Test Phase version — last updated 5 September 2026
NurturLog ("we", "us", "our") provides a digital visit check-in and reporting service for home-care agencies, carers, and the families of people receiving care.
NurturLog is operated by NurturLog Ltd (company number 17459362), a company registered in England and Wales with its registered office at Unit 8 Gate Way Court, Dankerwood Road, South Hykeham, Lincoln, Lincolnshire, LN6 9UL.
Contact: info@nurturlog.co.uk
NurturLog is currently in closed testing. It lets Carers record structured visit reports (tasks completed, issues found, notes, check-in/check-out times) against a Patient, and lets linked Family members and Admins view those reports. Patient records, schedules, and account access are managed by the Agency Admin.
Users must not: share their login with anyone else; attempt to access records for a patient they are not assigned/linked to; enter false or misleading information into a visit report; use the service for anything unlawful.
NurturLog is provided on an "as is" basis during this closed testing phase, for evaluation purposes. Please keep your existing primary record-keeping running alongside NurturLog during testing, rather than relying on it as your sole record.
To the fullest extent permitted by law, we exclude liability for indirect or consequential loss, and our total liability to you is limited to the fees you have paid us in the twelve months before a claim (which, during free closed testing, is £0). Nothing in this notice excludes or limits liability for death or personal injury caused by negligence, fraud, or anything else that the law does not allow us to exclude.
Either you or NurturLog may end your participation in the closed testing phase at any time, by emailing info@nurturlog.co.uk. We may also suspend or close an account for a breach of Section 5 (Acceptable use), or when the testing phase ends, giving reasonable notice where practical.
This notice is governed by the law of England & Wales, and the courts of England & Wales have jurisdiction over any dispute. We intend this to remain appropriate for agencies based anywhere in the UK, and will confirm this with a solicitor before NurturLog is made generally available.
This statement explains how NurturLog collects, uses, and protects personal data, in line with the UK GDPR and the Data Protection Act 2018.
| Data | About whom | Collected from |
|---|---|---|
| Name, email, role | Carers, Family members, Admins, Emergency Workers | Entered by the person themselves at sign-up, reviewed by an Admin |
| Job role title, staff number, professional registration number | Emergency Workers | Entered by the Emergency Worker at sign-up |
| Care needs, required visit duration | Patients | Entered by Admin |
| Visit reports: task status, notes, check-in/out times, issues logged, wellbeing check | Patients (about their care) | Entered by Carer at each visit |
| Notification content | Family members | Generated automatically from visit reports |
The Emergency Worker fields above exist so the responder's own organisation can verify an applicant against their internal HR or rostering records before approving them — NurturLog itself never checks or verifies these details.
We do not store payment details, government ID numbers, or special-category data beyond what's needed to describe a patient's care needs.
By ticking the acceptance checkbox at sign-up and creating an account, you confirm you have read and accept this notice — including that a patient's visit report information (check-in/check-out times, task completion status, carer notes) will be visible to the Carer(s) assigned to that patient, the Family member(s) linked to that patient's account, and Agency Admin users for account and service management. Your acceptance is recorded with a timestamp.
Some patients' records can also be accessed by an approved Emergency Worker via a scan of the patient's own NFC tag. This is a genuinely separate access route — a different legal basis, a much narrower scope, and no standing access at any point.
Data is stored using Firebase (Google Cloud) — Firestore database and Firebase Authentication, hosted in the United Kingdom (Google Cloud's europe-west2 region, London).
We do not sell personal data, and do not share it with any other third party except where required by law.
These are the retention rules we're currently following; we will confirm them against the UK GDPR storage-limitation principle, and any care-sector-specific record-keeping requirements, with a solicitor before general availability.
A note on Freedom of Information requests: the UK Freedom of Information Act 2000 (FOIA) applies to public authorities, not private companies, so NurturLog itself would not receive or need to respond to FOI requests directly. Family members cannot use an FOI request to obtain another person's personal data — the correct route for someone to request data about themselves is a UK GDPR Subject Access Request (see Section 8). A family member wanting data about a patient would need to be acting with the patient's consent or as their legally recognised representative.
Under UK GDPR, individuals have the right to: access the personal data held about them; ask for it to be corrected or deleted; restrict or object to processing; and request a copy in a portable format. Requests can be sent to info@nurturlog.co.uk. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
We protect your data using role-based Firestore security rules, enforced on Google's servers, that restrict each account to only its own assigned or linked patients; Firebase Authentication for sign-in, including account-enumeration-safe password reset; and encryption in transit and at rest, provided by Firebase's infrastructure defaults.
We may update this notice from time to time. The current version will always be available at nurturlog.co.uk/privacy.
Questions about this notice, or about your data: info@nurturlog.co.uk. We have not appointed a formal Data Protection Officer — given the small scale of this closed testing phase, we don't believe one is currently required under Article 37, and we'll reassess as NurturLog grows.