Privacy Policy
What personal data we hold about you, why, and what you can require us to do about it.
Version 2.0 · Effective 6 August 2026 · Last updated 6 August 2026
Africa Procurement Group Ltd, trading as Care Shield Compliance, operates the Care Shield Compliance platform at app.careshieldcompliance.co.uk and the website at careshieldcompliance.co.uk.
This policy covers personal data we hold as controller — about account holders, staff users, prospective customers and website visitors. Where we hold personal data on behalf of a subscribing organisation, that organisation is the controller and we are its processor; the Data Processing Agreement governs that, and their own privacy notice applies to it.
1. Controller and contact
Controller: Africa Procurement Group Ltd, registered in England and Wales number 10553435, registered office Devonshire House, One Mayfair Place, London, England, W1J 8AJ.
Data protection contact: hello@careshieldcompliance.co.uk. We have not appointed a statutory Data Protection Officer; we are not a public authority and our core activities do not consist of large-scale monitoring or large-scale processing of special category data as controller. Responsibility sits with the director, Dr Washington Kapapiro.
2. What we collect, why, and on what basis
| Data | Why | Lawful basis |
|---|---|---|
| Name, work email, job role, organisation, telephone | Creating and running your account; support; service messages | Contract — Article 6(1)(b) |
| Service type, regulator, local authority, registered manager | Tailoring documents to your service | Contract — Article 6(1)(b) |
| Sign-in records, session and device information, IP address | Security, session limits, detecting misuse | Legitimate interests — securing the Service |
| Reading, acknowledgement, audit and export activity | Providing the evidence features you subscribe for; enforcing licence terms | Contract; legitimate interests — protecting our intellectual property |
| Billing contact, subscription and invoice records | Taking payment; statutory accounting records | Contract; legal obligation |
| Enquiries, demo bookings, correspondence, support tickets | Answering you; keeping a record of what was agreed | Legitimate interests — running a business you contacted |
| Marketing preferences and email engagement | Sending regulatory updates you asked for | Consent, or the soft opt-in under PECR for existing customers |
| Website analytics and error diagnostics | Keeping the site working and finding faults | Legitimate interests — see the Cookie Policy for what is exempt from consent |
Where we rely on legitimate interests we have assessed the balance and recorded it. You may object; see section 6.
We do not seek special category data about you as a user of the Service. Health information belonging to the people your organisation supports may be entered into the Service by your organisation — we hold that as processor, not as controller, and it is governed by the Data Processing Agreement.
3. Where it comes from
- From you, when you register, book a demonstration, contact us or use the Service.
- From your employer, when they invite you as a staff user.
- Automatically, from your device when you use the Service.
- From public sources — a company website or Companies House — when we research an organisation that has contacted us.
4. Who we share it with
We do not sell personal data and we do not share it for anyone else's marketing. We share it with the service providers listed in the Sub-processors document, each under a written contract restricting them to our instructions.
We also disclose where we are legally required to, and to professional advisers under a duty of confidence, and to a buyer if the business is sold — in which case you would be told.
5. How long we keep it
| Record | Kept for |
|---|---|
| Account and profile data | For the subscription, then 30 days, then deleted |
| Content created in the Service | For the subscription, then 30 days for export, then deleted |
| Invoices and financial records | 6 years from the end of the accounting period (Companies Act 2006) |
| Sign-in, session and export logs | 12 months |
| Support correspondence | 24 months after the ticket closes |
| Marketing consent and unsubscribe records | Until withdrawn, plus a suppression record kept indefinitely so we do not contact you again |
| Enquiries that did not become customers | 24 months from last contact |
The full schedule, including the position on backups, is in the Data Retention and Deletion document.
6. Your rights
You have the right to be informed; of access; to rectification; to erasure; to restrict processing; to data portability; to object, including to direct marketing at any time; and not to be subject to certain solely automated decisions.
To exercise any of them, email hello@careshieldcompliance.co.uk. We will respond within one month. Where a request is complex or you have made several, we may extend by up to two further months and will tell you why within the first month. We may ask for proof of identity before acting.
If your organisation subscribes to Care Shield Compliance and your request concerns records held in their account — your acknowledgements, your training record, your supervision notes — the request is properly made to your employer, who controls that data. Tell us and we will point you to them and assist them in responding.
We do not make solely automated decisions producing legal or similarly significant effects about you.
7. Complaints
Tell us first: hello@careshieldcompliance.co.uk. We will acknowledge within 30 days, keep you informed of progress, and tell you the outcome. That is what the Data (Use and Access) Act 2025 requires of us from 19 June 2026, and it is also simply how we want to handle it.
You may also complain to the Information Commissioner's Office at ico.org.uk, by telephone on 0303 123 1113, or in writing to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. You do not have to come to us first.
8. International transfers
Our infrastructure is hosted in the United Kingdom and the European Economic Area. Some of our providers process limited data outside the UK. Where that happens we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. The Sub-processors document names each provider and where it processes.
9. Security
Encryption in transit and at rest, row-level access control in the database so one organisation cannot read another's records, least-privilege service credentials, session limits and idle timeout, rate limiting, logged administrative access, and monitored backups. The Security Statement describes the measures; the Security Incident and Breach Response document describes what happens when something goes wrong.
No system is perfectly secure and we do not claim otherwise. What we commit to is a defined set of controls, a tested restore, and honest and prompt notification.
10. Cookies
See the Cookie Policy. In short: the cookies that keep you signed in are strictly necessary and are always set. Statistical and appearance cookies are used under the exemptions introduced by the Data (Use and Access) Act 2025 and can be turned off. We set no advertising cookies.
11. Children
The Service is for care professionals and is not directed at children. We do not knowingly collect personal data from anyone under 18 as a user. Records about children supported by a subscribing organisation may be held in that organisation's account, where they are the controller.
12. Changes
We will post any change here with a new version number and date, and will tell you by email where the change is material.
Care Shield Compliance is a division of Africa Procurement Group Ltd, registered in England and Wales, company number 10553435. Registered office: Devonshire House, One Mayfair Place, London, England, W1J 8AJ. Questions about this document: hello@careshieldcompliance.co.uk.