Best-You
Best-You is an evidence-based digital health and wellbeing service offering free, user-friendly self-care support alongside an optional CRM and case management system. It combines behavioural science, peer support and digital tools to improve population wellbeing, resilience and health outcomes while reducing demand on services.
Features
- Web and app based digital wellbeing platform accessible anytime anywhere
- Integrated lifestyle tracking across weight activity smoking alcohol eating journeys
- Personalised goal setting reminders notifications supporting sustained behaviour change outcomes
- Peer support groups and friends features enabling collaboration motivation accountability
- Service locator integration with NHS and trusted local services
- CRM case management system enabling referrals caseload tracking hybrid coaching
- Secure remote access for coaches via web browser based interface
- Real time population level reporting outcomes dashboards management information insights
- Virtual chat messaging between clients and coaches for ongoing support
- Anonymous data collection supporting service planning prevention and demand reduction
Benefits
- Manage multiple lifestyle services within one integrated system
- Reduce manual administration through automated referrals and caseload management
- Support clients remotely using hybrid digital and coach led approaches
- Track progress and outcomes in real time across populations
- Make informed decisions using live dashboards and management reports
- Improve user engagement through personalised goals reminders and peer support
- Enable seamless collaboration between providers teams and coaches
- Deliver consistent evidence based interventions at scale efficiently
- Support prevention focused care reducing demand on frontline services
- Increase service reach without increasing workforce or infrastructure costs
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 6 1 6 3 2 0 2 7 5 1 4 5 8 9
Contact
ICE CREATES LIMITED
Stuart Jackson
Telephone: 07970 226640
Email: tenders@icecreates.com
About your service
- Service categories
-
Applications
Customer relationship management
- Customer service
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- Requires internet connectivity for full app and web functionality. Mobile device compatibility. Initial setup and personalisation
- System requirements
-
- Modern browser / modern device
- Stable broadband internet connection with minimum 5 Mbps download speed.
- IOS 14+ or Android 10+ for full mobile app compatibility.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Monday to Friday: Initial response within 1 working day.
Weekends and public holidays: Queries acknowledged next working day.
Response times may vary depending on issue complexity and contracted support level. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Screen reader device testing and automated accessibility testing.
- Onsite support
- No
- Support levels
-
Standard Support (included)
Email and helpdesk support during business hours (Monday–Friday).
Access to user guides, training materials and knowledge base.
Initial response within one working day.
Cost: Included within the service licence.
Enhanced Support (optional, paid)
Priority response times and extended support hours.
Telephone and email support for operational and technical issues.
Support for configuration, reporting and service optimisation.
Cost: Priced separately depending on scope and contract.
Technical account management
A dedicated Technical Account Manager or support engineer can be provided for commissioned deployments.
Ongoing relationship management, escalation handling and service reviews.
Cost: Available as an add-on within enhanced support agreements. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
ICE Creates supports users to start using the Best-You service through a structured, supported onboarding and implementation approach designed to ensure confident and effective adoption.
During implementation, administrators, coaches and delivery teams are provided with online training sessions tailored to their role. These sessions cover system setup, day-to-day use of the platform, case management, reporting and good practice. Training can be delivered virtually and, where required, onsite workshops can also be arranged to support larger or more complex deployments.
Comprehensive user documentation is provided, including user guides, manuals and step-by-step instructions to support both professional users and end users. These materials are available digitally and can be revisited at any time.
ICE Creates also provides access to a helpdesk and technical support team to answer questions, resolve issues and provide ongoing assistance after go-live. For commissioned services, onboarding may include configuration support, data setup and integration guidance to ensure the service is aligned to local requirements.
This combination of training, documentation and ongoing support ensures users can quickly understand, adopt and maximise the value of the Best-You service. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Online help articles
- User guides
- End-of-contract data extraction
-
When a contract ends, users are supported through a structured and secure data exit process to ensure continuity, transparency and compliance with data protection requirements.
ICE Creates works with the buyer to agree the scope of data to be extracted, the format required and the delivery timescales. Data can include user records, referral and caseload information, activity and outcome data, and reporting outputs. Exports are typically provided in commonly used, open formats such as CSV or Excel to ensure compatibility with other systems.
The data extraction process is carried out securely, with appropriate access controls and encryption applied during transfer. ICE Creates provides guidance and support throughout the process to ensure the buyer can successfully receive, validate and use the exported data.
