Privacy Policy

Corporate B2B Privacy Policy for AgencySoftware.io

Last updated: January 2025

AgencySoftware.io is officially registered with the Information Commissioner's Office (ICO)

Registration Reference: ZC136598

1. Introduction

AgencySoftware.io is the trading name of Tarquin Barnsby (Sole Trader), the parent entity and primary data processor for FosterFlow.uk, a UK foster care management platform. We are committed to protecting your privacy and ensuring 100% compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all Information Commissioner's Office (ICO) guidelines.

This Privacy Policy explains how we collect, use, disclose, and safeguard information when you engage with our services as a business customer.

2. Data Controller and Data Processor Roles

For B2B Customer Data (Your Agency's Data):

  • You (the Fostering Agency or Local Authority) are the Data Controller for all foster placement data, carer information, and operational records entered into the system.
  • AgencySoftware.io acts as the Data Processor, processing this data solely on your documented instructions and in accordance with our Data Processing Agreement.

For Contract Administration Data: AgencySoftware.io acts as the Data Controller for billing contacts, agency administrator login credentials, and other contract-related information necessary to provide our services.

3. Information We Collect

3.1. Contract Administration Data (Collected by AgencySoftware.io as Controller):

  • Billing contact details (name, email, phone number, business address)
  • Agency administrator login credentials
  • Payment and invoicing information
  • Correspondence and support ticket history

3.2. Foster Care Data (Processed by AgencySoftware.io as Processor):

  • Foster carer personal details and contact information
  • Prospective carer enquiry data
  • Pseudonymised placement observations, incidents, and daily notes
  • Compliance documents and training records
  • Communication logs (SMS, email)

3.3. Technical Data:

  • IP addresses and browser information
  • Device and operating system details
  • Usage analytics (pages visited, features used)
  • Error logs and performance data

4. Legal Basis for Processing

We process personal data under the following legal bases as defined in UK GDPR Article 6:

UK GDPR Article 6(1)(b) – Contractual Necessity

We collect billing contacts and agency administrator logins solely for contract administration. This data is necessary to perform the contract we have with you.

  • Article 6(1)(a) Consent: Where you have given explicit consent for specific processing activities.
  • Article 6(1)(c) Legal Obligation: Where we must comply with a legal requirement (e.g., financial record-keeping, safeguarding obligations).
  • Article 6(1)(f) Legitimate Interests: For service improvement, fraud prevention, and security monitoring, where these interests do not override your rights.

5. Data Storage and Security

UK-Based Data Storage

All data is stored on secure servers physically located within the United Kingdom. We do not transfer primary data outside the UK.

We implement robust technical and organisational security measures:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Multi-factor authentication for all administrative access
  • Regular penetration testing and vulnerability assessments
  • Comprehensive audit logging and monitoring
  • Regular backups with secure offsite storage
  • Access controls based on the principle of least privilege

6. Data Sharing – We Never Sell Your Data

Absolute Commitment

Zero B2B or B2C customer database records are sold, rented, or shared with third parties for their own marketing or commercial purposes. Ever.

We only share data with the following categories of recipients, solely to provide our services:

  • Sub-processors: As detailed in Section 7 below, bound by strict DPAs.
  • Legal Requirements: Where required by law, court order, or a regulatory authority (e.g., ICO, Ofsted).
  • Safeguarding: Where necessary to protect the welfare of a child or vulnerable adult.
  • Business Transfers: In the event of a merger or acquisition, with prior notice to you.

7. Sub-processors

We use carefully selected sub-processors to deliver our services. All sub-processors have active Data Processing Agreements (DPAs) in place and meet our security standards.

Sub-processorPurposeDPA Status
Stripe, Inc.Payment processing and billingActive DPA
ClerkUser authentication servicesActive DPA
Amazon Web Services (AWS)UK-based cloud hosting infrastructureActive DPA
Cloudflare, Inc.CDN, DDoS protection, and securityActive DPA
Mailgun (Sinch)Transactional email deliveryActive DPA
MongoDB AtlasDatabase hosting (UK Region)Active DPA

A complete list of sub-processors is available in our Data Processing Agreement.

8. Data Retention and Purge Policy

We enforce a strict data retention policy:

  • Active Accounts: Data is retained for the duration of your subscription.
  • Cancelled Accounts: B2B data is soft-deleted for 30 days to allow recovery, then permanently purged from all systems including backups.
  • Contract Administration Records: Billing and invoice records retained for 7 years as required by UK tax law.

Safeguarding Exception

Where a LADO (Local Authority Designated Officer) safeguarding lock or active investigation is in place, data preservation shall be maintained for the duration required by the relevant authority, overriding standard retention periods. We will not delete data subject to such a hold without written confirmation from the appropriate authority.

9. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

  • Right of Access (Article 15): Request copies of your personal data.
  • Right to Rectification (Article 16): Request correction of inaccurate data.
  • Right to Erasure (Article 17): Request deletion of your data ("right to be forgotten").
  • Right to Restrict Processing (Article 18): Request limitation of processing.
  • Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format.
  • Right to Object (Article 21): Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Where processing is based on consent.

To exercise any of these rights, please contact us using the details in Section 12.

10. Cookies and Tracking

We use cookies and similar technologies to enhance your experience. Non-essential cookies (such as analytics) are blocked until you explicitly consent. For detailed information on the cookies we use and how to manage them, please see our Cookie Policy.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to active customers via email at least 30 days before taking effect. The "Last updated" date at the top of this page indicates when the policy was last revised.

12. Contact Us

For all Subject Access Requests (SARs), data portability requests, or privacy inquiries:

Email: privacy@agencysoftware.io

Data Controller

Tarquin Barnsby (Sole Trader)

Trading as AgencySoftware.io

Little Waterham Farm
Highstreet
Faversham
Kent
ME13 9EJ

ICO Registration Reference: ZC136598

13. Supervisory Authority

If you have concerns about how we handle your data that we cannot resolve, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Cookie Preferences

We use essential cookies to make our site work. We would also like to set optional analytics cookies to help us improve it. We will not set optional cookies unless you enable them. Read our Cookie Policy for more details.