Legal
Data protection at Pelp
Last updated: August 2026
Care information deserves serious protection.
Pelp is being designed for environments where information can be sensitive, personal and important to someone's wellbeing.
Our approach is to build privacy, security and accountability into the product from the beginning.
Privacy by design
Data protection should be considered throughout the design and development of Pelp rather than added after the product has been built.
Access based on responsibility
Pelp is being designed so that users see information appropriate to their role and responsibilities.
Different permissions may apply to:
- Support Workers
- Key Workers
- Senior staff
- Registered Managers
- Administrators
- Authorised family members
Sensitive care information
Information about someone's physical or mental health can constitute special category personal data and requires additional protection under UK data protection law.
Pelp's product architecture should therefore support appropriate safeguards around the collection, access, use, storage and sharing of care information.
Human reviewed AI
Pelp's AI features are intended to assist professionals, not replace them.
AI may help:
- Summarise authorised records
- Structure assessment conversations
- Prepare document drafts
- Identify patterns requiring attention
- Highlight possible changes from an Individual's usual presentation
AI generated content should remain clearly identified and subject to human review before becoming part of an official care record.
Auditability
Pelp is being designed to maintain records of important activity such as:
- Records created
- Information changed
- Documents reviewed
- Documents approved
- Reports generated
- Records viewed
- Files downloaded
- Information securely shared
Data minimisation
Pelp should only collect and process information needed for a clear purpose.
Retention and deletion
Care organisations should be able to manage information according to applicable retention requirements and organisational policies.
Secure development
Security should be considered throughout product development, including:
- Authentication
- Role permissions
- Secure data transmission
- Secure storage
- Activity logging
- Backups
- Environment separation
- Secrets management
- Vulnerability management
We do not claim specific encryption standards, certifications or compliance badges until they have genuinely been implemented or obtained.
Data controllers and processors
For the live platform, the relationship will depend on the specific service.
In many provider deployments, the care organisation may determine why and how Individual care information is processed, while Pelp may process that information on the organisation's behalf.
This must be defined properly in customer contracts and data processing agreements rather than assumed.
Data Protection Impact Assessments
Given Pelp's planned processing of sensitive care information, voice assessment data and predictive care intelligence, a formal Data Protection Impact Assessment should be completed before relevant live processing begins.
Contact
For questions about privacy and data protection:
