Privacy Policy

Your Privacy Matters to Us

At Rickeston Mill Nursing Home, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Please read this policy carefully. If you have any questions about how we handle your data, contact us using the information provided at the bottom of this page.

What Data We Collect

We collect information you provide directly to us, such as when you:

  • Arrange a visit or enquire about our services: Name, email address, phone number, message content
  • Become a resident or family member: Full name, date of birth, address, contact details, medical information (where applicable)
  • Subscribe to our blog or communications: Email address and preferences
  • Contact us directly: Any information you provide in your message

We may also collect information automatically when you visit our website, including IP address, browser type, pages visited, and time spent on the site through our analytics systems.

How We Use Your Information

We use the information we collect for the following purposes:

  • To respond to your enquiries and provide information about our services
  • To process residency applications and maintain resident records
  • To deliver and improve our care services
  • To communicate important updates and newsletters (with your consent)
  • To maintain the security and functionality of our website
  • To comply with legal obligations and regulatory requirements
  • To understand how our website is used and improve user experience

Legal Basis for Processing

Under UK GDPR, we process your data on the following legal bases:

  • Consent: Where you have explicitly given us permission to process your data
  • Contract: Where necessary to fulfill a contract or provide services you've requested
  • Legal Obligation: Where required by law, including health and social care regulations
  • Legitimate Interests: Where we have a legitimate interest in processing your data that is not overridden by your rights (e.g., website security)

Cookies and Tracking

Our website uses cookies to enhance your browsing experience. Cookies are small files stored on your device that help us remember your preferences and analyze site usage.

Essential cookies are necessary for the website to function properly. Analytics cookies help us understand how visitors use our site, and are only used with your consent.

You can control cookie settings through your browser. For more details, please visit our Cookie Policy.

Third-Party Sharing

We do not sell your personal data. We only share your information with third parties when:

  • You have given us explicit permission
  • We are required to do so by law or regulatory bodies
  • We use trusted service providers to help deliver our services (e.g., email providers, payment processors) who are bound by confidentiality agreements
  • As necessary for healthcare provision and coordination with health professionals

All third parties are required to protect your information with appropriate security measures.

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law.

  • Residency enquiries: Up to 2 years unless you become a resident
  • Resident and family records: For the duration of care provision plus 7 years (as required by health and social care regulations)
  • Newsletter subscribers: Until you unsubscribe
  • Website analytics: Up to 26 months

After the retention period, we securely delete or anonymize your data.

Your Data Rights

Under UK GDPR, you have the following rights:

  • Right of Access: You can request a copy of the data we hold about you
  • Right to Rectification: You can request we correct inaccurate data
  • Right to Erasure: You can request deletion of your data (with some exceptions)
  • Right to Restrict Processing: You can ask us to limit how we use your data
  • Right to Data Portability: You can request your data in a structured, portable format
  • Right to Object: You can object to certain types of processing
  • Rights Related to Automated Decision Making: You have rights regarding decisions made about you by automated systems

Exercising Your Rights

To exercise any of your data rights, please contact us with a clear description of your request. We will respond within 30 days of receiving your request. You may need to provide identification to verify your identity.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent authority for data protection.

Contact Us

For privacy-related enquiries, data subject access requests, or to exercise your rights:

Rickeston Mill Nursing Home
Rickeston Bridge
Haverfordwest SA62 3DJ
Wales, United Kingdom

Email: enquiries@sricares.co.uk
Phone: 01646 695 142

Last updated: March 2026