Privacy notice

Version 1.0 · Last updated 16 September 2026

This notice explains what personal information HeraIQ holds, why, and what you can do about it. It covers visitors to this website, people who join our waitlist or contact us, people with a HeraIQ account, carers, and the care organisations on our prospect list.

Who we are

HeraIQ is a trading name of HERA INTELLIGENCE LTD, a company registered in England and Wales (company number 17459930).

Registered office: as shown on the Companies House register

Our ICO registration reference will be published here once issued.

Contact: hello@heraiq.io

For the information described in the sections on website visitors, the waitlist and contact requests, accounts, carers, the prospect list, AI misuse flags and running the service, we are the controller. That means we decide how the information is used and we are responsible for it.

For the records a care provider keeps in HeraIQ, the care provider is the controller and we act on its instructions. The section When we act for a care provider explains what that means for you.

We have not appointed a Data Protection Officer. We have recorded our reasons for that decision, and data protection questions go to hello@heraiq.io.

To report a security problem, email security@heraiq.io.

The short version

  • HeraIQ is software for care providers registered with the Care Quality Commission (CQC). The records they keep about the people they support and their staff are theirs. They are the controller, and we process those records for them.
  • About you directly, we hold what you give us to join, get in touch or sign in, and the records that keep the service secure.
  • Website analytics runs only if you accept it, and only on our public pages. See cookies.
  • Our AI features use OpenAI. They prepare answers and drafts for people to check, and changes to care records wait for a person to confirm. A few preferences, notes and reminders save straight away instead, and Hera can run the organisation's own CQC self-audit without asking; each one is recorded in the audit trail. We keep a record of AI requests in LangSmith, in the EU, to find and fix problems. We do not train AI models on your information.
  • We do not sell personal information.
  • You have rights over your information, and you can complain to us or to the Information Commissioner's Office (ICO).

Visitors to this website

What we collect
Only if you accept analytics cookies: the public pages you view, two actions (clicking a sign-up button and sending a contact message), a random identifier stored in a cookie, and the IP address and browser details that reach PostHog with each of these. No session recordings, heatmaps or automatic click tracking. If you refuse, PostHog is never loaded and none of this is sent to it.
Why
To understand which pages are useful and where people stop on the way to joining.
Lawful basis
Your consent. You can withdraw it at any time, and withdrawing does not affect what was collected before.
How long
12 months
Who receives it
PostHog, Inc., our analytics provider, which holds it on its EU cloud in Frankfurt, Germany. Analytics never runs in the signed-in product.

Some cookies are needed whether or not you accept analytics, for example to remember your choice and to keep you signed in. Our cookie notice names each one and explains how to change your choice.

Whether or not you accept analytics, our hosting provider logs each request to this website. See Keeping the service secure and running.

Waitlist and contact requests

Waitlist requests we already hold

This website used to carry a form for joining a waitlist, before anyone could sign up. That form has gone and we are not collecting waitlist requests any more, but we still hold the requests people sent while it was there.

What we hold
Your email address, the name of your care service, and any note you added.
Why
To contact you about getting access to HeraIQ.
Lawful basis
Legitimate interests: replying to your request for access to HeraIQ.
How long
12 months after your request
Who receives it
Supabase, which hosts our database in London.

Contacting us

What we collect
Your email address, your name if you give it, the subject, your message and the replies in the conversation. If you are signed in, we link the request to your account instead of storing your email address again, and note which organisation you belong to.
Why
To answer your question or help with your problem.
Lawful basis
Legitimate interests: answering the people who contact us.
Do you have to give it?
A way to reply, a subject and your message are needed so we can answer. Your name is optional.
How long
24 months after the request is closed
Who receives it
Supabase stores the conversation. Resend emails a copy of a new request to our inbox and delivers our emailed replies. If you use the HeraIQ Care app, Expo delivers a notification that we have replied, without the content of the reply.

Your employer cannot read a request you send us. It goes to HeraIQ staff only.

People with a HeraIQ account

This section is for managers and office staff at a care provider.

What we collect
Your name, work email address and password, your organisation's name, the care home or site, and its CQC location ID if you give it. Your password is handled by our sign-in service, Supabase, and we never see it. We also set sign-in cookies, store a push notification token if you use the app, and, when you use second-factor sign-in by email, store the one-time code in scrambled form.
Why
To create and run your account, keep it secure, send you service emails and help when you ask.
Lawful basis
Legitimate interests: providing the service your organisation signed up for, and keeping accounts secure.
Do you have to give it?
A name, email address and password are needed for an account. Without them we cannot create one.
How long
Account details: for the life of the account, plus 90 days. Push notification tokens: stop being used when you sign out and deleted within 24 hours, or after 180 days without use. Second-factor codes: Deleted when used, or within 24 hours of expiring.
Who receives it
Supabase (database and sign-in), Vercel (hosting), Resend (service emails and sign-in codes) and Expo (app notifications).

