NurturLog
  • Home
  • About
  • Demo
  • Contact Us
Admin Login

Test Phase Notice. This notice applies during NurturLog's closed testing phase only, for the group of testers taking part. We will have this reviewed by a solicitor and issue a formally revised version before NurturLog is made generally available.

Privacy & Terms Notice

Test Phase version — last updated 5 September 2026

Part A — Terms & Conditions

1. Who we are

NurturLog ("we", "us", "our") provides a digital visit check-in and reporting service for home-care agencies, carers, and the families of people receiving care.

NurturLog is operated by NurturLog Ltd (company number 17459362), a company registered in England and Wales with its registered office at Unit 8 Gate Way Court, Dankerwood Road, South Hykeham, Lincoln, Lincolnshire, LN6 9UL.

Contact: info@nurturlog.co.uk

2. Definitions

  • Owner ("NurturLog", "we", "us", "our") — the team that owns and operates the NurturLog platform, responsible for the technical operation, availability, and security of the service, and processing personal data on the instructions of the Agency in order to provide it.
  • Agency Admin ("Admin") — a staff member of the care agency who manages carer accounts, family accounts, and patient records within NurturLog.
  • Carer — a care worker who uses NurturLog to record visit check-ins, check-outs, and care reports for the patients assigned to them.
  • Family — a family member or other nominated contact of a patient, who can view visit reports and notifications for the patient(s) they are linked to.
  • Emergency Worker — an approved first responder (e.g. a paramedic) from a partner organisation such as an NHS ambulance trust, who can access a narrow, emergency-only summary of a patient's record by scanning the patient's own NFC tag. See Part B, Section 4a for the full detail.
  • Patient — the person receiving care, whose visit records are stored in NurturLog. Patients are not typically direct users of the app themselves.

3. The service

NurturLog is currently in closed testing. It lets Carers record structured visit reports (tasks completed, issues found, notes, check-in/check-out times) against a Patient, and lets linked Family members and Admins view those reports. Patient records, schedules, and account access are managed by the Agency Admin.

4. Accounts

  • Carer, Family, and Emergency Worker accounts are created by the person themselves (self-registration), then reviewed and approved by an Agency Admin (or, for Emergency Workers, their trust's own Admin) before the account has any real access.
  • Each person is responsible for keeping their own login credentials confidential and for all activity on their account.
  • What happens to an account when a Patient, Family member, Carer, or the Agency itself leaves NurturLog — including how long data is kept — is set out in full in Part B, Section 7.

5. Acceptable use

Users must not: share their login with anyone else; attempt to access records for a patient they are not assigned/linked to; enter false or misleading information into a visit report; use the service for anything unlawful.

6. Availability and liability

NurturLog is provided on an "as is" basis during this closed testing phase, for evaluation purposes. Please keep your existing primary record-keeping running alongside NurturLog during testing, rather than relying on it as your sole record.

To the fullest extent permitted by law, we exclude liability for indirect or consequential loss, and our total liability to you is limited to the fees you have paid us in the twelve months before a claim (which, during free closed testing, is £0). Nothing in this notice excludes or limits liability for death or personal injury caused by negligence, fraud, or anything else that the law does not allow us to exclude.

7. Termination

Either you or NurturLog may end your participation in the closed testing phase at any time, by emailing info@nurturlog.co.uk. We may also suspend or close an account for a breach of Section 5 (Acceptable use), or when the testing phase ends, giving reasonable notice where practical.

8. Governing law

This notice is governed by the law of England & Wales, and the courts of England & Wales have jurisdiction over any dispute. We intend this to remain appropriate for agencies based anywhere in the UK, and will confirm this with a solicitor before NurturLog is made generally available.


Part B — Privacy / GDPR Statement

1. What this covers

This statement explains how NurturLog collects, uses, and protects personal data, in line with the UK GDPR and the Data Protection Act 2018.

2. Data we collect

DataAbout whomCollected from
Name, email, roleCarers, Family members, Admins, Emergency WorkersEntered by the person themselves at sign-up, reviewed by an Admin
Job role title, staff number, professional registration numberEmergency WorkersEntered by the Emergency Worker at sign-up
Care needs, required visit durationPatientsEntered by Admin
Visit reports: task status, notes, check-in/out times, issues logged, wellbeing checkPatients (about their care)Entered by Carer at each visit
Notification contentFamily membersGenerated automatically from visit reports

The Emergency Worker fields above exist so the responder's own organisation can verify an applicant against their internal HR or rostering records before approving them — NurturLog itself never checks or verifies these details.

We do not store payment details, government ID numbers, or special-category data beyond what's needed to describe a patient's care needs.

3. Why we process this data (lawful basis)

  • Performance of a contract — processing Carer/Family/Admin account data and visit records is necessary to provide the care-coordination service the agency has engaged us for.
  • Special category data (health-related care information) — visit report content (e.g. medication reminders, care needs, task notes) is processed under Article 9(2)(h) UK GDPR — provision of health/social care — on the basis of the agency's contract with the patient/family for care provision. We also record your explicit acceptance of this notice at sign-up, with a timestamp, as an additional basis.
  • Legitimate interests — basic security logging (e.g. login activity) to keep accounts safe.

