Privacy Policy (v2.2)
Last updated: 10 September 2026
1. Introduction
AmbuNet is a software platform provided by Care Nav Ltd ("we", "us", "our").
We are committed to protecting personal data and respecting privacy. This Privacy Policy explains how we collect, use, store, and protect personal data processed through the AmbuNet platform.
AmbuNet is designed for use by organisations providing healthcare, medical, event, patient transport, and ambulance services ("tenants").
AmbuNet acts as a Data Processor on behalf of its tenants, who act as Data Controllers.
2. Data Controller and Data Processor Roles
Platform role
Care Nav Ltd (trading as AmbuNet) acts as a Data Processor.
Tenant role
Each organisation using AmbuNet acts as the Data Controller for:
- Employees
- Applicants
- Patients
- Clients and contacts
We process personal data only on the instructions of the tenant, except where required by law.
As Data Controller, the tenant — not Care Nav Ltd — is responsible for the lawfulness, accuracy, and appropriateness of all personal data entered into the platform, and for all decisions made using that data.
3. Types of Data We Process
AmbuNet may process the following categories of personal data:
a) Employee Data
- Name, contact details, date of birth
- Employment records
- Payroll information
- Qualifications and training
- DBS and right-to-work information
- Driving licence information
- Medical assessments (where provided)
- Uniform and equipment allocation
b) Applicant Data
- Application forms
- Employment history
- References
- Identity and right-to-work documentation
- Qualifications
- Personal statements
- Interview notes
- DBS information
c) Patient Data (Special Category Data)
- Name, date of birth, demographics
- Clinical observations and assessments
- Treatments and medications
- Medical history and presenting complaints
- Safeguarding information
- Electronic Patient Care Records (ePCRs)
- Clinical advice records
- Patient transport journeys, bookings, and related information
d) Client and Contact Data
- Names and contact details
- Organisation details
- Roles and responsibilities
- Event-related information
- Patient transport-related information
e) System and Usage Data
- Login activity
- Access logs (including access to patient records)
- Device and browser information
- Completion of forms
- Mobile app data described in section 13 (push notification tokens and, where enabled, live location)
f) Patient Feedback
AmbuNet allows tenants to request feedback from patients following care. Where a patient has consented and given a mobile number on their care record, the tenant's AmbuNet workspace sends an SMS invitation containing a unique feedback link.
The person leaving feedback chooses how it is handled:
- Linked feedback. They may link their feedback to the care record by confirming the patient's surname and date of birth. These details are checked against the care record on our servers and are not stored with the feedback. Linked feedback records a reference to the care record and to the staff who provided the care, so that the tenant can use it for clinical governance, service improvement, staff appraisal, and the investigation of complaints or compliments.
- Anonymous feedback. They may instead leave feedback anonymously. Anonymous feedback is not linked to any care record, invitation or identity.
In both cases:
- Name and contact details are stored only if the person chooses to provide them.
- Nothing from the care record is displayed to the person leaving feedback.
- Feedback links expire after 60 days, and identity confirmation is protected against repeated guessing.
- Feedback is visible only to the tenant's governance team.
Tenants are responsible for telling patients about feedback processing in their own privacy notices.
4. How We Use Personal Data
We process personal data to:
- Provide and maintain the AmbuNet platform
- Enable tenants to manage staff, events, and patient care
- Store and manage electronic patient care records
- Support clinical governance and audit processes
- Facilitate communication (e.g. email and SMS notifications)
- Improve system performance and security
We do not use personal data for our own marketing purposes.
5. Lawful Basis for Processing
Tenants are responsible for determining the lawful basis under UK GDPR for processing personal data.
Common lawful bases include:
- Performance of a contract
- Legal obligation
- Legitimate interests (e.g. service delivery and audit logging)
- Provision of health or social care (Article 9(2)(h) UK GDPR)
- Consent (where applicable, e.g. recruitment or optional features)
AmbuNet processes data only in accordance with the tenant’s instructions. Responsibility for identifying and documenting a lawful basis rests entirely with the tenant.
6. Data Storage and Security
We implement appropriate technical and organisational measures to protect data, including:
- Encrypted transmission (HTTPS)
- Password hashing using bcrypt
- Role-based access controls
- Multi-factor authentication for access to patient data
- Audit logging of access to sensitive records
- Encryption at rest for offline records held on mobile devices (see section 13)
Data is stored on servers hosted in the United Kingdom, with backups stored within the European Economic Area (EEA).
No system can be guaranteed to be completely secure. Tenants remain responsible for the security of their own devices, networks, credentials, and user access decisions.
7. Data Retention
Tenants are responsible for defining and managing their data retention policies.
AmbuNet retains data for:
- The duration of an active tenant account
- A reasonable period afterwards for recovery, legal, and operational purposes
In healthcare contexts, records may be retained for several years in line with NHS and regulatory guidance. It is the tenant's responsibility to ensure retention practices meet the regulatory requirements applicable to their organisation.
8. Data Sharing
We do not sell personal data.