What you record in HeraIQ about the people your organisation supports, and about its staff, is covered in When we act for a care provider.

Carers

A carer can hold their own HeraIQ Care account, profile and document cabinet, and keep them when they move between employers.

What we collect
Your name, email address and password (handled by Supabase, and never seen by us), your phone number and date of birth if you add them, a push notification token, the one-time code in scrambled form when you use second-factor sign-in by email, and the documents you upload to your cabinet, such as an identity document, right to work evidence, a DBS certificate, training certificates or proof of address.
Why
To give you an account and a profile that belong to you, and to let you offer your documents to an employer when you choose to.
Lawful basis
Contract: providing the account and document cabinet you signed up for.
Do you have to give it?
A name, email address and password are needed for an account. Everything else is up to you.
How long
Account details: for the life of the account, plus 90 days. Push notification tokens: stop being used when you sign out and deleted within 24 hours, or after 180 days without use. Second-factor codes: Deleted when used, or within 24 hours of expiring.
Who receives it
Supabase (database, sign-in and file storage), Vercel (hosting), Resend (service emails and sign-in codes) and Expo (app notifications). If you use Hera or dictate a note, OpenAI processes what you say or type, and LangSmith keeps a record of the request, as described in How we use AI.

A DBS certificate can contain criminal record information, which the law treats with extra care. It is in your cabinet only because you uploaded it, and no employer can see a document until you offer it to them.

When you join an employer, or offer a document to one, that employer becomes the controller of its copy and of your work records, such as your rota, visits, check-in and check-out records, notes and training. Questions about those records go to your employer. See When we act for a care provider.

Care organisations on our prospect list

This section is for care organisations registered with CQC, and for anyone who reads an email address we hold for one. We did not collect most of this information from you, so we are telling you where it came from.

What we hold
For each CQC-registered location whose provider CQC lists as an organisation or an NHS body: its name, address, phone number, website, service types, size and rating, and details of the provider such as its company or charity number. Where we have one, an email address for the organisation. We do not take the names of registered managers or other people from the register, and we do not include providers that CQC lists as individuals, such as sole traders, or as partnerships.
Where it came from
The CQC register of active locations, which is public and licensed under the Open Government Licence v3.0. Email addresses come from the Charity Commission's public register of charities or from the organisation's own website, and are general mailboxes such as info@ or enquiries@. Our staff can also enter an address that someone at the organisation gave us, for example on a phone call, which may be a named person's work address.
Why
To tell care organisations about HeraIQ by email.
Lawful basis
Legitimate interests: telling care organisations about a service built for them.
What happens now
Sending is switched off, and we have not emailed anyone on this list. If we switch it on, every email will say who we are and include a link to unsubscribe.
How long
We keep each entry while its location is on the CQC register. When a location leaves the register, we mark it inactive. We have not yet decided how long inactive entries are kept before they are deleted. If you object, we keep a record of the objection for as long as we hold the list, so that we keep honouring it.
Who receives it
Supabase, which hosts our database. If sending is switched on, Resend delivers the emails.

Your right to object

You can object at any time to our using these details to tell you about HeraIQ, whether you speak for the organisation or are a person who reads one of these mailboxes. Email hello@heraiq.io and we will stop. We keep the objection so that the address is not emailed in future.

AI misuse flags and account blocking

Hera, our AI assistant, is for care management. When it declines a request as off-topic, we record that request so we can spot misuse.

What we record
Up to 500 characters of your message (not Hera's reply or the rest of the conversation), your account, your organisation, whether it came from the manager portal, the carer app or voice, the AI model used, and our staff's review decision.
Why
To detect and stop use of Hera for things it is not for, and to protect the service for everyone.
Lawful basis
Legitimate interests: preventing misuse of the service.
Who can see it
Only named HeraIQ staff, in a console that needs a second sign-in step. Your organisation cannot see it.
What can happen
A flag is only a prompt for review. A member of our staff reads it and may dismiss it, escalate it, or block an account or an organisation. Nothing is blocked automatically.
How long
180 days, after which a nightly job deletes it. A record of each block or unblock, with its reason, is kept for 730 days.
Who receives it
Supabase, which hosts our database.

If you think a flag or a block was wrong, email hello@heraiq.io.

Keeping the service secure and running

We keep a few records about how the service is used, so we can keep it secure, fix problems, stop abuse and control costs. Our lawful basis is legitimate interests in running a secure and reliable service. Supabase hosts these records, apart from request logs, which Vercel keeps.