4. Who can see what — consent to visibility

By ticking the acceptance checkbox at sign-up and creating an account, you confirm you have read and accept this notice — including that a patient's visit report information (check-in/check-out times, task completion status, carer notes) will be visible to the Carer(s) assigned to that patient, the Family member(s) linked to that patient's account, and Agency Admin users for account and service management. Your acceptance is recorded with a timestamp.

4a. Emergency access via NFC scan

Some patients' records can also be accessed by an approved Emergency Worker via a scan of the patient's own NFC tag. This is a genuinely separate access route — a different legal basis, a much narrower scope, and no standing access at any point.

  • Legal basis: Article 9(2)(c) UK GDPR — processing necessary to protect someone's vital interests, used specifically because the responder is very often unable to obtain consent at the point of need.
  • What is shown: a narrow, purpose-built summary only — allergies, current medications, and emergency contact details. Never the full patient record, never visit reports, and never anything about scheduling or which carer attends.
  • How access is granted: scanning the tag creates a genuinely time-limited grant — one hour — after which the responder's access ends automatically. There is no standing or ongoing access for any Emergency Worker to any patient's record outside of that window.
  • Who can be an Emergency Worker: only someone who has self-registered and been individually approved by their own organisation's admin.
  • Audit trail: every scan — who scanned, whose tag, and when — is permanently recorded and cannot be edited or deleted through the app by anyone, and it survives even if the responder's account is later closed. We retain this indefinitely to preserve accountability for emergency access to patient data, and will confirm this retention period with a solicitor before general availability.
  • Notification: a factual, minimal message is generated automatically whenever a scan happens, naming the responder's role and organisation (e.g. "A Paramedic from [Trust Name] accessed [Patient]'s record") — never the responder's own personal name.
  • What the responder's own organisation can see: their own admin can see a log of scans made by their own staff (who scanned, whose tag, when) for oversight purposes, but never the medical content shown during any individual scan.

5. Where data is stored

Data is stored using Firebase (Google Cloud) — Firestore database and Firebase Authentication, hosted in the United Kingdom (Google Cloud's europe-west2 region, London).

6. Who we share data with (processors)

  • Google Firebase / Google Cloud — hosting, database, authentication.
  • Formspree — processes messages submitted via the website contact form only (not app data).

We do not sell personal data, and do not share it with any other third party except where required by law.

7. How long we keep data

  • Patients — when a patient leaves NurturLog's care coordination, their account is deleted. Their visit reports are retained digitally for 2 years from the date they left, then deleted. Their record is unlinked from any Family accounts that were linked to them.
  • Family accounts — if a Family account has no patients linked to it for more than 3 months, the account is disabled. If it remains inactive for more than 6 months, the account and all associated data are permanently deleted.
  • Carer accounts — when a Carer leaves the agency, their account is disabled immediately, a performance overview record is generated for the agency's own records, and the account (including login credentials) is deleted after 1 year.
  • Emergency Worker accounts — if an account shows no activity for more than 14 days, it is automatically disabled the next time that person tries to log in. If it remains disabled for more than 4 weeks, it becomes eligible for deletion by their own organisation's admin. The permanent scan audit trail is not affected by this.
  • Agency accounts — if an agency stops using NurturLog, their account access is removed, but agency-level records are retained for up to 2 years for auditing purposes before deletion.

These are the retention rules we're currently following; we will confirm them against the UK GDPR storage-limitation principle, and any care-sector-specific record-keeping requirements, with a solicitor before general availability.

A note on Freedom of Information requests: the UK Freedom of Information Act 2000 (FOIA) applies to public authorities, not private companies, so NurturLog itself would not receive or need to respond to FOI requests directly. Family members cannot use an FOI request to obtain another person's personal data — the correct route for someone to request data about themselves is a UK GDPR Subject Access Request (see Section 8). A family member wanting data about a patient would need to be acting with the patient's consent or as their legally recognised representative.

8. Your rights

Under UK GDPR, individuals have the right to: access the personal data held about them; ask for it to be corrected or deleted; restrict or object to processing; and request a copy in a portable format. Requests can be sent to info@nurturlog.co.uk. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

9. Security

We protect your data using role-based Firestore security rules, enforced on Google's servers, that restrict each account to only its own assigned or linked patients; Firebase Authentication for sign-in, including account-enumeration-safe password reset; and encryption in transit and at rest, provided by Firebase's infrastructure defaults.

10. Changes to this notice

We may update this notice from time to time. The current version will always be available at nurturlog.co.uk/privacy.

11. Contact

Questions about this notice, or about your data: info@nurturlog.co.uk. We have not appointed a formal Data Protection Officer — given the small scale of this closed testing phase, we don't believe one is currently required under Article 37, and we'll reassess as NurturLog grows.

NurturLog
  • About
  • Demo
  • Contact Us
  • Privacy & Terms
© 2026 NurturLog