Sub-processors
Byte River Ltd (the company behind CareOS) uses a small number of sub-processors to deliver the platform. This is the published register referenced by our Data Processing Addendum. We give customers at least 30 days' notice before adding or replacing a sub-processor, with a right to object on reasonable data-protection grounds. Every sub-processor is bound by data-protection obligations equivalent to our own, and we remain fully liable to customers for their performance.
| Sub-processor | Purpose | Personal data involved | Location | Safeguards |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Hosting: application compute, managed PostgreSQL databases, file storage (S3), transactional email (SES) | All platform data, including special category care records | UK (London, eu-west-2) | ISO 27001, SOC 1/2/3; encryption at rest and in transit; AWS GDPR Data Processing Addendum |
| OpenAI, L.L.C. | Optional AI-assisted features: care-plan drafting, document extraction, chat assistance, transcription | Care-record text submitted by customers using AI features. Customer-controllable per organisation — AI can run in anonymised mode or be disabled entirely. API data is not used for model training. | US | UK IDTA / UK Addendum to the EU SCCs; enterprise privacy commitments; every call audit-logged in-platform |
| Anthropic, PBC | Staff-operated migration tooling: reads a new customer's outgoing care system with the customer's own login and populates their CareOS tenant. Used only during an agreed migration engagement. | Care-record content extracted from the outgoing provider's system for the customer being migrated, including special category data. Not used for training. Every action logged in the per-migration run log. | US | UK IDTA / UK Addendum to the EU SCCs; Anthropic Commercial Terms and DPA; zero-retention API mode; access limited to the CareOS staff running the migration |
| Stripe Payments Europe Ltd / Stripe, Inc. | Subscription payment processing | Customer organisation billing contacts and payment records only — card data is held by Stripe and never touches CareOS; no care data | EU / US | PCI-DSS Level 1; UK IDTA / UK Addendum; Stripe DPA |
| Functional Software, Inc. (Sentry) | Application error monitoring | Error telemetry; failed-request context may incidentally contain personal data (suppression rules minimise this) | US | SOC 2; UK IDTA / UK Addendum; Sentry DPA |
| Google Ireland Ltd / Google LLC (Firebase) | Mobile and web push notification delivery; platform-site analytics | Push tokens and notification payloads; site analytics | EU / US | ISO 27001; Google Cloud / Firebase DPA |
| Twilio Ireland Ltd / Twilio Inc. | SMS dispatch (only where enabled by the customer) | Phone numbers and SMS message bodies | EU / US | ISO 27001, SOC 2; UK IDTA / UK Addendum; Twilio DPA |
Postcodes.io (UK postcode geocoding, used for capacity checks) receives postcodes only, with no accompanying identifiers, and is therefore not a processor of personal data. Suppliers that never touch personal data — such as source-code hosting and DNS — are out of scope of this register.
Last reviewed: 19 August 2026. Questions about this register? Contact us.