PlacementHub
Privacy

How PlacementHub handles data

PlacementHub is designed so that the people being placed are never identifiable on the platform. This policy explains, in plain English, what we collect, why, and your rights under UK GDPR.

De-identified by design

Placement, cleaning and transport requests carry requirement bands only — for example an age band, care-need categories and a mobility level. Names, addresses, dates of birth and NHS numbers are never collected, and the request form actively reminds officers not to enter them. Identifying detail is shared directly between the council and the awarded provider by secure email, outside the platform; both parties act as independent data controllers for that exchange.

What we do store

Organisation and business-contact details (work email, work phone) for officers and providers; provider credentials such as CQC registration; bids, awards and billing records.

Lawful basis

We process business-contact and organisational data on the basis of legitimate interests and the performance of our agreement with your organisation. No special-category or resident data is processed by the platform.

Where it lives

Data is stored with Supabase (PostgreSQL, EU/UK region) with row-level security, so each organisation can only see its own records. The public directory shows only information providers choose to publish.

Processors we use

Supabase (database & authentication), Vercel (hosting), Stripe (billing) and Resend (transactional email). Each processes data only to provide its part of the service, under its own data-protection terms.

Retention

Account and transaction records are kept for the life of the account and for as long as needed to meet legal, accounting and audit obligations, then deleted or anonymised.

Your rights

Organisations can request access, correction, export or deletion of their account data at any time via the contact page. You may also complain to the ICO.

Effective 18 June 2026 · Operated by Aclean Solutions Ltd, United Kingdom.