Privacy policy.
Your privacy is very important to us.
Last updated: 8 October 2026
This notice explains how Soma Healthcare Ltd uses personal information when you visit this website, contact us, call us, use our care services or apply to work with us. Soma Healthcare Ltd is the controller of this information.
Soma Healthcare Ltd, Unit 2, 7 Tarves Way, Greenwich, London SE10 9JP. Registered in England and Wales, company number 02754194.
CEO: Jayson Walker. Executive Chair: Yemisi Gibbons.
The email address to contact is info@somahealthcare.co.uk.
We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
What information we collect
When you visit our website
Our website host, Netlify, records technical information such as your IP address, the page you asked for and the time, so that it can deliver the website and keep it secure. Legal basis: legitimate interests (running a secure website). This website sets no cookies and uses no analytics or advertising tools.
When you contact us by email
- Your email address and message content
- Any personal information you choose to include
Legal basis: legitimate interests (replying to you).
When you call us
- Your name and phone number
- Voice recordings of the conversation
- Information about your care needs (if discussed)
- Date, time, and duration of call
Legal basis: legitimate interests (answering your call, passing your message to the right person, keeping an accurate record, handling complaints and keeping people safe). If you tell us about health or care needs, we use that information for health and social care purposes.
When you use our care services
- Personal details (name, date of birth, address, next of kin)
- Health and care information (care plans, medications, medical conditions)
- Emergency contact information
- Records of care visits and services provided
Legal basis:
- Contractual necessity (to provide care services)
- Legal obligation (CQC, NHS, and social care regulations)
- Vital interests (in emergencies)
Special category data (health information) processed under:
- Health and social care purposes (Article 9(2)(h) UK GDPR)
Forms on this website
This section explains the forms on this website.
Free care assessment requests
We collect your name, phone number, the postcode of the person who needs care, who needs care, how care might be paid for (optional) and the best time to call. We use these details only to call you back and arrange the assessment. The form asks you not to include medical details. Legal basis: taking steps at your request before a possible contract, and our legitimate interest in responding to enquiries.
Referrals from professionals
We collect the referrer's name, organisation, role, direct phone and email, the first part of the client's postcode, the type of care, the funding route and the date care is needed by. We do not collect the client's name, diagnosis or clinical details through the form; we take the clinical picture by phone. If you were referred to us, we received your postcode area and the type of care needed from the professional who referred you, and we will tell you this when we first speak to you. Legal basis: legitimate interests (arranging care a professional has asked us to provide).
Supplier pack requests
We collect your name, organisation and email to send the pack and answer your questions. Legal basis: legitimate interests.
Job applicants
What we collect: the details in the application request (name, phone, email, role, any extra information). We then ask you to complete our applicant forms and email them to our recruitment team: the application form, availability form, interview questionnaire, a conviction declaration, a fitness to work declaration, the DBS form and our confidentiality and data protection declarations. These include information about criminal records and your health. We check your identity and right to work in person.
Why and legal basis: to decide whether to employ you (steps you ask us to take before a possible contract); to check your right to work and meet our legal duties as a CQC-registered care provider (legal obligation); criminal record and health information only as employment law and the rules for care roles allow.
Who sees it: our recruitment team and managers; the recruitment mailbox you send your forms to; the DBS and the body that processes our DBS checks; the Home Office online right-to-work service; our website host Netlify for the first request.
How long we keep it: if you are not offered a job, we delete your application 6 months after our decision. If you join us, it becomes part of your staff file. We delete DBS certificate details within 6 months of the recruitment decision and keep only the date, certificate number and outcome.
Please do not email your passport, ID or right-to-work documents. Bring them to your interview.
Postcode checks
When you use the postcode checker, we keep a statistical count: the first part of the postcode only (for example RM2, never the full postcode), whether we cover it, the date and hour, the page, the kind of site you came from, the type of device, and whether you then called us or sent the assessment form from the same browser tab. We do not store your IP address or anything that identifies you with these counts, and we use these counts only to understand where people look for care. We keep them for 24 months. You can switch this off for your browser on our cookie policy page.
Who receives form submissions
Each form submission is emailed to our office inbox, with a copy to robin@somahealth.care, the mailbox of Robin, the call-handling service PriorityLine runs for us. Form submissions are received through our website host, Netlify, Inc., which processes them for us and stores them in the United States. A written data processing agreement between Soma Healthcare Ltd and CS Platforms Ltd is being put in place. Netlify checks each submission for spam using Akismet (Automattic Inc., United States). Netlify is certified under the UK Extension to the EU-US Data Privacy Framework, and its contract includes the UK International Data Transfer Addendum as a fallback. We delete submissions from Netlify 30 days after we receive them. Enquiries and referrals that do not lead to care are deleted from our inbox after 12 months. We do not use form details for marketing, and no form asks for marketing consent.
Call recording
Calls to 020 7093 4710 are answered by Robin, an AI assistant provided for us by PriorityLine. Robin is not a person. Every call is recorded and transcribed. You are told at the start of the call that it is recorded.
We record calls so that your message reaches the right person accurately, to keep people safe, to deal with complaints, and to train staff and improve the service.
Recordings and transcripts are held for us by PriorityLine and its technology providers in the UK, the EU and the United States. A written data processing agreement between Soma Healthcare Ltd and CS Platforms Ltd is being put in place. Transfers outside the UK are protected by the safeguards UK data protection law requires, such as the UK Extension to the EU-US Data Privacy Framework or the UK International Data Transfer Addendum. You can ask us for details.
