Effective 12 July 2026 · Morro Care Ltd (Company No. 17326603)
This Privacy Policy explains how Morro Care Ltd, a company registered in England and Wales (company number 17326603), whose registered office is at Hartford Marina, Banks End, Wyton, Huntingdon, PE28 2AA ("Morro", "we", "us", "our"), collects, uses, shares, and protects personal data when you use the Morro application and related services ("the Service").
Morro is the data controller for the personal data described in this policy. We are registered with the UK Information Commissioner's Office (ICO) under registration reference 00014726889.
This policy should be read together with our Terms of Service.
This policy applies to everyone who uses the Service, including account holders, members of a Morro Group (family and carers), and the people receiving care whose information is recorded in the Service ("patients").
Where you add information about another person (for example a patient or another carer), you are responsible for ensuring you have the authority or consent to do so, as set out in our Terms of Service.
We collect and process the following categories of personal data:
Under the UK GDPR we rely on the following lawful bases:
Special category (health) data. Care information is special category data. We process it on the basis of your explicit consent, given when you use the Service to record and share care information, and/or where processing is necessary for the provision of care under applicable conditions in the Data Protection Act 2018. You may withdraw consent at any time, though this may limit your ability to use core features.
If you enable notifications, we use device tokens to deliver reminders and alerts (for example medication reminders and check-in prompts) via push and web-push services. You can control notifications and quiet hours in the app, and disable them in your device settings.
Care information is visible only to members of the relevant Morro Group, and only according to the permissions set by the group owner. It is not shared with other users outside that group. You control who is invited to a Morro Group and what they can access.
We use trusted third parties to operate the Service. They act as our processors under appropriate data protection agreements, or as independent controllers where noted:
We only share the data each provider needs to perform its function.
Some of our providers may process data outside the United Kingdom. Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place, such as an adequacy decision or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses. Our primary hosting region is the United Kingdom. You can contact us for more information about the safeguards we use.
We keep personal data for as long as your account is active and for a reasonable period afterwards, so that we can meet legal, security, and operational requirements. When data is no longer needed, we delete or anonymise it. Specific retention periods for each category are set out in our Data Retention Schedule in the Appendix below, and are available on request from support@morro.health.
If you close your account, we will delete or anonymise your personal data in accordance with that schedule, except where we are required to retain certain records by law.
We take appropriate technical and organisational measures to protect personal data, including encryption of data in transit and at rest, access controls that restrict data to permitted Morro Group members, and secured infrastructure. No system can be guaranteed completely secure, but we work to protect your data and to respond appropriately to any incident.
Under the UK GDPR you have the right to:
To exercise any of these rights, contact us at support@morro.health. We will respond within the timeframes required by law. Note that some data relates to a shared care record within a Morro Group, and we will handle requests in a way that respects the rights of all members and the patient.
The Service is intended for users aged 16 or over. Carers under 16 may only participate under the consent and oversight of a responsible adult guardian who controls the account and data, as set out in our Terms of Service.
We may update this policy from time to time. Where changes are significant we will take reasonable steps to notify you. The "Last updated" date shows when this policy was last revised.
For any questions about this policy or your data, contact us at:
Email: support@morro.health
Company: Morro Care Ltd, company number 17326603
If you are not satisfied with how we have handled your data, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Effective 13 July 2026 · Last reviewed 13 July 2026
This schedule sets out how long Morro keeps each category of personal data, and what happens to it when you close your account or leave a Morro Group. It supports section 8 above. Where we say "anonymised", the data can no longer be linked to you.
A note on shared records: Morro Groups hold a shared care record about the person receiving care. Information you contribute to a group (for example a wellbeing check-in or a medication log) forms part of that shared record. If you leave a group, your access ends, but the entries themselves remain part of the group's record, attributed to the group rather than to your account.
| Data category | What it includes | Kept while account active | After account closure / trigger | Why |
|---|---|---|---|---|
| Account & identity | Name, email, language preference, profile photo | Yes | Deleted within 30 days of account closure | Operational only; no reason to keep longer |
| Health & care records (shared group record) | Medications, dose logs, side-effect reports, wellbeing check-ins, emergency events, care timeline | Yes — belongs to the Morro Group | Deleted within 30 days of the group being deleted, or of the last member's account closing. A member leaving does not delete group records (see note above) | The record supports ongoing care of the patient; it is group-scoped, not individual-scoped |
| Group membership & roles | Membership records, roles, permissions | Yes | Removed when you leave a group or close your account; deleted with the group | Access control only |
| Invitations | Invite email, name, role, token | Until accepted, cancelled, or expired (7 days) | Unaccepted invites deleted 90 days after expiry | Kept briefly for resend/troubleshooting, then no purpose |
| Messages, feed & attachments | Group chat, activity feed posts, files shared in a group | Yes — part of the shared group record | Deleted with the group, within 30 days | Same basis as care records |
| Documents | Care documents uploaded to a group | Yes — part of the shared group record | Deleted with the group, within 30 days | Same basis as care records |
| Support tickets | Reference, your email, correspondence | Yes | 24 months from ticket closure, then deleted or anonymised | Handling follow-ups, complaints, and service-quality review |
| Billing & subscription records | Plan, billing status, renewal dates, Stripe identifiers, invoices (held by Stripe) | Yes | 6 years from the end of the relevant financial year | Required for HMRC / Companies Act accounting records; also covers the limitation period for contract claims |
| Device & notification data | Push tokens, notification preferences, quiet hours | Yes | Deleted within 30 days of account closure; stale device tokens removed on rolling basis | Delivery only |
| Technical & audit logs | System logs, security and audit events | Rolling 12 months | Expire on the rolling schedule regardless of account status | Security investigation and abuse prevention |
| Backups | Encrypted database backups | Rolling window (typically 35 days) | Deleted data leaves backups as the window rolls over | Disaster recovery; deletion propagates automatically |
Closing your account triggers deletion of your identity, device, and preference data within 30 days. Content you contributed to Morro Groups that continue to operate remains part of those groups' shared records. Billing records are retained for 6 years as required by law, and support correspondence per the schedule above. Data in encrypted backups is removed as the backup window rolls over (up to ~35 days after deletion).
We may retain specific data for longer where required by law, to establish or defend legal claims, or where a regulator requires it. Where we do, we retain only what is necessary, for only as long as necessary.
This schedule is reviewed at least annually, and whenever we add a new category of data processing (any such addition is also assessed in our Data Protection Impact Assessment).