Legal

Privacy Policy

Version 1.0 · Last updated 23 August 2026

1. About this policy

This Privacy Policy explains how Sanka Ventures ("we", "us", "our") collects, uses, stores, and protects personal data in connection with the CQC Evidence platform ("the Service"), available at cqcevidence.com.

CQC Evidence is a CQC-preparedness and evidence-organisation tool for health and social care providers, in particular mental health and learning disability services. It helps provider organisations record and review their own governance and compliance evidence against the CQC key questions.

We are committed to protecting personal data and handling it in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This policy applies to personal data we process as a data controller — principally the account and contact details of the staff who use the Service. Section 8 explains our separate role as a data processor for the evidence content that customer organisations enter into the Service.

2. Who we are and how to contact us

Sanka Ventures is the data controller for the personal data described in this policy.

If you have any question about this policy, or wish to exercise any of your data protection rights, please contact us at the address above.

3. The personal data we collect

We have designed the Service to hold as little personal data as possible. The Service is an evidence and governance tool; it is not a clinical record system and is not intended to store personal or clinical data about service users or patients.

The personal data we process falls into the following categories:

Account data. When a user account is created for a member of a provider organisation's staff, we process their name, username, work email address (where provided), job role or discipline, and the organisation they belong to. We also store an encrypted (hashed) version of their password. We never store passwords in plain text.

Usage and technical data. When you use the Service we process limited technical information necessary to operate it securely, such as your login session, the date and time of actions taken, and standard server logs (for example, IP address and browser type) generated for security and troubleshooting purposes.

Contact data. If you contact us — for example to request a demonstration or ask a question — we process the information you choose to give us, such as your name, email address, and the content of your message.

Evidence content you enter. Users of the Service upload and record governance and compliance evidence (such as policies, audits, and records of activities) on behalf of their organisation. This content is entered by the customer organisation and is intended to consist of organisational governance evidence, not personal data about individuals. Where a customer organisation chooses to enter documents that happen to name or identify individuals (for example, a staff member named in an audit), we process that content on the customer's behalf as a data processor — see Section 8.

4. How we use personal data, and our lawful bases

We use personal data only for the purposes set out below, and we rely on the following lawful bases under UK GDPR:

To provide and operate the Service — creating and managing user accounts, authenticating logins, and delivering the Service's features. Lawful basis: performance of a contract, or our legitimate interests in providing a service that has been requested.

To keep the Service secure — authenticating users, maintaining security logs, preventing and investigating unauthorised access, and protecting the integrity of the data held. Lawful basis: our legitimate interests in operating a secure service, and our legal obligation to keep personal data secure.

To respond to enquiries — dealing with demonstration requests, questions, and support messages. Lawful basis: our legitimate interests in responding to those who contact us, and taking steps at your request prior to entering a contract.

To comply with our legal obligations — for example, responding to lawful requests and meeting our obligations under data protection law. Lawful basis: compliance with a legal obligation.

We do not use personal data for advertising, and we do not sell personal data to anyone.

5. Artificial intelligence — what we do not do

We think this is important enough to state plainly. The CQC Evidence Service does not send your data, your account information, or the evidence content you enter to any third-party artificial intelligence service. Features within the Service that suggest categories or classifications operate using built-in rules within our own software; they do not transmit your data to an external AI provider.

6. Cookies

The Service uses a single, essential session cookie. This cookie is strictly necessary to keep you securely logged in as you move between pages; it does not track you, and it is deleted when your session ends.

We do not use advertising cookies, analytics cookies, or any third-party tracking cookies. Because we only use a strictly necessary cookie, no cookie consent banner is required.

7. Who we share personal data with

We do not sell personal data, and we share it only where necessary to run the Service or where we are required to by law. The categories of recipient are:

Our hosting provider. The Service is hosted on secure server infrastructure provided by Hostinger, located within the UK/EU. Our hosting provider processes data on our behalf as a data processor, under contractual terms that require appropriate security measures.

Professional advisers and authorities. We may disclose personal data to our professional advisers, or to regulators, law enforcement, or other authorities, where we are legally required to do so or where it is necessary to protect our rights.

We do not transfer personal data outside the UK or European Economic Area. Should this ever change, we will update this policy and ensure an appropriate safeguard (such as UK adequacy or standard contractual clauses) is in place.

8. Our role as a data processor

For the evidence content that a customer organisation enters into the Service, the customer organisation is the data controller and we act as a data processor on their behalf. This means:

Customer organisations that use the Service to hold any personal data are responsible for having their own lawful basis and, where appropriate, a data processing agreement with us. We can provide a data processing agreement on request.

9. How long we keep personal data

We keep personal data only for as long as necessary for the purposes described in this policy.

Account data is retained for as long as the user's account is active. When an organisation stops using the Service, we retain account and associated data for the duration of the customer agreement and for a period of up to 12 months afterwards, unless the customer requests earlier deletion or a longer period is required by law. After that period, the data is securely deleted.

Contact and enquiry data is retained for as long as necessary to deal with your enquiry and, where a business relationship follows, for the duration of that relationship.

Security and server logs are retained for a limited period appropriate to their security purpose and are then deleted or overwritten.

10. How we protect personal data

We take the security of personal data seriously and apply appropriate technical and organisational measures, including:

No system can be guaranteed to be completely secure, but we work to protect personal data and to reduce risk through appropriate safeguards.

11. Your data protection rights

Under UK GDPR you have the following rights in relation to your personal data:

Where the personal data concerned is evidence content held on behalf of a customer organisation, you should direct your request to that organisation as the data controller; we will support them in responding.

To exercise any of these rights in respect of data for which we are the controller, contact us at info@sankaventures.com. We will respond within one month. There is normally no charge, although we may charge a reasonable fee or decline a request that is manifestly unfounded or excessive, as permitted by law.

12. Your right to complain

If you have a concern about how we handle your personal data, we would ask you to contact us first so we can try to resolve it. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:

13. Changes to this policy

We may update this policy from time to time to reflect changes in the Service or in the law. When we make material changes, we will update the version number and date at the top of this policy and, where appropriate, notify customer organisations directly. Please review this policy periodically.

14. About the Care Quality Commission

CQC Evidence is an independent tool. It is not affiliated with, endorsed by, or connected to the Care Quality Commission (CQC). It does not assess, score, or guarantee regulatory compliance. References to the CQC and its key questions are used solely to describe how the tool helps providers organise their own evidence.