Data processing and security

Last updated: 12 September 2026

AJG Compliance holds records about care services and the people who work in them. This page sets out who is responsible for that data, what we do with it, and the measures that protect it. It supports — and does not replace — the written agreement between AJG Advisory and each provider.

1. Controller and processor roles

Each provider organisation is the controller of the personal data it enters into its workspace: staff records, audit findings, evidence documents and improvement actions. AJG Advisory acts as a processor for that data, handling it only on the provider's documented instructions.

Where AJG Advisory consultants deliver advisory work, or where we process enquiry and account data for our own business purposes, AJG Advisory is the controller. Those activities are covered by our privacy notice.

2. Subject matter and duration

Processing runs for the duration of the provider's subscription and any agreed wind-down period. The subject matter is CQC compliance management: audits, evidence, action plans, workforce compliance monitoring, governance reporting and inspection readiness.

3. Categories of data subject

  • Employees, bank staff, volunteers and applicants of the provider.
  • Named portal users at the provider, including registered managers, nominated individuals and directors.
  • People using the service, where a provider chooses to include identifiable information in uploaded evidence or audit notes.

4. Categories of personal data

  • Contact and identity data: name, work email address, job role, branch and organisation.
  • Workforce compliance data: recruitment records, DBS check details, right-to-work and sponsorship information, training, supervision and appraisal dates, and driving documents.
  • Account and activity data: sign-in events, audit responses, evidence uploads and action history.
  • Any personal data contained in documents a provider uploads to its evidence library, which the provider controls.

Special category data. DBS and criminal record information, and health information that may appear in uploaded records, are sensitive. Providers should upload only what is necessary to evidence compliance and should redact information that is not needed.

5. Security measures

  • Encryption of data in transit.
  • A separate, private workspace per provider, with database-level rules preventing cross-provider access.
  • Role-based permissions with granular provider-defined roles, plus branch-level restrictions, so users see only what their role allows.
  • Invitation-only accounts; there is no public sign-up and no anonymous access.
  • Automatic session timeout and secure password reset with leaked-password checking at sign-up and reset.
  • Private document storage — evidence files are never publicly addressable.
  • An immutable audit trail for role changes, action verification and data protection activity.

Hosting is provided by Lovable and data is stored in the United Kingdom. Backups are taken monthly and retained for the duration of the contract. Disaster recovery is completed internally. Independent penetration testing is carried out monthly.

6. Sub-processors

We use a small number of infrastructure providers to host the platform, store documents and send email. Each is engaged under written terms that impose data protection obligations equivalent to our own. The current list of sub-processors is available to providers on request from info@ajgadvisory.co.uk. We will give providers advance notice of any intended change so they can object.

7. International transfers

Our intention is to keep provider data within the UK or the European Economic Area. Hosting is provided by Lovable and data is stored in the United Kingdom. Where any transfer outside that area is necessary, it will be made under a UK adequacy decision or the International Data Transfer Addendum to the EU Standard Contractual Clauses.

8. Confidentiality and staff access

AJG Advisory staff and consultants access provider data only where necessary to deliver the service. Access is limited by role, logged, and subject to written confidentiality obligations.

9. Assisting the provider

We assist providers with data subject requests, data protection impact assessments and consultations with the Information Commissioner's Office. The portal includes a data protection area with a subject rights register, statutory deadlines, data exports and staff record erasure so providers can respond within one calendar month.

10. Personal data breaches

We will notify the affected provider without undue delay after becoming aware of a personal data breach affecting its data, with the information the provider needs to meet its own 72-hour reporting duty to the Information Commissioner's Office.

11. Retention, return and deletion

Provider data is retained while the subscription is active. On termination, and on the provider's instruction, we will return an export of the data and then delete it within 90 days of contract end, except where we are required by law to retain a copy. Providers should set their own retention periods in line with regulatory requirements for care records and employment files.

12. Audits

We will make available the information reasonably required to demonstrate compliance with these obligations and will support audits arranged by a provider on reasonable notice.

13. Contact

For a copy of our data processing agreement, the sub-processor list, or any question about this page, email info@ajgadvisory.co.uk or call 07809 332395. AJG Advisory is a trading name of Assured Care Hub Limited, registered in England and Wales under company number 17183813. Registered office: 9 West Street, Wilton, SP2 0NT. Our data protection lead is registered with the Information Commissioner's Office; the ICO registration number is available on request.