Compliance
How CareLedgerPro helps CQC‑regulated providers meet their legal and regulatory duties when handling the personal money of vulnerable adults.
Version 1.2 — Last reviewed: June 2026
Compliance statement
CareLedgerPro is a staff-facing client-money and petty-cash ledger designed to help CQC-registered providers evidence safe handling of the personal money of the people they support. It is not a certification, an inspection outcome, or legal advice, and it is not independently audited against ISO 27001, SOC 2, Cyber Essentials, or DSPT.
CareLedgerPro operates as a data processor. The registered provider remains the data controller and is responsible for lawful basis, staff training, safeguarding procedures, ICO registration and internal operational policies. CareLedgerPro processes personal data strictly under the controller's documented lawful basis and provides technical, organisational and record-keeping features intended to support compliance.
The application provides controls designed to support the CQC Fundamental Standards, UK GDPR, the Data Protection Act 2018, the Mental Capacity Act 2005 and financial-safeguarding expectations through enforced workflows, an append-only audit log and secure data-handling practices. These include encryption in transit and at rest (via our hosting sub-processor), role-based access with row-level security, mandatory receipts above configurable thresholds, two-person verification, weekly reconciliation sign-off, capacity-aware signatures and exportable audit logs for internal review.
The platform provides a structured audit trail for all financial activity, including transaction histories, receipt evidence, discrepancy flags, corrections with full before/after visibility, and timestamped managerial sign‑off. Every access and change is recorded against the responsible user, supporting accountability and inspection readiness. Spending made on behalf of individuals lacking capacity is recorded with the authoriser, rationale and supporting evidence, aligning with best‑interests decision‑making under the Mental Capacity Act.
CareLedgerPro maintains GDPR‑aligned data‑protection practices, including documented retention schedules, deletion procedures, breach‑response workflows, sub‑processor governance, password breach‑checking and managed hosting in UK/EU‑aligned regions. Subject‑access, rectification and erasure requests are handled by the controller’s Data Protection Officer, whose contact details are published for data‑subject queries and ICO correspondence.
CareLedgerPro aims to meet WCAG 2.2 AA where reasonably practicable and provides structured, exportable records designed to help providers prepare evidence for internal audit and CQC inspections. Full policy documents — including the Data Processing Agreement, Record of Processing Activities, Sub‑processor List, Data Retention Policy, Data Deletion Policy, Incident Response Plan and Security Overview — are available for auditors, buyers and the provider's DPO.
This Compliance Statement summarises how CareLedgerPro supports regulatory alignment. It is not legal advice. The registered provider remains responsible for its own lawful basis, policies, staff training, safeguarding procedures and regulatory obligations.
DSPT Alignment
CareLedgerPro is designed to support regulated care providers with the controls and evidence commonly needed for their own NHS Data Security and Protection Toolkit (DSPT) work. It supports role-based access, audit logging, encryption, backups, incident response, retention, deletion, and supplier governance, but it does not replace the provider’s own DSPT responsibilities or submission.
Policy documents
Detailed versions of each policy are available for audits, buyers and regulators:
- Data Processing Agreement
- Record of Processing Activities
- Sub‑processor List
- Data Retention Policy
- Data Deletion Policy
- Incident Response Plan
- Testing Schedule
- Security Overview
- DPIA Support Pack
- Data Protection Impact Assessment (full)
- Processor & Article 28 Statement
- Backup & Disaster Recovery
- Fraud Prevention & Staff Accountability
- DSPT Support Summary
- Accessibility Statement
- Billing Terms
- Refund Policy
Data protection — UK GDPR & DPA 2018
CareLedgerPro acts as a data processor. The registered provider remains the data controller and is responsible for lawful basis, staff training, safeguarding and operational policies.
- Lawful basis — controllers typically rely on legal obligation, public task or legitimate interests. CareLedgerPro processes data strictly under the controller’s documented lawful basis.
- Special‑category data — where financial records relate to care plans or capacity decisions, they may constitute special‑category data. CareLedgerPro supports this through encryption, role‑based access, audit logging and separation of duties.
- Privacy notice and cookies — a published privacy notice explains lawful basis, special‑category handling and cookie use. Only essential cookies are used; no advertising or third‑party tracking.
