Graham Digital Privacy Notice
Last updated: 1st October 2026
At Graham Digital, we take your privacy seriously. This notice explains how we collect, use, store, and protect your personal data, in line with the UK General Data Protection Regulation (UK GDPR) and the Privacy and Electronic Communications Regulations (PECR).
This notice covers both parts of our business: the Graham Digital care planning app, which we provide to care homes, and our bespoke automation, analytics and consulting work.
Who we are
Graham Digital is a trading name of Anna Graham Limited, a company registered in England and Wales (Company No. 16946571), providing:
- The Graham Digital app – care planning software for care homes. It connects to the care home’s existing electronic care record system, uses AI to draft care plans, reviews and risk assessments from the resident’s records, and lets the home’s nurses and managers review, edit and sign them off before they are sent back to the care record.
- Software, bespoke automation, analytics, and consulting services for clinical and service-based organisations
Data Controller:
Anna Graham Limited, a company registered in England and Wales (Company No. 16946571). Registered office: 20 Cranley Road, Walton-on-Thames, Surrey, KT12 5BP
Email: anna@grahamdigital.ai
If you purchase consulting services, or receive marketing from us, Anna Graham Limited is the entity legally responsible for your data.
Our role when a care home uses the Graham Digital app
When a care home uses the Graham Digital app, the care home is the data controller for the information about its residents held in the app. Anna Graham Limited acts as a data processor on the care home’s behalf. This means we only use resident information on the care home’s documented instructions and under a written data processing agreement, as required by Article 28 of UK GDPR.
We are the data controller for the account details of care home staff who use the app, for the security and usage logs we keep to run the service, and for business contact and billing information about the care home organisation.
If you are a resident, or a relative or representative of a resident, please contact the care home first about how your information is used. If you contact us instead, we will pass your request to the care home promptly and help it respond.
What data we process
We may process the following categories of data depending on your interaction with us:
If you are a care home staff member using the Graham Digital app
- Account information (e.g., name, work email address, job role, organisation, the care home locations you work at, and your permissions in the app)
- Files you upload (e.g., audio files, documents, templates)
- Sign-in information: where your organisation uses Microsoft sign-in, we receive your Microsoft account identifier, name and email address. We never see or store your Microsoft password.
- Report templates and guidance documents you provide
- Technical data (IP address, device type, browser version)
- Usage and audit logs for security, troubleshooting, and service improvement, including a record of the care plans you edit, approve and send to the care record
If you are a resident of a care home that uses the Graham Digital app
We process the following information on behalf of the care home, as its processor. Much of it is health and care information, which is special category data under UK GDPR and receives extra protection.
- Identity details held in the care record (e.g., name, date of birth, room and care home location, and NHS number where recorded)
- Names and contact details of relatives, representatives and professionals involved in your care, where recorded
- Health and care information from the care record, such as existing care plans and care needs, care notes (including safeguarding notes), risk assessments, accident and incident records, medication records, and mental capacity assessments
- GP and NHS records that the care home is authorised to access, such as your GP Connect summary record
- Documents scanned into or attached to your care record (e.g., hospital discharge letters and assessments)
- Audio recordings and transcripts of conversations with you, your relatives or staff, where the care home chooses to record them to inform your care plan
- Information about your preferences, routines, relationships and wishes, including end-of-life wishes where an end-of-life plan is being prepared
- Draft and final care plans, reviews and risk assessments created in the app, with a record of who edited and approved them
If you receive outreach or contact us for business enquiries
- Business contact information (name, job title, email, organisation)
- Publicly available professional data (website, directories, LinkedIn)
- Interaction history with our communications (e.g., email opens, responses)
How we collect your data
We may collect data:
- Directly from you (e.g., account creation, uploading files, contacting us)
- Through your use of the Graham Digital app
- From the care home’s electronic care record system, and any other care systems the home chooses to connect (e.g., medication or staffing systems), using access the care home has authorised
- From documents, audio recordings and information that care home staff upload or enter in the app
- From publicly available sources (e.g., company websites, directories, LinkedIn)
- Via third-party tools or data providers that aggregate publicly available B2B information (e.g., Apify/Leads Finder, Apollo, or similar services)
- From contractors/freelancers working on our behalf
- When you interact with our emails or visit our website
We do not purchase consumer marketing lists.
Any third-party B2B data we obtain is limited to business contact information of professionals in relevant roles.
