hold information about real people. These pages are published early so they can be read and challenged before anyone signs up. They take effect only when the platform is released for real use, and some points below are still outstanding — they are shown as outstanding rather than filled in with a guess.

Who we are

MW Integrated Care Consultancy Ltd provides the MW Compliance Hub platform. Company number 15816816. Registered office: 71–75 Shelton Street, London, WC2H 9JQ, United Kingdom. "MW Compliance Hub" is a product and trading name, not a separate company.

Questions about information handling go to the Data Protection Contact, MW Integrated Care Consultancy Ltd, at the registered office above. The person who holds that role is recorded in our internal governance records and is not named publicly.

Still outstanding

  • A monitored email address for data-protection enquiries has not yet been created, so none is stated here. Until it exists, the postal address above is the only route.
  • Whether we are required to appoint a data protection officer is still being checked with a qualified adviser. Nobody at MW is described as one.
  • Registration with the Information Commissioner's Office, and payment of the data-protection fee, happen before any real personal information is handled. No registration number is claimed until then.

When this notice applies

It covers the information we decide the use of: enquiries, demonstration and consultation bookings, consultancy records, the accounts of people who use the platform on behalf of an organisation, our customer and billing records, security administration and service messages.

Where a care provider uses the platform to keep its own records — incidents, complaints, safeguarding concerns, staff training, and information about the people it supports — that provider decides how those records are used and remains responsible for them, and its own privacy notice applies. We hold that information only on its instructions. Hosting it does not make us responsible for deciding how it is used.

What we collect, why, and for how long

InformationWhy we have itHow long we keep it
Name, email, phone, organisation and message from enquiries, demonstration requests and bookingsTo reply and arrange a demonstration or consultation24 months after the last contact
Account details: name, work email, role, and which organisation and locations you belong toTo give you access and keep the platform secureWhile the account is active, then a further 12 months
Sign-in and security eventsTo protect accounts and investigate misuse12 months from the event
Consultancy engagement recordsTo carry out work we have agreed with an organisation6 years after the engagement ends
Website measurementNot usedNothing non-essential is collected

These periods are our own retention decisions for information we are responsible for; they are not legal requirements. For records a care provider enters about the people it supports, that organisation decides how long they are kept — where we offer a default period it is only a default, which the organisation can change.

Still outstanding

  • The retention period for safeguarding records is not settled and needs safeguarding and legal input before real records are held.
  • How long copies persist in our hosting provider's backups is not confirmed, because we do not yet hold that information from the provider.

Who else is involved

The platform and its database are hosted by a managed cloud provider in Ireland. Assistant features send your question to an AI service at the moment you ask it. We do not sell information, share it with advertisers, or use customer records to train AI models. The current list is on our sub-processor page.

Still outstanding

  • The complete list of recipients, every location information is handled in, and the arrangement covering any transfer outside the UK are not stated, because they depend on written evidence we have requested from our providers and do not yet hold. No real personal information is handled until that is resolved.

Your rights

You can ask for a copy of your information, ask us to correct or delete it, ask us to restrict or stop some uses, object, or ask for it in a portable form. Write to the data-protection contact at the registered office. That is the first route, but you do not have to use it before complaining. We answer within one month, as the law requires; we do not promise anything faster.

If your information sits inside a care provider's own records on the platform, that provider decides those requests. We pass the request to it and help it respond, rather than deciding ourselves.

You can complain to the Information Commissioner's Office at any time, whether or not you have contacted us first.

One limit we will not overstate: some records sit in a tamper-proof audit trail, so compliance evidence cannot be quietly altered. Individual entries in that trail cannot be deleted one by one. Where that affects a deletion request we say so, explain what we can do instead — including correcting a record by adding a superseding entry — and record the outcome. Removing that material entirely is only possible by destroying a whole organisation's records at the end of the contract. Whether that is enough in law is still under advice.

Things we do not claim

  • We give no guarantee about recovering information after loss: a restore has not yet been carried out and proven.
  • We hold no independent certification and have not been independently audited.
  • The platform helps organisations manage their own compliance. It does not give regulatory advice and does not predict any inspection result.