AuditReady.care
Legal

Data Processing Addendum

This addendum sets out how Audit Ready Solutions Limited, as processor, handles personal data controlled by your organisation when you use the AuditReady.care Platform, in line with UK GDPR.

Care groups with their own Data Protection Officer are welcome to review this addendum and, if preferred, execute a signed counterpart. Contact us to arrange that.

Last updated: 21 August 2026

1. Definitions

Terms such as Controller, Processor, Personal Data, Processing, Data Subject, Sub-processor and Personal Data Breach have the meanings given in UK GDPR / Data Protection Act 2018.

2. Roles

Your organisation is the Controller of the Personal Data uploaded to the AuditReady.care Platform. Audit Ready Solutions Limited is the Processor. We process Personal Data only on your documented instructions, which are set out (a) in the Platform’s user interface and configuration, and (b) in any order form or written agreement.

3. Subject matter, duration, nature and purpose

  • Subject matter: sponsor-licence and worker compliance management.
  • Duration: the term of the service agreement.
  • Nature and purpose: storing, indexing, retrieving and displaying Personal Data submitted by Controller users; generating compliance reports; sending operational notifications.
  • Data subjects: your organisation’s sponsored workers, employees, contractors and named contacts.
  • Categories of Personal Data: identity, right to work, sponsorship, employment, salary, hours, absence, documents relevant to Home Office sponsor-licence compliance.

4. Processor obligations

We will:

  • Process Personal Data only on your documented instructions and only for the purposes above.
  • Ensure staff authorised to process Personal Data are subject to appropriate confidentiality obligations.
  • Implement the technical and organisational security measures described in our Security page, which include at minimum: TLS in transit, encrypted Postgres at rest, mandatory two-factor authentication, tenant-isolated Row Level Security, immutable audit logging, and least-privilege staff access.
  • Assist you with data-subject rights requests and with data protection impact assessments to the extent reasonably necessary.
  • Notify you without undue delay (and in any event within 72 hours) of becoming aware of a Personal Data Breach affecting your data.
  • On termination, at your choice, delete or return all Personal Data to you, and delete existing copies unless we are required by law to retain them.
  • Make available such information as is reasonably necessary to demonstrate compliance with these obligations and allow for audits as agreed with you (see Section 8).

5. Sub-processors

You give general authorisation for us to engage the sub-processors listed on our Security page (Supabase, Vercel, Brevo, Cloudflare). We will notify you at least 30 days before appointing any new sub-processor that processes Personal Data. You may object on reasonable data-protection grounds; if the objection cannot be resolved, you may terminate the affected services.

6. International transfers

Personal Data is stored in the United Kingdom. We do not routinely transfer Personal Data outside the UK / EU. Where any incidental transfer occurs (for example diagnostic logs processed by a sub-processor), we will ensure appropriate safeguards under Article 46 UK GDPR are in place.

7. Security

The technical and organisational measures we apply are set out on the Security page and form part of this DPA. We keep those measures under review and may update them from time to time, provided the level of protection is not reduced.

8. Audit

Once per year, or after a Personal Data Breach that affects your data, you may request evidence of our compliance with this DPA. We will respond with reasonable documentation and, where necessary, agree scope and timing of an on-site or remote audit conducted at your reasonable cost.

9. Liability

Liability under this DPA is subject to the limitation of liability set out in the applicable service agreement or Terms of service, save where such limitation is not permitted by law.

10. Precedence

In the event of conflict between this DPA and the Terms of service or any order form, this DPA prevails on matters of data protection.

11. Contact

Data-protection contact: sales@audit-ready.org.