ISO Care logo

ISO Care

Data Processing Addendum

Version 1.0 · Last updated: 22 August 2026 · Effective: 22 August 2026

This Data Processing Addendum (“DPA”) sets out the terms on which Offboard HQ Ltd processes Customer Personal Data on behalf of a customer care organisation through ISO Care.

This DPA forms part of the ISO Care Terms of Service and the Agreement whenever Offboard HQ Ltd processes Customer Personal Data as processor on behalf of a Customer. No electronic signature is required on this page.

1. Scope and relationship to the Agreement

This DPA applies where Offboard HQ Ltd processes personal data on behalf of a Customer organisation through ISO Care, including the ISO Care software service and the ISO Care companion mobile application.

Processor: Offboard HQ Ltd, company number 17015641, registered office 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

Controller: the care organisation that uses ISO Care and determines the purposes and means of the relevant processing of Customer Personal Data.

This DPA is intended to meet the requirements of Article 28 of the UK GDPR for processing carried out by Offboard HQ Ltd as processor. It does not replace the Customer’s own privacy information to data subjects, nor Offboard HQ Ltd’s Privacy Policy for processing where Offboard HQ Ltd acts as controller.

2. Definitions

In this DPA, the following terms have the meanings below. Terms such as “personal data”, “special category data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the UK GDPR unless the context requires otherwise.

  • Agreement means the contract under which the Customer uses ISO Care, including the ISO Care Terms of Service and any order, trial or subscription terms that apply.
  • Applicable Data Protection Law means the UK GDPR, the Data Protection Act 2018 and other UK data-protection law applicable to the processing of Customer Personal Data under this DPA.
  • Customer (the Controller) means the care organisation using ISO Care.
  • Customer Personal Data means personal data processed by Offboard HQ Ltd on behalf of the Customer through ISO Care, as described in Schedule 1.
  • ISO Care means the ISO Care care-operations software service and companion mobile application provided by Offboard HQ Ltd, including related hosted infrastructure used to operate that service.
  • Processor means Offboard HQ Ltd.
  • Subprocessor means a third party engaged by Offboard HQ Ltd to process Customer Personal Data in connection with ISO Care.
  • UK GDPR means the United Kingdom General Data Protection Regulation as defined in the Data Protection Act 2018.

3. Roles of the parties

For Customer Personal Data processed through ISO Care to provide care-operations services to the Customer, the Customer is the controller and Offboard HQ Ltd is the processor.

Offboard HQ Ltd may separately act as controller for its own business activities. Those activities typically include trial and enquiry handling, account administration, authentication and security of the platform, support communications initiated with Offboard HQ Ltd, and related business records. That controller processing is outside the processor obligations in this DPA and is described in the Privacy Policy.

Offboard HQ Ltd does not decide the Customer’s purposes for care, staff or family records entered into ISO Care, and does not select the Customer’s Article 6 lawful basis or Article 9 condition.

4. Processing instructions

Offboard HQ Ltd shall process Customer Personal Data only on the Customer’s documented instructions, unless required to do so by UK law. In that case, Offboard HQ Ltd shall inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

The Customer’s documented instructions are:

  • this DPA, including Schedule 1;
  • the Agreement;
  • the Customer’s configuration of ISO Care and the actions of its authorised users in the service; and
  • other written instructions the Customer gives through agreed support or account channels that are consistent with the Agreement and Applicable Data Protection Law.

Offboard HQ Ltd shall immediately inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. That notice does not constitute legal advice and does not require Offboard HQ Ltd to monitor the lawfulness of the Customer’s underlying care or employment practices.

Offboard HQ Ltd is not obliged to follow an instruction that would require it to act unlawfully, compromise the security of ISO Care, or process data in a way ISO Care is not designed to support.

5. Controller obligations

The Customer remains responsible, as controller, for the lawfulness of its processing of Customer Personal Data. Without limiting Offboard HQ Ltd’s own processor duties under Applicable Data Protection Law, the Customer shall:

  • ensure that its instructions to Offboard HQ Ltd are lawful and documented;
  • ensure it has an appropriate Article 6 lawful basis, and an Article 9 condition where special-category data is processed;
  • provide required privacy information to data subjects (including service users, staff and family members) in respect of the Customer’s processing;
  • ensure that only authorised users are given access, and that roles, branches and permissions remain current;
  • not instruct Offboard HQ Ltd to process personal data unlawfully;
  • ensure that information uploaded to or entered into ISO Care is relevant and appropriate to the Customer’s care-operations purposes; and
  • remain primarily responsible for responding to data-subject requests relating to Customer Personal Data, with assistance from Offboard HQ Ltd as set out in this DPA.