- Data‑subject rights — subject‑access, rectification and erasure requests are handled by the controller’s Data Protection Officer (DPO). CareLedgerPro does not process rights requests directly.
- Password security — passwords are checked against Have I Been Pwned to block sign-ups and password changes using known-leaked credentials.
Security & encryption
- TLS encryption in transit; encryption at rest for all data.
- Automated backups with point‑in‑time recovery.
- Documented disaster‑recovery process.
- Secrets stored in managed secret storage.
- No anonymous sign‑ups; access controlled by the controller.
- Full technical details are available in the Security Overview.
Financial safeguarding — CQC fundamental standards
CareLedgerPro supports safe handling of service‑user money through:
- Two‑person verification above configurable thresholds.
- Mandatory receipts above configurable thresholds.
- Append-only audit trail — transactions can be voided with a reason but never silently deleted.
- Per‑client and per‑group balances.
- Petty‑cash floats with discrepancy and low‑cash alerts.
- Exportable audit logs for safeguarding investigations.
- Controllers remain responsible for safeguarding escalation and internal financial policies.
Access & accountability
- Role‑based access; staff only see assigned service users.
- Staff cannot grant their own roles.
- Session timeout and re‑authentication for sensitive actions.
- Every access and change recorded against the responsible user.
- Administrators must review access regularly and revoke unused accounts.
Staff training & data‑subject requests
- Staff receive data‑protection and safeguarding training before handling service‑user money.
- Subject‑access, rectification and erasure requests answered within one month (extendable for complex cases).
- All requests routed to the DPO and logged for accountability.
Complaints & escalation
Service users, families and representatives can raise concerns about financial handling. Concerns may be raised with the registered provider or the DPO.
- If unresolved, individuals may complain directly to the ICO.
- Complaints and outcomes are recorded for learning and improvement.
Sub‑processors & third parties
- Cloud hosting and database in UK/EU‑aligned regions.
- Transactional email provider.
- PCI‑DSS‑compliant payment processor.
- All sub-processors are engaged under agreements designed to support UK GDPR obligations.
- See the current Sub‑processor List.
Incident response & breach notification
CareLedgerPro provides a breach-response workflow designed to support UK GDPR and CQC expectations:
- Detect and log.
- Contain.
- Triage and assess.
- Notify ICO within 72 hours if reportable.
- Record rationale for any delay.
- Inform affected individuals where high risk exists.
- Close and review.
- Export full CSV evidence for ICO, CQC or internal audits.
- Controllers remain responsible for notifying local authorities, safeguarding teams and families where required.
- Read the full Incident Response Plan.
Data Protection Officer (DPO)
The following contact details are published for data‑subject queries, ICO correspondence and breach reporting:
- Name — Natasha Dhliwayo
- Email — Natasha@litaniahealthcareps.com
- Available for subject‑access, rectification, erasure, restriction, portability and objection requests.
Mental Capacity Act 2005
Where spending is made on a person’s behalf, CareLedgerPro records who authorised the purchase, the reason for the decision and supporting evidence. This supports best‑interests decision‑making and provides an accountable trail.
Data retention & deletion
Retention periods follow legal, regulatory and operational requirements:
- Financial records: 7 years.
- Care‑related records: duration of active support + 8 years.
- Audit logs and security‑incident records: 7 years.
- Full schedules are in the Data Retention Policy.
- Deletion procedures are in the Data Deletion Policy.
Hosting & business continuity
- UK/EU‑aligned hosting regions.
- Automated backups with point‑in‑time recovery.
- Documented disaster‑recovery process.
- High‑availability infrastructure.
- Backups and replicas kept in‑region unless business‑continuity requires otherwise.
- Controllers must maintain their own business‑continuity plans.
Accessibility
CareLedgerPro aims to meet WCAG 2.2 AA where reasonably practicable. We have not yet completed an independent accessibility audit.
ICO registration
As the data controller, the registered provider must hold a valid ICO registration and pay the applicable data‑protection fee.
Inspection & record‑keeping
Records are structured for accessible review and export, enabling providers to evidence safe financial management during CQC inspection.
Disclaimer — This page summarises features that support compliance. It is not legal advice. The registered provider remains the data controller and is responsible for its own policies, lawful basis, staff training, safeguarding and regulatory obligations.
Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.