We keep call recordings only as long as we need them for these purposes, then delete them. If a call becomes part of a care record, a safeguarding matter or a complaint, we keep it as long as that record.
Phone greeting
When you call, you'll hear: "Thank you for contacting Soma Healthcare. This call is being recorded for training and monitoring purposes. How can I help you today?"
How we use your information
We use your personal information to:
- Provide care services - delivering your care plan, coordinating visits
- Communicate with you - responding to enquiries, appointment reminders
- Meet legal obligations - CQC inspections, safeguarding duties, NHS reporting
- Improve our services - quality monitoring, staff training, service development
- Manage our business - billing, complaints handling, record keeping
We will not:
- Sell your information to third parties
- Use it for marketing without your explicit consent
- Share it except as described in this policy
Who we share your information with
We may share your information with:
Essential care partners
- NHS and local authority commissioners
- GPs and other healthcare professionals involved in your care
- Pharmacies (for medication management)
- Equipment suppliers
- Emergency services (in urgent situations)
Technology service providers
- PriorityLine - AI call handling (Robin)
- Netlify - website hosting and website forms, with Akismet spam checks
- Cloud storage providers - secure data hosting
- IT support services - system maintenance
Regulatory and legal
- Care Quality Commission (CQC) - inspections and investigations
- Local Authority safeguarding teams - if we have concerns about your safety
- Police or courts - if legally required
- Professional indemnity insurers - if there is a claim
With your consent
- Family members or representatives you have authorised
- Other care providers you have asked us to coordinate with
All third parties are required to keep your information secure and use it only for the purposes we specify.
International transfers
Some of our service providers are in the United States: PriorityLine's technology providers for call recordings and transcripts, and Netlify and Akismet for this website and its forms. Transfers outside the UK are protected by the safeguards UK data protection law requires, such as the UK Extension to the EU-US Data Privacy Framework or the UK International Data Transfer Addendum. You can ask us for details.
How long we keep your information
| Information type | Retention period | Reason |
|---|---|---|
| Call recordings | Until they are no longer needed for the purposes above; as long as the care record, safeguarding matter or complaint if they become part of one | Purposes above |
| Website form submissions held by Netlify | 30 days | Deleted automatically |
| Enquiries and referrals that do not lead to care | 12 months | Responding to you |
| Job applications that do not lead to a job offer | 6 months after our decision | Recruitment |
| DBS certificate details | 6 months after the recruitment decision, then only the date, certificate number and outcome | Recruitment checks |
| Postcode statistics | 24 months | Deleted automatically |
| Care records | 7 years after last service | CQC and NHS requirements |
| Financial records | 6 years | HMRC requirement |
| Emails and correspondence | 2 years | Business purposes |
| Marketing consent | Until withdrawn | Legal requirement |
After these periods, information is securely deleted or anonymised.
Your rights
Under UK GDPR, you have the following rights:
- Right of access (subject access request). Request a copy of the personal information we hold about you.
- Right to rectification. Ask us to correct inaccurate or incomplete information.
- Right to erasure. Request deletion of your information (subject to legal retention requirements).
- Right to restriction. Ask us to stop using your information while we investigate a concern.
- Right to data portability. Receive your information in a portable format to transfer to another provider.
- Right to object. Object to processing based on legitimate interests.
- Rights related to automated decision-making. We use AI (Robin) to answer calls and pass on messages, but all care decisions are made by our staff.
Please note: some rights are limited by legal obligations (for example, we cannot delete care records we must keep).
How to exercise your rights
Email info@somahealthcare.co.uk or use the details on our contact page.
We will respond within one month. If a request is complex, we may extend this by up to two further months and will tell you why.
Cookies
This website sets no cookies. The postcode checker uses your browser's session storage, and the CQC rating boxes load from cqc.org.uk. Our cookie policy explains both.
Email policies
What we do
- Use your email only for the purposes you provided it
- Keep your email address confidential
- Comply with the UK Privacy and Electronic Communications Regulations (PECR)
- Include unsubscribe options in all marketing emails
What we do not do
- Sell or rent email lists
- Send unsolicited marketing (unless you have consented)
- Share your email with third parties (except as listed above)
To unsubscribe
Click the "unsubscribe" link at the bottom of any marketing email.
Security
We protect your information through:
- Access controls - only authorised staff can access care records
- Staff training - all staff trained in data protection
- Secure systems - regular security updates and monitoring
Email is not a secure communication method. Please do not send highly sensitive information by email. Call us instead.
Changes to this notice
We last updated this notice on 8 October 2026. If we make significant changes, we will say so on this page.
Complaints
If you are unhappy with how we have handled your information:
- Contact us first: email info@somahealthcare.co.uk or use our contact page.
- If you are still unsatisfied, contact the Information Commissioner's Office (ICO): ico.org.uk, phone 0303 123 1113, post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
You have the right to complain to the ICO at any time.
External links
Our website may contain links to other websites. We are not responsible for the privacy practices of external sites. Please read their privacy policies before providing personal information.
Children
We also care for children. When we do, we usually deal with a parent, guardian or the local authority, and we explain to the child, in a way they can understand, how we use their information.
Contact us
For any questions about this privacy notice or your personal information: Soma Healthcare Ltd, info@somahealthcare.co.uk, 020 7093 4710.