We may share data with trusted service providers (sub-processors), including:
- Hosting providers (e.g. IONOS)
- Cloud storage providers (e.g. AWS)
- Email providers (e.g. Microsoft)
- SMS providers (e.g. ClickSend)
- Website live-chat providers (e.g. Crisp)
- Task management providers (e.g. ClickUp)
- Billing and subscription providers (e.g. Stripe)
- Accounting integrations (e.g. Xero, if enabled)
All third parties are subject to appropriate data protection obligations.
9. Data Sharing by Tenants
Tenants may use AmbuNet to share data with authorised third parties.
For example:
- Patient data may be shared via secure access codes with authorised recipients (e.g. hospitals)
Tenants are solely responsible for ensuring such sharing is lawful and appropriate. We accept no responsibility for any sharing of data initiated by a tenant or its users, to the maximum extent permitted by law.
10. International Transfers
Where data is transferred outside the UK, we ensure appropriate safeguards are in place, including:
- Adequacy regulations
- Standard contractual clauses
11. Data Subject Rights
Individuals have the right to:
- Access their personal data
- Request correction of inaccurate data
- Request deletion (where applicable)
- Restrict or object to processing
- Data portability (where applicable)
Requests should be directed to the relevant tenant (Data Controller).
AmbuNet will assist tenants in fulfilling these requests where required.
12. Cookies
AmbuNet uses cookies only as necessary to:
- Maintain secure login sessions
- Ensure proper functioning of the platform
We do not use tracking, analytics, or advertising cookies on the platform.
Website visitors
Our public website (ambunet.co.uk / ambunet.ie) is separate from the platform. It uses a live-chat service (Crisp) so that visitors can ask us questions. Crisp sets a small number of cookies to keep a chat conversation open between pages and may process the messages, name, and email address a visitor chooses to give in the chat. The website does not use advertising cookies. Visitors who sign up for a demo or an account are asked for their details on our signup pages, and those details are used only to set up and support the account.
13. The AmbuNet Mobile App
Staff of tenant organisations may use the AmbuNet mobile app (iOS and Android). In addition to the data described above, the app involves the following processing:
a) Live location
Where a tenant uses dispatch or patient transport features, the app can share a staff member's live location with their organisation's control room. Location sharing:
- Happens only with the staff member's explicit in-app consent, given per request or started by the staff member themselves;
- Is limited to while they are clocked into a shift and crewed on a live resource, and ends automatically at the agreed time or when they clock out;
- Can be declined without affecting any other use of the app;
- Is visible only to their own organisation. Location history is processed on the tenant's instructions like other operational data.
b) Push notifications
To deliver operational alerts (for example incident assignments, stand-downs, and shift reminders), the app registers a device push notification token with our servers. The token identifies the device, not its location, and is removed when the user signs out.
c) Camera and photo library
The app requests camera or photo library access only when a user chooses to attach an image (for example to a patient care record or defect report). Images become part of the tenant's records and are handled like other tenant data.
d) Offline records stored on the device
To support working without signal, patient care record drafts may be held temporarily on the device. These drafts are encrypted at rest, with encryption keys stored in the device's secure keychain/keystore, and are synchronised to the tenant's workspace when connectivity returns. Staff and tenants remain responsible for their devices' physical security and for using the device security features (passcode/biometrics) required by their organisation.
e) App permissions
The app requests only the permissions needed for the features above (notifications, location, camera/photos). Each permission is optional and requested in context; declining a permission only disables the related feature.
14. Data Access Logging
Access to sensitive data (including patient records) is logged to provide an audit trail for governance, security, and compliance purposes.
15. Children’s Data
AmbuNet may process data relating to minors as part of patient care records.
It is the responsibility of the tenant to ensure appropriate legal basis and safeguarding measures are in place when processing children’s data.
16. Automated Decision-Making
AmbuNet does not perform automated decision-making or profiling.
All decisions involving personal data (e.g. clinical decisions, recruitment outcomes, or training compliance) are made by users of the platform, and responsibility for those decisions rests with the tenant and its users.
17. Data Breaches
In the event of a data breach affecting tenant data, AmbuNet will:
- Notify the affected tenant(s) without undue delay
- Support tenants in meeting regulatory obligations, including notification to the ICO and affected individuals where required
Responsibility for controller-side breach obligations (including assessing risk, notifying the ICO, and informing affected individuals) rests with the tenant.
18. Responsibility and Liability
As a Data Processor, our obligations are limited to those imposed on processors by UK GDPR and to processing carried out on the tenant's documented instructions.
To the maximum extent permitted by law, responsibility and liability for the collection, accuracy, use, sharing, and retention of personal data in AmbuNet rests with the tenant as Data Controller.
Any liability we may have in connection with the platform is excluded and limited as set out in our Terms of Use. Nothing in this policy excludes any liability or statutory obligation that cannot be excluded under UK law, including our obligations as a processor under UK GDPR.
19. ICO Registration
Care Nav Ltd, trading as AmbuNet, is registered with the Information Commissioner's Office (ICO) under the UK GDPR.
20. Changes to This Policy
We may update this Privacy Policy from time to time.
Where changes are significant, users will be required to review and acknowledge the updated policy before continuing to use the platform.
21. Contact
For any privacy-related queries, please contact:
Care Nav Ltd (AmbuNet)
📧 support@ambunet.co.uk
📍 Beacon Innovation Centre, Beacon Park, Gorleston-on-Sea, Norfolk, NR31 6LF