Legal
Privacy Policy
How S&N Flexi Agency Ltd collects, uses, and protects your personal data — in plain English.
S&N Flexi Agency Ltd is committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, how we use it, and your rights under UK GDPR and the Data Protection Act 2018.
1. Who We Are
S&N Flexi Agency Ltd is a CQC-registered domiciliary care provider based in Bolton and Carlisle, England. We are the data controller for the personal information you provide to us.
Registered address: 1–3 The Courtyard, Calvin Street, The Valley, Bolton, BL1 8PB
Email: hello@snflexiagency.co.uk
Phone: 01204 952 009
2. What Personal Data We Collect
Depending on how you interact with us, we may collect the following types of personal data:
- Contact information — name, email address, phone number, postal address
- Care-related information — health and care needs, medical conditions, next of kin details, GP and healthcare professional details
- Financial information — billing details, funding source (e.g. self-funded, local authority, NHS-funded)
- Technical data — IP address, browser type, pages visited, if you use our website
- Communications — records of emails, calls, and enquiries you send to us
3. How We Collect Your Data
We collect personal data through:
- Enquiry and contact forms on our website
- Telephone conversations and email correspondence
- Care assessments and care planning meetings
- Referrals from GPs, social workers, local authorities, or family members
- Automatic collection via cookies and analytics tools on our website
4. Why We Use Your Data (Legal Basis)
We process personal data under the following lawful bases:
- Contract performance — to deliver care services you have engaged us to provide
- Legal obligation — to comply with CQC regulations, safeguarding duties, and employment law
- Legitimate interests — to respond to enquiries, improve our services, and manage our business
- Consent — where we ask for your explicit permission, such as for marketing communications
- Vital interests — in emergency situations where processing is necessary to protect life
Where we process special category data (health information), we do so under Article 9(2)(h) of UK GDPR — for the purposes of providing healthcare and social care services.
5. How We Share Your Data
We do not sell your personal data. We may share it with:
- Healthcare professionals — GPs, district nurses, hospital teams, where relevant to your care
- Local authorities and commissioners — where care is funded or arranged through social services
- Regulatory bodies — the Care Quality Commission (CQC) and other statutory bodies as required
- IT and software providers — care management software, email hosting, and website analytics providers acting as data processors under contract
- Legal and professional advisors — where required for compliance or dispute resolution
All third parties we work with are required to handle your data securely and in accordance with UK GDPR.
6. How Long We Keep Your Data
We retain personal data for as long as necessary to fulfil the purposes for which it was collected, and in line with our legal and regulatory obligations:
- Care records — retained for a minimum of 8 years after the end of the care relationship (or until the age of 25 for younger adults), in line with NHS and CQC guidance
- Financial records — 7 years, in line with HMRC requirements
- Enquiry data (non-clients) — 12 months from the date of last contact
- Website analytics data — up to 26 months
7. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access — to request a copy of the data we hold about you (subject access request)
- Right to rectification — to have inaccurate data corrected
- Right to erasure — to request deletion of your data, where no overriding legal obligation requires us to retain it
- Right to restrict processing — to ask us to pause processing your data in certain circumstances
- Right to data portability — to receive your data in a structured, machine-readable format
- Right to object — to processing based on legitimate interests or for direct marketing
- Rights related to automated decision-making — we do not carry out automated profiling or decision-making
To exercise any of these rights, please contact us at hello@snflexiagency.co.uk. We will respond within one month.
8. Cookies
Our website uses cookies to improve your experience and understand how visitors use our site. These include:
- Essential cookies — necessary for the website to function correctly
- Analytics cookies — used to understand visitor behaviour (e.g. Google Analytics), anonymised where possible
You can control cookies through your browser settings. Disabling analytics cookies will not affect your ability to use the website.
9. Data Security
We take the security of your personal data seriously. We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, alteration, or disclosure. These include access controls, encryption of sensitive records, and regular staff training on data protection.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and inform affected individuals without undue delay.
10. International Transfers
We do not routinely transfer personal data outside the United Kingdom. Where any transfer is necessary, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
11. The Information Commissioner's Office
You have the right to lodge a complaint with the UK's data protection authority if you are unhappy with how we have handled your data:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113
We would always welcome the opportunity to resolve any concern directly — please contact us first at hello@snflexiagency.co.uk.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Any significant changes will be communicated via our website. The date at the top of this page reflects when the policy was last revised.