Privacy Policy

Effective date: 27th June 2024

About this notice

This notice tells you what personal information National Disability Card Ltd ("NDC", "we", "us") holds about you when you apply for a National Carers Card, hold one, or use our website at nationalcarerscard.org.uk, what we do with it, who we share it with, how long we keep it, and what your rights are.

It is issued under Articles 13 and 14 of the UK General Data Protection Regulation (UK GDPR) and the

Data Protection Act 2018.

The National Carers Card is run by NDC, the same UK social enterprise that runs the National Disability Card. NDC's broader privacy approach covers both products together.

1. Who we are

NDC is the data controller for your personal information. Our details:

• Name: National Disability Card Ltd

• Trading names: National Disability Card, National Carers Card, and DisabilityID (DisabilityID is our registered trade mark)

• Company number: 12275048

• Registered office: 15a Deben Mill Business Centre, Old Maltings Approach, Melton, Woodbridge, England, IP12 1BL

• ICO registration: ZA733593

• Day-to-day data protection contact: Dianne Taylor

• Data Protection Lead: contact via info@disabilityid.co.uk

NDC is a UK social enterprise founded in 2019. We operate the National Disability and Carers Card Scheme.

2. Who this notice covers

This notice applies to:

• People who apply for a National Carers Card.

• Current carer cardholders.

• Former cardholders.

• Parents or guardians applying on behalf of a young carer (a child carer).

• Visitors to nationalcarerscard.org.uk.

• People who contact us in connection with the National Carers Card. It does not cover NDC employees, contractors, or job applicants — see our separate Employee Privacy Notice. Where you also apply for or hold a National Disability Card, the Cardholder Privacy Notice on disabilityid.co.uk covers that side, but the same overall approach applies.

3. What personal information we collect

The information we hold depends on what you do. It typically includes:

When you apply for a National Carers Card

• Your full name and date of birth.

• Your address, email address, and phone number.

• A photograph for your card (you upload this).

• A self-declaration that you provide unpaid care to someone who needs help due to illness, frailty, disability, mental health problems, or addiction.

• Information about the care you provide: the types of support and your average weekly hours of care. We do not collect or keep identifiable information about the person you care for. The postcode you enter for the person you care for is used only to check whether a council-funded scheme applies in their area, and where you claim the cardholder discount we use their National Disability Card number only to confirm it. We do not routinely ask for documentary evidence, though we may request further information where we need to check an application.

• If you choose the optional emergency contact QR code: your emergency contact’s name, their relationship to you, and their phone number. Only the phone number is encoded in the QR code printed on your card. We keep the name and relationship in our records solely so that we know whose number it is, for example if a data protection query arises; they never appear on the card.

• Payment details for the card (handled by Stripe, see Section 7).

When you hold a card

• The cards we have issued to you, their unique card numbers, and their expiry dates.

• Records of any contact with our support team.

• Any renewals, changes to your details, or replacement requests.

• Any additional purchases (lanyards, RADAR keys).

Young carers (under 18)

Where a parent or person with parental responsibility applies on behalf of a child carer:

• The child's name, date of birth, address, photo, and eligibility evidence.

• Your name, contact details, and confirmation that you have parental responsibility for the child.

See Section 5 for how we handle children's data.

When you contact us

• The content of your messages, emails, or calls.

• Records of complaints and how they were resolved.

When you visit our website

• Your IP address, browser type, device type, pages visited, and how you arrived on the site.

• Cookies, see Section 11 for details.

When you use the NDC mobile app

• Your device type, operating system, app version, and basic error and crash logs, to help us keep the app working.

• Your account details (name, email, card number) so we can show you your card and cardholder features.

• Location data, only where you grant the app location permission through your device settings. The app uses your device’s precise (GPS) location solely to search for and display places, discounts, and services near you at the time of your request (for example, nearby accessible facilities or cardholder offers). Your location is processed only transiently for that immediate search: it is not stored on our servers or on your device after the search is complete, and we never build a history of where you have been. To run the search, your coordinates are passed to the mapping service on your device (Google Maps on Android, Apple Maps on iOS), whose processing is covered by Google’s or Apple’s own privacy policy.

We do not share your location with advertisers, analytics providers, or any other external companies. You can withdraw location permission at any time in your device settings; the app will still work, but it will not be able to show you nearby results.

