WELMA — Care Management App for children’s homes
Applies to the WELMA mobile app for Android and iOS (
ai.welcare.welma) and the WELMA web platform at welma.welcare.ai.Published by Welcare Global Ltd
Version 1.0 · Effective 25 August 2026 · Last updated 24 August 2026
1. Who we are and how to contact us
WELMA is a care-management platform for Ofsted-registered children’s homes in England, supplied by Welcare Global Ltd (“Welcare”, “we”, “us”). This policy explains what the WELMA app and web platform do with personal information.
| Registered address | Bizspace Business Centre, Knowles Lane, Bradford, England, BD4 9SW |
| Company number | 14773007 |
| General support | support@welcare.org.uk |
You can raise any privacy question, or make a request about your information, by emailing the privacy contact above. We reply within one month.
2. Who is responsible for your information
Two different roles apply, and which one is relevant depends on the information. This matters, because it decides who you contact to exercise your rights.
| Information | Who decides how it is used (“controller”) | Our role |
| Your WELMA account — name, work email, password, job title, role, devices, sign-in history | Welcare | Controller |
| An organisation’s registration details — organisation name, Ofsted URN, Companies House number, address, contact email and phone | Welcare | Controller |
| Support tickets you raise with us | Welcare | Controller |
| Everything recorded about a child or young person — care records, daily logs, incidents, medication, photographs, care plans, key work sessions, handovers | The children’s home provider that employs you | Processor, acting on that provider’s instructions |
| Staff activity, performance and shift records inside a provider’s account | The provider, as your employer | Processor |
If you are a member of staff asking about your own account, contact us.If you are a child, a parent, a carer, a social worker or an advocate asking about a child’s records, contact the children’s home — they decide what is held and for how long, and we act only on their instructions. If you do not know which home to contact, write to us and we will point you to the right one. We will always help a home respond, and we will never obstruct a request.
Each provider signs a data processing agreement with us under UK GDPR Article 28 before their organisation is activated.
3. The short version
- WELMA is a workplace app for professional adults. Children are not users of the mobile app and cannot sign in to it.
- Most of the personal information in WELMA is about children in care, entered by staff — it is not information about the person holding the phone.
- We do not use analytics, crash-reporting, advertising or tracking software of any kind. We do not track you across other apps or websites, and there is no advertising identifier.
- We do not access your location, your contacts or your calendar.
- The app uses the Android system photo picker, so it can only ever see the photographs you choose to attach — never your whole gallery.
- Everything the app sends travels over HTTPS, and your sign-in token is held in your device’s encrypted keystore.
- Some information is processed by AI providers, which may involve a transfer outside the UK/EU. Sections 9 and 11 explain this in full.
- You can delete your account from inside the app, or from a public web page if you have already uninstalled it. Section 17 explains exactly what is removed and what is kept.
- We never sell personal information.
4. Whose information WELMA holds
4.1 Staff and other app users
Care staff, key workers, managers, registered managers and organisation administrators employed by, or working for, a provider using WELMA.
4.2 Children and young people
Children and young people placed in a home that uses WELMA. They are not users of the mobile app. Their information is entered about them by staff, as part of the statutory record-keeping a children’s home is required to carry out.
Some homes also operate the Child Voice Portal, a separate web feature through which a young person can view and contribute to parts of their own record. Every access to it is logged, and those logs are visible to the home’s managers.
4.3 Other people named in records
Care records frequently name other people — social workers, team managers, family members, teachers, GPs, police officers, other professionals and, occasionally, other children. Where those names appear, that is personal information about those people too, and this policy covers it.
5. What information we hold
5.1 Your staff account
| What | Where it comes from |
| Name, work email address, job title | Entered when your organisation registers you, or when you accept an invitation |
| Password | Set by you. It is never stored in a form we can read |
| Role and permissions, and the home or homes you are assigned to | Set by your organisation’s administrator |
| Profile photograph or avatar, if you add one | You |
| Sign-in and session records, including the model name of the device you sign in from | Sent by the app at sign-in |
| Devices registered for push notifications: the notification token, platform, device name and app version | Sent by the app when you allow notifications |
5.2 If you register an organisation
The self-service sign-up form collects the organisation’s name, Ofsted URN, Companies House number (optional), address, city and postcode, plus the applying administrator’s name, job title and email, and an organisation contact email and phone number. We use it to verify that the applicant genuinely operates registered children’s homes before we activate the account.
