Data Processing Addendum

These are the Article 28(3) data processing terms incorporated into the Byte River Ltd customer Terms & Conditions. They apply whenever Byte River Ltd (company no. 14472223, the Provider) processes Personal Data on behalf of a customer care organisation (the Customer) in providing the CareOS platform (the Service). Terms such as "Personal Data", "processing", "Controller", "Processor" and "Data Subject" have the meanings given in UK GDPR.

1. Roles and scope

1.1 The Customer is the Controller and the Provider is the Processorof all Personal Data entered into or generated within the Service by or on behalf of the Customer ("Customer Data").

1.2 The Provider is a Controller in its own right only for: Customer account and billing records, and its own business records. Those are outside this Addendum and covered by the Provider's privacy notice.

2. Details of processing

Subject matterProvision of a care-management software platform (client records, care planning, medication records, scheduling, workforce compliance, messaging, finance)
DurationThe term of the agreement, plus the wind-down period in §10
Nature and purposeHosting, storage, display, transmission, backup, and processing of care management records to enable the Customer to deliver and evidence regulated care services; optional AI-assisted features (e.g. care-plan drafting, document extraction) where enabled by the Customer
Categories of Data SubjectsThe Customer's service users (people receiving care); their family members, representatives, and professional contacts; the Customer's staff and job applicants
Categories of Personal DataIdentity and contact details; care and support records; special category data — health data (medical conditions, medications, care needs, incident records) and other special category data the Customer records; staff employment, vetting (including DBS status), and payroll-input data; location data (visit check-in/out coordinates)

3. Processor obligations

The Provider shall:

  • process Customer Data only on the Customer's documented instructions (the agreement, this Addendum, and the Customer's configuration and use of the Service constitute those instructions), unless required otherwise by law — in which case the Provider will inform the Customer before processing unless that law prohibits it;
  • ensure all personnel authorised to process Customer Data are bound by confidentiality obligations and trained in data protection;
  • implement and maintain the technical and organisational measures described in Appendix 1, reviewing and updating them so they do not materially degrade during the term;
  • not access Customer Data except as necessary to provide and support the Service, investigate security or operational issues, or as instructed by the Customer (all platform-administrator access is permission-gated and audit-logged);
  • assist the Customer, taking into account the nature of the processing, in responding to Data Subject rights requests (§7) and in meeting its obligations under Articles 32–36 (security, breach notification, DPIAs, prior consultation);
  • make available information reasonably necessary to demonstrate compliance with Article 28, and allow and contribute to audits as set out in §9;
  • notify the Customer without undue delay if, in its opinion, an instruction infringes UK GDPR.

4. Security

4.1 The Provider maintains the measures in Appendix 1, including: UK data residency for data at rest (AWS London, eu-west-2); per-customer database isolation; encryption in transit (TLS) and at rest, with additional field-level encryption of designated identifiers; role-based access control; comprehensive audit logging; and independently assessed controls (Cyber Essentials Plus; annual NHS DSPT self-assessment).

4.2 The Provider holds and maintains a published NHS Data Security and Protection Toolkit (DSPT) submission for the duration of the agreement.

5. Sub-processors

5.1 The Customer gives general written authorisation for the sub-processors listed in Appendix 2 (maintained at the Provider's published sub-processor list).

5.2 The Provider will give the Customer at least 30 days' notice of any intended addition or replacement of a sub-processor. The Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, the Customer may terminate the affected part of the Service without penalty.

5.3 The Provider imposes data-protection obligations on each sub-processor equivalent to those in this Addendum and remains fully liable to the Customer for sub-processor performance.

6. International transfers

6.1 Customer Data at rest is stored in the United Kingdom. Limited transfers to sub-processors outside the UK (Appendix 2 — e.g. AI processing, error monitoring, SMS dispatch) are made only under appropriate safeguards: UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.

6.2 AI-assisted features involve transferring relevant record text to the AI sub-processor (currently OpenAI, US; API data is not used for model training). The Customer controls this per its configuration — AI features can be run in anonymised mode or disabled entirely, in which case no such transfer occurs.

7. Data Subject rights

The Service provides the Customer with self-serve means to access, export, rectify, and restrict Customer Data. Where a Data Subject contacts the Provider directly, the Provider will forward the request to the Customer within 3 working days and not respond substantively itself (unless legally required).

8. Personal data breach

The Provider will notify the Customer without undue delay (target: within 24 hours) after becoming aware of a personal data breach affecting Customer Data, providing — as information becomes available — the nature of the breach, categories and approximate numbers of Data Subjects and records affected, likely consequences, and measures taken or proposed. The Provider will cooperate with the Customer's own ICO and Data Subject notification obligations.

9. Audit

No more than once per 12 months (and additionally following a material breach), the Customer may request: (a) the Provider's then-current DSPT publication, Cyber Essentials Plus certificate, and security summary; and (b) written responses to reasonable security questionnaires. On-site or technical audits, where genuinely required by the Customer's regulator, shall be on at least 30 days' notice, during business hours, at the Customer's cost, and must not compromise other customers' data (the per-customer database architecture supports scoped inspection).

10. Return and deletion

On termination or expiry, the Provider will, at the Customer's choice, make Customer Data available for export in a structured, commonly used format. 90 days after termination the Provider will delete the Customer's database and stored files, except where retention is required by law. Backups containing Customer Data expire through the standard backup rotation (maximum 30 days). The Provider will confirm deletion in writing on request. The Customer acknowledges its own statutory care-record retention duties (typically 8+ years) and is responsible for exporting before deletion.

11. Liability

Liability under this Addendum is subject to the limitations and exclusions of the main agreement.

Appendix 1 — Technical and organisational measures (summary)

  • Data residency: all Customer Data at rest in AWS London (eu-west-2)
  • Isolation: dedicated PostgreSQL database per customer; organisation claim validated on every request
  • Encryption: TLS 1.2+ in transit; disk encryption at rest; application-layer field encryption of designated identifiers (e.g. NHS numbers, medical conditions)
  • Access control: role-based permissions enforced server-side; scoped, audited platform-administrator access; optional customer-controlled 2FA and mandatory-biometrics policies
  • Audit: append-only audit log of all data mutations; request, email, and AI-call logging
  • Resilience: automated backups (30-day retention, point-in-time recovery); documented business continuity and disaster recovery plan
  • Assurance: Cyber Essentials Plus certification; annual NHS DSPT self-assessment; documented incident response with breach-notification commitments
  • Personnel: confidentiality obligations, annual data security training, least-privilege access, leaver revocation process

Appendix 2 — Authorised sub-processors

The authoritative, current list is published at careos.uk/subprocessors, together with what each sub-processor processes, where, and under what safeguards.

Last reviewed: July 2026. Questions? Contact us.