HOME by HandoverMed — Privacy Notice

Version:
1.0
Effective:
17th september 2026
Last reviewed:
17th september 2026
Owner:
Data Protection Officer
User-facing
Contents
  1. 1. About this notice
  2. 2. Who is responsible for your information
  3. 3. Information about patients
  4. 4. Information about staff who use HOME
  5. 5. Why the information is used, and the lawful basis
  6. 6. How HOME uses the information
  7. 7. What we never do
  8. 8. Who can see the information
  9. 9. Where the information is stored
  10. 10. How the information is protected
  11. 11. How long the information is kept
  12. 12. Your rights
  13. 13. National data opt-out
  14. 14. Alerts and automated decisions
  15. 15. Cookies and browser storage
  16. 16. Children
  17. 17. Changes to this notice
  18. 18. Contact and complaints
  19. Change history

Looking for how HandoverMed uses information from our website, enquiries or business contacts? See the HandoverMed Ltd Privacy Notice.


1. About this notice

HOME by HandoverMed ("HOME") is software that hospitals, NHS trusts and other health and care organisations use to hand over patient care safely between shifts. Clinical teams use it to record and share handover notes, patient status, tasks and messages.

This notice is for:

  • patients whose care is recorded in HOME
  • staff who use HOME at work, on the web or on the mobile app
  • organisations using or considering HOME, and their information governance teams

It explains what information HOME holds, who is responsible for it, how it is protected and how you can use your rights. Read it together with the privacy notice of the organisation providing your care, or the organisation you work for.


2. Who is responsible for your information

RoleWhat this means
The organisation using HOME (for example, your hospital or NHS trust)ControllerDecides what information is recorded in HOME, why it is used, who in the organisation can see it and how long it is kept. Responsible for answering requests about your information.
HandoverMed LtdProcessorProvides, hosts and supports HOME, and processes information only on the organisation's documented instructions, under a written contract that meets data protection law.

About HandoverMed Ltd: company number 17341097; registered office 119 Uxbridge Road, Harrow, England, HA3 6DJ; ICO registration number ZC204034.

Our Data Protection Officer can be contacted at privacy@handovermed.com.


3. Information about patients

Depending on how the organisation uses HOME, it may hold:

  • identifiers, such as name, date of birth, sex, NHS number and hospital record number
  • location in the hospital, such as ward, department and bed
  • dates of admission, transfer, discharge or death
  • clinical information needed for handover, such as diagnoses, current condition, observations, allergies, risks, treatment plans, outstanding tasks and follow-ups
  • documents, images, voice notes or other files added by clinical staff
  • messages between clinical staff about a patient's care

Most of this is health information, which the law treats as special category data and protects more strictly.

Where it comes from: the clinical staff caring for the patient enter it into HOME. It may also come from the organisation's other systems, where the organisation has chosen to connect them.


4. Information about staff who use HOME

  • account details, such as name, work email address, job role, department and account status
  • sign-in information, such as when you signed in and which authentication method was used. Depending on how your organisation has set up HOME, sign-in may be handled by your organisation's own identity system or by an account set up for you in HOME.
  • a work mobile number, if your organisation uses text message alerts or sign-in codes
  • mobile app information, such as a notification token, device type and app version, if your organisation uses the HOME mobile app
  • content you create, such as handover notes, tasks, messages, files and personal notes
  • an audit trail of your actions, such as viewing, creating, changing, signing or exporting records
  • technical and security information, such as IP address, browser and device details

Where it comes from: your organisation, when it sets up your access; you, when you use HOME; and your organisation's identity system, if it is used for sign-in.


5. Why the information is used, and the lawful basis

The organisation using HOME uses it to provide safe, continuous care. HOME makes sure the right information passes between clinical teams at every change of shift, and records who did what, and when.

The organisation decides the lawful basis. For NHS organisations this is usually:

  • UK GDPR Article 6(1)(e): the processing is necessary for a task carried out in the public interest (providing health care)
  • UK GDPR Article 9(2)(h): the processing is necessary for health or social care purposes

Other organisations will tell you the basis they rely on in their own privacy notice.

Confidentiality: HOME is used only by the people directly involved in a patient's care, for that patient's care. The organisation relies on implied consent under the common law duty of confidentiality, as is normal for sharing information within a care team.

Information about staff is used to give them secure access to HOME, show who wrote or changed a record, and keep an audit trail. This helps protect patients, staff and the organisation.


6. How HOME uses the information

On the organisation's instructions, HandoverMed uses information in HOME only to:

  • host and run HOME, and make it available to authorised users
  • provide HOME's features, such as handover notes, patient and shift views, tasks, secure messaging and notifications
  • keep an audit trail of access to, and changes in, records
  • produce a copy of a patient's record when an authorised user asks, which is itself recorded in the audit trail
  • scan uploaded files for malware before anyone can open them
  • keep HOME secure, make backups, and prevent, detect and investigate security incidents
  • provide technical support when the organisation asks for it, and fix problems
  • return or delete information when the organisation asks, or when our contract ends

We may use information about how the service is performing, such as uptime, errors and volume of use, to run and improve HOME. Wherever possible this information does not identify anyone, and we use it only as our contract with the organisation allows.


