Policy
Data Protection Policy
Processes personal information lawfully, fairly, transparently and securely, using only what is necessary.
Applies to
Policy statement and likely data
Shinezone will process personal information lawfully, fairly, transparently and securely, using only what is necessary for defined purposes.
Likely data includes client and staff contacts, supplier details, bookings, access information, complaints, incidents, authorised photographs, vetting or training evidence and limited resident information required for safe delivery.
Data minimisation and principles
Do not request resident diagnoses, full care plans, medication information, unrelated identity documents or unnecessary sensitive histories.
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
Security, photographs, rights and breaches
Use role-based access, strong authentication, least privilege, device controls, encryption where appropriate, secure backups, private storage, controlled sharing, audit logs, secure disposal, training and incident response.
Photographs require client authority, should avoid identifiable people and personal documents, must have a defined purpose and secure storage, and need separate permission for marketing.
Breaches must be reported internally immediately, contained, assessed, documented and notified where legally required.
Related policies and evidence
Request controlled evidenceNext step
Tell us about your property and receive a tailored proposal.
The form captures property, access, risk and date preferences so Shinezone can triage the work properly.