Privacy Policy

Last updated: 24 May 2026  •  Version 1.0  •  Mandy Support Ltd (trading as KingCare)

This policy explains how KingCare collects, uses and protects your personal data. It is written in plain English. If you have any questions, email branson@kingcare.uk.

1. Who we are

KingCare is a trading name of Mandy Support Ltd, a company registered in England and Wales. We operate a software-as-a-service platform for children's residential care providers.

Data Controller: Mandy Support Ltd
ICO Registration: ZB763838
Contact: branson@kingcare.uk
Registered address: Leicester, England, United Kingdom

2. What personal data we collect

2.1 Account holders (staff, managers, administrators)

2.2 Children's records (entered by your staff)

Your staff enter records about the children in your care. This data is your data — you are the Data Controller for children's records; KingCare acts as Data Processor. See our Data Processing Agreement for full details.

Types of children's data your staff may enter include: names, dates of birth, incident records, daily logs, health and wellbeing notes, education information, and Annex A assessment responses.

2.3 Technical and usage data

3. Legal basis for processing

Purpose Legal basis (UK GDPR Art. 6)
Providing the KingCare service Art. 6(1)(b) — performance of a contract
Account management and billing Art. 6(1)(b) — performance of a contract
Security logging and fraud prevention Art. 6(1)(f) — legitimate interests
Legal obligations (tax, regulatory) Art. 6(1)(c) — legal obligation
Marketing emails (if opted in) Art. 6(1)(a) — consent

For children's special category data (health, wellbeing) processed on your behalf, the basis is Art. 9(2)(g) — substantial public interest, under Schedule 1 DPA 2018 (safeguarding).

4. Where your data is stored

All data is stored within the United Kingdom. We use Microsoft Azure UK South (London) as our primary database region. We do not transfer personal data outside the UK without adequate safeguards.

Our infrastructure sub-processors include:

5. How long we keep your data

Data type Retention period
Account data (active) Duration of subscription + 90 days after cancellation
Account data (exported on request) Deleted within 30 days of export confirmation
Children's records Per your instructions as Data Controller (see DPA)
Billing records 7 years (HMRC requirement)
Security logs 12 months

6. Your rights under UK GDPR

You have the right to:

To exercise any right, email branson@kingcare.uk. We will respond within 30 days. If you are unsatisfied with our response, you may complain to the Information Commissioner's Office (ICO) at ico.org.uk.

7. Cookies

The KingCare application uses the following cookies and local storage:

We do not use third-party analytics cookies or advertising cookies.

8. Security

We implement the following technical and organisational measures:

9. Children's data

Children in residential care are a vulnerable group. We treat their data with the highest level of care:

10. Changes to this policy

We may update this policy to reflect changes in law or our practices. We will notify account holders by email at least 14 days before material changes take effect. The current version is always available at kingcare.uk/privacy-policy.html.

11. Contact

For any privacy questions or to exercise your rights:
Email: branson@kingcare.uk
Subject line: "Privacy Request — [your name]"