4. How we use your information and our lawful basis

UK GDPR requires us to have a lawful basis for everything we do with your personal information. The

bases we rely on are:

What we do Lawful basis (UK GDPR Article 6)
Process your card application and issue your card Necessary for the performance of a contract with you (Article 6(1)(b))
Verify your eligibility as a carer Necessary for the performance of a contract (Article 6(1)(b)); for any special category data, see below
Send you service messages Necessary for the performance of a contract (Article 6(1)(b)) and our legitimate interests (Article 6(1)(f))
Send you marketing emails Your consent (Article 6(1)(a)), or soft opt-in under PECR 2003
Comply with HMRC, ICO, and other legal obligations Compliance with a legal obligation (Article 6(1)(c))
Prevent and detect fraud Our legitimate interests (Article 6(1)(f))
Improve our service, website, and processes Our legitimate interests (Article 6(1)(f))
Show you nearby places, discounts, and services in the NDC mobile app Your consent (Article 6(1)(a)), given through your device’s location permission; you can revoke it at any time in your device settings

Special category data

Your declaration tells us about the care you provide, not about the health of the person you care for, so we do not routinely hold special category data about you or them. Where information you volunteer (for example, in correspondence with our support team) does include health or other special category data, it is protected under UK GDPR Article 9. We process it on the following conditions:

• Article 9(2)(g) and Schedule 1, Part 2, Paragraph 16 of the Data Protection Act 2018: substantial public interest, support for individuals with a particular disability or medical condition. A scheme that allows unpaid carers to identify themselves so they can access reasonable adjustments and concessions is recognised public-interest activity.

• Article 9(2)(a): explicit consent, in the limited cases where we specifically ask for it. We do not rely on consent for eligibility evidence itself; that is covered by the substantial public interest condition above.

We do not use special category data for marketing or any purpose other than running the scheme.

5. Young carers (under 18)

The National Carers Card is available to carers aged 5 and over. Carers aged 16 or 17 may apply for themselves, or a parent or guardian may apply for them. Where the applicant is under 16:

• A parent or person with parental responsibility must apply on the child's behalf.

• We confirm the applying adult's relationship to the child and their parental responsibility.

• We hold the child's information for the same purposes and the same periods as we would for an adult cardholder.

• The applying adult exercises the child's rights under UK GDPR until the child is old enough to do so themselves (typically from age 13 for online services in the UK, or earlier where the child has sufficient understanding).

• We do not aim our marketing at children. Marketing emails are sent to the email address given on the application, which for a child’s application is the applying adult’s address. If you are 13 or older and want to take over the running of your own card, contact us and we will work with your parent or guardian to make that happen.

6. Who we share your information with

We share your information only where we need to and only with the people who need to see it.

Inside NDC

NDC staff with a legitimate need (for example, the verification team and customer support) can see your information. We control access so that staff see only what they need for their role.

Service providers we work with

• Stripe, our payment processor. Stripe handles your card details on our behalf. NDC never sees or stores your full bank-card number or security code.

• Mailchimp, our email service provider, where you have opted in to marketing or where we are sending service messages.

• Zendesk and Google Workspace (Gmail), our customer-service tools, where you contact us with an enquiry, complaint, or subject access request.

• Google Maps (on Android) or Apple Maps (on iOS): when you use the app’s nearby-search features, your coordinates are passed transiently to the mapping service on your device to find results near you. We do not give the mapping service your name or card details, and we share nothing else with it.

• Royal Mail, for the postal delivery of your National Carers Card to your address.

• Our website hosting and supporting providers, who help us run the website and the application system. These providers are bound by data processing agreements.

• Xero, our accounting system, for payment records.

• Our accountants, for payroll, tax, and statutory accounts.

• Our legal advisers, where needed for tax, compliance, or legal reasons.

Public bodies, regulators, and law-enforcement

We may share information where the law requires it, for example:

• HMRC, where we are required to share information for tax purposes.

• The Information Commissioner's Office (ICO), where required.

• Law enforcement, where we are required to assist with the prevention or detection of crime.

Retailers, venues, and partners

When you show your card at a venue or to a retailer, you are sharing the information visible on the card with that person (your name, photo, card type, and card number). NDC does not share additional information with retailers or venues without your explicit consent.

If you chose the optional emergency contact QR code, anyone who scans the code on your card can obtain the phone number you provided. Only the number is encoded, never your contact’s name.

Because the code is printed on the card itself (so that it works in an emergency without any data connection), it cannot be changed or removed once the card has been produced; if the number needs updating or removing, a replacement card must be ordered, and a fee may be charged for this service. If you are an emergency contact and want a number taken out of use, contact us using the details in Section 14: we will remove your details from our records where you ask, and email the cardholder to ask them to order a replacement card.

Where a retailer or venue contacts us to confirm that a card is current and valid, we will confirm only the validity of the card. We do not share your underlying evidence or any further detail.

What we don't do

We do not sell your personal information. We do not share it for third-party marketing.

7. International transfers

NDC is based in the UK and most of our processing happens in the UK.

