Last updated: 9 August 2026
Verioos Ltd ("we", "our", "us") is committed to protecting your privacy. This policy explains what personal data we process when you use the Verio Care Operating System, why we process it, and the rights and choices you have. We process data for each care organisation in a separately isolated tenant โ data from one provider is never mixed with another's.
We only collect and use data for the purpose it was given. Access to personal data is limited by field-level permissions: you see only the data your role needs. For example, a Carer sees their own availability, credits and wallet; a Coordinator sees allocation-relevant facts but not sensitive HR adjustments; a Recognition panel sees controlled evidence packs but not a public ranking. Sensitive HR data and private feedback are protected and only reachable through a consent or safety route.
We process personal data under: your consent (where you have given it, e.g. for optional feedback); performance of a contract with your organisation; our legitimate interests in security, improvement and fraud prevention; and legal obligations (e.g. safeguarding and records law). Where data includes health or other special-category information, processing is limited to what is necessary for care, employment and social security purposes, under Article 9(2)(h).
We apply least-privilege access controls, encryption in transit and at rest, per-tenant isolation, session and device controls, and continuous audit monitoring. Our staff access is role-limited and logged.
We keep personal data only as long as needed for the purposes in this Policy or to meet legal, regulatory, safeguarding and tax requirements (for example, payroll and care records retention periods). When data is no longer needed, it is securely deleted.
You have the right to access, correct, erase or restrict the data we hold about you, to object to processing, to data portability, and to withdraw consent where consent is the basis. To exercise any of these rights, use the data-subject route in your portal, contact your organisation's administrator, or email sboniface@c2flexicare.co.uk. You can also raise a concern with your local data protection authority.
The Family Portal shares only the updates a family member is authorised to see, such as shift summaries and wellbeing notes. It never exposes other clients' data, internal rankings or payroll information.
We use essential cookies and session controls to keep you signed in securely. "Remember this device" is optional and can be changed in your session and device settings at any time.
We may update this Policy. Changes are versioned and effective-dated and you will be notified on your next sign-in. Continued use of the Service means you accept the updated Policy.
For privacy enquiries, contact our Data Protection Officer at sboniface@c2flexicare.co.uk or write to: Unit 5, Midshires Business Park, Smeaton Close, Aylesbury HP19 8HL.