All legal documents

Privacy Policy

What personal data we hold about you, why, and what you can require us to do about it.

Version 2.0 · Effective 6 August 2026 · Last updated 6 August 2026

Africa Procurement Group Ltd, trading as Care Shield Compliance, operates the Care Shield Compliance platform at app.careshieldcompliance.co.uk and the website at careshieldcompliance.co.uk.

This policy covers personal data we hold as controller — about account holders, staff users, prospective customers and website visitors. Where we hold personal data on behalf of a subscribing organisation, that organisation is the controller and we are its processor; the Data Processing Agreement governs that, and their own privacy notice applies to it.

1. Controller and contact

Controller: Africa Procurement Group Ltd, registered in England and Wales number 10553435, registered office Devonshire House, One Mayfair Place, London, England, W1J 8AJ.

Data protection contact: hello@careshieldcompliance.co.uk. We have not appointed a statutory Data Protection Officer; we are not a public authority and our core activities do not consist of large-scale monitoring or large-scale processing of special category data as controller. Responsibility sits with the director, Dr Washington Kapapiro.

2. What we collect, why, and on what basis

DataWhyLawful basis
Name, work email, job role, organisation, telephoneCreating and running your account; support; service messagesContract — Article 6(1)(b)
Service type, regulator, local authority, registered managerTailoring documents to your serviceContract — Article 6(1)(b)
Sign-in records, session and device information, IP addressSecurity, session limits, detecting misuseLegitimate interests — securing the Service
Reading, acknowledgement, audit and export activityProviding the evidence features you subscribe for; enforcing licence termsContract; legitimate interests — protecting our intellectual property
Billing contact, subscription and invoice recordsTaking payment; statutory accounting recordsContract; legal obligation
Enquiries, demo bookings, correspondence, support ticketsAnswering you; keeping a record of what was agreedLegitimate interests — running a business you contacted
Marketing preferences and email engagementSending regulatory updates you asked forConsent, or the soft opt-in under PECR for existing customers
Website analytics and error diagnosticsKeeping the site working and finding faultsLegitimate interests — see the Cookie Policy for what is exempt from consent

Where we rely on legitimate interests we have assessed the balance and recorded it. You may object; see section 6.

We do not seek special category data about you as a user of the Service. Health information belonging to the people your organisation supports may be entered into the Service by your organisation — we hold that as processor, not as controller, and it is governed by the Data Processing Agreement.

3. Where it comes from

  • From you, when you register, book a demonstration, contact us or use the Service.
  • From your employer, when they invite you as a staff user.
  • Automatically, from your device when you use the Service.
  • From public sources — a company website or Companies House — when we research an organisation that has contacted us.

4. Who we share it with

We do not sell personal data and we do not share it for anyone else's marketing. We share it with the service providers listed in the Sub-processors document, each under a written contract restricting them to our instructions.

We also disclose where we are legally required to, and to professional advisers under a duty of confidence, and to a buyer if the business is sold — in which case you would be told.

5. How long we keep it

RecordKept for
Account and profile dataFor the subscription, then 30 days, then deleted
Content created in the ServiceFor the subscription, then 30 days for export, then deleted
Invoices and financial records6 years from the end of the accounting period (Companies Act 2006)
Sign-in, session and export logs12 months
Support correspondence24 months after the ticket closes
Marketing consent and unsubscribe recordsUntil withdrawn, plus a suppression record kept indefinitely so we do not contact you again
Enquiries that did not become customers24 months from last contact

The full schedule, including the position on backups, is in the Data Retention and Deletion document.

6. Your rights

You have the right to be informed; of access; to rectification; to erasure; to restrict processing; to data portability; to object, including to direct marketing at any time; and not to be subject to certain solely automated decisions.

To exercise any of them, email hello@careshieldcompliance.co.uk. We will respond within one month. Where a request is complex or you have made several, we may extend by up to two further months and will tell you why within the first month. We may ask for proof of identity before acting.

If your organisation subscribes to Care Shield Compliance and your request concerns records held in their account — your acknowledgements, your training record, your supervision notes — the request is properly made to your employer, who controls that data. Tell us and we will point you to them and assist them in responding.

We do not make solely automated decisions producing legal or similarly significant effects about you.

7. Complaints

Tell us first: hello@careshieldcompliance.co.uk. We will acknowledge within 30 days, keep you informed of progress, and tell you the outcome. That is what the Data (Use and Access) Act 2025 requires of us from 19 June 2026, and it is also simply how we want to handle it.

You may also complain to the Information Commissioner's Office at ico.org.uk, by telephone on 0303 123 1113, or in writing to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. You do not have to come to us first.

8. International transfers

Our infrastructure is hosted in the United Kingdom and the European Economic Area. Some of our providers process limited data outside the UK. Where that happens we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. The Sub-processors document names each provider and where it processes.

9. Security

Encryption in transit and at rest, row-level access control in the database so one organisation cannot read another's records, least-privilege service credentials, session limits and idle timeout, rate limiting, logged administrative access, and monitored backups. The Security Statement describes the measures; the Security Incident and Breach Response document describes what happens when something goes wrong.

No system is perfectly secure and we do not claim otherwise. What we commit to is a defined set of controls, a tested restore, and honest and prompt notification.

10. Cookies

See the Cookie Policy. In short: the cookies that keep you signed in are strictly necessary and are always set. Statistical and appearance cookies are used under the exemptions introduced by the Data (Use and Access) Act 2025 and can be turned off. We set no advertising cookies.

11. Children

The Service is for care professionals and is not directed at children. We do not knowingly collect personal data from anyone under 18 as a user. Records about children supported by a subscribing organisation may be held in that organisation's account, where they are the controller.

12. Changes

We will post any change here with a new version number and date, and will tell you by email where the change is material.

Care Shield Compliance is a division of Africa Procurement Group Ltd, registered in England and Wales, company number 10553435. Registered office: Devonshire House, One Mayfair Place, London, England, W1J 8AJ. Questions about this document: hello@careshieldcompliance.co.uk.