Care records are among the most personal data there is. This page explains, in plain English, how Careloom stores and protects them — and what happens to your data if you ever leave.
All data lives on servers in the European Union and never leaves it. Careloom is designed for GDPR from the ground up — we act as data processor, your agency remains the data controller, and a data-processing agreement is part of every subscription.
Your agency's records are separated from every other agency's at the database level — isolation is enforced by the database itself, not just by application code. One agency can never see another's data, even in the event of a software bug.
Staff see only what their role needs — a carer sees their own visits, not the whole book. Every change to a care record is logged with who made it and when, and that audit trail cannot be edited or deleted. Data is encrypted in transit and at rest.
Records are backed up daily to a separate EU location. A lost phone, a leaver, or a broken laptop never means lost care records — the record of care lives on the platform, not on any one device.
A full export of everything — clients, rotas, records, files — is one click away and always free, whether you're staying or going. And if Careloom ever closed, we guarantee twelve months' notice and wind-down support, in writing, so no agency is ever stranded.
Questions about any of this — or something your registration paperwork needs answered? Ask directly: book a 20-minute walkthrough and put them to the person who built it.
Careloom