Trust Centre

Last updated: 2026-09-16

SweetTree Connect builds the technology platform behind SweetTree's home care services: in-home sensing, care and outcome monitoring, and the applications used by care teams and families. The people our platform serves are often vulnerable, and their information is health information — we treat the responsibility that follows as a design constraint, not a policy afterthought. This page sets out how we handle data, the controls we run, and the documents we can share. If something you need is not here, ask: every request below starts a direct conversation with us.

Privacy & data protection

UK GDPR & Data Protection Act 2018

Care records are processed on behalf of the responsible care provider; for our own product data we act as controller. A records-of-processing and DPIA programme is in progress, and our privacy policy explains both roles in plain language.

Data residency — United Kingdom

Our core platform — database, application services, and device telemetry processing — runs in Google Cloud's London region (europe-west2).

No tracking, no ad-tech

Our public website sets no cookies and runs no analytics or advertising trackers — so it needs no consent banner. Our care applications contain no third-party advertising or analytics SDKs.

Certifications & assessments

Where a certification is held, we show the certificate number and expiry and link the official register so you can verify it — not just our badge. Items marked Planned are on our assurance roadmap and will gain their evidence here as they complete.

Cyber Essentials

Planned

On our assurance roadmap: we are scoping our Cyber Essentials certification with our leadership team ahead of a formal submission. This page will carry the certificate number and expiry when it is awarded — verifiable on the official register.

Official register →

NHS Data Security & Protection Toolkit (DSPT)

Planned

On our assurance roadmap: the NHS annual self-assessment that supports data sharing with NHS and local-authority partners. Once published, our status will be checkable on the official register alongside our ODS code.

Official register →

How we secure the platform

Data security

  • Encryption in transit — TLS on every public endpoint, with HTTP Strict Transport Security enforced across our domains.
  • Encryption at rest — all platform data is stored on Google Cloud, which encrypts data at rest by default (AES-256).
  • Centralised secret management — credentials and API keys live in Google Secret Manager, never in code or configuration files.

Access control

  • Role-based access — staff and family users authenticate through Google Firebase Authentication, and what each account can see is governed by per-role access claims enforced in database security rules.
  • Least privilege — each platform service runs as its own dedicated service account with only the permissions that service needs.
  • No shared accounts — access is individual, provisioned and revoked per person.

Auditability & monitoring

  • Clinical and administrative actions are recorded as structured audit events alongside Google Cloud's own audit logging.
  • Continuous monitoring — uptime checks, delivery monitors, and automated first-line alert triage page the team when something is wrong.
  • Configuration drift detection — broker and infrastructure state is version-controlled and checked daily against what is actually running.

Engineering practice

  • Every change ships through version control and pull-request review; deployments are automated and gated.
  • Infrastructure is defined as code, with daily drift checks against the live estate.
  • Data-integrity guards run in the write path and continuously in production to catch structural corruption before it spreads.

Infrastructure & service providers

Providers that process data on our behalf as part of running the platform.

ProviderPurposeLocation
Google Cloud PlatformCore hosting — database, application services, analyticsLondon, UK (europe-west2)
Google FirebaseIdentity (sign-in) and push notification deliveryGoogle global infrastructure
ApplePush notification delivery to iOS devices (APNs)Global
EMQXIoT message broker for in-home device telemetry

Documents

Privacy policy
How we handle personal data, and our controller/processor roles.
View
Data deletion requests
How to have personal data associated with our apps deleted.
View
Security & architecture overview
How the platform is built — hosting, data flows, and controls.
Request access
Data protection documentation
Records of processing and DPIA materials relevant to your assessment.
Request access

Requesting a document opens a tracked conversation with our team — a person replies, and where material is commercially sensitive we may ask for a confidentiality agreement first. Anything you need that is not listed: just ask.

Common questions

Where is our data stored?

The platform's core database and services run in Google Cloud's London region (europe-west2). Sign-in and push notifications use Google Firebase and Apple services, which run on those providers' global infrastructure.

Does this website track me?

No. The public website and this page set no cookies and load no analytics or advertising scripts.

Do you sell personal data?

No. We never sell personal data, and we never share it for advertising.

How do I get access to a restricted document?

Use the request link on any document above, or email support@sweettreeconnect.com naming the document. Requests open a tracked conversation with us — we respond personally, and where a document is commercially sensitive we may ask for a confidentiality agreement before sharing.

How do I report a security concern?

Email support@sweettreeconnect.com with "SECURITY" in the subject line. Reports go straight to the engineering team and we will acknowledge promptly. Please do not include personal or sensitive data in the initial report.

Report a security concern

If you believe you have found a security vulnerability in any SweetTree Connect service, email support@sweettreeconnect.com with "SECURITY" in the subject line and we will acknowledge promptly. We welcome good-faith reports and will work with you on a fix and on disclosure timing. Please do not access other people's data, degrade the service, or include personal or sensitive data in your report. A machine-readable contact is published at /.well-known/security.txt. We do not currently operate a bug bounty programme.

Updates