7. What we never do

  • We do not sell information from HOME.
  • We do not use it for marketing, advertising or profiling.
  • We do not use it for research, or share it with third parties for their own purposes.
  • We do not use it to train artificial intelligence models.
  • We do not use it for any purpose that the organisation has not instructed.

If HOME introduces features that use artificial intelligence, each organisation will decide whether to use them, and this notice will explain how they work before they are made available.


8. Who can see the information

  • Staff at the organisation, only if the organisation has given them access. What they can see and do depends on the role the organisation assigns. Private messages are visible only to the people in the conversation.
  • Other organisations using HOME cannot see it. Each organisation's information is kept separate, and this separation is enforced within the database itself.
  • HandoverMed staff and our contracted engineers, only when this is needed to provide support the organisation has requested, fix a problem or keep HOME secure. They are bound by confidentiality obligations, and their access is controlled and logged.
  • Our sub-processors, such as our cloud hosting provider, and providers of text message or email delivery if the organisation uses those notifications. They process information only on our instructions, under contracts with data protection obligations. We share our list of sub-processors with the organisations using HOME, and change sub-processors only as our contracts allow.
  • Others, only where the law requires (for example, a court order) or the organisation instructs us. Where the law allows, we tell the organisation first.

9. Where the information is stored

Information in HOME is stored in data centres in the United Kingdom, provided by Microsoft Azure.

We do not transfer information in HOME outside the UK unless the organisation has agreed and appropriate legal safeguards are in place.


10. How the information is protected

  • Encryption of information in transit and at rest
  • Separation of each organisation's information at database level
  • Secure sign-in with multi-factor authentication for every user. New accounts have no access until the organisation assigns a role.
  • Role-based access, so people see only what their role needs
  • A detailed audit trail that users, including administrators, cannot change or delete
  • Malware scanning of every uploaded file
  • No clinical information stored on mobile devices, beyond an unsaved note while you are working on it
  • Regular security testing, including independent penetration testing before HOME is made available to organisations and at least once a year after that
  • Staff training, confidentiality obligations, and security checks on the suppliers we use
  • Incident management: if a personal data breach affects information in HOME, we tell the organisation without undue delay, so that it can meet its obligations, including telling the ICO and the people affected where required

HandoverMed assesses itself against the NHS Data Security and Protection Toolkit.


11. How long the information is kept

  • Patient and clinical information is kept for as long as the organisation instructs, in line with the NHS Records Management Code of Practice and other legal requirements.
  • The audit trail is kept for at least 8 years, because it is evidence of how the clinical record was created and used.
  • Backup copies are deleted automatically on a rolling cycle, normally within 12 months.
  • When an organisation stops using HOME, its information is returned to it or securely deleted, as it instructs.

12. Your rights

Patients, and staff who use HOME, have rights under data protection law, including the right to:

  • access your information and receive a copy of it
  • rectification of information that is inaccurate or incomplete
  • erasure or restriction of your information, in certain circumstances
  • object to how your information is used, in certain circumstances

How to use your rights: contact the organisation that provides your care, or the organisation you work for. It is the controller and is responsible for responding, normally within one calendar month.

If you contact HandoverMed instead, we will pass your request to the organisation without delay and help it respond. HOME supports this: organisations can produce a copy of a patient's record, and correct records through an audited correction process that keeps the original.

Health records: clinical records must normally be kept for set periods under NHS and legal requirements. This means some rights, such as the right to have information deleted, may not apply to them.


13. National data opt-out

The national data opt-out lets patients in England choose whether their confidential patient information is used for research and planning. HOME uses patient information only for patients' individual care, not for research or planning, so the national data opt-out does not apply to HOME.


14. Alerts and automated decisions

HOME can send automatic reminders and alerts to clinical staff, for example when a handover note or task is overdue. These help staff do their work.

HOME does not make decisions about patients or staff. Decisions about care are always made by clinicians.


15. Cookies and browser storage

Web app: HOME uses your browser's temporary session storage to keep you signed in, and to protect unsaved work if your connection drops. It is strictly necessary for HOME to work, and is cleared when you sign out or close your browser. HOME does not use advertising or tracking cookies.

Mobile app: the app stores only what it needs to keep you signed in securely and deliver notifications. It does not keep a copy of patient records on your device.


16. Children

HOME may hold information about children who receive care. That information is controlled by the organisation providing their care. Parents, guardians and young people can use the rights in section 12 by contacting that organisation.


17. Changes to this notice

We review this notice at least once a year, and whenever HOME changes in a way that affects personal information. The version details at the top show when it was last updated. Significant changes are recorded in the change history below, and we tell the organisations using HOME before they take effect.


18. Contact and complaints

About your care or your work records in HOME: contact the organisation that provides your care or that you work for, usually its Information Governance, Data Protection or Patient Advice and Liaison Service (PALS) team.

About HandoverMed's role:
Data Protection Officer, HandoverMed Ltd
Email: privacy@handovermed.com
Post: 119 Uxbridge Road, Harrow, England, HA3 6DJ

If you are unhappy, please contact the organisation or us first, so we can try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO):

  • Website: ico.org.uk/make-a-complaint
  • Helpline: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Other formats: this notice is available in large print, easy read, printed copy or another language on request. Email privacy@handovermed.com.


Change history

VersionDateSummary of changes
1.017th september 2026First published