Back to Compliance

Processor and Article 28 Statement

Hosting, database, authentication and storage sub-processor

Version 1.0 — Last updated: 6 August 2026

Care providers act as Controller. CareLedgerPro acts as Processor. The managed platform that provides the database, authentication and file storage underneath CareLedgerPro acts as a sub-processor. This page documents that relationship so it can be attached to a Controller's own records without further enquiry.

1. Who the sub-processor is and what it does

The database, authentication and object-storage layer of CareLedgerPro is delivered by Supabase (Supabase, Inc.), a managed PostgreSQL platform. It hosts the tables that hold service-user financial records, staff accounts and roles, audit logs, receipt images and communication attachments.

It is engaged for infrastructure only. It does not analyse, profile, market from, or otherwise make independent use of Controller data. It is listed with purpose, data categories and safeguards on the sub-processors page.

2. Contractual basis

CareLedgerPro's use of the platform is governed by the provider's terms of service and Data Processing Addendum, which incorporate the Article 28(3) obligations and, where relevant, the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum.

The obligations CareLedgerPro accepts towards Controllers in its Data Processing Agreement are flowed down to this sub-processor as required by Article 28(4).

3. Article 28(3) mapping

ClauseRequirementPosition
28(3)(a)Process only on documented instructions, including on transfers.The provider processes data only as instructed through the platform's configuration and API calls. No independent use of Controller data for its own purposes is permitted under its data processing addendum.
28(3)(b)Confidentiality commitments from personnel.Provider personnel are bound by confidentiality obligations in their contracts of employment and internal access-control policy.
28(3)(c)Article 32 security measures.Encryption in transit and at rest, network isolation, managed patching, automated backups with point-in-time recovery, and independent audit reporting (SOC 2 Type II) at the infrastructure layer.
28(3)(d)No further sub-processor without authorisation.Onward sub-processors (principally cloud infrastructure regions) are published by the provider and changes are notified, allowing CareLedgerPro to pass notice to Controllers.
28(3)(e)Assist with data subject rights.Full programmatic export and deletion capability is available to CareLedgerPro, which is what enables access, portability and erasure requests to be actioned for Controllers.
28(3)(f)Assist with Articles 32–36 (security, breach, DPIA).The provider operates an incident notification process and publishes security documentation used as input to this DPIA and to breach assessment.
28(3)(g)Delete or return data at end of provision.Data is deleted on project deletion in line with the provider's retention window for backups, following the Controller's export.
28(3)(h)Make available information to demonstrate compliance and allow audits.Compliance documentation and audit reports are made available under NDA and can be shared with Controllers' auditors on request.

4. Where data is held

The production database, authentication store and storage buckets are provisioned in an EU/UK region. Backups remain within the same region. Support access by provider personnel is controlled and logged on their side.

Where any incidental processing occurs outside the UK — for example support tooling — it is covered by the transfer safeguards in section 2.

5. What CareLedgerPro controls, not the sub-processor

  • Row-level security policies that decide which staff member can read which service-user record.
  • The role model and the security-definer functions that evaluate it.
  • Append-only enforcement on the audit, user-audit, data-access and communication-edit logs.
  • Mandatory two-factor authentication and the session and password rules.
  • Private bucket configuration and short-lived signed URLs for receipts and attachments.
  • Retention, archiving and deletion behaviour within the application.

The sub-processor supplies the infrastructure primitives; the access-control design and its enforcement are CareLedgerPro's responsibility and are the subject of our own testing.

6. Change and exit

Controllers receive reasonable prior notice of any intended change of sub-processor and may raise a reasoned objection under the Data Processing Agreement. Because the schema is defined in version-controlled migrations and the data is standard PostgreSQL, the service can be rebuilt on alternative managed PostgreSQL infrastructure if required, which limits lock-in risk for Controllers.

Contact

To request the sub-processor's DPA references or audit documentation for your own records, contact support@careledgerpro.co.uk.

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.