6. Confidentiality

Offboard HQ Ltd shall ensure that persons authorised to process Customer Personal Data are under an appropriate duty of confidentiality, whether by contract or by statutory obligation.

Offboard HQ Ltd shall not disclose Customer Personal Data except as this DPA, the Agreement or Applicable Data Protection Law permits, or as required by a competent authority.

7. Security

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to individuals, Offboard HQ Ltd shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Those measures include the measures described in Schedule 2, which may be updated as ISO Care develops provided the overall security posture is not materially reduced without a corresponding improvement or notice where appropriate.

Schedule 2 describes measures that are actually used in ISO Care. It does not claim certification, absolute security, or 100% availability.

The Customer is responsible for configuring access within its organisation, for the security of devices and accounts under its control, and for instructing its users on appropriate use of ISO Care, including the mobile application’s offline capabilities.

8. Personal-data breaches

Offboard HQ Ltd shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notifications will be made using the Customer’s account or support contacts then on record, including support@isocare.uk where appropriate.

Offboard HQ Ltd shall provide reasonable information and assistance as it becomes available to help the Customer meet its own obligations, including a description of the nature of the breach (where known), the likely categories and approximate number of data subjects and records affected (where known), likely consequences, and measures taken or proposed.

The Customer remains responsible, as controller, for determining whether to notify the Information Commissioner’s Office and/or affected data subjects, and for making any such notifications. Offboard HQ Ltd will not make those controller notifications on the Customer’s behalf unless the parties agree otherwise in writing or Applicable Data Protection Law requires Offboard HQ Ltd to do so.

This clause does not impose a fixed contractual deadline (such as 24 hours) beyond the “without undue delay” standard.

9. Data-subject rights

Taking into account the nature of the processing, Offboard HQ Ltd shall provide reasonable technical and organisational assistance to the Customer in responding to requests from data subjects to exercise their rights under Applicable Data Protection Law in respect of Customer Personal Data.

Offboard HQ Ltd shall not independently determine or fulfil a request that relates to Customer Personal Data unless legally required to do so. Where a data subject contacts Offboard HQ Ltd about Customer Personal Data and it is practicable to identify the relevant Customer, Offboard HQ Ltd shall promptly refer or forward the request to the Customer.

ISO Care does not currently provide a self-service data-subject access pack or organisation-wide erasure workflow. Assistance will be provided through agreed support channels and the capabilities of the service as they exist at the time, which may include authorised-user access to records the Customer controls.

10. DPIAs and regulatory assistance

Taking into account the nature of the processing and the information available to Offboard HQ Ltd, Offboard HQ Ltd shall provide reasonable assistance to the Customer with:

  • the Customer’s security obligations under Applicable Data Protection Law relating to Customer Personal Data;
  • data protection impact assessments;
  • prior consultation with a supervisory authority; and
  • enquiries from the Information Commissioner’s Office or another competent authority relating to processing under this DPA.

Assistance is limited to information and measures reasonably available to Offboard HQ Ltd as processor. Offboard HQ Ltd is not required to provide legal advice or to disclose information that would compromise the security of ISO Care or other customers’ data.

11. Subprocessors

The Customer gives a general written authorisation for Offboard HQ Ltd to engage subprocessors to process Customer Personal Data as needed to provide ISO Care. The current approved subprocessors are listed in Schedule 3.

Offboard HQ Ltd may add or replace subprocessors. Where practicable, Offboard HQ Ltd will give the Customer reasonable advance notice of a material new subprocessor (for example by updating Schedule 3 on https://www.isocare.uk/dpa and/or by account or support communication).

The Customer may raise a reasonable, documented objection on data-protection grounds within a reasonable period after notice. The parties shall attempt in good faith to resolve the objection. The Customer does not have an unlimited veto that would prevent ISO Care from operating.

If no reasonable resolution is possible, the Customer may terminate the affected ISO Care service in accordance with the Agreement as its commercially reasonable remedy. Offboard HQ Ltd does not promise technical segregation that would allow ISO Care to continue without a material infrastructure subprocessor.

Offboard HQ Ltd shall impose data-protection obligations on subprocessors that provide an equivalent level of protection for Customer Personal Data as required by Applicable Data Protection Law. Offboard HQ Ltd remains responsible to the Customer for the performance of its subprocessors’ data-protection obligations to the extent required by UK GDPR Article 28.

