Pelp Care logo
Pelp Care

Legal

Data protection at Pelp

Last updated: August 2026

Care information deserves serious protection.

Pelp is being designed for environments where information can be sensitive, personal and important to someone's wellbeing.

Our approach is to build privacy, security and accountability into the product from the beginning.

Privacy by design

Data protection should be considered throughout the design and development of Pelp rather than added after the product has been built.

Access based on responsibility

Pelp is being designed so that users see information appropriate to their role and responsibilities.

Different permissions may apply to:

  • Support Workers
  • Key Workers
  • Senior staff
  • Registered Managers
  • Administrators
  • Authorised family members

Sensitive care information

Information about someone's physical or mental health can constitute special category personal data and requires additional protection under UK data protection law.

Pelp's product architecture should therefore support appropriate safeguards around the collection, access, use, storage and sharing of care information.

Human reviewed AI

Pelp's AI features are intended to assist professionals, not replace them.

AI may help:

  • Summarise authorised records
  • Structure assessment conversations
  • Prepare document drafts
  • Identify patterns requiring attention
  • Highlight possible changes from an Individual's usual presentation

AI generated content should remain clearly identified and subject to human review before becoming part of an official care record.

Auditability

Pelp is being designed to maintain records of important activity such as:

  • Records created
  • Information changed
  • Documents reviewed
  • Documents approved
  • Reports generated
  • Records viewed
  • Files downloaded
  • Information securely shared

Data minimisation

Pelp should only collect and process information needed for a clear purpose.

Retention and deletion

Care organisations should be able to manage information according to applicable retention requirements and organisational policies.

Secure development

Security should be considered throughout product development, including:

  • Authentication
  • Role permissions
  • Secure data transmission
  • Secure storage
  • Activity logging
  • Backups
  • Environment separation
  • Secrets management
  • Vulnerability management

We do not claim specific encryption standards, certifications or compliance badges until they have genuinely been implemented or obtained.

Data controllers and processors

For the live platform, the relationship will depend on the specific service.

In many provider deployments, the care organisation may determine why and how Individual care information is processed, while Pelp may process that information on the organisation's behalf.

This must be defined properly in customer contracts and data processing agreements rather than assumed.

Data Protection Impact Assessments

Given Pelp's planned processing of sensitive care information, voice assessment data and predictive care intelligence, a formal Data Protection Impact Assessment should be completed before relevant live processing begins.

Contact

For questions about privacy and data protection:

privacy@pelpcare.co.uk