Security

    Security, sign-in and the data processing agreement (DPA)

    Who is responsible for the personal data, how you accept the DPA, what it unlocks, and where you see and control access to your data.

    Who is responsible for the data

    When Caire is used by a home-care organization, the organization is normally the controller for data about employees, clients, schedules, visits and care documentation.

    Caire (EirTech AB) acts as processor under the DPA and documented instructions. If you are a processor for a municipality, Caire is a subprocessor and you need the controller’s authorisation. The DPA does not replace confidentiality assessments, municipal contracts or a lawful basis; it is not patient consent.

    How you accept the DPA

    An organization administrator reads the data processing agreement (DPA) in Caire when the organization is created, and it must be accepted before the organization can be created. The agreement is versioned, and Caire records which version you accepted.

    Reach the end of the agreement, confirm your authority to represent the named organisation and choose ”I accept the DPA on behalf of the organisation”. Account terms and an administrator role do not by themselves provide authority to share client data.

    The same acceptance can be done later from the ”DPA required before personal data” banner, which leads to Getting started. Only an organization administrator can accept the agreement.

    What the DPA unlocks

    Before you add personal data about employees, clients and their care plans, the organization must have accepted the DPA with EirTech AB (Caire).

    You can explore the product meanwhile, but adding personal data stays locked until the agreement is accepted. Report imports and integration API keys, for example Carefox, also require an accepted DPA before personal data may be imported.

    Where you find the agreement afterwards

    The report upload step has a ”Safe handling of the reports” box. There, the ”Show the DPA for the organization” link shows the agreement you already accepted — it is not a new acceptance.

    Once the agreement is accepted you can download a copy for your own records. The same box holds the contact link ”Questions about the DPA or security? Contact Caire”.

    AI features

    Your earlier DPA still covers the ordinary product and report import. Before Azure AI can be used, an organization administrator must accept the DPA version that explicitly describes Microsoft Azure/Azure OpenAI in Sweden Central.

    That covers Ask Caire, speech recognition and clinical AI features; the ordinary Excel preview of the reports does not use Azure AI. The notice about the updated agreement appears on the Ask Caire card in Caire.

    Sign-in, permissions and support access

    Colleagues are invited and given roles under Settings → Users. Only an organization administrator can reach that view.

    Under Settings → Support access, an organization administrator sees whether anyone at Caire has access to your data right now, and can end that access. Caire has no standing access — every session is time-limited and listed there.

    The connection that lets an AI tool read your planning sits under Settings → Integrations. It requires Caire to have enabled MCP for your organization, and your own organization administrator to have granted you permission to use Ask Caire.

    What happens to the reports?

    Reports are uploaded in the signed-in import flow, after you accept the terms, the privacy policy and the DPA. Do not submit client data through the website’s Ask Caire, contact form or email.

    Source reports are processed for preview and register joins. After confirmation, supported names, source identifiers, addresses, visits and time data are retained. In verified import, any personal identity numbers are used only for temporary upload-specific joins; raw numbers, salts and salted joins are not persisted in registers or logs by that import. Do not include diagnoses, door codes or free text in analysis inputs.

    Timefold receives pseudonymous identifiers and necessary location, time, availability and skill data, without client or employee names. Addresses and coordinates can still make the data identifiable. Pseudonymisation is not anonymisation.

    End the analysis or request deletion

    A complimentary analysis does not automatically order a paid service. Completion does not mean immediate deletion either. An authorised representative can contact info@caire.se to request return or deletion under the DPA, without sensitive attachments.

    Identify the organisation and analysis. We check authority and handle source material, derived data and copies under the instruction and applicable law. Ask about retention and backup procedures if needed for your internal assessment. An account or DPA is not a blanket clearance under social-care, confidentiality, healthcare or patient-data rules.

    Where the data is processed

    Production planning data is processed in AWS Stockholm. Account data is also processed by Clerk in the US. The DPA appendix describes each recipient, region and transfer safeguard; an EU-only promise does not apply to all data.