Data Protection Statement
Last updated: 7 September 2026
Data protection in Ostorra is not a bolt-on — it is enforced by the platform itself. This statement summarises the measures we apply and the controls each organisation gets over its own data.
1. Tenant isolation
Every organisation's data is logically isolated and enforced at the database level through row-level security on every table. A signed-in user can only ever read or write records belonging to their own organisation, and staff cannot move records between organisations.
2. Role-based and scoped access
Access follows each user's role — clinician, carer, rota manager, billing, administrator and more — and can be scoped to specific sites, wards, homes or beds. Clinical records can be placed behind additional step-up checks, and sensitive actions are restricted to the roles that need them.
3. Organisation-controlled access policies
Each organisation configures its own sign-in policy: managed-device requirements, trusted network ranges and approved VPNs, two-step verification for clinical records, and session re-check intervals. Blocked attempts and policy violations are visible to administrators in a live security dashboard.
4. Audit and accountability
Actions across the platform are written to an append-only audit trail. Notes and records lock after signing, medication administration is witnessed where required, and finance movements carry evidence and approval chains — supporting regulatory evidence requirements across jurisdictions (such as the CQC in England and equivalent care regulators worldwide).
5. Encryption and infrastructure
Data is encrypted in transit and at rest. The platform runs on managed, access-controlled infrastructure with no public exposure of service keys, and privileged operations are confined to audited server-side processes.
6. Data subject requests
Ostorra includes a built-in data-request register so organisations can log, assign, track and evidence subject access, rectification and erasure requests within statutory timeframes.
7. Incident response
Suspected personal-data breaches are assessed, contained and documented without delay. Where a breach meets the notification threshold under the applicable law, the affected organisation is informed promptly so it can meet its own regulator-notification duty within the required timeframe (72 hours under GDPR/UK GDPR and equivalent deadlines elsewhere).
Related documents: Cookie Policy · Privacy Policy · Data Protection Statement · All Policies
