This notice explains how ResiNotes handles information submitted through this public website, including enquiries, idea submissions, cookies, website security information and email communications.
ResiNotes is designed for UK residential care settings, so confidentiality, professional boundaries, safeguarding, auditability and careful handling of information are central to the way the service is presented and developed.
Last updated: 24 June 2026
1. Who we are
ResiNotes is a UK-focused care recording and operations platform for residential children’s homes. For this public website, ResiNotes is responsible for deciding how website enquiry information is collected and used.
This notice applies to the public website at resinotes.co.uk and related public contact forms. It does not replace any separate contract, data processing agreement, service-level privacy notice, internal staff policy or young person privacy information used by a children’s home, local authority, provider or other organisation.
2. Scope of this notice
This page covers information handled through the public ResiNotes website, including contact forms, idea submissions, demo or pilot enquiries, direct emails and basic website security logs.
Operational care records, staff records, young person records, audit logs, incident information, missing episode information and any live client data within the ResiNotes platform are separate from the public website. Those records should be governed by client contracts, role-based permissions, audit controls, retention rules, safeguarding duties and the privacy information of the relevant organisation using the platform.
3. Information we may collect
When you use this website, we may collect information that you choose to provide, such as your name, email address, organisation, role, telephone number, enquiry details, demo interest, pilot interest and ideas submitted through the ideas form.
Standard technical information may also be processed by the web server, such as IP address, browser type, device information, dates and times of access, pages requested, referral information, error logs and security logs.
You should avoid submitting unnecessary personal information, confidential care records, details about an identifiable child or young person, case files, incident reports, health information, legal documents or safeguarding information through public website forms unless there is a clear and secure reason to do so.
4. Special category, safeguarding and child-related information
The public website is intended for adults, professionals and organisations. It is not designed for children or young people to submit personal information directly.
Information about health, ethnicity, religion, sexuality, disability, care history, safeguarding, allegations, criminal justice involvement or similar matters may be special category data or otherwise highly confidential. If such information is accidentally submitted through the public website, it will be treated with additional care and used only as necessary to handle the enquiry, protect individuals, meet legal obligations or direct the matter to the appropriate professional route.
Where information appears to raise an immediate safeguarding concern, risk of harm, unlawful activity or a duty to disclose, confidentiality may be limited. In those circumstances, information may need to be shared with an appropriate safeguarding lead, statutory body, emergency service, regulator or other competent authority.
5. How we use information
We use website information to respond to enquiries, discuss pilot or demo interest, review submitted ideas, provide requested information, maintain business contact records, protect the website, prevent misuse, investigate technical issues and improve the clarity of the public website.
We do not use public website submissions to make automated decisions about individuals. We do not sell personal information or use website enquiry data for unrelated commercial resale.
6. Lawful bases under UK GDPR
Depending on the situation, we may rely on one or more lawful bases under UK GDPR:
Consent where you actively choose to submit information, ask us to contact you, request updates or accept optional cookies.
Legitimate interests to respond to professional enquiries, manage service interest, review ideas, protect the website, prevent misuse and keep proportionate business records.
Contract or pre-contract steps where an organisation asks about using ResiNotes, arranging a demo, exploring a pilot or discussing service terms.
Legal obligation where information must be kept, used or disclosed to comply with UK law.
Vital interests or substantial public interest may apply in rare situations involving serious risk, safeguarding, protection from harm or other legally recognised public interest reasons.
Where special category information is processed, an additional UK GDPR Article 9 condition or Data Protection Act 2018 condition may be required depending on the circumstances.
7. Confidentiality and professional information
ResiNotes recognises that professionals in residential care may contact us about systems, recording, incidents, safeguarding workflows, missing protocols, staff access, audit requirements or sensitive operational needs. Such communications may include confidential context even where no young person is directly named.
We will treat professional enquiries, demo discussions, pilot discussions, technical support messages and business emails as confidential unless disclosure is authorised, required by law, necessary for security, necessary to protect someone from harm, or needed to provide the requested response or service.
Confidentiality does not mean secrecy in all circumstances. It may be necessary to share limited information where there is a safeguarding concern, a legal obligation, a serious risk to a person, a regulatory requirement, a court order, a law enforcement request with appropriate authority, or a need to investigate misuse of the website or service.
Where information is shared, it should be limited to what is necessary, proportionate and relevant to the purpose.
8. Care records and client-controlled data
The public website should not be used as a route for sending live care records or identifiable young person information. If ResiNotes is used by an organisation as a live platform, the organisation using the service will usually decide the purpose and lawful basis for operational care records.