Some of our service providers (for example Stripe and Mailchimp) are based in the United States or store data in the United States. Where we transfer your information outside the UK, we rely on appropriate safeguards under UK GDPR, including:

• The UK Extension to the EU-US Data Privacy Framework.

• The UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses.

• UK adequacy regulations where they apply.

You can request a copy of the relevant safeguard from us.

8. How long we keep your information

We keep your information only as long as we need to. The detail is in our Records Retention Schedule, but the headline periods for cardholder data are:

• Active cardholder profile (name, date of birth, contact details, carer self-declaration, photo): while you have a current card, plus a 12-month grace period after a card has expired without renewal.

• Any additional evidence or information we request to check an application: 3 months after your card is printed, so that we can deal with any printing errors and issue reprints where needed; it is then deleted.

• Signed cardholder declaration and verification log: 6 years.

• Renewal history: 6 years from your final card expiry without renewal.

• Declined applications: 12 months.

• Payment metadata (date, amount, Stripe reference, never your full card number): 6 years.

• Cardholder support correspondence (non-complaint): 3 years from last interaction.

• Complaints and disputes: 6 years from resolution.

• Marketing-only contact (opted in but rest of profile deleted): while consent stands and you remain engaged; reviewed at 2 years of no engagement.

• Suppression list (so we don't accidentally re-email people who unsubscribed): 5 years.

• Location data from the mobile app: processed only transiently to run your nearby search; never stored on our servers or your device once the search is complete.

• Deceased cardholder records: anonymised within 6 months of confirmed notification.

At the end of these periods we securely delete the data, or anonymise it so that you can no longer be identified.

9. Your rights

You have the following rights in relation to your personal information under UK GDPR. We will respond to any request within one month of receiving it. For complex or multiple requests we may extend this by up to two further months, and we will tell you within the first month if so; the period may also pause while we verify your identity or clarify your request.

• Right of access — ask for a copy of the personal information we hold about you.

• Right to rectification — correct any information that is wrong or incomplete.

• Right to erasure — ask us to delete your information, in certain circumstances.

• Right to restrict processing — in certain circumstances.

• Right to object to processing based on legitimate interests — in certain circumstances.

• Right to data portability — receive a copy in a structured, machine-readable format.

• Right to withdraw consent where we rely on your consent (for example, for marketing emails).

• Right to object to direct marketing at any time.

• Right to complain to the Information Commissioner’s Office (ico.org.uk), the UK’s data protection regulator, at any time.

• Right to ask us to take another look at any decision we make about you. Any decision to decline an application is reviewed by a person on our team and is not made by automated processing alone; if you would like someone else to take a fresh look at any decision, just ask.

To exercise any of these rights, email us or write to us using the contact details in Section 14.

10. Marketing

Service messages

We send service messages without needing your marketing consent. These include renewal reminders, account-related updates, replies to your enquiries, and important changes to our service.

Marketing emails

We send marketing emails under the PECR 2003 soft opt-in: when you apply for or buy something from us, the application form gives you a clear chance to say no to marketing at the time, and every email we send includes an unsubscribe link. We also send them where you have separately opted in to hear from us. Every marketing email contains an unsubscribe link.

11. Cookies

Our website uses cookies. Cookies are small text files stored on your device that help our website work, remember your preferences, and help us understand how visitors use the site.

We use the following categories of cookie: strictly necessary, analytical/performance, functionality, and targeting/advertising. Non-essential cookies are only set if you give consent (via the cookie banner). You can change your preferences at any time. For a full list of cookies used, see our separate Cookie Notice.

12. Keeping your information secure

We take security seriously. Our measures include strong authentication, multi-factor authentication where available, encryption in transit and at rest, restricted access, a documented incident-response process, and regular review of our security practices.

If you spot something that looks wrong, please tell us immediately at info@disabilityid.co.uk.

13. Changes to this notice

We review this notice at least once a year and whenever there is a material change in how we process your information. The current version is published on nationalcarerscard.org.uk. We will tell you about significant changes by email.

Version: August 2026.

14. Contact and complaints

Contact

• General queries: info@disabilityid.co.uk

• Day-to-day data protection contact: Dianne Taylor, at the Woodbridge office.

• Data Protection Lead: contact via info@disabilityid.co.uk.

• Post: 15a Deben Mill Business Centre, Old Maltings Approach, Melton, Woodbridge, England, IP12 1BL.

Complaints

If you are not happy with how we handle your information, please tell us first so we can try to put things right. You have a legal right to complain to us about how we handle your personal information, by any of the contact routes above or any other reasonable means; we will acknowledge your complaint within 30 days and respond without undue delay.

Governing law: this notice is governed by the laws of England and Wales.

Open Doors with the National Carers Card

Secure, easy to carry visual ID, designed exclusively by and for carers.