5.3 Information about children and young people
Recorded by staff, on the provider’s instructions:
- Identity and placement — names and preferred name, date of birth, gender and pronouns, photograph, NHS number, Unique Pupil Number, LAC number, placement start and end dates, placement type, legal status, placing authority, staffing ratio, observation level, discharge reason and date.
- Health — medical conditions, allergies, dietary requirements, medication records including doses given, refused and PRN administrations, and welfare checks. This is special category health data (section 8).
- Day-to-day care records — daily logs, incidents, handovers, key work sessions, care plans, care summaries, risk assessments, goals, movements, tasks and welfare checks.
- Photographs and video attached to any of those records (section 12).
- Professional contacts — the child’s social worker’s name, email and phone, and the team manager’s name.
- Documents uploaded for processing — assessments, reports and similar files, together with the text and structured details extracted from them (section 9.3).
Free-text care records may, by their nature, also contain information about a child’s ethnicity, religion, sexuality, family relationships, or involvement with the police or the courts.
5.4 Staff activity and performance
WELMA records what staff do in the system and presents it to managers: activity timelines, counts of logs, incidents, medications and messages, performance metrics and comparisons, leaderboards, and gamification points, streaks and daily tasks. Section 13 covers this in full, because it is monitoring of you at work and you are entitled to know about it.
5.5 Support and communications
Support tickets and their attachments, email groups, and the log of emails the platform has sent.
5.6 What the app keeps on your device
| Stored | Protection |
| Your sign-in token | Encrypted by the operating system — Android Keystore or iOS Keychain |
| The home you last selected, onboarding and guided-tour progress, your calendar view preference, and whether assistant replies are read aloud | Ordinary app storage. No personal information about any child is cached here |
Uninstalling the app removes all of it.
5.7 What we deliberately do not collect
No analytics or usage-tracking software. No crash or performance reporting software. No advertising software, advertising identifier or advertising ID. No location data, contacts or calendar access. No biometric data — WELMA never asks for a fingerprint or face scan. No broad access to your photo gallery — the app uses the Android system photo picker, which returns only the individual photographs you select.
6. Why we use it, and our lawful basis
Under UK GDPR we need a lawful basis for everything we do with personal information.
| What we do | Whose information | Lawful basis (UK GDPR Article 6) |
| Create and run your account; authenticate you; keep you signed in | Staff | Contract (6(1)(b)) with you or your employer, and our legitimate interests (6(1)(f)) in operating a secure service |
| Verify a provider’s registration before activating it | Organisation applicants | Legitimate interests (6(1)(f)) — preventing unauthorised access to children’s records |
| Record and maintain the care of a child | Children, and people named in records | Legal obligation (6(1)(c)) on the home under the Children’s Homes (England) Regulations 2015, and the performance of a task in the public interest (6(1)(e)) where the placing authority’s duties apply |
| Send push notifications about shifts, tasks, handovers and alerts | Staff | Legitimate interests (6(1)(f)) in the safe running of the home |
| Manage rotas and shifts, including the RotaCloud integration | Staff | Contract (6(1)(b)) — your employment — and legitimate interests |
| Show managers staff activity, performance and gamification | Staff | Legitimate interests (6(1)(f)) of the provider in supervision, safeguarding oversight and quality assurance |
| Provide AI assistance, search, summaries and document extraction | Staff, children | Legitimate interests (6(1)(f)) in reducing the administrative burden on care staff, and legal obligation where the output forms part of a statutory record |
| Keep the service secure, investigate misuse, maintain audit logs | Everyone | Legitimate interests (6(1)(f)) and legal obligation (6(1)(c)) |
| Respond to support requests | Staff | Contract (6(1)(b)) and legitimate interests |
Where we rely on legitimate interests we have carried out a balancing assessment, and you can ask us for a summary of it.
We do not sell personal information. We do not use it for advertising, ad personalisation, credit scoring or lending decisions, and we do not share it with data brokers. We do not use health information to decide anyone’s employment or insurance eligibility, and we never publish or socially share it.
7. Where the information comes from
From you directly — your account details, and anything you type or photograph. From your employer — your role, permissions, and the homes you are assigned to. From your device — device model, notification token and app version. From documents uploaded to the platform. And, where a provider has enabled the integration, from RotaCloud, their rota system.
8. Special category and criminal offence information
WELMA necessarily holds special category data under UK GDPR Article 9 — principally health data about children (medical conditions, allergies, dietary needs, medication administration and welfare checks), and, where staff record it, information that reveals ethnicity, religion or sexual orientation. It may also hold criminal offence data under Article 10, where an incident involves the police, a missing-from-home episode or court proceedings.
