Security and data protection

Last updated: 12 September 2026

Care records are among the most sensitive information an organisation holds. This page explains, in plain terms, how My Care Compliance protects the information you and your staff put into the portal — and what we commit to as your data processor. Share it with your information governance lead or your local authority contract team.

1. One provider can never see another

Every record in the portal — audits, evidence, actions, staff files, incidents, notifications and documents — belongs to one organisation. That separation is enforced inside the database itself, not only in the screens, so a request for another provider's data simply returns nothing. Branches within your organisation can be restricted further so that a manager only sees the locations they are responsible for.

2. Staff only see their own file

Care staff using the Employee Hub are linked to their existing workforce record. They can see their own documents, their own actions and the policies they have been asked to read — nothing about a colleague, and nothing from the management side of the portal. They cannot change their own compliance status, approve their own evidence, alter an expiry date or delete anything they have submitted.

3. Access is by invitation and by role

There is no public sign-up for the provider portal. Accounts are created by your director, nominated individual or by AJG Advisory, and each person is given a role that controls what they can do — for example closing actions, viewing staff files, downloading or emailing records, or managing which sections your organisation uses. Passwords are checked against known breached-password lists, sessions time out, and access is removed immediately when someone leaves.

4. Documents are stored privately

Uploaded files — DBS certificates, training records, policies, evidence and incident paperwork — are held in private storage with no public web addresses. Files open through short-lived links issued only to a person entitled to see that file, and a member of staff can only open files inside their own folder.

5. Everything important leaves a trail

Submissions, reviews, approvals, acknowledgements and electronic signatures are written to an audit trail that records who did what and when. Signed acknowledgements and submitted documents cannot be edited or deleted after the event — a correction is made by submitting a new version, with the original preserved. This is what allows you to evidence good governance to an inspector rather than simply assert it.

6. Exports are controlled and traceable

Downloading, printing and emailing records is a permission in its own right, so it can be limited to the people who need it. Exported reports are watermarked, download activity is logged against the named user, unusual volumes are rate-limited and flagged, and emailed report links expire.

7. Data in transit and where it lives

All traffic to the website and portal is encrypted in transit. Data is hosted in the United Kingdom, and our intention is to keep it within the UK or the European Economic Area. Any transfer beyond that relies on a UK adequacy decision or the International Data Transfer Addendum to the Standard Contractual Clauses.

8. Payments

Subscription payments are handled by Stripe. Card details are entered directly with Stripe and are never stored on, or passed through, the My Care Compliance platform.

9. Your role and ours under UK GDPR

For the compliance records you enter, your organisation is the controller and AJG Advisory acts as processor on your instructions. Our written processing terms form part of your subscription agreement and cover confidentiality, security, sub-processors, assistance with data subject requests, breach notification, and return or deletion of your data at the end of the contract. See data processing and the subscription agreement.

10. Tools that help you meet your own obligations

  • A register of data protection requests and the actions taken on each one.
  • Unique identifiers for the people you support and for employees, so records can avoid using names.
  • Role and branch permissions so information is available on a need-to-know basis.
  • Evidence of who has read and signed each version of a policy.

11. Retention and getting your data back

Your content is kept for the life of your subscription and is returned or deleted within 90 days of the contract ending, unless we are legally required to keep a copy. You can export your records at any point during the subscription.

12. Independently generated security evidence

Alongside this page, an independently generated Trust Center is published for the platform at /.well-known/trust.html. Its contents are produced outside this website, so it can be shared with commissioners or information governance teams as evidence that is not simply our own wording.

13. Reporting a security concern

If you believe there is a security problem, or that information has been seen by someone who should not have seen it, email info@ajgadvisory.co.uk with the subject line "Security" and we will respond promptly. Please do not include personal data about the people you support in your report. Our full privacy notice sets out your rights and how to complain to the Information Commissioner's Office.