Privacy notice

Last updated 21 September 2026

Who this notice covers

This notice explains how personal data is used when you visit HAMS (the Healthcare Agency Management System), create an organisation, sign in, or apply to work with a care agency that uses HAMS.

It is written for UK GDPR. It is not a substitute for legal advice. Each care agency remains responsible for its own privacy information to staff, applicants, and people who use its services.

Who is responsible

When you use an agency workspace or submit a job application, that care agency is the data controller. It decides why staff, applicant, and service-user records are kept.

Wilok Solutions Limited operates HAMS and acts as a data processor for the agency. We process that data on the agency’s instructions to provide the software.

For your HAMS login account itself (email address, authentication, two-factor settings), Wilok Solutions Limited is the controller.

What we collect

Depending on how you use HAMS, records may include:

  • Identity and contact details for staff, applicants, organisation owners, and people who use the agency’s services
  • Employment and vetting information, including qualifications, DBS certificate details, right-to-work documents, and application forms
  • Care records such as care plans, medication administration, incidents, risk assessments, and related files
  • Timesheets, payroll exports, expenses, and bank details
  • Account data: email address, mobile number when you choose text-message verification, hashed credentials held by our auth provider, and two-factor authentication settings
  • Technical logs needed to keep the service secure and available

Some of this is special-category health data or criminal-offence data. Agencies should only collect it where they have a lawful basis and an appropriate condition for processing.

Why we use it

Agencies typically use HAMS to recruit and manage staff, keep care records, and run payroll and timesheets. Common lawful bases (for the agency to confirm with its own counsel) include contract, legal obligation, legitimate interests, and, where relevant, vital interests. Login accounts are used to authenticate you and protect access to organisation data.

Processors and other recipients

HAMS uses specialist providers to run the service. Agencies should sign a data processing agreement with each provider they rely on before going live. Current processors include:

  • Supabase — database, authentication, and private file storage
  • Vercel — application hosting
  • The email (SMTP) provider configured for the deployment — password reset, staff invites, application emails, and daily care notes sent to a client’s primary contact
  • The SMS provider configured for the deployment (Brevo) — two-factor verification codes when you choose text-message sign-in
  • Sentry — error monitoring, with default PII disabled and additional scrubbing in the app
  • The DBS Update Service — when an agency runs a status check, certificate number, date of birth, and surname are sent to that service

Organisation owners can review this list under Organisation settings. HAMS does not sign those vendor contracts on the agency’s behalf.

How long we keep data

Retention is set by the agency as controller and recorded under Organisation settings. HAMS lists records that have passed those periods for review. It does not delete them automatically. An organisation owner can delete a staff member or the whole organisation, which removes associated records and stored files.

Your rights

Under UK GDPR you can ask for access, rectification, erasure, restriction, objection, or portability, and you can complain to the Information Commissioner’s Office. For data an agency holds about you, contact that agency — typically the organisation owner or their privacy lead. Agency owners and admins can download a personal-data pack from a staff, client, or application record to help fulfil a subject access request. For your HAMS login account, contact Wilok Solutions Limited using the details on your service agreement.

Security

Access is limited to people the agency has invited. Files are stored privately and downloaded through short-lived signed URLs. Two-factor authentication is required for HAMS accounts unless the operator has turned that requirement off for a specific environment. You should keep your password and authenticator details confidential.

Cookies

HAMS uses cookies that are necessary to keep you signed in and to protect the session. We do not use advertising or analytics cookies on these pages.

Changes

We may update this notice when the product or the law changes. The date at the top of this page will change when we do. Related terms are at the terms of service.