CareGist

Acceptable Use Policy

Version 2.0 · In force from 9 August 2026

1. Scope

This policy governs the CareGist Directory, Radar, Intelligence Feed Pilot, Embedded Enterprise services, exports, APIs, and webhooks operated by H-Kay Limited (company number 10417923). It supplements the Business Terms of Service.

2. Permitted use

  • Search and verify public CQC location information through the free Directory.
  • Use Radar events, saved views, provider lists, actions, outcomes, and included exports within the organisation and territory stated by the customer's plan.
  • Use Feed APIs and signed webhooks only within the region, signal, volume, retention, and integration scope stated in the pilot agreement.
  • Use CareGist output in internal analysis and client work while retaining the supplied source attribution and evidence links.
  • Submit genuine provider correction or claim requests when authorised to represent the provider.

3. Evidence and high-impact decisions

CareGist is independent of CQC. A signal is not regulatory advice, a vacancy, a prediction, or a guaranteed commercial opportunity. You must review the linked official evidence before relying on an event in a regulated, clinical, safeguarding, employment, credit, or other high-impact decision.

You must not present a location-level event as a provider-group conclusion, remove the distinction between source fact and CareGist interpretation, or represent CareGist output as official CQC guidance.

4. Data protection and outreach

  • Do not upload patient records, care records, special-category data, or other information the product does not request.
  • Do not use CareGist to send unlawful unsolicited communications or to harass a provider, employee, resident, or service user.
  • Maintain your own lawful basis and transparency information for customer data, provider lists, outcomes, and outreach activity.
  • Do not infer a named individual's vacancy, performance, health, or employment status from a CareGist event.

5. Security and access

  • Keep account credentials and Feed signing secrets confidential and rotate them if compromise is suspected.
  • Do not share access outside the contracted organisation or attempt to access another organisation's workspace.
  • Do not bypass authentication, tenant controls, territory restrictions, export windows, rate limits, cursors, or delivery controls.
  • Do not introduce malicious code, interfere with service availability, or conduct load testing or security scanning without written permission.
  • Do not place credentials or signing secrets in browser code, public repositories, public URLs, or unprotected logs.

6. Reuse and redistribution

CQC source information remains available under its applicable source rights, including the Open Government Licence v3.0. CareGist does not restrict rights granted directly by that licence. CareGist's original event model, interface, delivery system, explanations, and customer workspace content remain subject to the Business Terms and the contracted scope.

You may not remove supplied CQC/OGL attribution, resell CareGist outputs as a competing signal service, redistribute customer-specific intelligence, or use the service to systematically replicate CareGist's event ledger. White-label, sublicensing, and embedded redistribution require an Embedded Enterprise agreement.

7. Enforcement and contact

CareGist may warn, throttle, suspend, or terminate access where reasonably necessary to protect evidence integrity, tenant isolation, security, lawful operation, or other customers. Where practical, CareGist will give notice and an opportunity to remedy the issue.

Report suspected abuse to abuse@caregist.co.uk and policy questions to legal@caregist.co.uk.