Privacy Policy
Last updated: 7 September 2026
Ostorra is a modular healthcare management platform used by hospitals, care homes, supported living services and home-care providers. This policy explains what personal data we handle, why, and the choices and rights you have.
1. Who is responsible for your data
For data entered into the platform about patients, residents and staff, the healthcare organisation using Ostorra is the data controller and Ostorra acts as its data processor. For data we collect directly — such as demo enquiries and website contact — Ostorra is the data controller.
2. What data we process
- Account and identity data — names, work email addresses, roles and professional details for platform users, set up by each organisation's administrator.
- Clinical and care data — entered by organisations into modules they have activated, such as care records, medication administration (eMAR), observations, risk assessments, appointments and incident reports.
- Workforce data — rosters, timesheets, leave, payroll details and training compliance entered by the employing organisation.
- Security and audit data — sign-in events, device and network information, access decisions and a tamper-evident audit trail of actions taken in the platform.
- Website enquiries — name, organisation, contact details and module interests submitted through our demo request form.
3. How we use it
- To provide, secure and support the platform for each organisation.
- To enforce each organisation's own access policies, including role-based access, trusted networks and managed devices.
- To maintain the audit trails that care regulations require.
- To respond to demo and sales enquiries. We do not use platform data for marketing.
4. What we never do
We do not sell personal data, we do not use patient, resident or staff data for advertising, and we do not share data between customer organisations. Each organisation's data is isolated to that organisation and enforced at the database level.
5. Retention
Platform data is retained for as long as the organisation's contract and legal obligations require — for example, care records and audit logs follow the organisation's statutory retention schedules. Website enquiry data is kept for up to 24 months or until you ask us to delete it.
6. Applicable laws and your rights
Ostorra is designed to support compliance with major data-protection and health-privacy laws worldwide, including the EU and UK GDPR, the US CCPA/CPRA and HIPAA, Canada's PIPEDA, Australia's Privacy Act, and equivalent frameworks elsewhere. Wherever you are, you have the rights granted by your local law — typically access, rectification, erasure, restriction, portability and objection.
For data held inside an organisation's Ostorra account, contact that organisation first — the platform includes a built-in data-request workflow so organisations can log, track and fulfil subject access requests within statutory timeframes. For data Ostorra controls directly, contact us using the details below. You also have the right to complain to your local data-protection supervisory authority.
7. International transfers
Where personal data is transferred across borders, we apply appropriate safeguards such as standard contractual clauses, adequacy decisions and encryption in transit and at rest, so the data remains protected to the standard required by its originating jurisdiction.
8. Contact
For privacy questions or to exercise your rights in relation to data Ostorra controls, email privacy@ostorra.com.
Related documents: Cookie Policy · Privacy Policy · Data Protection Statement · All Policies
