Legal

Data processing agreement

What we do with the personal data you put into Rostera, and what you can hold us to. This is the agreement referred to in your order form — a signable copy is attached to it.

Version 1.0Effective 27 August 2026Article 28 UK GDPR

This agreement sets out how Rostera handles the personal data a care provider puts into the service, and what the provider is entitled to ask of Rostera. It is written to be read by the people who have to rely on it — a registered manager, a data protection officer, a commissioner — and it forms part of the subscription agreement.

The customer stays in charge of its data. Rostera processes it to run the service and for nothing else: it is never sold, never used to advertise, and never used to train anybody’s model.

  1. 1. Who this is between, and what it covers

    This data processing agreement is between Rostera Ltd (company number 17376616, “Rostera”) and the customer named in the order form (the “Customer”). It forms part of the agreement between them for the Rostera service (the “Agreement”) and applies to all personal data Rostera processes on the Customer’s behalf.

    Where this agreement and the rest of the Agreement disagree about data protection, this agreement wins.

  2. 2. Which of us is the controller

    The Customer is the controller of the personal data in its Rostera account and Rostera is the processor. The Customer decides what data goes in, who may see it, and how long it is kept.

    Where the Customer is itself a processor — for example where a local authority or an integrated care board is the controller of a service user’s data — Rostera acts as a sub-processor, and the Customer confirms it has the controller’s authority to appoint one on these terms.

    Rostera is a controller in its own right for a small, separate set of data: the Customer’s billing contact and subscription record, and the account and support correspondence of the people who administer the service. That processing is covered by Rostera’s privacy notice, not by this agreement.

  3. 3. Only on the Customer’s instructions

    Rostera processes personal data only on the Customer’s documented instructions, including about transfers out of the UK, unless required otherwise by law — in which case Rostera will tell the Customer first, unless the law forbids it.

    The Agreement, this agreement and the Customer’s use of the service (its settings, its role permissions, and the features it switches on) are the Customer’s complete instructions. If Rostera believes an instruction breaks data protection law, it will say so.

  4. 4. Confidentiality

    Everyone Rostera authorises to process the Customer’s personal data is bound by a duty of confidence, is told what they may and may not do with it, and is given access only to what their job needs.

  5. 5. Security

    Rostera implements the technical and organisational measures set out in Annex II, taking account of the state of the art, the cost of implementation, and the risk to the people whose data it is — in particular that this service holds health data about people receiving care.

    Rostera may change a measure, but not in a way that materially weakens the protection described in Annex II.

  6. 6. Sub-processors — general authorisation

    The Customer gives general authorisation for Rostera to engage the sub-processors listed in Annex III, and to change them as the service develops.

    Rostera maintains the current list at rostera.co.uk/sub-processors and will give the Customer at least 30 days’ notice before adding or replacing one. The Customer may object within that period on reasonable data-protection grounds. The parties will discuss the objection in good faith; if it cannot be resolved, the Customer may terminate the affected part of the service without penalty and without owing the balance of any initial term.

    Rostera engages each sub-processor under a written contract imposing data-protection obligations equivalent to those in this agreement, and remains fully liable to the Customer for what its sub-processors do.

  7. 7. Sending data outside the UK

    The care record — the database that stores it and the application that serves it — is hosted in the United Kingdom. Care plans, medication records, observations, rotas, clock-ins and pay do not leave the country in the ordinary running of the service.

    Some sub-processors in Annex III are outside the UK. Where Rostera transfers personal data to a country without a UK adequacy decision, it does so under the UK International Data Transfer Agreement, or the EU standard contractual clauses with the UK addendum, together with a transfer risk assessment.

    The AI drafting feature, if the Customer switches it on, sends scoped care content to a sub-processor outside the UK. It is off unless the Customer turns it on, and the exact fields are listed before anyone can agree to it.

  8. 8. Helping the Customer answer data subjects

    Most requests the Customer can handle itself: the service lets an administrator search the care record, export a person’s records, correct an entry with the change recorded, and remove a record from view.

    Where a request cannot be answered through the service, Rostera will help the Customer respond within the statutory deadline, taking account of the nature of the processing. If a data subject contacts Rostera directly, Rostera will not respond substantively but will pass the request to the Customer without undue delay.

  9. 9. Helping with impact assessments and consultation

    Rostera will give the Customer the information it reasonably needs for a data protection impact assessment or a prior consultation with the ICO about the service — including the data-flow map, the record of processing activities and the sub-processor register that this agreement draws on.

  10. 10. Personal data breaches

    Rostera will notify the Customer of a personal data breach affecting the Customer’s personal data without undue delay and in any event within 24 hours of becoming aware of it.