12. International transfers

ISO Care’s production Supabase database is hosted in West EU (Ireland), AWS region eu-west-1. Vercel web compute for ISO Care is configured in Dublin. Other subprocessors may process personal data outside the United Kingdom, as noted in Schedule 3.

This DPA does not claim that all subprocessors, or all processing, remain within the United Kingdom or the European Economic Area.

If a restricted transfer of Customer Personal Data under UK GDPR occurs, Offboard HQ Ltd shall ensure that an appropriate lawful transfer mechanism is in place. Mechanisms may include UK adequacy regulations where they apply, the ICO International Data Transfer Agreement (IDTA), the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another valid safeguard recognised under UK law at the relevant time.

This DPA does not reproduce mandatory ICO IDTA clauses. Any required transfer mechanism may be incorporated separately or by reference where necessary. Not every international processing activity currently requires an IDTA.

If separately executed mandatory UK transfer clauses conflict with this DPA, those clauses prevail where legally required.

13. Return and deletion

Upon termination or expiry of the Agreement, and on the Customer’s written request, Offboard HQ Ltd shall return or delete Customer Personal Data in accordance with agreed offboarding procedures, except to the extent Applicable Data Protection Law or other applicable law requires retention.

ISO Care does not currently provide a self-service organisation export or instant organisation-wide database erasure. Return or deletion will be handled through support and offboarding processes using the capabilities available at the time.

Where immediate selective deletion from backups is technically impracticable, Customer Personal Data may remain in backups until those backups are overwritten or retired in the ordinary backup lifecycle. Retained backup data will remain subject to appropriate protection and will not be restored except for legitimate recovery or legal purposes. This DPA does not specify a backup retention period.

This clause does not require Offboard HQ Ltd to delete information it holds as controller, or information it must retain to establish, exercise or defend legal claims, to meet accounting or tax obligations, or otherwise as required by law.

14. Audits and compliance information

Offboard HQ Ltd shall make available to the Customer information reasonably necessary to demonstrate compliance with its obligations under UK GDPR Article 28 and this DPA.

The parties intend that this will ordinarily be satisfied by relevant security and privacy documentation, written answers to reasonable questionnaires, and other evidence reasonably available to Offboard HQ Ltd, rather than an on-site or intrusive technical audit.

Where an on-site inspection or technical audit is reasonably necessary to verify Article 28 compliance (including where documentation is insufficient, or Applicable Data Protection Law requires it), the Customer may exercise that right on reasonable written notice, during normal business hours, under confidentiality obligations, and in a manner that does not disrupt ISO Care, does not compromise security, and does not give access to other customers’ data. Offboard HQ Ltd may require the audit to be carried out by an independent auditor bound by confidentiality.

The Customer shall bear the costs of an audit that is unreasonable or excessive in scope or frequency, unless serious non-compliance by Offboard HQ Ltd is discovered or Applicable Data Protection Law requires otherwise. Nothing in this clause waives the Customer’s statutory audit rights under Article 28.

15. Liability

Liability arising under or in connection with this DPA is subject to the liability provisions of the Agreement (including the ISO Care Terms of Service), except to the extent Applicable Data Protection Law prohibits that limitation or exclusion. Those Terms include a general aggregate cap and a separate aggregate super-cap for breach of data-protection or confidentiality obligations. The super-cap is not additional recovery for the same loss.

This DPA does not create a separate unlimited liability regime. Nothing in this DPA excludes or limits liability that cannot lawfully be excluded or limited.

16. Priority and conflicts

If this DPA conflicts with the Agreement in respect of the processing of Customer Personal Data, this DPA prevails to the extent of that conflict.

Mandatory UK international transfer clauses, if separately executed, prevail where legally required.

For processing where Offboard HQ Ltd acts as controller, the Privacy Policy and the Agreement apply and this DPA does not govern that controller processing.

17. Changes

Offboard HQ Ltd may update this DPA from time to time, including to reflect changes in ISO Care, subprocessors, hosting arrangements or Applicable Data Protection Law. The current version will be published at https://www.isocare.uk/dpa with an updated date and version.

Material changes that affect the processing of Customer Personal Data will take effect in accordance with the Agreement, or otherwise on reasonable notice. Continued use of ISO Care after a change becomes effective constitutes acceptance of the updated DPA to the extent permitted by the Agreement and Applicable Data Protection Law.

18. Contact

Questions about this DPA or processing of Customer Personal Data may be sent to support@isocare.uk.

Offboard HQ Ltd
Company number: 17015641
Registered office: 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ

You may also use our Contact page.

19. Governing law

This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, consistently with the ISO Care Terms of Service, except to the extent Applicable Data Protection Law requires otherwise.

