Data Protection Statement

Last updated: 7 September 2026

Data protection in Ostorra is not a bolt-on — it is enforced by the platform itself. This statement summarises the measures we apply and the controls each organisation gets over its own data.

1. Tenant isolation

Every organisation's data is logically isolated and enforced at the database level through row-level security on every table. A signed-in user can only ever read or write records belonging to their own organisation, and staff cannot move records between organisations.

2. Role-based and scoped access

Access follows each user's role — clinician, carer, rota manager, billing, administrator and more — and can be scoped to specific sites, wards, homes or beds. Clinical records can be placed behind additional step-up checks, and sensitive actions are restricted to the roles that need them.

3. Organisation-controlled access policies

Each organisation configures its own sign-in policy: managed-device requirements, trusted network ranges and approved VPNs, two-step verification for clinical records, and session re-check intervals. Blocked attempts and policy violations are visible to administrators in a live security dashboard.

4. Audit and accountability

Actions across the platform are written to an append-only audit trail. Notes and records lock after signing, medication administration is witnessed where required, and finance movements carry evidence and approval chains — supporting regulatory evidence requirements across jurisdictions (such as the CQC in England and equivalent care regulators worldwide).

5. Encryption and infrastructure

Data is encrypted in transit and at rest. The platform runs on managed, access-controlled infrastructure with no public exposure of service keys, and privileged operations are confined to audited server-side processes.

6. Data subject requests

Ostorra includes a built-in data-request register so organisations can log, assign, track and evidence subject access, rectification and erasure requests within statutory timeframes.

7. Incident response

Suspected personal-data breaches are assessed, contained and documented without delay. Where a breach meets the notification threshold under the applicable law, the affected organisation is informed promptly so it can meet its own regulator-notification duty within the required timeframe (72 hours under GDPR/UK GDPR and equivalent deadlines elsewhere).