Legal

Sub-processors

The third parties we use to run Rostera, what each one receives, and where it sits. If we add or replace one, every customer gets 30 days’ notice and can object.

12 sub-processorsCare record hosted in the UKUpdated 27 August 2026

A sub-processor is any company that touches your data in the course of us delivering the service — the database that stores it, the service that sends a push notification, the tool that tells us an error happened. Publishing the list is how you can complete your own record of processing, your DPIA and your Data Security and Protection Toolkit submission without having to ask us first.

The care record itself is hosted in the United Kingdom. Care plans, medication records, observations, rotas, clock-ins and pay all live in a UK database. Where a sub-processor sits outside the UK, we say so plainly below and cover the transfer with the UK International Data Transfer Agreement or the standard contractual clauses with the UK addendum.

Sub-processorWhat it doesWhat it receivesWhereSafeguard
NeonManaged Postgres — the primary datastoreAll persisted data, including health dataUnited Kingdom (London)Hosted in the UK — no transfer
VercelApplication hosting and API computeAll categories in transit. Nothing is persisted hereUnited Kingdom (London)Hosted in the UK — no transfer
Cloudflare R2Document and photo storageCiphertext only — the provider holds no keys and cannot read the contentsCloudflare global networkCiphertext only; UK IDTA / SCCs
StripeSubscription billingBilling contact and subscription record. No care data. Card details never reach RosteraUnited StatesUK IDTA / SCCs with UK addendum
Email providerPayslips and notification fallbackRecipient name and email, payslip figures, notification textUnited Kingdom / European UnionProvider data processing agreement
Firebase Cloud MessagingPush notifications to the mobile appsDevice token and notification textUnited StatesUK IDTA / SCCs with UK addendum
Apple Push Notification serviceiOS push delivery, reached through FirebaseDevice token and notification textUnited StatesUK IDTA / SCCs with UK addendum
Browser push servicesPush to browsers and installed web appsPush endpoint and notification textThe browser vendor’s own servicePer endpoint operator
UpstashRate-limit counters that protect sign-inAn IP address or user id and a counter. No care dataEuropean UnionProvider data processing agreement
Google Maps PlatformAddress lookup and the map pin pickerAddress strings and coordinates. No care dataUnited StatesUK IDTA / SCCs with UK addendum
SentryError monitoringDiagnostic traces, which may incidentally include personal dataEuropean Union (Germany)Within UK adequacy
AnthropicAI drafting — off unless you switch it onTwo features send no personal data at all. Two send scoped care content with names, dates of birth, NHS numbers and addresses structurally excluded — and only where your organisation has recorded its consentUnited StatesUK IDTA / SCCs; not enabled for anyone until in place

Changes

How you hear about a change

Before we add or replace a sub-processor we give at least 30 days’ notice to the billing and data protection contacts on your account, and update this page. If you object on reasonable data-protection grounds, we will work through it with you — and if we cannot resolve it, you can end the affected part of your subscription without penalty and without owing the balance of any initial term. That is clause 6 of the data processing agreement.

AI drafting is the one entry that is off by default. Anthropic is listed because the capability exists, not because your data goes there. It stays switched off until your organisation turns it on, having read the exact list of fields that would leave — and two of the four AI features send no personal data at all.

Questions, or want the underlying data-flow map for your own DPIA? Write to admin@rostera.co.uk.