This Privacy Policy describes how Orobo Healthcare ("we", "us", or "our") collects, uses, and protects the personal information you provide to us when using our websites, orobohealthcare.com and orobohealthcare.co.uk (together, the "Site").
Orobo Healthcare Ltd is the data controller responsible for your personal data. You can contact us at:
We may collect the following types of personal information:
We obtain your personal data either because you give it to us directly, for example when you make an enquiry, book a call or become a client, or because we collect it from publicly available sources.
We provide compliance support to care homes, care services and individual practitioners. To identify organisations and practitioners who may need that support, we use a customer relationship management system that draws on publicly available UK data. This means we may hold information about you that we did not get from you, taken from:
All of this information is already published on those registers. We only use professional and business contact information, and we do not add anything that is not already public.
Our lawful basis for this is legitimate interests: identifying and contacting health and social care organisations and practitioners who may need compliance support. We have considered your rights and interests in reaching that decision.
When we first contact you, we link to this policy, so that you can see where your data came from, what we use it for, and how to tell us to stop. We do not send out separate notices listing what we hold, but if you want to know what we hold about you, ask us and we will tell you.
We do not use data from the Information Commissioner's Office register of fee payers for direct marketing, and we use address data from the Energy Performance Certificate register only to identify a property.
You can object to us holding or using data about you that came from a register at any time, and we will stop unless we have compelling legitimate grounds that override your interests. See section 11 for how to contact us.
We use your information to:
Under UK data protection law, we rely on the following lawful bases to process your personal data:
We may contact you by email, telephone, post, or through a professional network such as LinkedIn, about our services.
We update our system with your contact preferences for email, phone and post as soon as you tell us. Where you are not interested, we move you to a do-not-contact list to make sure we do not accidentally contact you again in the future.
Where someone at a service tells us they do not want to be contacted, we apply that to the whole location rather than only to that person. Nobody at that service is contacted, including anyone who joins it later.
We keep that list for as long as we are in business. Deleting your details altogether would mean we could add you again from a public register without realising. We hold no more than we need to recognise you.
We do nothing else with a suppressed record. We do not contact you, we do not share it with anyone, and we do not market to you from it. It exists for one purpose only, which is to make sure we do not breach your preferences.
We also stop maintaining it ourselves. The organisation's profile still reflects what the public registers publish, so a new inspection report, a change of rating, or another change recorded on a register may still appear. What we stop doing is curating it. Our system may suggest people it has found on a register, but adding anyone is a manual step and we do not take it for a suppressed record: we do not add a new registered manager, provider or nominated individual, and we do not update contact details to keep them current, as we would for an active client. We will only change a suppressed record if you or your organisation ask us to.
If you change your mind later, tell us and we will update your preferences.
When we send you an email, a quote or an invoice, we may be able to see whether it was delivered, whether it was opened, and which links were clicked, along with the browser or email application used. Where you sign a document or open a secure document room, we keep a record of when you viewed, signed, opened or uploaded.
We use this to understand whether our messages are reaching people and to keep an audit trail for documents. If you would rather not be tracked in this way, most email applications let you block images from loading, which prevents open tracking.
We do not sell your data. We use the following providers to run our business and our website. Each processes your data only on our instructions, under contractual terms that require them to keep it secure.
Our customer relationship management system and its database are hosted in the United Kingdom. Some of our other providers may store or process data outside the UK. Where they do, we rely on UK adequacy regulations where they apply, and otherwise on the UK International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses. Google may process data outside the United Kingdom.
We use cookies and similar technologies. Cookies that are necessary for the site to work, and to remember your cookie choice, are always set. Analytics and advertising cookies, which are Google Analytics and Google advertising measurement, are switched off by default and are only set after you press Accept on our cookie banner. If you press Decline, we do not set them.
You can change your mind at any time by clearing the cookies for this site in your browser, which will bring the banner back. You can also block or delete cookies through your browser settings, though some parts of the site may not work as well.
We keep personal data only as long as necessary for the purposes set out above, or for as long as the law requires. In practice that means:
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects. Any assessments or recommendations we provide are reviewed by our consultants.
You have the right to:
If you have a concern about how we handle your data, please contact us. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk.
We take appropriate technical and organisational measures to protect your data from loss, misuse, or unauthorised access.
Our website may contain links to other websites. We are not responsible for their content or privacy practices.
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.
If you have any questions about this policy, or wish to exercise your rights, please contact us:
Orobo Healthcare Ltd, Bank Gallery, High Street, Kenilworth, Warwickshire, England, CV8 1LY
Email: hello@orobohealthcare.com
Or via our contact form: orobohealthcare.com/contact
Last updated: 29 July 2026

Services
© 2026 Orobo Healthcare Ltd
Orobo Healthcare is an independent consultancy and is not affiliated with, endorsed by, or representing the Care Quality Commission.
Orobo Healthcare Ltd is registered in England and Wales under registration number 16729327 at Bank Gallery, High Street, Kenilworth, CV8 1LY
All prices exclude VAT (20%).