Who We Are
King's Lodge is a specialist neurological and complex care home operated by Alum Care Limited. We are the data controller for the personal information we collect through this website and in the course of providing care services.
Address: Kings Cross Lane, South Nutfield, Surrey, RH1 5PA
Phone: 01737 822221
Email: info@complexneeds.com
What Data We Collect
We may collect the following types of personal data:
Through This Website
- Contact form submissions: name, email address, phone number, and the content of your message
- Referral form submissions: referrer details (name, organisation, role, phone, email), patient details (name, condition type, urgency, funding status, clinical summary)
- Cookies and analytics: anonymised usage data including pages visited, time spent, and device information (see Cookies section below)
In the Course of Providing Care
- Resident data: health records, care plans, medication records, assessments, and correspondence with healthcare professionals and family members
- Family and visitor data: names, contact details, and visiting records
- Staff data: employment records, training records, DBS checks, and professional registration details
How We Use Your Data
We use personal data for the following purposes:
- Responding to enquiries submitted through our website or by phone and email
- Processing referrals and arranging pre-admission assessments
- Providing nursing and personal care to residents
- Communicating with families, healthcare professionals, and commissioners about resident care
- Meeting our regulatory obligations to the Care Quality Commission (CQC)
- Staff recruitment, employment, and training
- Improving our website and services
Legal Basis for Processing
Under UK GDPR, we process personal data on the following legal bases:
- Consent: When you submit a form on our website, you consent to us using your data to respond to your enquiry.
- Contract: When we provide care services, processing is necessary for the performance of our contract with the resident or their representative.
- Legal obligation: We are required to maintain certain records under the Health and Social Care Act 2008 and CQC regulations.
- Vital interests: In emergencies, we may process health data to protect the vital interests of a resident.
- Legitimate interests: We may process data for the legitimate interests of running our care home, provided this does not override your rights.
Where we process special category data (such as health records), we do so under the additional conditions set out in Article 9 of UK GDPR, including the provision of health or social care.
How We Protect Your Data
We take the security of your personal data seriously. Measures we have in place include:
- Secure, encrypted storage of electronic records
- Locked storage for paper records
- Staff training on data protection and confidentiality
- Access controls ensuring only authorised staff can view personal data
- Regular review of data security practices
Data Sharing
We may share personal data with:
- GPs, hospitals, and other healthcare providers involved in a resident's care
- NHS Integrated Care Boards and local authority commissioners responsible for funding
- The Care Quality Commission (CQC) as our regulator
- Emergency services where necessary
- Our professional advisers (legal, accounting) where required
We do not sell personal data to third parties. We do not share personal data for marketing purposes.
Data Retention
We retain personal data for as long as necessary to fulfil the purposes for which it was collected:
- Website enquiries: 2 years from the date of the last communication
- Referral data: 3 years if the referral does not result in admission; for the duration of residency plus 8 years if it does
- Resident care records: 8 years after the resident leaves our care (or 25 years for records of children), in line with NHS guidelines
- Staff records: 6 years after employment ends
Cookies
This website uses minimal cookies:
- Essential cookies: Required for the website to function properly (e.g., session management). These cannot be switched off.
- Analytics cookies: We may use anonymised analytics to understand how visitors use our website. No personally identifiable information is collected through analytics.
We do not use advertising cookies or tracking pixels. Most browsers allow you to control cookies through their settings.
Your Rights
Under UK GDPR, you have the following rights:
- Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You can ask us to correct inaccurate or incomplete data.
- Right to erasure: In certain circumstances, you can ask us to delete your personal data.
- Right to restrict processing: You can ask us to limit how we use your data.
- Right to data portability: You can request your data in a structured, commonly used format.
- Right to object: You can object to processing based on legitimate interests.
- Rights related to automated decision-making: We do not make automated decisions about you.
To exercise any of these rights, contact us at info@complexneeds.com or call 01737 822221. We will respond within one calendar month.
Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
We would appreciate the opportunity to address your concerns directly before you contact the ICO.
Changes to This Policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated date.
This policy was last updated on 2 April 2026.