DPIA Support Statement
CareLedgerPro
Version 1.1 — Last updated: 19 July 2026
This page provides reference information intended to help Controllers complete a Data Protection Impact Assessment (DPIA) when adopting CareLedgerPro. It is not a DPIA in itself and does not remove the Controller's obligation to carry out and document their own DPIA where required under UK GDPR Article 35.
1. What CareLedgerPro is
CareLedgerPro is financial-safeguarding software for regulated care providers. It is not accounting software. It helps care services record, track, reconcile, and audit client money, petty cash, deposits, spending plans, and related financial activity.
The care provider using CareLedgerPro is the data controller. CareLedgerPro acts as a data processor and processes personal data only on the controller’s documented instructions.
2. Personal data processed
CareLedgerPro may process the following categories of personal data:
| Category | Examples |
|---|---|
| Service-user identity data | Full name, group or care-unit assignment, date of birth where recorded |
| Financial records | Client balances, transactions, deposits, petty-cash spends, receipts, spending-plan limits |
| Staff account data | Name, email address, role, house/client assignments |
| Audit and access logs | Who accessed or changed a record, when, and from where |
| Communications and signatures | Notes, messages, consent records, electronic signatures where captured |
| Care-related context | Information relating to capacity, safeguarding, or care arrangements, depending on how the controller uses the platform |
Special-category data may be processed where the controller records it. Additional safeguards are applied appropriate to the risk.
3. Purpose of processing
Personal data is processed to:
- record and track client money and financial transactions
- manage petty cash and house-level funds
- provide audit trails for financial safeguarding
- support spending plans and budget controls
- generate reports for oversight, inspection, and reconciliation
- facilitate staff access based on role and assignment
- send transactional notifications, such as daily alerts, invites, and breach alerts
CareLedgerPro does not use personal data for advertising, analytics, or profiling.
4. Data storage location
Primary data is stored in a managed PostgreSQL database hosted in EU/UK regions.
Static assets and backups are held by the underlying infrastructure provider in the same regions where possible. Controllers may request further information about the hosting region for a specific deployment.
5. Sub-processors
| Sub-processor | Purpose | Data processed |
|---|---|---|
| Supabase | Managed database, authentication, file storage | Controller-supplied data including financial records, staff accounts, receipts, and audit logs |
| Cloudflare | Edge hosting, CDN, DNS, WAF, TLS | Request metadata and encrypted traffic |
| Resend | Transactional email delivery | Recipient email address, message content, delivery metadata |
| Stripe | Subscription billing | Billing contact details and subscription metadata. Card data is handled directly by Stripe. |
A current list is maintained at: /subprocessors
6. Access control and permissions
Access is controlled through role-based permissions. Default roles include admin, manager, and staff.
Users can only access clients, groups, and records they are explicitly assigned to, unless they hold an admin or manager role. All access and modifications are recorded in append-only audit logs.
Authentication is handled through secure password-based sign-in with leaked-password protection.
7. Encryption and security
CareLedgerPro uses the following security measures:
- encryption in transit using TLS 1.2+
- encryption at rest through managed database encryption
- role-based access control with least-privilege permissions
- append-only audit logging for all data access and changes
- secure authentication with leaked-password detection
- web application firewall and DDoS protection at the edge
- regular monitoring for suspicious activity
Further detail is available at: /security
8. Backup and recovery
Automated backups are maintained by the managed database provider.
Backups are encrypted and retained according to the provider’s standard schedule. Recovery procedures are in place to restore service availability in the event of data loss or infrastructure failure.
Backups are not routinely used to reintroduce deleted personal data.
9. Deletion and retention
Personal data is retained only for as long as necessary to provide the Service or as instructed by the controller.
Standard retention periods apply to financial and care records, typically 7 years or duration of care plus 8 years depending on record type.
Controllers can export data before deletion. Deletion requests are authenticated and processed through an irreversible purge process.
Further detail is available at: /data-retention and /data-deletion
10. Breach notification and incident response
CareLedgerPro will notify the controller without undue delay after becoming aware of a personal data breach.
The incident response process includes detection, triage, containment, eradication, notification, and review. Severity levels define response times, for example SEV-1 acknowledgement within 30 minutes.
The Data Protection Officer is involved where notification to the ICO or data subjects may be required.
Full plan available at: /incident-response
11. International transfers
Personal data is primarily hosted on infrastructure designed to support UK data protection requirements.
Where any transfer outside the UK occurs, appropriate safeguards are applied, including:
- UK International Data Transfer Addendum
- Standard Contractual Clauses where relevant
- additional technical and organisational measures where required
12. Automated decision-making and profiling
CareLedgerPro does not perform automated decision-making or profiling that produces legal or similarly significant effects on individuals.
Some features provide automated alerts, for example spending-plan thresholds or low-balance warnings, but these are advisory and do not make decisions on behalf of the controller.
13. How to use this pack
This summary is designed to be inserted directly into a customer DPIA template or linked from compliance pages. For the full policies, direct customers to:
Contact
For DPIA-related questions or a signed Data Processing Agreement, contact: support@careledgerpro.co.uk
Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.