
Last updated: August 2026
KinMerge is a workforce compliance platform for UK domiciliary care providers, offering training, appraisal, supervision, and absence management. This Privacy Policy explains how we collect, use, and protect personal data when you use the KinMerge platform.
We process the following categories of personal data: • Account data: name, email address, and authentication credentials. • Workforce data: carer names, email addresses, job roles, start dates, training records, course completions, certificates, appraisal and supervision records. • Absence data: holiday bookings, sickness records, and entitlement balances. • Compliance data: Certificate of Sponsorship (COS/visa) details, driver information (MOT, insurance, tax renewal dates, vehicle numberplate), and fire drill records. • Support data: information you provide when contacting support (name, email, issue description). • Usage data: IP address (for rate limiting and security), and platform usage analytics.
We process personal data for the following purposes: • Providing and managing the platform, including user accounts and authentication. • Tracking and managing workforce training, compliance, appraisals, and supervisions. • Recording and calculating absence (holidays and sickness) and entitlements. • Sending automated email reminders for expiring documents, training, appraisals, and supervisions. • Processing membership subscriptions and payments (via our payment provider). • Responding to support requests and providing customer service. • Maintaining platform security, including IP-based rate limiting and bot protection.
Under the UK GDPR and EU GDPR, we process personal data on the following legal bases: • Performance of a contract: providing the workforce compliance services you have subscribed to. • Legal obligation: maintaining records required for CQC compliance and employment law. • Legitimate interests: platform security, fraud prevention, and service improvement. • Consent: where you explicitly provide information (e.g., support requests). Your organisation (the care provider) acts as the data controller for workforce data entered into the platform. KinMerge acts as a data processor on behalf of the controller.
We do not sell your personal data. We share data only with: • Your employer (the care provider organisation that created your account). • Our payment provider (Stripe) — for processing membership subscription payments. Stripe processes card data under its own PCI-DSS compliant systems; we do not store card numbers. • Our hosting and infrastructure provider (Base44) — for data storage and application hosting. • Telegram — for internal admin alert notifications (support ticket notifications only, no personal data of carers). • Authorities where legally required (e.g., CQC compliance audits).
We retain personal data for as long as your account is active. When a carer is archived or deleted, their data is retained for the period required by CQC and employment law (typically 6 years for employment records). Deleted carer records are moved to a deleted carers archive accessible to administrators for audit purposes.
Under the UK GDPR, you have the following rights: • Right of access — request a copy of your personal data. • Right to rectification — correct inaccurate or incomplete data. • Right to erasure — request deletion of your data (subject to legal retention requirements). • Right to restrict processing — limit how we use your data. • Right to data portability — receive your data in a structured, machine-readable format. • Right to object — object to processing based on legitimate interests. • Right to withdraw consent — where processing is based on consent. To exercise these rights, contact your employer (the data controller) or KinMerge support.
We implement appropriate technical and organisational measures to protect your data: • TLS/HTTPS encryption for all data in transit. • Row-level security isolating data between different care provider organisations. • IP-based rate limiting to prevent abuse and bot attacks. • Honeypot bot detection on public forms. • Content-Security-Policy and security headers to mitigate XSS and clickjacking. • No storage of payment card details (handled by Stripe). • Regular security reviews and vulnerability scanning.
Your data is stored on servers located within the European Union / United Kingdom. Where any processing occurs outside the UK/EU, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or adequacy decisions.
KinMerge uses minimal cookies strictly necessary for authentication and platform functionality. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. No cookies with personal or tracking information are sent to third parties.
We may update this Privacy Policy from time to time. We will notify users of significant changes through the platform. The effective date is shown below.
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact KinMerge support through the in-app support chat, or contact your organisation's designated data protection officer.
KinMerge — Workforce compliance, training and absence management for UK domiciliary care providers.