    The notification will describe what happened, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point — as far as those are known at the time, with further detail to follow as the investigation progresses. Rostera will not make a public statement identifying the Customer without consulting it first, unless the law requires one.

  11. 11. Returning and deleting data

    During the term and at any time after it, the Customer can export its data from the service itself — staff, rotas, clock history, care records and payroll — including after cancellation or non-payment. There is no charge for this and no exit fee.

    On the Customer’s written request after the Agreement ends, Rostera will delete the Customer’s personal data within 30 days, except where it must be kept longer by law. Data held in encrypted backups is deleted on the ordinary backup rotation, and remains protected by this agreement until it is.

  12. 12. Audits and information

    Rostera will make available the information reasonably needed to show it meets Article 28, and will allow audits by the Customer or an auditor it appoints — at most once in any 12 months unless a breach or a regulator says otherwise, on at least 30 days’ notice, during business hours, without unreasonable disruption, and subject to confidentiality.

    Rostera may satisfy an audit request by providing current third-party assurance instead, where it holds it. What exists today and what is still in progress is stated on the DSCR and compliance page rather than claimed here.

  13. 13. Records

    Each party keeps the records of processing that Article 30 requires of it. Rostera’s record for this service is maintained alongside the data-flow map and sub-processor register referenced in Annex III.

  14. 14. How long this lasts

    This agreement applies for as long as Rostera processes personal data for the Customer, and the obligations that by their nature should survive — confidentiality, deletion, and the treatment of data still held in backups — continue after the Agreement ends.

  15. 15. Liability

    Liability under this agreement is subject to the limitations and exclusions in the Agreement, except that nothing limits either party’s liability to a data subject or a regulator under data protection law.

  16. 16. Law

    This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Annex I

What we process

The detail Article 28(3) requires, and what your own record of processing needs from us.

Subject matter
Provision of the Rostera workforce and care-management service to the Customer.
Duration
The term of the Agreement, plus the deletion period in clause 11.
Nature and purpose
Hosting and processing the Customer’s staff, rota, visit and care records so the Customer can plan and evidence the care it delivers: scheduling, geofenced clock-in, care planning, medication administration, clinical observations, incidents and safeguarding, staff compliance, payroll and funder invoicing, notifications, and family access.
Categories of data subject
The Customer’s staff (carers, managers, administrators); the people receiving care from the Customer (service users); their family members, next of kin and guardians; and the professional contacts recorded on a care record (GP, social worker, commissioner).
Categories of personal data
Identity and contact details; date of birth; employment data including role, pay rate, working hours and leave; location data from geofenced clock-in and out; device and push-token identifiers; authentication data; photographs and uploaded documents; audit records of who viewed, created, changed or deleted a record; and, for service users, address and care-package details.
Special category data (Article 9)
Health data, extensively: care and support plans, medication administration records, clinical observations and charts, body maps, wound records, incidents, safeguarding concerns, and daily care notes. Care preferences may also reveal religious belief, ethnicity or sexual orientation.
Criminal offence data (Article 10)
Yes — enhanced DBS certificate details and expiry are recorded against staff as part of the compliance record.
Frequency
Continuous, for as long as the Customer uses the service.

Annex II

How it is protected

The measures in place today. Where an assurance programme is still running we say so on the compliance page rather than implying it is finished.

Access control
Role-based access (administrator, manager, carer, family) with every query scoped to the Customer’s own organisation and, for managers, to their branch. Least privilege by default.
Authentication
Password hashing, signed session tokens, forced password reset where an account is at risk, and multi-factor authentication.
Encryption
TLS for all data in transit. Encryption at rest in the managed database. Uploaded documents and photos are envelope-encrypted by the application before storage, so the storage provider holds ciphertext only and never the keys.
Audit trail
An append-only log of administrative creates, changes and deletions, with the actor, the record and the time. Care records use soft deletion, so a removal is recoverable and attributable.
Abuse protection
Fail-closed rate limiting on authentication and other sensitive endpoints.
Resilience
Managed database backups with point-in-time recovery, a documented disaster-recovery runbook, and periodic restore verification.
Monitoring
Server-side error and exception monitoring, hosted in the EU.
Secure development
Dependency and code scanning in continuous integration, and an automated test suite covering tenancy isolation and the export rules this agreement relies on.

Annex III

Who else touches the data

The sub-processors you authorise by agreeing to this, kept as a living list with 30 days’ notice before it changes.

See the sub-processor list →

Questions about this agreement

If you are a data protection officer reviewing Rostera for a provider, or a commissioner asking on their behalf, write to admin@rostera.co.uk and ask for the data-flow map and record of processing activities. We will send them.

See also our privacy notice, which covers the data we hold as a controller in our own right, and DSCR & compliance for the standards this service is built to.