We rely on the following additional conditions:
| Condition | Where it applies |
| Article 9(2)(b) — obligations in the field of employment and social protection law, with DPA 2018 Schedule 1 Part 1 paragraph 1 | Staff records where health or similar information arises |
| Article 9(2)(g) — substantial public interest, with DPA 2018 Schedule 1 Part 2 paragraph 18 (safeguarding of children and of individuals at risk) | The core of the children’s care records, incidents and safeguarding content |
| Article 9(2)(h) — the provision of health or social care, with DPA 2018 Schedule 1 Part 1 paragraph 2 | Medication administration, welfare checks and health-related care records |
| DPA 2018 Schedule 1 Part 2 paragraph 18, and paragraph 10 where the processing is for preventing or detecting unlawful acts | Criminal offence information appearing in incident records |
An Appropriate Policy Document, as required by DPA 2018 Schedule 1 Part 4 for these conditions, is maintained and is available on request from the privacy contact in section 1.
9. Artificial intelligence features
WELMA includes an AI assistant, automated care summaries, voice/speech features, and automated search and document extraction.
9.1 What is sent, and to whom
When you use these features, your request and the record content needed to answer it are sent from the WELMA backend to one or more of the following providers:
| Provider | Used for |
| AI assistant, written summaries, voice input and speech features | |
| OpenAI | Search within the service |
Limited use. Each provider acts as our processor under a written data processing agreement. They process personal data only on our documented instructions to return a response to the request made. They are contractually prohibited from using it to train or improve their models, from using it for their own purposes, from selling it, and from disclosing it to anyone else except as we instruct or the law requires.Welcare remains responsible for how these providers handle information, and for ensuring their use complies with this policy and with applicable law.
9.2 The AI assistant and speech features
Your messages to the assistant, voice inputs, and the record content used to answer them are processed as described above. Conversations are stored in your organisation’s account and are visible to managers as part of staff oversight (section 13). Speech and voice functionality are provided via Google integrations.
9.3 Document extraction and search
Documents uploaded for processing are converted to text and analysed to classify the document and extract structured details, which can include a child’s name and date of birth. OpenAI supports search functionality across records within the service. The extracted text and search indices are maintained securely within your organisation’s account.
9.4 Automated decision-making
WELMA does not make automated decisions with legal or similarly significant effects about any child or member of staff. AI output is a draft or a suggestion: a member of staff reviews, edits and confirms it before it becomes part of a record, and performance metrics inform management judgement rather than replacing it. A human therefore remains in the loop at every point, and UK GDPR Article 22 rights are not engaged. If that ever changes, we will update this policy before the change goes live.
10. Who we share information with
We do not sell personal information and we do not share it for anyone else’s marketing. We share it only with the following parties, and only as far as needed:
| Who | What | Why |
| Your employing provider | Everything in their account | They are the controller of the care records |
| Supabase | Account data, credentials, and service records | Primary hosting, storage, backups, and authentication (Servers located in Helsinki, Finland) |
| Assistant queries, record context for summaries, voice/speech data | AI assistant, written summaries, voice/speech features | |
| OpenAI | Search queries and relevant record data | In-service search functionality |
| Google (Firebase Cloud Messaging) on Android and Apple (APNs) on iOS | Notification tokens and notification content | Delivering push notifications. Notification text is written so as not to identify a child on a lock screen |
| RotaCloud | Shift, location and staff-matching data | Rota synchronisation for staff only (does not receive any information about children) |
| Self-hosted Email Infrastructure | Recipient addresses and message content | Platform emails and system notifications |
| Regulators including Ofsted, local authorities and the police | Records they are entitled to | Where a provider or the law requires disclosure |
| Professional advisers, auditors, and a purchaser in a corporate transaction | As strictly necessary | Legal and business obligations, under confidentiality |
Sharing you start yourself. Some records can be marked to be shared with a child’s social worker or family. Some screens let you export a file — an activity log, a policy document, a support attachment — through your device’s own share sheet. Once you send a file somewhere else, that copy is outside WELMA, and your organisation’s own information-governance rules apply to it.
Not used. WELMA contains no analytics, crash-reporting or advertising software, so no information goes to any such provider.
11. Sending information outside the UK
Primary hosting and storage via Supabase are located within Europe (Helsinki, Finland). Third-party AI processors (Google and OpenAI) may process data outside the UK/EEA.
Where information leaves the UK we rely on:
- the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum; and
- a transfer risk assessment, plus technical measures including encryption in transit and contractual bans on onward use.
