Sub-processors

Byte River Ltd (the company behind CareOS) uses a small number of sub-processors to deliver the platform. This is the published register referenced by our Data Processing Addendum. We give customers at least 30 days' notice before adding or replacing a sub-processor, with a right to object on reasonable data-protection grounds. Every sub-processor is bound by data-protection obligations equivalent to our own, and we remain fully liable to customers for their performance.

Sub-processorPurposePersonal data involvedLocationSafeguards
Amazon Web Services (AWS)Hosting: application compute, managed PostgreSQL databases, file storage (S3), transactional email (SES)All platform data, including special category care recordsUK (London, eu-west-2)ISO 27001, SOC 1/2/3; encryption at rest and in transit; AWS GDPR Data Processing Addendum
OpenAI, L.L.C.Optional AI-assisted features: care-plan drafting, document extraction, chat assistance, transcriptionCare-record text submitted by customers using AI features. Customer-controllable per organisation — AI can run in anonymised mode or be disabled entirely. API data is not used for model training.USUK IDTA / UK Addendum to the EU SCCs; enterprise privacy commitments; every call audit-logged in-platform
Anthropic, PBCStaff-operated migration tooling: reads a new customer's outgoing care system with the customer's own login and populates their CareOS tenant. Used only during an agreed migration engagement.Care-record content extracted from the outgoing provider's system for the customer being migrated, including special category data. Not used for training. Every action logged in the per-migration run log.USUK IDTA / UK Addendum to the EU SCCs; Anthropic Commercial Terms and DPA; zero-retention API mode; access limited to the CareOS staff running the migration
Stripe Payments Europe Ltd / Stripe, Inc.Subscription payment processingCustomer organisation billing contacts and payment records only — card data is held by Stripe and never touches CareOS; no care dataEU / USPCI-DSS Level 1; UK IDTA / UK Addendum; Stripe DPA
Functional Software, Inc. (Sentry)Application error monitoringError telemetry; failed-request context may incidentally contain personal data (suppression rules minimise this)USSOC 2; UK IDTA / UK Addendum; Sentry DPA
Google Ireland Ltd / Google LLC (Firebase)Mobile and web push notification delivery; platform-site analyticsPush tokens and notification payloads; site analyticsEU / USISO 27001; Google Cloud / Firebase DPA
Twilio Ireland Ltd / Twilio Inc.SMS dispatch (only where enabled by the customer)Phone numbers and SMS message bodiesEU / USISO 27001, SOC 2; UK IDTA / UK Addendum; Twilio DPA

Postcodes.io (UK postcode geocoding, used for capacity checks) receives postcodes only, with no accompanying identifiers, and is therefore not a processor of personal data. Suppliers that never touch personal data — such as source-code hosting and DNS — are out of scope of this register.

Last reviewed: 19 August 2026. Questions about this register? Contact us.