Privacy

Your privacy,
in plain English.

This notice explains what the Nanum app and website collect, why we collect it, and the control you have over it.

Last updated: 19 July 2026

Who we are

Nanum is a product of Yielda UK Private Limited. Depending on the information involved, Yielda acts either as the data controller or as a data processor — see “Our role” below.

Yielda UK Private Limited

Registered in England and Wales, company number 16707290.

Registered office: 60 Tottenham Court Road, Office 322, Fitzrovia, London, W1T 2EW, United Kingdom.

Registered with the Information Commissioner’s Office (ICO).

Contact: privacy@yielda.co.uk

Data Protection Officer: Versha Sharma (versha.sharma@yielda.co.uk)

Our role

For records about the people receiving care (visits, medication, tasks, notes and related information) in the Nanum app, your care provider is the data controller and we provide the software as a data processor, acting on the provider’s documented instructions. For your own account information, your care provider is the controller and we act as processor.

If you use Nanum as an independent (freelance) carer who registered with us directly, we are the controller of your registration, verification and payment information.

For the public marketing website at nanum.co.uk — including the “Book a demo” and enquiry forms — Yielda is the data controller. See “The nanum.co.uk website” below.

Who Nanum is for

Nanum is a professional tool used through a care provider. Most people sign in with an account issued by their provider; some are independent (freelance) carers who have registered with us and been verified. It is not a consumer social app — access is controlled, not open sign-up.

What we process

  • Account & identity — your work email and sign-in credentials, and your name, contact details and role as held by your care provider.
  • Location — your device location only at the moment you check in or out of a visit (foreground only), with the accuracy and distance to the visit address, to evidence attendance. We do not track you in the background or between visits.
  • Voice notes — when you choose to record a voice note, the audio is converted to text and only the resulting text is saved to the visit record; the underlying audio is not retained.
  • Care-delivery records — visit times, check-in/out, medication administrations, care-task outcomes and the notes you enter.
  • Care information you view — details about the people you are scheduled to visit, shown only for those individuals.

We collect only what is needed to deliver and evidence care — nothing more.

If you are an independent (freelance) carer, we also process the information you provide to register and be verified: your profile (experience, skills, area); vetting and compliance information — DBS, right-to-work, identity and address verification, references, training and National Insurance number — which we check before you can be booked, and keep an audit record of; the visits you accept and your availability; and the payment details needed to pay you. When you are booked for a visit, you receive a minimum, consent-scoped set of details about the person you will visit, for that visit only.

Why we process it

To provide the care-management service on the provider’s instructions and to support the safe delivery of care, including safeguarding and regulatory record-keeping. Health-related (special-category) information is processed for the provision of health and social care.

Service providers

We use a small number of carefully selected third-party providers — for example cloud hosting, database, authentication, communications and payment services — to deliver and support Nanum (payment services are used to pay independent carers). Each is bound by a Data Processing Agreement, processes personal data only on our instructions, and is not permitted to use it for their own purposes. We do not sell personal data, and we do not share it with anyone for their own marketing.

How we protect your data

Security is designed into Nanum, not bolted on. Our measures include:

  • Encryption in transit and at rest. All data is encrypted while moving between your device and our servers using industry-standard TLS, and encrypted at rest using AES-256.
  • Trusted, UK/EEA-based infrastructure. Care records are held on secure cloud infrastructure located in the UK/EEA, operated by established providers that maintain industry-recognised security certifications.
  • Strict, per-user access — enforced on our servers. Access is controlled at the database level so each person can only ever reach the records they are authorised to: a carer sees only the people they are scheduled to visit, a family member only their own relative’s consented information, and a provider only its own records. This isolation is applied server-side, not merely hidden in the app.
  • Least privilege & confidentiality. Access by our team and our providers is limited to what is strictly necessary and is subject to confidentiality obligations.
  • Protected credentials. Passwords are never stored in readable form — only as salted, hashed values — and access uses secure, time-limited sessions.
  • Tamper-evident care records. Medication and care entries are append-only: they cannot be silently altered or deleted, and any correction is added as a new, attributed entry — preserving an accurate, auditable history.
  • No tracking. The app contains no advertising, analytics or tracking technologies, and voice-note audio is not retained (see “What we process” above).
  • Resilience. Backups are encrypted, and our security measures are reviewed on an ongoing basis.

Retention

Specific retention periods are set by your care provider in line with its policy and applicable health and social-care requirements. We retain care records for as long as needed to provide the service, and then delete or return them on the provider’s instructions.

Your rights

Under UK GDPR you may have rights of access, rectification, erasure, restriction, objection and portability. As your care provider is the controller for care records, those requests are handled via your care provider. For anything else, contact privacy@yielda.co.uk.

Deleting your account

You can request deletion of your account from inside the app — open Me and tap Delete account. What happens depends on your role, because a care platform must keep certain records by law:

  • Carers, family members and independent carers. Your personal account is removed and you are signed out for good. Any legally-required care records you were part of — visit times, medication administrations, care-task outcomes and notes — are retained but de-identified: they are kept for your care provider (or, for independent carers, as an audit record) and are no longer linked to your name. Your provider must keep these under health and social-care record-keeping rules, so they cannot be erased on request.
  • Provider owners / managers. Your account owns a care provider with live resident and care records, so it cannot be deleted with a single tap. Your request is logged and we complete it with you — safely closing or transferring the provider first. Nothing is changed until then.

Deleting your account does not shorten the retention period your care provider applies to the underlying care records (see “Retention” above). You can also raise an erasure request at any time via your care provider or by emailing privacy@yielda.co.uk.

International transfers

Care records are held in the UK/EEA. Where personal data is transferred to, or accessed from, outside the UK/EEA, we ensure appropriate safeguards are in place — for example Standard Contractual Clauses or the UK International Data Transfer Agreement — together with the relevant Data Processing Agreement.

The nanum.co.uk website (enquiries & demo requests)

For the public marketing website at nanum.co.uk — including the “Book a demo” and enquiry forms — Yielda UK Private Limited is the data controller (not a processor).

  • What we collect: the details you enter in a form — typically your name, work email, organisation and role, and your message.
  • Why: to respond to your enquiry and arrange a demonstration of Nanum. Our lawful basis is our legitimate interest in responding to business enquiries, and your consent where you provide it.
  • Who helps us run the site: form submissions are handled by Formspree, Inc. and the site is hosted by Vercel Inc., both in the United States. Transfers outside the UK/EEA are safeguarded by Standard Contractual Clauses or the UK International Data Transfer Agreement, together with a Data Processing Agreement.
  • Retention: enquiry and demo-request details are kept for up to 24 months from our last contact, then deleted — unless we are in an ongoing business relationship.
  • Your rights: to access, correct or delete the details you submitted, contact privacy@yielda.co.uk.

The website does not host care records; those exist only in the Nanum app and are covered by the sections above.

Cookies

The Nanum website does not use cookies or similar technologies for advertising, analytics or tracking, and we do not build profiles of visitors. Any cookies we set are strictly necessary to make the site work and keep it secure; under UK law these are exempt from consent, so the site does not use a cookie-consent banner. The Nanum app likewise contains no advertising, analytics or tracking technologies (see “How we protect your data”).

Changes

We may update this notice from time to time; the “last updated” date above will change, and significant changes will be communicated appropriately.

Contact

Questions about this notice, or about your data? Email privacy@yielda.co.uk, or write to us at 60 Tottenham Court Road, Office 322, Fitzrovia, London, W1T 2EW, United Kingdom.