Record of Processing Activities (ROPA)

CareLedgerPro — Processor ROPA · Article 30 UK GDPR

This Record of Processing Activities describes the processing CareLedgerPro carries out as a processor on behalf of Controllers. Controllers must maintain their own ROPA covering the purposes for which they use CareLedgerPro. CareLedgerPro processes personal data only on the documented instructions of Controllers and does not determine the purposes of processing.

1. Activity: Financial Record Keeping for Service Users

Purpose
To enable controllers to record, safeguard, monitor, and audit personal money belonging to the people they support, in line with care-sector financial governance requirements.
Categories of data subjects
  • Service users.
  • Next of kin, where recorded by the controller.
  • The controller's staff.
Categories of personal data
  • Identifiers, such as name, group or unit, and internal reference IDs.
  • Balances and financial metadata.
  • Transactions, receipts, and spending plans.
  • Digital signatures and "signed on behalf" indicators.
  • Staff account IDs, roles, and activity metadata.
Special category data
Where the controller instructs processing of special category data, CareLedgerPro processes it only on documented instructions and with appropriate safeguards. This may include capacity indicators, safeguarding-related notes, or similar information where relevant.
Lawful basis
The lawful basis and any special category condition are the controller's responsibility.
Recipients
  • The controller's authorised staff, via role-based access control.
  • Sub-processors listed on the Sub-processors page.
International transfers
Data is hosted on UK-aligned infrastructure. Where any transfer outside the UK occurs, it is protected by appropriate transfer safeguards, such as the UK International Data Transfer Addendum or Standard Contractual Clauses, supported by transfer risk assessments where required.
Retention
Data is retained for the duration of the subscription and thereafter only as required for export, deletion, legal obligations, dispute handling, or documented controller instructions.
Security measures
  • TLS in transit.
  • Encryption at rest.
  • Role-based access control.
  • Row-level security.
  • Append-only audit logs.
  • Leaked-password protection.
  • Backups with point-in-time recovery.
  • MFA support.
  • Regular security testing.
  • Secure development lifecycle controls.

2. Activity: Account Authentication and Access Control

Purpose
To authenticate users and enforce role-based access to the Service.
Data subjects
The controller's staff and administrators.
Categories of personal data
  • Email address.
  • Hashed password, checked against known leaked-password databases.
  • Role assignments and permissions.
  • Session metadata.
  • Login timestamps.
Recipients
  • Authentication sub-processors.
  • Internal audit logs.
Retention
Retained for the lifetime of the account and deleted upon off-boarding, with audit references retained where needed for governance.
Security
  • Password hashing.
  • MFA support.
  • Session management.
  • Suspicious login detection.

3. Activity: Audit Trail and Safeguarding

Purpose
To provide append-only audit logs with recorded corrections that evidence safe financial management for CQC, local authorities, and internal governance teams.
Data subjects
  • Service users.
  • The controller's staff.
Categories of personal data
  • Who accessed or changed a record.
  • Timestamp of access or change.
  • Before-and-after values.
  • Correction reasons.
  • Device and session metadata.
Retention
Audit records are retained for at least 7 years, subject to controller instruction and any legal or regulatory requirement to retain records for longer.
Security
  • append-only audit logs.
  • Restricted access.
  • Monitoring for suspicious activity.

4. Activity: Transactional Email

Purpose
To send system emails, including invitations, password resets, low-cash alerts, daily digests, and breach notifications.
Data subjects
  • The controller's staff and administrators.
  • Opted-in alert recipients.
Categories of personal data
  • Email address.
  • Message metadata.
  • Delivery status.
Recipients
Transactional email sub-processors.
Retention
Delivery logs are retained for troubleshooting and service support. Suppression lists are retained only as long as necessary to honour opt-outs and any applicable legal or operational requirement.

5. Activity: Billing

Purpose
To process subscription payments for paid plans.
Data subjects
Billing contacts of the controller.
Categories of personal data
  • Billing email.
  • Plan and subscription metadata.
  • Card data is handled directly by the PCI-DSS-compliant payment processor; CareLedgerPro does not store card data.
Recipients
Payment sub-processors.
Retention
Retained for the lifetime of the account and thereafter as required for accounting, tax, and legal obligations.

6. Data Protection by Design and Default

CareLedgerPro implements data protection by design and by default through:

  • Data minimisation.
  • Role-based access control.
  • Secure development lifecycle controls.
  • Regular security testing.
  • Pseudonymisation where appropriate.
  • Separation of controller data.
  • No use of customer data for analytics or profiling.

7. Sub-Processor Governance

  • Sub-processors are listed publicly and updated as needed.
  • Controllers are given advance notice of intended changes where reasonably practicable.
  • Controllers may raise a justified objection in accordance with the Data Processing Agreement.
  • All sub-processors are bound by equivalent contractual, confidentiality, and security obligations.

8. Controller Instructions and Boundaries

CareLedgerPro acts only on the documented instructions of controllers.

CareLedgerPro is not a joint controller and does not determine the purposes or means of processing.

Controllers remain responsible for:

  • lawful basis;
  • data accuracy;
  • data subject rights;
  • retention obligations;
  • safeguarding decisions.

9. Automated Decision-Making

CareLedgerPro does not carry out automated decision-making or profiling within the meaning of Article 22 UK GDPR.

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.