Privacy Policy

How Formconnector handles your data using the CareHQ WordPress Form Connector.

1. Introduction

This Privacy Policy explains how Formconnector ("we", "us", or "our") collects, uses, stores, and protects personal data when you use the CareHQ WordPress Form Connector software, website, and related services (the "Service").

We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Third-Party Disclaimer

Formconnector is an independent company and is not affiliated with, endorsed by, or officially connected to CRMHQ Limited or their CareHQ® platform in any way.

The CareHQ WordPress Form Connector is a third-party integration tool designed to work with the CareHQ® API. We do not control, and are not responsible for, the data practices of CareHQ® or CRMHQ Limited. We recommend reviewing their own privacy policy for information about how they handle data received via their API.

3. Data We Collect

We may collect the following types of data:

3.1 Account Information

  • Name and email address (when you register for an account).
  • Billing information processed by our third-party payment provider.
  • Subscription plan and licence key details.

3.2 WordPress Form Submission Data

When you use our plugin, form submission data entered by visitors on your WordPress site is transmitted to the CareHQ® API via our Service. This data may include names, email addresses, phone numbers, and any other fields present in your forms.

Important: We act as a data processor for form submission data. You (the site owner) are the data controller and are responsible for ensuring you have lawful grounds to process this data, including obtaining appropriate consent from individuals.

3.3 Usage & Log Data

  • Plugin version, WordPress version, and PHP version.
  • Form submission logs (success/failure status, timestamps).
  • IP address and browser information when you visit our website.

3.4 Cookies

Our website uses essential cookies to maintain session state and authentication. We do not use third-party advertising or tracking cookies.

4. How We Use Your Data

We use the data we collect for the following purposes:

  • Service delivery — to provide, operate, and maintain the plugin and associated services.
  • Account management — to manage your subscription, licensing, and authentication.
  • Support — to respond to your enquiries and provide technical assistance.
  • Improvement — to analyse usage patterns and improve the Service (aggregated, non-identifiable data only).
  • Legal compliance — to comply with applicable laws, regulations, or legal obligations.

5. Legal Basis for Processing

We process personal data on the following legal bases under the UK GDPR:

  • Contract — processing necessary to perform our contract with you (e.g. providing the Service).
  • Legitimate interests — processing necessary for our legitimate business interests, such as improving the Service and preventing fraud.
  • Legal obligation — processing necessary to comply with legal requirements.
  • Consent — where you have given explicit consent, for example when submitting a contact form.

6. Data Sharing

We do not sell your personal data. We may share data with:

  • CareHQ® (CRMHQ Limited) — form submission data is transmitted to their API as part of the core functionality of the plugin. This occurs at your direction as the data controller.
  • Payment providers — billing data is processed by our third-party payment provider to handle subscriptions.
  • Hosting providers — our infrastructure providers may process data as part of hosting the Service.
  • Legal authorities — if required by law, regulation, or legal process.

7. Data Retention

We retain account data for as long as your account is active and for a reasonable period afterwards to comply with legal obligations. Form submission log data (success/failure status) is retained for up to 90 days by default, after which it is automatically purged.

You may request deletion of your data at any time by contacting us.

8. Data Security

We implement appropriate technical and organisational measures to protect your data, including:

  • Encryption of data in transit (TLS/SSL).
  • Secure authentication and access controls.
  • Regular security reviews and updates.

While we take reasonable steps to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

9. Your Rights

Under the UK GDPR, you have the following rights:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — request correction of inaccurate data.
  • Erasure — request deletion of your data ("right to be forgotten").
  • Restriction — request restriction of processing in certain circumstances.
  • Portability — request your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, please contact us at billy@victory.digital. We will respond within one month.

10. International Transfers

Your data may be processed and stored in the United Kingdom and the European Economic Area. If data is transferred outside these regions, we ensure appropriate safeguards are in place in accordance with the UK GDPR.

11. Children's Privacy

The Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or by email. The "Last updated" date at the top of this page indicates when the policy was last revised.

13. Contact & Complaints

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Formconnector
Email: billy@victory.digital

If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).