ReportRxClinical activity tracking
NHS governance Dashboard Completeness The report
Clinician log in Book a demo
Report Rx Ltd

Data protection

Supplier assurance information for information governance leads, DPOs and procurement teams.

Last updated 13 September 2026

At a glance — for information governance leads

  • No patient-identifiable data. ReportRx records activity counts and categories only.
  • Our role: data processor. The customer organisation remains the controller.
  • Hosting: processed in the UK (London), stored in the EU (Ireland). Nothing outside the UK or EU.
  • Special category data: none processed.
  • Data processing agreement: provided as standard with every contract.

This page sets out how ReportRx handles data for the organisations that use it. It is written for information governance leads, Caldicott Guardians, DPOs and procurement teams carrying out supplier assurance. Our general privacy policy covers personal data more broadly.

1. What ReportRx processes

ReportRx is a clinical activity tracking and productivity reporting platform. It holds:

  • Staff account data — name, work email address, job role, and the organisational unit the user belongs to.
  • Activity records — counts of clinical activity recorded against defined workstreams, with a date and organisational unit.
  • Audit data — sign-in events and a record of who recorded or amended what, and when.

What ReportRx does not process

The platform holds no patient-identifiable data. It does not accept and is not designed to store patient names, NHS numbers, dates of birth, addresses, contact details, clinical notes, diagnoses or prescribing records. Activity is captured as aggregate counts, not as patient-level records.

It follows that ReportRx processes no special category data relating to patients, and no confidential patient information as defined by the common law duty of confidentiality. There is no requirement for section 251 support, and the National Data Opt-Out does not apply.

The personal data that is processed relates to staff — the clinicians and administrators using the system — and is ordinary employment-context personal data.

2. Controller and processor roles

DataControllerOur role
Staff accounts and activity records in the platformThe customer organisationProcessor
Contract and billing contactsReport Rx LtdController
Website visitors and enquiriesReport Rx LtdController

As processor we act only on the customer's documented instructions. We do not use customer data for our own purposes, do not sell it, and do not use it to train machine learning models.

3. Lawful basis

The lawful basis for processing staff data within the platform is determined by the customer as controller. In practice this is usually the performance of a task carried out in the public interest (UK GDPR Article 6(1)(e)) for NHS organisations, or legitimate interests (Article 6(1)(f)) for independent providers, in each case for the purpose of workforce management, service oversight and assurance. As no special category data is processed, no Article 9 condition is required.

4. Where data is held

Application data is stored in the European Union (Ireland) and processed by servers in the United Kingdom (London). No application data is stored or processed outside the UK or the EU. Data is encrypted in transit using TLS and at rest using AES-256.

Sub-processorPurposeLocation
SupabaseDatabase, authentication, file storageEuropean Union (Ireland)
VercelApplication hosting and content deliveryUnited Kingdom (London)
ResendTransactional emailEuropean Union
Google WorkspaceBusiness email and calendarUnited Kingdom / European Union

We maintain this list and will give customers notice of any change to our sub-processors, with an opportunity to object, as set out in our data processing agreement. Where a sub-processor operates in the European Union, that country benefits from UK adequacy regulations; any transfer outside the UK or an adequate country is covered by the UK International Data Transfer Addendum.

5. Security measures

Access control

  • Row-level security enforced at the database layer, so a user can only retrieve data belonging to their own organisation.
  • Role-based permissions determining what each user can see and do within their organisation.
  • Multi-factor authentication on all administrative and infrastructure accounts.
  • Least-privilege access for our own personnel, reviewed periodically. Access to customer data is limited to what is necessary to support the service and is logged.

Technical measures

  • Encryption in transit (TLS 1.2 or above) and at rest (AES-256).
  • Automated daily backups with point-in-time recovery.
  • Audit logging of authentication events and data changes.
  • Dependency and vulnerability monitoring, with security patches applied promptly.
  • Separation of development, staging and production environments. Production data is not used in development.

6. Data breach notification

We will notify the affected customer without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting their data, providing the information the customer needs to meet its own obligations to the Information Commissioner and to data subjects. We will cooperate fully with the customer's investigation.

7. Supporting your obligations

  • DPIA — we provide the information you need to complete a data protection impact assessment, and will answer supplier assurance questionnaires on request.
  • Data subject requests — we assist the customer in responding to access, rectification, erasure and portability requests within the statutory timeframe.
  • Audit — we make available the information necessary to demonstrate compliance and will accommodate reasonable audit requests.

8. Retention and exit

We retain customer data for the duration of the contract. On termination, we will export the customer's data in a structured, commonly used format on request, and delete our copies — including from backups, in line with our backup rotation — within 90 days, unless a longer period is required by law or agreed in writing.

9. Data processing agreement

A written data processing agreement compliant with Article 28 of the UK GDPR is provided as standard with every customer contract. It covers the subject matter and duration of processing, the nature and purpose, the types of data and categories of data subject, and our obligations as processor. You can read it in full before contracting, and download a signable copy from that page.

10. Contact

For data protection queries, supplier assurance questionnaires or a copy of our data processing agreement, contact hello@reportrx.co.uk.

Report Rx Ltd
Imperial House
79–81 Hornby Street
Bury
BL9 5BN
Company number 17359078

ReportRxClinical activity tracking

Clinical activity tracking and productivity reporting for clinical teams across primary and community care.

Product
The dashboard The report How it works Sign in
Company
Report Rx Ltd Company no. 17359078 Imperial House
79–81 Hornby Street
Bury
BL9 5BN
Contact
hello@reportrx.co.uk Book a demo
© 2026 ReportRx. All rights reserved. Privacy policy · Terms · Data protection · DPA