Last updated: 15 June 2026
KareMate AI ("we", "our", "us") is the data controller for personal data processed through this service. We are subject to UK GDPR and the Data Protection Act 2018.
Data Protection Officer: dpo@caremate.ai
To exercise your rights or raise a concern, contact us at the address above. You may also lodge a complaint with the ICO (Information Commissioner's Office).
Health and care data is special category data under UK GDPR Article 9. We only process it with your explicit consent (Article 9(2)(a)), obtained at account registration.
| Purpose | Lawful basis |
|---|---|
| Providing care coordination features | Contract (Art. 6(1)(b)) + Explicit consent for health data (Art. 9(2)(a)) |
| AI-assisted summaries and plans | Explicit consent (Art. 6(1)(a) + Art. 9(2)(a)) |
| Subscription billing via Stripe | Contract (Art. 6(1)(b)) |
| Account security and authentication | Legitimate interests (Art. 6(1)(f)) |
| Improving our service | Legitimate interests (Art. 6(1)(f)) — anonymised data only |
To generate care summaries, appointment preparation notes, crisis plans, and AI chat responses, we transmit patient data to Google Gemini (Vertex AI), operated by Google LLC. This involves a transfer of personal data to the United States. We rely on Google's Data Processing Agreement and Standard Contractual Clauses (UK Addendum) as the transfer safeguard under UK GDPR Article 46.
You consented to this transfer at account registration. You may withdraw consent at any time by contacting dpo@caremate.ai — note that withdrawing AI processing consent will disable AI features.
Under UK GDPR you have the right to:
Exercise any right via Settings → Account → Data & Privacy, or by emailing dpo@caremate.ai. We respond within 30 days.
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256 via Google Cloud default encryption). Access is controlled via Firebase Authentication tokens. We maintain an access audit log for all operations on patient data.
Our service may be used to coordinate care for children. If a patient is under 16, the account holder (carer) confirms they have appropriate parental or guardian authority to input that data. We do not knowingly allow children under 16 to create their own accounts.
We will notify you by email of any material changes at least 14 days before they take effect. The current version is always available at this URL.