  • Request logs. When your browser or the app contacts HeraIQ, Vercel, our hosting provider, handles the request and logs details such as your IP address, browser and the page requested, whether or not you accept analytics. We also hold your IP address briefly in memory to limit how many requests one connection can make, for example to our contact form.
  • Sign-in cookies, which last until you sign out.
  • Error records: the kind of error, the screen and the organisation, without who saw it. Kept for 90 days.
  • AI usage records: the organisation, the task, the model, and the amount and cost of AI processing, without who made the request or what it said. Kept for 400 days.
  • Email delivery receipts: a scrambled form of the recipient's address and whether the email was sent. Kept for 365 days.
  • Push delivery receipts: the device token a notification was sent to and whether it was delivered. Kept for 180 days.
  • Second-factor sign-in codes, in scrambled form: Deleted when used, or within 24 hours of expiring.

When we act for a care provider

Care providers use HeraIQ to keep their records. For everything held in a care provider's account, the care provider is the controller and we are its processor. We use that information to provide HeraIQ to the care provider, under a data processing agreement. That includes:

  • records about the people they support: identity and contact details, health and care needs, risks, medication information, DNAR status, NHS number, next of kin and GP, mental capacity and safeguarding information, care plans, risk assessments and visit notes;
  • records about their staff: identity and contact details, rotas and visits, check-in and check-out location records, training, DBS certificate details, and right to work and identity documents;
  • messages, and conversations with Hera about the care provider's service.

Separately, we keep a few limited records for our own purposes of security, preventing misuse and controlling costs, and for those we are the controller. They are described in AI misuse flags and account blocking and Keeping the service secure and running.

If you receive care from, or work for, a care provider that uses HeraIQ, please contact that care provider about your information, including to use your rights. If you contact us instead, we will tell you which provider to contact, or pass your request on, and help the provider respond.

We do not train AI models on this information, and we do not use it as examples for anyone else.

When a care provider's subscription ends: 90 days to request an export, then deleted within 30 days. Backup copies then age out on their own schedules, which depend on where each copy is held. We will confirm the current periods in writing on request.

How we use AI

Hera and the other AI features in HeraIQ use OpenAI. OpenAI receives only what a request needs, in order to answer it:

  • the text you type to Hera, and the records Hera looks up to answer;
  • your voice in a voice conversation, sent straight from your browser to OpenAI;
  • dictated notes, to turn them into text;
  • documents it is asked to read, including identity documents and DBS certificates, to pull out details for a person to check;
  • text to be read aloud, descriptions for images, and text used to search records.

OpenAI processes this on its standard infrastructure, not in a UK or EU region. It keeps abuse-monitoring logs for up to 30 days, and by default does not use this information to train its models. We do not train AI models on your information either.

We keep a record of each AI request, including what it looked up and what it answered, in LangSmith, so that we can find and fix problems with Hera. LangSmith holds these records in its EU region for up to 400 days. If our systems are ever pointed at LangSmith anywhere else, this monitoring switches itself off.

AI prepares answers and drafts. Changes to clinical, identity, status or rota records are prepared as confirmations that a named person applies. Four preference fields on a person's record save straight away and are logged with their previous value. The notes and reminders Hera is asked to remember also save straight away, and you can ask Hera to forget a memory. Hera can also run the organisation's own CQC self-audit, and set how often it runs, without asking first; a run records a reading and a draft report and changes no care record.

We do not make decisions about anyone by automated means alone that have legal or similarly significant effects. AI drafts are reviewed by the care provider's staff, and an account is blocked only after one of our staff has reviewed it.

Who we share information with, and where it goes

We use the service providers below to run HeraIQ. They process information only on our instructions. Our sub-processors page gives more detail about each one, including what it receives.

Our service providers, where they process information and the safeguard for transfers
ProviderWhat it doesWhereTransfer safeguard
Supabase Pte. LtdDatabase, sign-in and file storage.London, United Kingdom (AWS eu-west-2). Supabase may process some data, such as logs and metrics, outside that region where needed to provide the service.EU Standard Contractual Clauses with the UK Addendum.
Vercel Inc.Hosting for the website, the app and its server functions.Server functions run in London, United Kingdom (lhr1). Vercel's primary processing facilities are in the United States.UK International Data Transfer Addendum (IDTA).
OpenAI OpCo, LLCAI processing: chat, realtime voice sent straight from the browser, transcription, reading documents (including identity documents and DBS certificates), speech, image generation and embeddings.OpenAI's standard infrastructure, not a UK or EU data residency region. OpenAI keeps abuse-monitoring logs for up to 30 days, and does not use API data to train its models by default.EU Standard Contractual Clauses with the UK Addendum.
LangChain, Inc. (LangSmith)Monitoring Hera's AI so that we can find and fix problems: a record of each AI request, the steps and tools it used, and its answer.LangSmith's EU region, hosted on Google Cloud in the European Union. If HeraIQ is ever pointed at LangSmith anywhere else, this monitoring switches itself off. Records are kept for up to 400 days.EU Standard Contractual Clauses with the UK Addendum.
Plus Five Five, Inc. (Resend)Sending transactional email.United States.EU Standard Contractual Clauses with the UK Addendum.
650 Industries, Inc. (Expo)Delivering push notifications to the HeraIQ Care app, passed on to Apple Push Notification service and Firebase Cloud Messaging.United States.UK Extension to the EU-U.S. Data Privacy Framework.

