Data Processing & GDPR
Last updated: 18 July 2026
1. Controller and Processor Roles
Under UK GDPR and the Data Protection Act 2018, the care provider using CareLedgerPro is the data controller and decides why and how personal data is processed. CareLedgerPro acts as the data processor and processes personal data only on the controller's documented instructions. We do not determine the purposes of processing.
The security measures described here are implemented in part by CareLedgerPro and in part by our sub-processors (hosting, authentication, payments, email). CareLedgerPro is not independently certified against ISO 27001, SOC 2, Cyber Essentials, or DSPT. Controllers who require certified processors should assess this before adopting the Service.
2. Scope of Processing
CareLedgerPro processes the following categories of personal data on behalf of the controller:
- Service user identity details and the groups or units they belong to.
- Financial records, including balances, transactions, petty cash, receipts, and signatures.
- Staff account details, roles, and access assignments.
- Audit logs recording who accessed or changed records and when.
Some records may include information relating to health, capacity, or care arrangements, depending on how the Service is used. Where special category data is processed, we apply additional safeguards appropriate to the risk.
3. Sub-Processors
We use carefully selected sub-processors to help provide the Service, including managed cloud hosting, infrastructure providers, authentication services, and secure communication tools. Each sub-processor is subject to written contractual obligations designed to protect personal data and meet UK GDPR requirements.
Where we intend to add or replace a sub-processor, we will give controllers notice where reasonably practicable. Controllers may raise a justified objection where the change creates a material data-protection concern.
A current list of sub-processors is available on the Sub-Processor page.
4. Confidentiality
All persons authorised to process personal data on behalf of CareLedgerPro are subject to confidentiality obligations. This includes our staff and any sub-processors where relevant. Appropriate training is provided in line with each person's role and level of access.
5. Security Measures
CareLedgerPro implements appropriate technical and organisational measures to protect personal data, including:
- encryption in transit and at rest;
- role-based access control;
- append-only audit logging;
- secure authentication and leaked-password protection;
- monitoring for suspicious activity.
Further information is available on the Security page.
6. International Transfers
Personal data is primarily hosted on managed infrastructure designed to support UK data protection requirements. Where any transfer of personal data outside the UK takes place, we use appropriate safeguards, which may include:
- the UK International Data Transfer Addendum;
- Standard Contractual Clauses where relevant; and
- additional technical and organisational measures where required.
Controllers may request further information about the transfer mechanism used for a particular service or sub-processor.
7. Assistance to the Controller
Where reasonably possible, CareLedgerPro will assist controllers with:
- responding to data subject requests;
- meeting obligations under Articles 32 to 36 UK GDPR;
- carrying out Data Protection Impact Assessments (DPIAs); and
- consulting the supervisory authority where required.
8. Retention and Deletion
CareLedgerPro retains personal data only for as long as necessary to provide the Service, or as instructed by the controller, subject to any legal obligations to retain information for longer.
When the Service ends:
- controllers may export their data in the available formats;
- data will be deleted or returned in line with the agreed retention and deletion arrangements; and
- any continued retention will only occur where required by UK law or an agreed legal basis.
9. Data Subject Rights
The controller is responsible for handling data subject requests. CareLedgerPro will assist controllers, where reasonably possible, in responding to requests to:
- access personal data;
- rectify inaccurate data;
- erase data, subject to legal retention requirements;
- restrict processing; and
- object to processing where applicable.
10. Personal Data Breaches
CareLedgerPro will notify the controller without undue delay after becoming aware of a personal data breach affecting the controller's data. Where reasonably possible, we will assist the controller with:
- investigating the breach;
- assessing risk;
- preparing notifications to the ICO; and
- communicating with affected individuals where required.
11. Instructions and Compliance
CareLedgerPro processes personal data only on the controller's documented instructions. If we believe an instruction is unlawful, we will notify the controller without undue delay.
12. Data Processing Agreement
Controllers that require a signed Data Processing Agreement should read the Data Processing Agreement page or contact CareLedgerPro. Further information is available in the Privacy Notice, Security, and Compliance pages.
Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.