Need urgent CQC support? Click here

This Privacy Policy describes how Orobo Healthcare ("we", "us", or "our") collects, uses, and protects the personal information you provide to us when using our websites, orobohealthcare.com and orobohealthcare.co.uk (together, the "Site").

Who we are

Orobo Healthcare Ltd is the data controller responsible for your personal data. You can contact us at:

  • Orobo Healthcare Ltd, Bank Gallery, High Street, Kenilworth, Warwickshire, England, CV8 1LY
  • Email: hello@orobohealthcare.com
  • Company number: 16729327
  • ICO registration number: ZC059284

1. Information we collect

We may collect the following types of personal information:

  • Contact details (name, email address, phone number)
  • Business information (company name, role, service interests)
  • Technical data (IP address, browser type, device type)
  • Usage data (pages visited, time on site, referral source)
  • Correspondence with us, including emails and their attachments, notes of our conversations, and records of calls we log
  • Whether emails, quotes and invoices we send you were delivered, opened and which links were clicked, together with the browser or email application used
  • If you sign a document electronically: your name, email address, signature, IP address and browser details, and a record of when you viewed and signed it
  • If we invite you to a secure document room: your name and email address, a record of what you opened or uploaded, and the IP address and browser used
  • Information published about you on public registers, as set out in section 2 below

We obtain your personal data either because you give it to us directly, for example when you make an enquiry, book a call or become a client, or because we collect it from publicly available sources.

2. Personal data we collect from public registers

We provide compliance support to care homes, care services and individual practitioners. To identify organisations and practitioners who may need that support, we use a customer relationship management system that draws on publicly available UK data. This means we may hold information about you that we did not get from you, taken from:

  • Companies House, including company officers and people with significant control
  • The Care Quality Commission, including registered managers and nominated individuals
  • The Care Inspectorate, including service operators
  • The Information Commissioner's Office register of fee payers
  • Food hygiene ratings
  • Gender pay gap reporting
  • The Energy Performance Certificate register
  • The Gazette, excluding personal insolvency notices

All of this information is already published on those registers. We only use professional and business contact information, and we do not add anything that is not already public.

Our lawful basis for this is legitimate interests: identifying and contacting health and social care organisations and practitioners who may need compliance support. We have considered your rights and interests in reaching that decision.

When we first contact you, we link to this policy, so that you can see where your data came from, what we use it for, and how to tell us to stop. We do not send out separate notices listing what we hold, but if you want to know what we hold about you, ask us and we will tell you.

We do not use data from the Information Commissioner's Office register of fee payers for direct marketing, and we use address data from the Energy Performance Certificate register only to identify a property.

You can object to us holding or using data about you that came from a register at any time, and we will stop unless we have compelling legitimate grounds that override your interests. See section 11 for how to contact us.

3. How we use your information

We use your information to:

  • Respond to enquiries and provide services
  • Improve our website and customer experience
  • Send you information about our services and check in about your service, by email and post
  • Comply with legal obligations

4. Our lawful basis for processing

Under UK data protection law, we rely on the following lawful bases to process your personal data:

  • Legitimate interests – to respond to your enquiries, provide our services, and run and improve our business, where this does not override your rights.
  • Consent – for marketing communications and non-essential cookies, which you can withdraw at any time.
  • Contract – where we need to process your data to provide a service you have requested.
  • Legal obligation – where the law requires us to process your data.

5. How we contact you, and how to stop us

We may contact you by email, telephone, post, or through a professional network such as LinkedIn, about our services.

  • Email. Where you are a corporate subscriber, such as a limited company, we rely on legitimate interests. Where you are a sole trader or a partnership, we rely on your consent or on a soft opt-in where you have previously enquired. You can reply to any email from us to say you are not interested, and every email in a sequence carries an opt-out link.
  • Telephone. We check numbers against both the Telephone Preference Service and the Corporate Telephone Preference Service before calling, and we check again each time rather than relying on an earlier check.
  • Post and professional networks. We rely on legitimate interests, and you can ask us to stop at any time.

We update our system with your contact preferences for email, phone and post as soon as you tell us. Where you are not interested, we move you to a do-not-contact list to make sure we do not accidentally contact you again in the future.

Where someone at a service tells us they do not want to be contacted, we apply that to the whole location rather than only to that person. Nobody at that service is contacted, including anyone who joins it later.