Once data transfer has been completed and confirmed, ICE Creates securely deletes remaining customer data from the platform in line with agreed retention schedules, contractual obligations and relevant data protection legislation. Backups are also managed in accordance with defined retention policies.
This approach ensures buyers retain access to their data, meet governance and compliance requirements, and experience a clear and well-managed service exit at the end of the contract. - End-of-contract process
-
ICE Creates follows a clear and structured off-boarding process to ensure an orderly and compliant service exit. This includes confirmation of contract end dates, agreement of final activities, and coordination with the buyer to minimise disruption.
As part of the standard contract price, ICE Creates will support an agreed data exit process, including secure export of customer data in commonly used formats (such as CSV or Excel), within agreed timescales. Guidance is provided to help buyers receive and validate their data. Following confirmation of successful data transfer, customer data is securely deleted from live systems in line with contractual terms, data protection legislation and retention policies.
The contract price also includes continued access to the service until the agreed end date, standard support up to contract completion, and secure handling of backups in accordance with defined retention schedules.
Additional costs may apply where buyers request services beyond the standard exit process. This can include bespoke data extracts, complex data transformations, additional reporting, extended access beyond the contract end date, or additional technical or consultancy support to assist migration to another system.
All end-of-contract activities and any associated additional costs are agreed in advance to ensure transparency and clarity for buyers. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The mobile service is designed for end users to support everyday self-care and wellbeing. It enables lifestyle tracking, goal setting, reminders, notifications, peer support, access to content, and in-app chat with coaches, supporting engagement and behaviour change on the move.
The desktop service is primarily for professionals, coaches and administrators. It provides browser-based access to the CRM and case management system, supporting referrals, caseload management, reporting, population insights and service configuration. Desktop access is optimised for more complex administrative and analytical tasks.
Both platforms are fully integrated, ensuring seamless data flow between user activity and professional oversight. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Yes, there is a service interface.
Best-You provides clear user and administrative interfaces:
A mobile and web user interface for individuals accessing the self-care and wellbeing service, designed to be intuitive, accessible and user-friendly.
A browser-based professional interface for coaches and administrators, providing access to the CRM and case management system, including referrals, caseloads, reporting and configuration.
These interfaces act as the primary point of interaction between users, professionals and the Best-You service, with seamless integration between them. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The service interface has been reviewed and tested against recognised accessibility best practice, including WCAG 2.1 guidance. Testing has included internal accessibility checks, use of screen readers, keyboard-only navigation, and contrast and readability testing tools. Feedback from users with accessibility needs has informed iterative improvements to layout, navigation and content clarity, with accessibility considerations embedded into ongoing design and development processes.
- API
- Yes
- What users can and can't do using the API
-
The Best-You API enables integration with external systems to support service setup, data exchange and ongoing management.
What users can do using the API
Set up integrations for referrals, user registration and service access.
Create, update and retrieve user records, referrals and journey status.
Synchronise activity, outcomes and progress data with external systems.
Support reporting and population-level insights through structured data feeds.
How users can make changes through the API
Update user details, referral status and service journey milestones.
Exchange data securely to keep systems aligned in near real time.
API limitations
Core system configuration, workflows and permissions are managed through the platform, not the API.
CRM configuration, reporting setup and customisations require administrative access and cannot be fully controlled via API.
API access and functionality are subject to agreed scope, security controls and contractual arrangements. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
What can be customised
Buyers can customise branding, content, local services, referral pathways, user journeys, reporting outputs and access permissions.
How users can customise
Customisation is completed through configuration settings within the platform, supported by ICE Creates during onboarding and implementation.
Who can customise
Customisation is carried out by authorised administrators and ICE Creates technical teams, based on agreed requirements and governance.