Schedule 1 — Details of Processing

Subject matter

Provision and operation of the ISO Care care-operations software service and companion mobile application for the Customer.

Duration

For the duration of the Customer’s ISO Care subscription or other Agreement, and any limited period afterwards required for secure return or deletion or for lawful retention. This Schedule does not set a fixed retention period.

Nature and purposes of processing

Processing as needed to provide ISO Care on the Customer’s instructions, which may include:

  • client/service-user record management;
  • care planning;
  • visit planning and delivery;
  • rota and workforce management;
  • check-in/check-out and attendance verification;
  • medication/eMAR;
  • notes and observations;
  • documents, forms and signatures;
  • family/guardian access;
  • staff records;
  • staff sickness and absence;
  • finance and invoicing;
  • reporting;
  • audit and accountability; and
  • offline mobile operation and synchronisation.

Categories of data subjects

Where applicable, and as entered or configured by the Customer:

  • clients/service users;
  • staff, carers and workers;
  • organisation owners and administrators;
  • guardians, family members and representatives;
  • payers and billing contacts; and
  • other authorised users or individuals whose information the Customer enters into ISO Care.

Types of personal data

Where applicable:

  • identity and contact details;
  • date of birth, address and contact information;
  • account and user identifiers;
  • workforce and employment information;
  • rota and visit records;
  • care plans and tasks;
  • notes and observations;
  • medication/eMAR information;
  • documents, forms and signatures;
  • guardian, family and legal-authority information;
  • finance and invoice information;
  • precise check-in/check-out GPS evidence;
  • device and sync identifiers; and
  • audit records.

Special-category data

ISO Care is designed so that authorised users may enter special-category data, including:

  • health and care needs;
  • allergies;
  • medical conditions;
  • medication;
  • NHS number;
  • DNR and other end-of-life information;
  • mobility and communication needs;
  • staff sickness and other staff health information; and
  • other health or care information entered by authorised users.

Offboard HQ Ltd does not decide the Customer’s lawful basis or Article 9 condition for this processing.

Schedule 2 — Technical and Organisational Measures

The following measures reflect ISO Care’s current implementation. They are not a certification, and they do not promise absolute security or uninterrupted availability.

  • Organisation (tenant) isolation of Customer data within the hosted service.
  • Database row-level security.
  • Branch-scoped access for relevant office users, and role and section access controls.
  • Authenticated access to the service.
  • Server-side handling of privileged credentials (service-role and similar secrets are not exposed to ordinary client sessions).
  • Audit logging of relevant actions.
  • Hashed invitation tokens for relevant staff and family invitation flows, rather than storing those tokens in recoverable plaintext.
  • Encryption in transit for communication with the hosted service.
  • Production Supabase database hosted in West EU (Ireland), AWS region eu-west-1.
  • Mobile authentication and session material stored using the device’s secure storage facilities provided for that purpose.
  • Controlled offline synchronisation and outbox mechanisms in the companion app.
  • A clean sign-out clears local offline operational data where the app’s sync state permits (unsynchronised work may block or alter that clearance until resolved).

The companion mobile application can temporarily store operational care information in a local SQLite database on the device to support offline working. That may include visit information, client identifiers and alerts, care tasks, medication information, notes and forms, check-in and check-out data, and GPS evidence. This DPA does not claim that that local SQLite database is encrypted.

Offboard HQ Ltd does not claim ISO 27001, SOC 2, Cyber Essentials, DSPT, HIPAA or “GDPR certification”, does not claim multi-factor authentication as a current ISO Care control in this Schedule, and does not publish backup recovery-point or recovery-time objectives in this DPA.

Schedule 3 — Approved Subprocessors

The Customer authorises the following subprocessors. This list reflects services currently used to operate ISO Care. Live ISO Care subscription payments are not enabled, so a payments processor is not listed.

  • Supabase — database, authentication and file storage. Production database region: West EU (Ireland), AWS eu-west-1.
  • Vercel — web hosting and web-application infrastructure. Web compute is configured in Dublin. Vercel Speed Insights is currently enabled for pre-launch performance monitoring.
  • Resend — transactional email where that sending is enabled in the relevant environment (for example invitations, owner setup messages, trial-application alerts and invoice emails). Password-reset messages are sent using the authentication provider’s email facilities.
  • Expo / EAS — mobile application tooling and build infrastructure.

Subprocessors may engage their own infrastructure providers (for example cloud regions). Use of a listed subprocessor does not mean that all processing by that subprocessor occurs in the United Kingdom or the EEA.