Back to Compliance

DPIA Support Statement

CareLedgerPro

Version 1.1 — Last updated: 19 July 2026

This page provides reference information intended to help Controllers complete a Data Protection Impact Assessment (DPIA) when adopting CareLedgerPro. It is not a DPIA in itself and does not remove the Controller's obligation to carry out and document their own DPIA where required under UK GDPR Article 35.

1. What CareLedgerPro is

CareLedgerPro is financial-safeguarding software for regulated care providers. It is not accounting software. It helps care services record, track, reconcile, and audit client money, petty cash, deposits, spending plans, and related financial activity.

The care provider using CareLedgerPro is the data controller. CareLedgerPro acts as a data processor and processes personal data only on the controller’s documented instructions.

2. Personal data processed

CareLedgerPro may process the following categories of personal data:

CategoryExamples
Service-user identity dataFull name, group or care-unit assignment, date of birth where recorded
Financial recordsClient balances, transactions, deposits, petty-cash spends, receipts, spending-plan limits
Staff account dataName, email address, role, house/client assignments
Audit and access logsWho accessed or changed a record, when, and from where
Communications and signaturesNotes, messages, consent records, electronic signatures where captured
Care-related contextInformation relating to capacity, safeguarding, or care arrangements, depending on how the controller uses the platform

Special-category data may be processed where the controller records it. Additional safeguards are applied appropriate to the risk.

3. Purpose of processing

Personal data is processed to:

  • record and track client money and financial transactions
  • manage petty cash and house-level funds
  • provide audit trails for financial safeguarding
  • support spending plans and budget controls
  • generate reports for oversight, inspection, and reconciliation
  • facilitate staff access based on role and assignment
  • send transactional notifications, such as daily alerts, invites, and breach alerts

CareLedgerPro does not use personal data for advertising, analytics, or profiling.

4. Data storage location

Primary data is stored in a managed PostgreSQL database hosted in EU/UK regions.

Static assets and backups are held by the underlying infrastructure provider in the same regions where possible. Controllers may request further information about the hosting region for a specific deployment.

5. Sub-processors

Sub-processorPurposeData processed
SupabaseManaged database, authentication, file storageController-supplied data including financial records, staff accounts, receipts, and audit logs
CloudflareEdge hosting, CDN, DNS, WAF, TLSRequest metadata and encrypted traffic
ResendTransactional email deliveryRecipient email address, message content, delivery metadata
StripeSubscription billingBilling contact details and subscription metadata. Card data is handled directly by Stripe.

A current list is maintained at: /subprocessors

6. Access control and permissions

Access is controlled through role-based permissions. Default roles include admin, manager, and staff.

Users can only access clients, groups, and records they are explicitly assigned to, unless they hold an admin or manager role. All access and modifications are recorded in append-only audit logs.

Authentication is handled through secure password-based sign-in with leaked-password protection.

7. Encryption and security

CareLedgerPro uses the following security measures:

  • encryption in transit using TLS 1.2+
  • encryption at rest through managed database encryption
  • role-based access control with least-privilege permissions
  • append-only audit logging for all data access and changes
  • secure authentication with leaked-password detection
  • web application firewall and DDoS protection at the edge
  • regular monitoring for suspicious activity

Further detail is available at: /security

8. Backup and recovery

Automated backups are maintained by the managed database provider.

Backups are encrypted and retained according to the provider’s standard schedule. Recovery procedures are in place to restore service availability in the event of data loss or infrastructure failure.

Backups are not routinely used to reintroduce deleted personal data.

9. Deletion and retention

Personal data is retained only for as long as necessary to provide the Service or as instructed by the controller.

Standard retention periods apply to financial and care records, typically 7 years or duration of care plus 8 years depending on record type.

Controllers can export data before deletion. Deletion requests are authenticated and processed through an irreversible purge process.

Further detail is available at: /data-retention and /data-deletion

10. Breach notification and incident response

CareLedgerPro will notify the controller without undue delay after becoming aware of a personal data breach.

The incident response process includes detection, triage, containment, eradication, notification, and review. Severity levels define response times, for example SEV-1 acknowledgement within 30 minutes.

The Data Protection Officer is involved where notification to the ICO or data subjects may be required.

Full plan available at: /incident-response

11. International transfers

Personal data is primarily hosted on infrastructure designed to support UK data protection requirements.

Where any transfer outside the UK occurs, appropriate safeguards are applied, including:

  • UK International Data Transfer Addendum
  • Standard Contractual Clauses where relevant
  • additional technical and organisational measures where required

12. Automated decision-making and profiling

CareLedgerPro does not perform automated decision-making or profiling that produces legal or similarly significant effects on individuals.

Some features provide automated alerts, for example spending-plan thresholds or low-balance warnings, but these are advisory and do not make decisions on behalf of the controller.

13. How to use this pack

This summary is designed to be inserted directly into a customer DPIA template or linked from compliance pages. For the full policies, direct customers to:

Contact

For DPIA-related questions or a signed Data Processing Agreement, contact: support@careledgerpro.co.uk

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.