A copy of the safeguards for any specific transfer is available on request from the privacy contact in section 1.
12. Photographs and images of children
Photographs are central to how care is evidenced, so they get their own section.
- The app uses your camera only when you choose to take a photograph, and the Android system photo picker when you choose to attach an existing one. The app never has access to your whole gallery, never reads it in the background, and never uploads anything you did not select.
- Photographs attached to daily logs, incidents, tasks and galleries may contain images of children, and are stored against those records in your organisation’s account.
- Photographs are visible to authorised staff at the same home, subject to their role.
- Consent for photographing a child is the provider’s responsibility, obtained under its own policy and the child’s placement arrangements before a photograph is taken. WELMA stores what staff record; it does not obtain that consent, and staff must not photograph a child where the home’s policy does not permit it.
- Photographs are retained and deleted on the same basis as the record they belong to (section 16).
13. Monitoring of staff
If you use WELMA at work, your employer can see what you do in it. We set this out plainly because you are entitled to know.
Managers at your organisation can see: the records you create and edit and when; an activity timeline and seven-day activity charts; counts of logs, incidents, medications and messages; performance metrics, pillar scores and trends; leaderboards ranking staff; your gamification points, streaks and daily tasks; your AI assistant conversations; and audit and activity logs of your actions.
This is monitoring for supervision, safeguarding oversight and quality assurance — not covert surveillance. It does not track your location, does not access your camera outside actions you take yourself, and does not extend to anything you do outside the app. Your employer, not Welcare, decides how this information is used in managing you, so any concern about that use should go to your employer in the first instance — though you can always contact us as well.
14. Push notifications
If you allow notifications, the app registers your device’s notification token, platform, device name and app version with WELMA so that it can send you shift reminders, task alerts, handover notifications and urgent alerts. You can turn notifications off at any time in your device settings, or adjust what you receive in the app’s notification preferences. Turning them off never prevents you from using the app. Signing out removes that device’s registration.
15. Secure data handling procedures
- Encryption in transit — the app communicates only over HTTPS with welma.welcare.ai. All data is encrypted in transit.
- Encrypted credential storage on your device — your sign-in token is held in the operating system’s encrypted keystore (Android Keystore / iOS Keychain), not in ordinary app storage.
- Encryption at rest — platform data and backups hosted on Supabase in Helsinki, Finland are encrypted at rest using industry-standard AES encryption.
- Sessions expire — sign-in tokens are time-limited (30 days) and refreshed, and signing out revokes them immediately.
- Access control — every request is scoped to your organisation and to the home you are working in, and features are gated by your role. Staff see only the children at their own home.
- Audit logging — actions are logged, including every access to the Child Voice Portal.
- Organisation verification — a provider’s application is checked by a Welcare administrator before anyone in that organisation can reach any care data.
- Confidentiality — staff and sub-processors are bound by confidentiality obligations, and access is granted on a least-privilege basis.
No system is perfectly secure. Where a breach is likely to result in a risk to people’s rights, we will notify the Information Commissioner’s Office within 72 hours and, where the risk is high, the people affected — working with the relevant provider, who as controller of the care records leads that notification.
16. Data retention and deletion policy
| Information | How long we keep it |
| Children’s care records — daily logs, incidents, medication administration, handovers, key work sessions, care plans, photographs | Retained by the provider under its statutory duties, under the Children’s Homes (England) Regulations 2015 and Ofsted retention requirements, and UK GDPR Article 17(3)(b). We do not delete them automatically; we delete or return them on the provider’s instruction. |
| Staff account records | For the life of your account. On deletion, the account is anonymised immediately and the anonymised row is retained indefinitely, because care records you authored point to it (section 17). |
| Audit and security logs | Retained in full for 12 months, then moved monthly into a long-term archive, which is retained for the life of the service. |
| Child Voice Portal access logs | 24 months |
| Sign-in sessions and registered devices | Sign-in tokens expire after 30 days and are revoked immediately when you sign out or delete your account. |
| Staff invitations | 7 days |
| Support tickets | Retained for the life of the organisation’s account. |
| AI assistant conversations | Retained in the organisation’s account for the life of that account. |
| Closed organisations | Access ends immediately on closure, followed by a 30-day grace period for data export. |
| Data stored on your device | Until you sign out or uninstall the app. |
Because the provider is the controller of the care records, the provider’s retention schedule governs them. We delete or return them on the provider’s instruction at the end of our contract, except where the law requires us to keep them.
