Legal
Sub-processors
The third parties we use to run Rostera, what each one receives, and where it sits. If we add or replace one, every customer gets 30 days’ notice and can object.
A sub-processor is any company that touches your data in the course of us delivering the service — the database that stores it, the service that sends a push notification, the tool that tells us an error happened. Publishing the list is how you can complete your own record of processing, your DPIA and your Data Security and Protection Toolkit submission without having to ask us first.
The care record itself is hosted in the United Kingdom. Care plans, medication records, observations, rotas, clock-ins and pay all live in a UK database. Where a sub-processor sits outside the UK, we say so plainly below and cover the transfer with the UK International Data Transfer Agreement or the standard contractual clauses with the UK addendum.
| Sub-processor | What it does | What it receives | Where | Safeguard |
|---|---|---|---|---|
| Neon | Managed Postgres — the primary datastore | All persisted data, including health data | United Kingdom (London) | Hosted in the UK — no transfer |
| Vercel | Application hosting and API compute | All categories in transit. Nothing is persisted here | United Kingdom (London) | Hosted in the UK — no transfer |
| Cloudflare R2 | Document and photo storage | Ciphertext only — the provider holds no keys and cannot read the contents | Cloudflare global network | Ciphertext only; UK IDTA / SCCs |
| Stripe | Subscription billing | Billing contact and subscription record. No care data. Card details never reach Rostera | United States | UK IDTA / SCCs with UK addendum |
| Email provider | Payslips and notification fallback | Recipient name and email, payslip figures, notification text | United Kingdom / European Union | Provider data processing agreement |
| Firebase Cloud Messaging | Push notifications to the mobile apps | Device token and notification text | United States | UK IDTA / SCCs with UK addendum |
| Apple Push Notification service | iOS push delivery, reached through Firebase | Device token and notification text | United States | UK IDTA / SCCs with UK addendum |
| Browser push services | Push to browsers and installed web apps | Push endpoint and notification text | The browser vendor’s own service | Per endpoint operator |
| Upstash | Rate-limit counters that protect sign-in | An IP address or user id and a counter. No care data | European Union | Provider data processing agreement |
| Google Maps Platform | Address lookup and the map pin picker | Address strings and coordinates. No care data | United States | UK IDTA / SCCs with UK addendum |
| Sentry | Error monitoring | Diagnostic traces, which may incidentally include personal data | European Union (Germany) | Within UK adequacy |
| Anthropic | AI drafting — off unless you switch it on | Two features send no personal data at all. Two send scoped care content with names, dates of birth, NHS numbers and addresses structurally excluded — and only where your organisation has recorded its consent | United States | UK IDTA / SCCs; not enabled for anyone until in place |
Changes
How you hear about a change
Before we add or replace a sub-processor we give at least 30 days’ notice to the billing and data protection contacts on your account, and update this page. If you object on reasonable data-protection grounds, we will work through it with you — and if we cannot resolve it, you can end the affected part of your subscription without penalty and without owing the balance of any initial term. That is clause 6 of the data processing agreement.
AI drafting is the one entry that is off by default. Anthropic is listed because the capability exists, not because your data goes there. It stays switched off until your organisation turns it on, having read the exact list of fields that would leave — and two of the four AI features send no personal data at all.
Questions, or want the underlying data-flow map for your own DPIA? Write to admin@rostera.co.uk.