Privacy notice
Last updated: 12 September 2026
1. Who we are
AJG Advisory operates AJG Compliance, a CQC compliance portal for adult social care providers in England. For any data protection question, email info@ajgadvisory.co.uk or call 07809 332395.
AJG Advisory is a trading name of Assured Care Hub Limited, registered in England and Wales under company number 17183813. Our registered office is 9 West Street, Wilton, SP2 0NT.
Our data protection lead is registered with the Information Commissioner's Office. The ICO registration number is available on request.
2. Controller or processor
For website visitors, enquiries and our own account administration, AJG Advisory is the controller. For the compliance records a provider enters into its workspace — staff files, audits, evidence and actions — the provider is the controller and we act as processor on its instructions. See data processing and security for the detail.
3. What we collect
- Enquiries and demonstration requests: name, organisation, email address, telephone number, service type, number of locations, your message and your consent record.
- Portal accounts: name, work email address, role and permissions, organisation and branch assignment, sign-in activity and session records.
- Portal content: audit responses, evidence documents, improvement actions, workforce compliance records and governance reports. This is provider-controlled data.
- Support and assistant messages: questions you ask the on-site assistant and any email you send us.
- Technical data: IP address, device and browser information, and pages visited. See our cookie notice.
We do not ask for personal data about the people you support through the public website. Please do not include it in an enquiry message.
4. Why we use it and our lawful basis
- Responding to enquiries and arranging demonstrations — legitimate interests in dealing with people who contact us about our service.
- Providing and supporting the portal, and administering accounts and billing — performance of a contract with the provider.
- Security, fraud prevention, access logging and service improvement — legitimate interests in running a secure and reliable platform.
- Meeting legal and regulatory obligations — legal obligation.
- Optional analytics and marketing emails — consent, which you can withdraw at any time.
Where portal content includes special category data, such as DBS or health information in uploaded files, the provider as controller is responsible for identifying its own condition for processing under Article 9 UK GDPR and Schedule 1 of the Data Protection Act 2018.
5. Automated decision-making
Compliance scores, RAG ratings and mock inspection outputs are calculated from the answers and records a provider enters. They are indicative readiness indicators reviewed by people; they are not automated decisions producing legal effects, and they do not predict or guarantee a CQC rating.
6. Who we share data with
We do not sell personal data and we do not share it for third-party advertising. We share it with: the infrastructure providers who host the platform, store documents and deliver email; AJG Advisory consultants assigned to a provider; professional advisers where necessary; and regulators or law enforcement where we are legally required to do so. Each supplier is engaged under written data protection terms.
7. International transfers
Our intention is to keep data within the UK or the European Economic Area. Hosting is provided by Lovable and data is stored in the United Kingdom. Any transfer beyond the UK/EEA will rely on a UK adequacy decision or the International Data Transfer Addendum to the Standard Contractual Clauses.
8. How long we keep it
- Enquiries that do not become customers: 24 months from last contact, or sooner on request.
- Portal accounts and content: for the life of the subscription, then returned or deleted within 90 days of contract end, unless we are legally required to keep a copy.
- Records we must keep by law, such as accounting records, are retained for the statutory period. Providers set their own retention for care and employment records within their workspace.
9. How we protect it
Encryption in transit, a private workspace per provider with database-level isolation, role-based and branch-level permissions, invitation-only accounts with no public sign-up, leaked-password checking, automatic session timeout, private document storage and an immutable audit trail of sensitive changes. Backups are taken monthly and retained for the duration of the contract. Disaster recovery is completed internally. Independent penetration testing is carried out monthly.
10. Your rights
Under UK GDPR you can ask for access to your data, correction, erasure, restriction of processing, portability, and you can object to processing based on legitimate interests. Where we rely on consent you can withdraw it at any time. Email info@ajgadvisory.co.uk and we will respond within one calendar month. If your request concerns records held by a provider, we will pass it to that provider as controller.
11. Complaints
If you are unhappy with how we have handled your data, please tell us first. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
12. Changes
We may update this notice. The current version is always on this page with the date it was last updated. We will tell providers directly about material changes.
Other legal information