Supplier assurance information for information governance leads, DPOs and procurement teams.
This page sets out how ReportRx handles data for the organisations that use it. It is written for information governance leads, Caldicott Guardians, DPOs and procurement teams carrying out supplier assurance. Our general privacy policy covers personal data more broadly.
ReportRx is a clinical activity tracking and productivity reporting platform. It holds:
The platform holds no patient-identifiable data. It does not accept and is not designed to store patient names, NHS numbers, dates of birth, addresses, contact details, clinical notes, diagnoses or prescribing records. Activity is captured as aggregate counts, not as patient-level records.
It follows that ReportRx processes no special category data relating to patients, and no confidential patient information as defined by the common law duty of confidentiality. There is no requirement for section 251 support, and the National Data Opt-Out does not apply.
The personal data that is processed relates to staff — the clinicians and administrators using the system — and is ordinary employment-context personal data.
| Data | Controller | Our role |
|---|---|---|
| Staff accounts and activity records in the platform | The customer organisation | Processor |
| Contract and billing contacts | Report Rx Ltd | Controller |
| Website visitors and enquiries | Report Rx Ltd | Controller |
As processor we act only on the customer's documented instructions. We do not use customer data for our own purposes, do not sell it, and do not use it to train machine learning models.
The lawful basis for processing staff data within the platform is determined by the customer as controller. In practice this is usually the performance of a task carried out in the public interest (UK GDPR Article 6(1)(e)) for NHS organisations, or legitimate interests (Article 6(1)(f)) for independent providers, in each case for the purpose of workforce management, service oversight and assurance. As no special category data is processed, no Article 9 condition is required.
Application data is stored in the European Union (Ireland) and processed by servers in the United Kingdom (London). No application data is stored or processed outside the UK or the EU. Data is encrypted in transit using TLS and at rest using AES-256.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | European Union (Ireland) |
| Vercel | Application hosting and content delivery | United Kingdom (London) |
| Resend | Transactional email | European Union |
| Google Workspace | Business email and calendar | United Kingdom / European Union |
We maintain this list and will give customers notice of any change to our sub-processors, with an opportunity to object, as set out in our data processing agreement. Where a sub-processor operates in the European Union, that country benefits from UK adequacy regulations; any transfer outside the UK or an adequate country is covered by the UK International Data Transfer Addendum.
We will notify the affected customer without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting their data, providing the information the customer needs to meet its own obligations to the Information Commissioner and to data subjects. We will cooperate fully with the customer's investigation.
We retain customer data for the duration of the contract. On termination, we will export the customer's data in a structured, commonly used format on request, and delete our copies — including from backups, in line with our backup rotation — within 90 days, unless a longer period is required by law or agreed in writing.
A written data processing agreement compliant with Article 28 of the UK GDPR is provided as standard with every customer contract. It covers the subject matter and duration of processing, the nature and purpose, the types of data and categories of data subject, and our obligations as processor. You can read it in full before contracting, and download a signable copy from that page.
For data protection queries, supplier assurance questionnaires or a copy of our data processing agreement, contact hello@reportrx.co.uk.
Report Rx Ltd
Imperial House
79–81 Hornby Street
Bury
BL9 5BN
Company number 17359078