PostHog is not a sub-processor. We use it for our own purposes, to measure visits to our public website, and only after you accept analytics cookies. It never runs in the signed-in product. Its data is held on PostHog's EU cloud in Frankfurt, Germany. The provider is PostHog, Inc.

Where a provider processes information outside the UK, we rely on the safeguard shown in the table. You can ask us for a copy by emailing hello@heraiq.io.

We also share information when the law requires it. We do not sell personal information.

Cookies

Our cookie notice lists every cookie this website sets, what each is for, and which ones appear only if you accept analytics.

How we protect information

In brief:

  • one care provider's records are kept apart from another's by database row-level security for reads from the browser and the carer assistant, and by organisation checks on our server;
  • an audit trail of changes made through Hera, which for supported actions keeps the state of the record before the change, and where undoing adds a new entry rather than deleting the original;
  • files are held in private storage and reached through short-lived links;
  • uploads are held apart and checked on our server before use;
  • connections are encrypted, and browsers are told to use encryption only;
  • our staff console is limited to named staff, with a second sign-in step;
  • the database is hosted in London.

What is not in place yet:

  • two-factor sign-in for customer accounts is built but not yet switched on;
  • we hold no ISO 27001, SOC 2, Cyber Essentials or DSPT certification;
  • no independent penetration test has been carried out;
  • uploaded files, such as the documents in a carer's cabinet, are not yet included in backups;
  • there is no DCB0129 clinical safety case.

Our security page has the details.

How long we keep information

The main periods for the information we hold as controller are below. The sections above give the rest, for the records that keep the service running.

How long we keep information we are responsible for
DataKept forNotes
Waitlist requests12 months after your requestYour email, service name and any note you added.
Contact and support requests24 months after the request is closedYour email, name if you gave it, subject and message, including the copy emailed to our support inbox.
Push notification tokensStop being used when you sign out and deleted within 24 hours, or after 180 days without useA token only lets us send a notification to your device.
Second-factor sign-in codesDeleted when used, or within 24 hours of expiringA code is only useful for the sign-in it was sent for.
Account detailsFor the life of the account, plus 90 daysFor managers and office staff: name, work email, organisation, site and CQC location ID. For carers: their own profile and document cabinet.
Website analytics12 monthsOnly collected if you accepted analytics cookies.
AI misuse flags180 daysUp to 500 characters of a message Hera declined as off-topic, with the account, organisation, surface and model.

For a care provider's records, the care provider decides. When a subscription ends: 90 days to request an export, then deleted within 30 days.

Your rights

You have these rights over the information we hold as controller:

Access
Ask for a copy of the information we hold about you.
Rectification
Ask us to correct information that is wrong or incomplete.
Erasure
Ask us to delete your information.
Restriction
Ask us to pause using your information while a concern is looked into.
Portability
Ask for information you gave us, in a common machine-readable format, where we rely on your consent or a contract.
Objection
Object to our using your information where we rely on legitimate interests. You can always object to marketing, and we will stop.
Withdrawing consent
Where we rely on your consent, such as for website analytics, withdraw it at any time.

Some rights apply only in certain situations, and we will explain if one does not apply. To use a right, email hello@heraiq.io. It is free. We may ask you to confirm who you are.

We reply within one month of receiving your request, or of receiving anything we asked for to confirm who you are, whichever is later. If we need you to tell us more about what you are asking for, the time until you reply does not count. If your request is complex, or you have made several requests, we may need up to two more months, and we will tell you within the first month.

For records a care provider keeps about you, please contact the care provider. We will help them respond.

Complaints

If you are unhappy with how we have handled your information, please tell us first by emailing hello@heraiq.io. We will acknowledge your complaint within 30 days, look into it, and tell you the outcome without undue delay.

You also have the right to complain to the Information Commissioner's Office, the UK regulator for data protection, at ico.org.uk/make-a-complaint.

Children

HeraIQ is for care businesses and the people who work for them. Care providers may use it only for adult social care, so it must not hold records about anyone under 18.

Changes to this notice

When we change this notice, we publish the new version here and update the version number and date at the top.