Legal
Access security, compliance, legal documentation and corporate policies.
Privacy Policy
How we handle personal data, keep your information secure and meet our data protection responsibilities.
Cookie Policy
Find out what cookies we use, why we use them and how you can control your cookie preferences when using our website.
Agreements
Access contractual documents, service agreements and legal terms related to PCS services.
Trust and compliance documentation
Review PCS security standards, certifications, infrastructure and compliance documentation
Website Terms of Use
Find out the terms that apply when you use the PCS website, including user responsibilities, intellectual property and liability information.
Partnerships Programme
View or download the Commercial Terms for the PCS Partnership Programme.
Responsible AI Statement
Our commitment to ethical AI. Discover how PCS protects data, mitigates bias and ensures accountability in our AI development practices.
FAQs
FAQs about PCS legal terms, compliance, security, data protection and privacy. Capitalised terms are defined in the PCS MSA or DPA, available on our Agreements page
PCS is committed to GDPR compliance and other data protection regulations through comprehensive data processing agreements and processes that respect your data rights.
We enter into a comprehensive Data Processing Addendum as part of our Master Services Agreement. Both documents are available here.
We use reputable companies for sub-processing such as Microsoft and store the resident data in the UK and/or European Economic Area.
Specifically, for our mCare Services, we store the resident data in the EEA with Microsoft.
You can view a detailed list of our infrastructure and subprocessors listed per product in the Infrastructure and Subprocessors documentation available here.
No. As explained above, for mCare Services we store the resident data in the European Economic Area. For other services, we can use the storage in the United Kingdom or in the European Economic Area.
For non-storage purposes there can be further transfers of the personal data in the meaning of the applicable privacy laws.
As we are a UK business, there is no international transfer established between our customers and ourselves. If there is an onward transfer, we commit to comply with the GDPR requirements, specifically Chapter V with our transfers.
The information about the location of storage and processing is available in the Infrastructure and Subprocessors documentation available here.
In the unlikely event of a data breach, PCS follows a strict protocol for detecting, notifying affected parties, and mitigating the impact, in accordance with legal requirements and our DPA.
We also notify you about Customer Data Incidents without undue delay as decribed in our DPA available here.
Each solution has its own documentation which is available to customers.
The list of product features is available under Product Description available on our Trust and compliance page
We process personal data for the purposes of providing the services to our customers under our agreement.
In addition, we may use such personal data to derive Anonymous Data for research and benchmarking purposes, analysing and improving our services as well as preparing aggregated reports and statistics.
Using Anonymous Data to identify trends, patterns, and areas for improvement, we mainly aim to:
-
enable research to enhance the identification of risk and quality of life factors among frail and elderly to provide predictive modelling of the likelihood of health-related outcomes functionality for customers, as well as general research for population health management purposes
-
provide benchmarking of resident care outcome metrics for our customers at their locations along with the comparison against industry metrics
-
enhance performance and optimise user experiences and our services
We make sure data used for analysis is properly anonymised. Directly identifiable personal data is removed or altered to protect individuals’ privacy. We use techniques such as pseudonymisation followed by anonymisation (aggregation and generalisation).
Robust security measures are in place to safeguard Anonymous Data, including encryption, access controls, and regular audits protect against breaches.
Customers are responsible for informing their residents (service users) and staff within a home (location) that:
- their personal data are being processed by PCS as customer data processor
and - PCS may derive anonymous data for research and benchmarking purposes, analysing and improving the services as well as preparing aggregated reports and statistics
For more information, data subjects can refer to PCS Privacy Policy.
This information may be included in the Customer’s Privacy Policy.
Contact us - we're always happy to help.