How PlacementHub handles data
PlacementHub is designed so that the people being placed are never identifiable on the platform. This policy explains, in plain English, what we collect, why, and your rights under UK GDPR.
De-identified by design
Placement, cleaning and transport requests carry requirement bands only — for example an age band, care-need categories and a mobility level. Names, addresses, dates of birth and NHS numbers are never collected, and the request form actively reminds officers not to enter them. Identifying detail is shared directly between the council and the awarded provider by secure email, outside the platform; both parties act as independent data controllers for that exchange.
What we do store
Organisation and business-contact details (work email, work phone) for officers and providers; provider credentials such as CQC registration; bids, awards and billing records.
Lawful basis
We process business-contact and organisational data on the basis of legitimate interests and the performance of our agreement with your organisation. No special-category or resident data is processed by the platform.
Where it lives
Data is stored with Supabase (PostgreSQL, EU/UK region) with row-level security, so each organisation can only see its own records. The public directory shows only information providers choose to publish.
Processors we use
Supabase (database & authentication), Vercel (hosting), Stripe (billing) and Resend (transactional email). Each processes data only to provide its part of the service, under its own data-protection terms.
Retention
Account and transaction records are kept for the life of the account and for as long as needed to meet legal, accounting and audit obligations, then deleted or anonymised.
Your rights
Organisations can request access, correction, export or deletion of their account data at any time via the contact page. You may also complain to the ICO.
Effective 18 June 2026 · Operated by Aclean Solutions Ltd, United Kingdom.