Scaling
- Independence of resources
- ICE Creates ensures users are not affected by demand from other users through a scalable, cloud-based service architecture designed to manage fluctuating usage levels. The platform uses resource monitoring, capacity planning and performance controls to maintain consistent responsiveness and availability. System usage is continuously monitored to identify and address potential bottlenecks before they impact users. Infrastructure can be scaled to meet increased demand, ensuring services remain stable during peak usage periods. This approach helps deliver a reliable experience for all users, prevents performance degradation, and supports secure, uninterrupted access to the service regardless of overall demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides a range of usage and performance metrics to support operational management and reporting. These include user registrations and engagement levels, activity across lifestyle journeys, goal completion and progress tracking, referrals and caseload volumes, and interaction with content and peer support features. For commissioned services, population-level metrics and outcome reporting are available through dashboards and reports, enabling buyers to monitor uptake, measure impact, evidence outcomes, and inform service improvement and strategic planning.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
Encryption of data at rest within secure, third-party cloud infrastructure, with strict access controls and role-based permissions
These measures align with the government’s Asset protection and resilience security principle and ensure data remains secure against unauthorised access. - Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users export their data through an agreed, secure data export process managed by ICE Creates. At contract end, or on request where contractually permitted, ICE Creates works with the buyer to define the data scope, format and timescales. Data is securely extracted from the platform and provided in commonly used, open formats such as CSV or Excel to support reuse and migration. Transfers are completed using secure methods in line with data protection requirements, and support is provided to help users validate and understand the exported data.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Excel-compatible formats such as XLSX
- Data import formats
-
- CSV
- Other
- Other data import formats
- Excel-compatible formats such as XLSX
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Industry standard security controls, including secure cloud infrastructure, access controls and encryption at rest.
Availability and resilience
- Guaranteed availability
-
Best-You is delivered as a cloud-hosted, fully managed service designed to provide high availability and reliability for users across web and mobile platforms. The service is supported by robust infrastructure, daily data backups, monitoring and planned maintenance arrangements, which are typically carried out out of hours with advance notice provided to minimise disruption.
Availability commitments and service levels are defined within the relevant Call Off Contract and associated IT Support Service Levels, rather than a single fixed uptime percentage applying to all customers. These service level agreements (SLAs) set out expected availability, incident prioritisation, response times and resolution targets appropriate to the commissioned service. Hosting, maintenance and support are included within the annual licence fee, ensuring ongoing operational stability throughout the contract term.
In the event that availability falls below the agreed SLA levels, the applicable Call Off Contract sets out the remedies available to the buyer. These may include service credits, service improvement actions or other remedies agreed contractually, rather than automatic financial refunds. Any service issues are managed through the agreed support and escalation processes.
This approach provides buyers with clear, contractually defined availability commitments, transparency around performance, and proportionate remedies aligned to the criticality of the service. - Approach to resilience
-
Best-You is designed as a resilient, cloud-hosted service, aligned with government’s cloud security principle of Asset protection and resilience. The service is delivered using secure, third-party cloud infrastructure designed to support high availability, fault tolerance and rapid recovery from incidents.
Hosted within UK-based datacentres using resilient architecture, including redundant power supplies, networking, storage and environmental controls. This reduces the risk of single points of failure and supports continuity of service in the event of hardware or infrastructure issues. Data is backed up daily and retained in line with defined retention policies, enabling recovery in the event of data loss or system failure.
Application-level resilience is supported through monitoring, capacity management and scalable infrastructure, allowing the service to handle changes in demand without degradation of performance for users. Planned maintenance is carried out out of hours wherever possible, with advance notice provided to minimise disruption.
Operational resilience is further supported by incident management processes, defined support response times and clear escalation routes. Security controls, access management and data protection measures help ensure the integrity and availability of customer data.
Technical details of the datacentre and infrastructure resilience arrangements can be available on request, subject to appropriate confidentiality and security considerations. - Outage reporting
-
Best-You uses a structured approach to outage detection and reporting to ensure transparency and timely communication with users and buyers. Service availability and performance are continuously monitored, allowing potential issues or outages to be identified quickly and assessed by the support team.
When an outage or significant service disruption is confirmed, affected customers are notified through direct communication channels, primarily email alerts to nominated contacts. These notifications include information on the nature of the issue, affected services, and expected next steps. Updates are provided at appropriate intervals until the issue is resolved.
Outage information is also managed through internal service management and incident tracking processes, ensuring issues are logged, prioritised and escalated in line with agreed support levels and SLAs. Where required, incident summaries and post-incident reports can be shared with buyers to support transparency and service improvement.
At present, the service does not provide a publicly accessible outage dashboard or a dedicated outage reporting API. However, outage status and performance information can be included within regular service reports or provided as part of contract management and governance meetings.
This approach ensures buyers receive clear, timely and proportionate communication about service outages while maintaining appropriate security and operational controls.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Username or password
- Other
- Other user authentication
- Role-based access controls and secure session management. Multi factor authentication, public key authentication, identity federation, government network access, and dedicated network links are NOT used as standard.