17. Deleting your account
You can delete your WELMA account from inside the app, at Settings → Delete my account. It is also reachable from the verification screen, so it works even if your organisation’s application is still pending or was declined.
If you have already uninstalled the app, you can do the same thing without signing in, at:
Deleting your account anonymises you rather than erasing the records you wrote:
| Permanently erased | Retained |
| Your name, contact details, profile photo, employment and DBS details, training records and password | Daily logs, incidents, medication administrations, handovers and key work sessions you authored… |
| Every sign-in session and registered device | …re-attributed to “Deleted user”, and no longer linked to your name |
Why the records stay. They are records of a child’s care, and a children’s home is legally required to keep them. Deleting a safeguarding record because the member of staff who wrote it has left would destroy the audit trail that protects the child.The retention basis is the Children’s Homes (England) Regulations 2015 and Ofsted retention requirements, and UK GDPR Article 17(3)(b) (legal obligation).
If you are the last administrator of an organisation, you will be asked to transfer that role before your account can be deleted. If deletion cannot be completed in the app, write to support@welcare.org.uk.
A child’s records cannot be deleted through this route. Requests about a child’s information go to the children’s home, as explained in section 2.
18. Your rights
Under UK GDPR you have the right to: be informed; access a copy of your information; have inaccurate information corrected; ask for erasure; ask us to restrict processing; data portability; object to processing based on legitimate interests, including staff monitoring; and, where we rely on consent, withdraw it at any time.
These rights are not absolute. Erasure in particular does not override the legal obligation to retain children’s care records (sections 16 and 17).
How to exercise them
| You are… | Contact |
| A member of staff, asking about your own account | The privacy contact in section 1 |
| A child or young person, a parent, a carer, an advocate or a social worker, asking about a child’s records | The children’s home, which is the controller. They will contact us if they need our help. If you do not know who to write to, contact us and we will point you to the right home |
We respond within one month. There is no charge in ordinary circumstances. We may need to verify your identity first.
Children exercising their own rights
A child can exercise these rights themselves if they are capable of understanding what they involve — in Scotland, twelve is presumed sufficient, and in England the test is the child’s actual understanding rather than their age. Where a child cannot yet do so, a parent or someone with parental responsibility can act for them, and for a looked-after child that will often be the local authority. Homes are expected to explain these rights to a child in a way the child can understand, and to involve the child’s advocate or Independent Reviewing Officer where appropriate. We support homes in responding, and we will never obstruct a child’s request.
Complaints
You can complain to us using the privacy contact in section 1, and we would prefer the chance to put things right first. You also have the right to complain to the Information Commissioner’s Office:
ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · 0303 123 1113 · ico.org.uk/make-a-complaint
19. Cookies, tracking and advertising
The mobile app does not use cookies, contains no advertising or analytics software, and does not track you across other apps or websites. There is no advertising identifier and no cross-app tracking, because there is nothing to track.
The web platform at welma.welcare.ai uses only cookies strictly necessary to sign you in and keep your session.
20. Children as users
The mobile app is intended for adults aged 18 and over working in children’s homes. It is not directed to children, and children cannot register for or sign in to it. Where a provider operates the Child Voice Portal, that is a separate web feature made available to a young person by their home, with its own access controls and audit logging.
21. Changes to this policy
We will update this policy when what we do changes — particularly if we add a feature that collects something new, or add or change an AI provider. The version and date are at the top of this page. For a significant change we will notify you in the app or by email before it takes effect, and we will never quietly widen how information is used.
22. Summary of data collected and shared
This summary corresponds to the Data safety information shown on the app’s Google Play store listing.
| Data type | Collected | Shared | Purpose |
| Name | Yes | No | App functionality, account management |
| Email address | Yes | No | App functionality, account management |
| Other personal information — records about children in care | Yes | Yes — AI & Search providers (section 9) | App functionality |
| Health information | Yes | Yes — AI & Search providers (section 9) | App functionality |
| Photos | Yes | No | App functionality |
| Other in-app actions — AI assistant messages | Yes | Yes — AI providers (section 9) | App functionality |
| Device or other identifiers — notification token | Yes | No | Delivering push notifications |
| App activity and crash or performance data | No | No | No analytics or crash-reporting software is present |
| Location, contacts, calendar, financial data | No | No | Never accessed |
- All data is encrypted in transit.
- You can request that your data be deleted — see section 17.
- Some data is retained after deletion where the law requires it — see sections 16 and 17.
WELMA Privacy Policy · Version 1.0 · Effective 25 August 2026. Published by Welcare Global Ltd.

