Sub-processors

Last updated: 15 July 2026

CareLedgerPro relies on the sub-processors listed below to deliver the Service. Technical claims such as encryption at rest, backups, payment processing, email delivery, and identity management are delivered in whole or in part by these providers. Where a sub-processor changes, we will update this page.

Card payments are processed by Stripe, a PCI-DSS Level 1 service provider. Card data is handled directly by Stripe and does not touch CareLedgerPro servers.

We will provide reasonable prior notice of any intended changes to sub-processors where practicable, so Controllers may raise a justified objection in accordance with the Data Processing Agreement.

Current sub-processors

Sub-processorPurposeData processedLocation / transfer safeguards
SupabaseManaged PostgreSQL database, authentication services, and file storage.Controller-supplied data, including service-user financial records, staff accounts, receipts, and audit logs.Hosted in EU/UK regions. Where any transfer outside the UK occurs, appropriate safeguards are applied, including the UK International Data Transfer Addendum or Standard Contractual Clauses where relevant.
CloudflareEdge hosting, CDN, DNS, WAF, and TLS termination.Request metadata, encrypted application traffic, and security logs.Global edge network. Where relevant, transfers are protected by Standard Contractual Clauses and Cloudflare's UK GDPR commitments.
ResendTransactional email delivery.Recipient email address, message content, and delivery metadata.EU/US regions. Where relevant, transfers are protected by appropriate contractual safeguards and data-protection commitments.
StripeSubscription billing and payment processing.Billing contact details and subscription metadata. Card data is handled directly by Stripe; CareLedgerPro does not store card data.UK/EU/US. Where relevant, transfers are protected by appropriate contractual safeguards and Stripe's PCI-DSS and data-protection framework.

Change notifications

Controllers may subscribe to sub-processor change notifications. To register, please contact support.

Additional notes

  • CareLedgerPro does not use sub-processors for analytics, advertising, or profiling.
  • CareLedgerPro only shares Controller data with sub-processors and other parties where necessary to deliver the Service or comply with law.
  • Sub-processors are reviewed before onboarding and monitored periodically for ongoing contractual and security obligations.

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.