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access controls and the principle of least privilege. Only authorised users are granted access to administrative and management functions based on their role and responsibilities. User accounts are individually assigned and protected through secure authentication mechanisms. Access rights are reviewed regularly and updated when roles change or staff leave. Support channels are limited to authorised customer contacts, and sensitive actions require additional verification. These controls help ensure that only approved users can access management features and support functions, protecting system integrity and customer data.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Username or password
- Other
- Description of management access authentication
- Role-based access controls and restricted administrative permissions. Multi factor authentication, public key authentication, identity federation, government network access, and dedicated network links are NOT used as standard.
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
ICE follows a defined set of information security policies and processes aligned with recognised best practice and data protection legislation. These policies cover information governance, access control, data protection, incident management, business continuity, secure system development and operation.
Security responsibilities are clearly defined within the organisation, with senior management accountable for information security oversight and operational teams responsible for day-to-day compliance. Information security forms part of organisational governance and is reviewed regularly to ensure continued effectiveness and alignment with regulatory and contractual requirements.
Processes are in place to ensure policies are followed, including role-based access controls, staff confidentiality obligations, secure onboarding and offboarding procedures, and the use of technical and organisational security measures appropriate to the sensitivity of the data being processed. Third-party suppliers and hosting providers are subject to assurance and contractual security requirements.
Compliance is supported through monitoring, incident logging, regular reviews, and external testing such as penetration testing. Security incidents are managed through defined incident response procedures, with escalation, investigation and reporting to customers and regulators where required.
Staff receive appropriate awareness and training, policies are reviewed and updated to reflect changes in risk, technology and legal requirements, ensuring a consistent and accountable approach to information security. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- ICE follows defined configuration and change management processes to ensure service stability and security. Service components are tracked throughout their lifecycle using controlled configuration records, version control and documented environments. Changes are requested, reviewed and approved through a structured process, ensuring clear accountability and traceability. All proposed changes are assessed for potential security, performance and operational impacts before implementation. Where relevant, changes are tested in controlled environments prior to release. Security considerations, including data protection and access controls, form part of the change assessment to ensure risks are identified and mitigated before deployment.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- ICE operates a defined vulnerability management process to protect the Best-You service. Potential threats are assessed through regular security reviews, monitoring of system components, and external penetration testing. Information about vulnerabilities is obtained from trusted sources, including cloud service providers, security advisories, and industry best practice guidance. Identified vulnerabilities are prioritised based on risk and potential impact. Security patches and updates are applied in a timely manner, with critical fixes deployed as soon as practicable and lower-risk updates scheduled into planned maintenance windows. This approach helps maintain service security and resilience.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- ICE uses protective monitoring to identify and respond to potential security incidents. Monitoring includes logging, alerting and review of system activity to detect unusual behaviour or potential compromise. Alerts are assessed promptly by the support team and escalated where required. When a potential compromise is identified, incident response procedures are followed, including investigation, containment, remediation and notification in line with contractual and regulatory requirements. Incidents are prioritised based on severity, with critical incidents responded to immediately and other incidents managed within agreed support response times.
- Incident management type
- Supplier-defined controls
- Incident management approach
- ICE follows a defined incident management process to ensure timely and effective handling of service issues and security incidents. Pre-defined procedures exist for common events, such as service outages, security alerts and data incidents, enabling consistent and controlled responses. Users report incidents through the service helpdesk or designated support contact points. Incidents are logged, assessed and prioritised based on severity and impact. Updates are provided during resolution, and incident reports or summaries can be shared with customers following resolution, in line with contractual and governance requirements.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0.25%
- Between £250,000 and £500,000
- 0.5%
- Between £500,001 and £1,000,000
- 0.75%
- Between £1,000,001 and £2,500,000
- 1%
- Between £2,500,001 and £5,000,000
- 1%
- Over £5,000,001
- 1%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- CQS
- ISO/IEC 27001 accreditation date
- Wednesday 10 December 2025
- What the ISO/IEC 27001 doesn’t cover
-
The ISO/IEC 27001:2022 certification does not cover activities or services outside the delivery of Social and Organisational Change, Branding and Design, Digital Media and Strategic Communications.
This includes any unrelated internal business functions or external third-party services that are not governed by our Information Security Management System. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- CQS
- ISO 9001 accreditation date
- Wednesday 17 December 2025
- What the ISO 9001 doesn’t cover
-
The ISO 9001 certification covers the Quality Management System for the provision of services related to Social and Organisational Change, Branding and Design, Digital Media and Strategic Communications.
It does not cover activities, services, or processes that sit outside this scope, including any unrelated internal operations or external services that are not part of the delivery of these services. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
- Data Protection Tool Kit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-