We keep that list for as long as we are in business. Deleting your details altogether would mean we could add you again from a public register without realising. We hold no more than we need to recognise you.

We do nothing else with a suppressed record. We do not contact you, we do not share it with anyone, and we do not market to you from it. It exists for one purpose only, which is to make sure we do not breach your preferences.

We also stop maintaining it ourselves. The organisation's profile still reflects what the public registers publish, so a new inspection report, a change of rating, or another change recorded on a register may still appear. What we stop doing is curating it. Our system may suggest people it has found on a register, but adding anyone is a manual step and we do not take it for a suppressed record: we do not add a new registered manager, provider or nominated individual, and we do not update contact details to keep them current, as we would for an active client. We will only change a suppressed record if you or your organisation ask us to.

If you change your mind later, tell us and we will update your preferences.

6. Email and document tracking

When we send you an email, a quote or an invoice, we may be able to see whether it was delivered, whether it was opened, and which links were clicked, along with the browser or email application used. Where you sign a document or open a secure document room, we keep a record of when you viewed, signed, opened or uploaded.

We use this to understand whether our messages are reaching people and to keep an audit trail for documents. If you would rather not be tracked in this way, most email applications let you block images from loading, which prevents open tracking.

7. Sharing your information

We do not sell your data. We use the following providers to run our business and our website. Each processes your data only on our instructions, under contractual terms that require them to keep it secure.

  • OroMiQ Ltd– our customer relationship management system, which holds our contact records, correspondence, documents and call logs. It is hosted in the United Kingdom and uses Microsoft Azure, MongoDB Atlas, Twilio SendGrid and Microsoft 365 in turn.
  • Microsoft 365 – our email and calendars
  • Cal.com – booking consultations
  • Crisp – live chat on our website
  • Cloudflare – checking that form submissions are not automated
  • Stripe– taking payments. We do not receive or store your full card details.
  • Google– website analytics and advertising measurement, only where you have accepted cookies
  • Our professional advisers, and legal or regulatory authorities where required

8. International data transfers

Our customer relationship management system and its database are hosted in the United Kingdom. Some of our other providers may store or process data outside the UK. Where they do, we rely on UK adequacy regulations where they apply, and otherwise on the UK International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses. Google may process data outside the United Kingdom.

9. Cookies and tracking technologies

We use cookies and similar technologies. Cookies that are necessary for the site to work, and to remember your cookie choice, are always set. Analytics and advertising cookies, which are Google Analytics and Google advertising measurement, are switched off by default and are only set after you press Accept on our cookie banner. If you press Decline, we do not set them.

You can change your mind at any time by clearing the cookies for this site in your browser, which will bring the banner back. You can also block or delete cookies through your browser settings, though some parts of the site may not work as well.

10. Data retention

We keep personal data only as long as necessary for the purposes set out above, or for as long as the law requires. In practice that means:

  • Records relating to work we have done for a client are kept for as long as we may need them to answer a question or a claim about that work
  • Billing records are kept for at least six years, because tax law requires it
  • Data taken from a public register is deleted when it stops being published there, or sooner if you ask us to stop using it
  • Our do-not-contact list is kept indefinitely, as explained in section 5

11. Automated decision-making

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects. Any assessments or recommendations we provide are reviewed by our consultants.

12. Your rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction or deletion of your data
  • Withdraw consent for marketing communications
  • Object to, or request that we restrict, how we process your data
  • Receive a copy of the data you gave us in a portable format, or ask us to send it to another provider

If you have a concern about how we handle your data, please contact us. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk.

13. Security

We take appropriate technical and organisational measures to protect your data from loss, misuse, or unauthorised access.

14. Third-party links

Our website may contain links to other websites. We are not responsible for their content or privacy practices.

15. Changes to this policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.

16. Contact us

If you have any questions about this policy, or wish to exercise your rights, please contact us:

Orobo Healthcare Ltd, Bank Gallery, High Street, Kenilworth, Warwickshire, England, CV8 1LY

Email: hello@orobohealthcare.com

Or via our contact form: orobohealthcare.com/contact

Last updated: 29 July 2026

© 2026 Orobo Healthcare Ltd

Orobo Healthcare is an independent consultancy and is not affiliated with, endorsed by, or representing the Care Quality Commission.

Orobo Healthcare Ltd is registered in England and Wales under registration number 16729327 at Bank Gallery, High Street, Kenilworth, CV8 1LY

All prices exclude VAT (20%).