Client-controlled data should be handled under the relevant service agreement, data processing terms, role permissions, audit logging, access controls, retention policies and safeguarding procedures. Access to children’s records should be restricted to authorised users with a legitimate professional reason.
External access, archived records, exports and disclosure to third parties should be controlled, justified, recorded and limited to the relevant date range, purpose and authority.
9. Cookies and similar technologies
The public website currently uses essential browser storage to remember your cookie choice. This prevents the privacy options control appearing as a new request every time you visit. That preference is stored in your browser and is not used for advertising.
If analytics, embedded media, marketing pixels or third-party tracking are added later, they should not be activated unless you have been given clear information and a genuine choice to accept or reject them.
Technology
Purpose
Type
Duration
resinotesCookieChoice
Stores whether you accepted or rejected optional cookies.
Essential local storage
Up to 12 months, or until you clear browser data.
Standard server logs
Supports website security, debugging and misuse prevention.
Technical logging
Kept for a limited operational period unless needed for investigation or legal reasons.
10. Sharing information
We may share limited information with trusted service providers that help run the website, email, hosting, security, backups, technical support or enquiry handling. Where a supplier processes personal data for us, they should only process it under appropriate instructions and safeguards.
We may also share information where required by law, necessary to protect rights or security, necessary to prevent harm, necessary for safeguarding, required by a competent authority or needed in connection with professional advice, legal claims, business continuity or service administration.
We do not sell personal information.
11. International transfers
Website, email or support suppliers may occasionally process information outside the UK. Where this happens, appropriate safeguards should be used, such as UK adequacy arrangements, approved contractual clauses or another lawful transfer mechanism.
12. How long we keep information
Website enquiry and idea submission information is kept only for as long as needed to deal with the enquiry, maintain a reasonable record of contact, support service development or meet legal, audit and security requirements.
Server and security logs are usually kept for a limited operational period unless needed to investigate misuse, protect the service, resolve technical issues or comply with legal obligations.
Where an enquiry becomes part of a pilot, contract, procurement process, complaint, safeguarding concern or formal service matter, information may be kept for longer under the relevant business, legal or safeguarding requirement.
13. Security
We use reasonable technical and organisational measures to protect website information. These may include secure hosting controls, access restrictions, HTTPS, security logging, careful email handling and proportionate retention.
No website or email system can be guaranteed completely secure. Please do not send highly sensitive, confidential or child-identifiable information through public website forms unless you have been specifically asked to do so through an appropriate secure route.
14. Your rights
Under UK data protection law, you may have rights to access your personal data, correct inaccurate information, request erasure, restrict processing, object to processing, request data portability where applicable and withdraw consent where consent is the lawful basis.
You can make a request by emailing hello@resinotes.co.uk. We may need to confirm your identity before acting on a request. Some rights are not absolute and may depend on the lawful basis, legal duties, safeguarding issues, confidentiality owed to others or the need to keep records for legitimate reasons.
You also have the right to complain to the Information Commissioner’s Office if you are unhappy with how your information is handled.
15. Children and young people
This public website is aimed at adults, professionals and organisations. It is not designed for children to submit personal information directly.
ResiNotes product areas dealing with children’s records are separate from this public website and should be governed by client contracts, role-based access, audit controls, safeguarding procedures and the relevant organisation’s own privacy information. Children’s information should be handled with particular care, with access limited to those who need it for a legitimate professional purpose.
16. Email disclaimer
Emails sent by or to ResiNotes may contain confidential, commercially sensitive or legally privileged information intended only for the named recipient. If you receive an email in error, please notify the sender, delete it and do not copy, disclose, forward, rely on or use its contents.
Email communication is not guaranteed to be secure, error-free, complete or virus-free. You should check attachments and links before opening them. ResiNotes may monitor emails and attachments for security, compliance, service administration and misuse prevention where lawful and proportionate.
Unless clearly stated otherwise by an authorised representative, email messages do not create a binding contract, formal instruction, acceptance of liability or professional advice. Any views expressed in an email are those of the sender unless confirmed as an authorised ResiNotes communication.
If an email contains information about a child, young person, staff member, care setting, safeguarding matter, incident, allegation, missing episode, health matter or other confidential issue, it must be handled securely and shared only with people who have a legitimate reason to receive it.
17. Updates to this notice
This notice may be updated as the website, public contact routes, cookies, service structure or legal requirements change. The latest version will be shown on this page.
18. Important note
This page is a public website privacy and confidentiality notice. It is not legal advice. Organisations using ResiNotes should ensure their own privacy notices, contracts, data processing agreements, retention schedules, staff policies and safeguarding procedures are reviewed by appropriately qualified professionals.