Last updated: 30 July 2026
ENSEAK Solutions Ltd ("ENSEAK Solutions", "we", "us", or "our") is committed to protecting the privacy and security of personal data. This Privacy Policy explains how we collect, use, store, share, and protect personal information in compliance with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.
This Privacy Policy applies to the ACT360 software platform, our websites, and our wider business operations. It is intended to be read together with any applicable Terms of Use and Data Processing Agreements.
ENSEAK Solutions Ltd owns and operates the ACT360 platform, a digital compliance and audit intelligence solution for care providers and related organisations.
ENSEAK Solutions Ltd acts as:
Customer organisations (e.g. care homes, healthcare providers) act as Data Controllers for any resident/patient/service user data they enter into ACT360. ENSEAK Solutions processes that data strictly in accordance with their documented instructions.
This Privacy Policy applies to customers and users of ACT360, employees, contractors, suppliers of ENSEAK Solutions Ltd, and visitors to our websites and digital platforms.
It covers personal data processed in connection with provision and use of the ACT360 platform, our marketing website and communications, and our internal business operations.
ENSEAK Solutions Ltd is the Data Controller for personal data collected via our marketing website, customer account and subscription information, user registration details, employee and contractor data, and supplier and partner data.
Your organisation (e.g. care home, healthcare provider) is the Data Controller for resident, patient, and service user data entered into ACT360, and any clinical, care, or compliance records relating to individuals that you store or manage within ACT360.
ENSEAK Solutions acts as Data Processor for this data and processes it only on documented instructions from your organisation, in accordance with the applicable Data Processing Agreement, and in compliance with UK GDPR Article 28.
When processing resident/patient/service user data on behalf of customer organisations, ENSEAK Solutions implements appropriate technical and organisational measures, ensures staff are subject to confidentiality obligations, engages sub-processors only under written contracts, and assists customer organisations in meeting their obligations under UK GDPR.
We may collect and process the following categories of personal data:
| Category | Examples |
|---|---|
| Customer Data | Names, business contact details, care home information, subscription details, payment information (via Stripe). |
| User Data | Login credentials, role, usage logs, audit answers, action plans, compliance artefacts, communication records (via Brevo SMTP). |
| Resident/Patient Data (customer-controlled) | Care records, audit findings, incident logs, and other data entered by customer organisations into ACT360. |
| Employee Data | Employment records, payroll information, training logs, HR documentation. |
| Supplier Data | Contact details, contracts, SLAs, compliance certifications. |
| Usage & Cookie Data | Browser settings, visit logs, traffic and location data, consent status, application preferences. |
We rely on the following lawful bases under UK GDPR:
Where your organisation is the Data Controller for resident/patient data, it is responsible for determining the appropriate lawful basis for that processing. ENSEAK Solutions processes such data under contractual necessity and documented instructions as a Data Processor.
To provide core functionality and a better user experience, we use:
Where required, we obtain consent for non-essential cookies and provide options to manage your preferences.
ACT360 utilizes Artificial Intelligence (AI) to enhance the efficiency, safety, and quality of care management. The AI features process data entered into the system to provide the following capabilities:
AI features do not constitute solely automated decision-making with legal or similarly significant effects on individuals under UK GDPR. They are designed to support—not replace—regulatory decision-making and clinical or managerial judgment.
"Certain features of our platform are powered by Artificial Intelligence (AI) provided by third-party infrastructure partners (Google Cloud Vertex AI / OpenAI). When you utilize these features, relevant data is securely transmitted to these sub-processors exclusively to fulfil your immediate request. We have implemented strict contractual safeguards ensuring that data is encrypted, temporarily processed, and under no circumstances used to train public foundational AI models or shared with unauthorized third parties."
Throughout the ACT360 platform, we utilize various scoring systems and metrics to assist in quality monitoring, including but not limited to dashboard scorecards and CQC framework Quality Statement scoring.
These scoring systems are provided solely for internal representation, benchmarking, and continuous improvement tracking. They do not equate to, nor should they be interpreted as, a real or official regulatory rating from the Care Quality Commission (CQC) or any other regulatory body.
We may share personal data with suppliers and sub-processors:
All suppliers are subject to Data Processing Agreements (DPAs) and compliance checks. We may also disclose personal data to regulators and authorities (ICO, CQC, NHS) or auditors and certification bodies where required by law.
Some data may be stored or processed outside the UK, including in the European Economic Area (EEA) and the United States, particularly via Google Firebase (US-based) and Stripe (US-based).
We rely on appropriate safeguards for international transfers, including Standard Contractual Clauses approved by the European Commission or UK-approved equivalents, and technical and organisational measures to protect data in transit and at rest.
We implement administrative, technical, and physical security measures to protect personal data, including:
While we take appropriate measures to protect your data, transmission of information via the internet can never be completely secure.
We retain personal data only for as long as necessary for the purposes described in this Policy or as required by law. Typical retention periods include:
| Data Category | Retention Period |
|---|---|
| Customer Data | Duration of the contract plus 7 years for audit/legal purposes. |
| Audit & Event Data | Up to 7 years to support inspection readiness and historical reporting. |
| User Account Data | For the duration of your active subscription; deleted or anonymised within 90 days of account closure. |
| Employee Data | Duration of employment plus statutory retention periods. |
| Supplier Data | Duration of the relationship plus 7 years. |
We periodically review stored data and anonymise or delete records that are no longer necessary for operational or legal purposes.
Under UK GDPR, individuals have the right to:
Requests can be made by contacting our Data Protection Officer. Where ENSEAK Solutions acts as Data Processor, we will assist the relevant customer organisation in responding to such requests.
If you have concerns about how we handle your personal data, you can contact our Data Protection Officer or lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
Data Protection Officer (DPO)
ENSEAK Solutions Ltd
Dunstable, England, United Kingdom
Email: admin@enseaksolutions.com
We may update this Privacy Policy from time to time. Any changes will be posted on this page within the ACT360 platform and/or our website. Notified to you by email where appropriate or required.