How we protect care data | Careloom
Careloom ← Back to home
Security & data protection

How we protect care data

Care records are among the most personal data there is. This page explains, in plain English, how Careloom stores and protects them — and what happens to your data if you ever leave.

Hosted in the EU

All data lives on servers in the European Union and never leaves it. Careloom is designed for GDPR from the ground up — we act as data processor, your agency remains the data controller, and a data-processing agreement is part of every subscription.

Each agency is isolated

Your agency's records are separated from every other agency's at the database level — isolation is enforced by the database itself, not just by application code. One agency can never see another's data, even in the event of a software bug.

Access is controlled and recorded

Staff see only what their role needs — a carer sees their own visits, not the whole book. Every change to a care record is logged with who made it and when, and that audit trail cannot be edited or deleted. Data is encrypted in transit and at rest.

Backed up, every day

Records are backed up daily to a separate EU location. A lost phone, a leaver, or a broken laptop never means lost care records — the record of care lives on the platform, not on any one device.

Your data is yours — leaving included

A full export of everything — clients, rotas, records, files — is one click away and always free, whether you're staying or going. And if Careloom ever closed, we guarantee twelve months' notice and wind-down support, in writing, so no agency is ever stranded.

Questions about any of this — or something your registration paperwork needs answered? Ask directly: book a 20-minute walkthrough and put them to the person who built it.

Careloom
Built in Donegal, Ireland · © 2026 Careloom. All rights reserved.