Why we process your data
We process personal data for the following purposes:
Graham Digital app (care homes and their staff)
- To provide the Graham Digital service (e.g., care planning)
- To create and manage user accounts
- To secure our systems and detect misuse
- To improve and maintain the platform
- To provide customer support
- To manage billing and subscriptions
Resident information processed on behalf of care homes
- To bring together a resident’s existing records so staff can see the relevant information in one place
- To draft care plans, 90-day and ad hoc reviews, end-of-life plans, pre-admission care plans and risk assessments
- To transcribe audio recordings and extract text from scanned documents
- To highlight complex health needs evidenced in the records (e.g., diabetes, catheter care, epilepsy, swallowing difficulties) so they are covered in the plan
- To let the care home’s nurses and managers review, edit and sign off each plan, and then send approved plans back to the care home’s care record system
- To keep an audit trail of what was drafted, edited, approved and sent, and by whom
- To diagnose faults and keep the service secure
Consulting clients
- To deliver contracted services
- To communicate and manage projects
- For invoicing and record-keeping
B2B direct marketing
- To contact relevant professionals about Graham Digital or our consultancy services
- To maintain internal business development records
How the Graham Digital app uses AI
The app uses AI language models (provided by Anthropic and OpenAI) and Microsoft Azure AI services to draft content from the information in a resident’s records, and AssemblyAI to transcribe audio recordings.
- A person always decides – every AI draft is reviewed, edited where needed and approved by a member of the care home’s staff before it is sent to the care record. The app does not make decisions about anyone’s care, and we do not carry out solely automated decision-making that has legal or similarly significant effects on individuals.
- No model training – we use these AI services under business terms under which customer data is not used to train their models. We do not use resident information to train AI models of our own.
- Only what is needed – we send AI services only the information needed to prepare the document being drafted.
Lawful bases for processing
We rely on the following lawful bases under UK GDPR:
- Contract – for providing the Graham Digital app, consulting services, customer support, and billing.
- Legitimate interests – for B2B outreach to relevant professionals, platform security, analytics, and service improvement.
- Consent – where required for cookies or optional marketing sign-ups.
- Legal obligation – for tax, accounting, and statutory record-keeping.
Resident information in the Graham Digital app: the care home, as controller, decides the lawful basis for processing its residents’ information. Care homes generally rely on their legal obligations under care regulations (such as the duty to keep accurate and complete care records) or on their contract with the resident, and, for health information, on Article 9(2)(h) of UK GDPR (the provision of health or social care) together with Schedule 1, Part 1, paragraph 2 of the Data Protection Act 2018. We process this information only on the care home’s instructions.
If you object to marketing, we will stop immediately and place your details on a suppression list to ensure no further contact.
Who processes your data
We use trusted third-party processors to help operate our business and app. These may include:
- Base44 (app infrastructure)
- Microsoft Azure (hosting, database and file storage, document text extraction, user sign-in)
- Anthropic and OpenAI (AI processing)
- AssemblyAI (audio transcription)
- Microsoft 365 (SharePoint document storage and email)
- GoCardless (payment processing)
- Feathery (file uploads, forms)
- Instantly.ai (B2B email outreach)
- Google Workspace (email and storage)
- Other cloud tools for operations and analytics
Where a care home connects the Graham Digital app to its care record system or other care systems, those systems are the care home’s own suppliers, contracted directly by the care home. We send approved care plans to them only on the care home’s instructions.
For the Graham Digital app, we only use a sub-processor that has agreed to data protection terms at least as protective as our agreement with the care home, and we tell care homes about any new sub-processors before they start processing resident information.
Some providers process data outside the UK/EEA. Where this occurs, we use:
- Standard Contractual Clauses (SCCs)
- UK International Data Transfer Agreement (IDTA)
- Additional contractual and technical safeguards
We do not sell your personal data.
How we keep data secure
- Data is encrypted in transit and at rest
- Care home staff sign in through their organisation’s account, and permissions limit each user to the care homes and functions they need
- Access credentials for connected care systems are stored securely and used only to exchange information for the care home
- We keep audit logs of key actions, including every care plan sent to a care record
- Our own staff and contractors access resident information only where necessary to support the care home or fix a fault, and are bound by confidentiality
- If a personal data breach affects resident information, we will notify the care home without undue delay so it can meet its own obligations
Retention
We keep personal data only as long as necessary for its purpose:
- App accounts & generated reports – retained until your account is deleted (unless required for legal retention)
- Resident information processed for care homes – held only for as long as the care home’s contract and instructions require. The care home’s own care record remains the master record. When the contract ends, we delete or return the information, as the care home chooses, unless the law requires us to keep it.
- Audio recordings and uploaded documents – kept only as long as needed to prepare and evidence the care plan, in line with the care home’s instructions
- Bespoke client project files – retained for up to 7 years for legal/accounting obligations
- Marketing contacts – retained until you object or we determine they are no longer relevant
- Suppression list – retained indefinitely to honour opt-outs
You can request deletion at any time.
Your rights
Under UK GDPR, you have the right to:
- Access your data (Subject Access Request)
- Correct inaccuracies
- Request deletion
- Request restriction of processing
- Object to processing (including all marketing)
- Port your data to another service provider
- Complain to the ICO: www.ico.org.uk
If your request is about resident information held in the Graham Digital app, please contact the care home, which is the controller. If you contact us, we will pass your request to the care home promptly and help it respond.
To exercise your rights, email anna@grahamdigital.ai.
We aim to respond within one month.
Questions?
If you have any concerns about your data or this notice, please contact:
Graham Digital
(Graham Digital.ai)
