Data Sub-processors & Systems Directory
Last Updated: July 2026
Document Reference: CMUK-DPA-SUB-004
At Care Match UK (CMUK), clinical safety, data integrity, and regulatory compliance sit at the heart of everything we do. Whether we are managing a paper-to-digital migration, executing system optimisation, or delivering ad-hoc technical support, we maintain strict adherence to UK GDPR, the Data Protection Act 2018, the Data Security and Protection Toolkit (DSPT), and CQC “Well-Led” standards.
Where Care Match UK acts as a Data Sub-processor (or Data Processor acting on instruction from care provider Data Controllers), we utilise a carefully vetted infrastructure of third-party software tools and care software platforms to deliver our services securely.
1. Operational & Business Support Infrastructure
These sub-processors enable Care Match UK to manage project pipelines, securely communicate with care teams, handle helpdesk tickets, and maintain commercial operations.
| Software / Partner Name | Description & Purpose of Processing | Location of Data | Transfer Safeguards & Compliance Frameworks |
| Gsuite for Business | Secure cloud-based collaboration, internal document architecture, and corporate email. | UK / EEA | UK GDPR Compliant, Standard Contractual Clauses (SCCs), Encrypted in Transit/Rest. |
| Bitrix24 | Customer Relationship Management (CRM) for pipeline management and operational workflows. | UK / EEA | UK GDPR Compliant, Data Processing Agreement (DPA). |
| Trello | High-level project pipeline management and non-PID task tracking. | UK / EEA / USA | UK GDPR Compliant, EU-US / UK Data Bridge Framework. |
| Jira | Technical ticket management, issue tracking, and software migration task allocation. | UK / EEA | UK GDPR Compliant, SOC2 Type II, ISO27001 Certified. |
| Intercom | Real-time customer support chat and user communication platform. | UK / EEA / USA | UK GDPR Compliant, DPA, Encrypted Endpoints. |
| Xero | Financial accounting, invoicing, and commercial ledger management. | UK / EEA | UK GDPR Compliant, ISO27001 Certified, Encrypted SSL/TLS. |
| 3CX | Business telecommunications, VoIP, and helpdesk telephony systems. | UK | UK GDPR Compliant, Ofcom Regulated, UK-Based Data Centres. |
| Microsoft Teams | Secure video conferencing, drop-in sessions, and remote steering group meetings. | UK / EEA | UK GDPR Compliant, Microsoft Enterprise Security Framework. |
| Mailchimp | Managed email communications, client newsletters, and system updates. | UK / EEA / USA | UK GDPR Compliant, Standard Contractual Clauses (SCCs). |
| WordPress | Client-facing web content management system (hosting directory notices & public resources). | UK | UK GDPR Compliant, Encrypted SSL, Cyber Essentials Managed Infrastructure. |
2. Client Digital Social Care Record (DSCR) & Care Tech Systems
During migration, auditing, or ad-hoc technical support, Care Match UK specialists access client environments via restricted, role-based permissions granted directly by the Data Controller.
Important Governance Note: Care Match UK operates on a real-time viewing and direct-entry model inside client environments. We do not extract, mirror, or store Personally Identifiable Data (PID) or resident clinical histories on local CMUK infrastructure. All access is strictly governed by password-protected credentials, Multi-Factor Authentication (MFA), and our formal Cyber Essentials Accreditation.
3. Data Governance & Security Assurances
To satisfy your CQC “Well-Led” audits and DSPT (Data Security and Protection Toolkit) compliance:
- Cyber Essentials Accredited: Care Match UK operates under formal Cyber Essentials Accreditation (Certificate Number: c89d10a1-e745-4c94-bbc4-9f74548070c2).
- Strict Sub-processor Notification Period: In accordance with our Master Services Agreements (MSA) and standard DPAs, Care Match UK provides clients with at least 14 days’ written notice prior to onboarding or replacing any new sub-processor involved in processing care data.
- Clean Data & Zero Local Retention: Upon project completion, all client-provided access tokens are immediately decommissioned. Source documents scanned at care homes are processed directly into the target DSCR environment, leaving zero resident footprints on local sub-processor hardware.
Questions or Data Protection Inquiries?
If you are a Registered Manager, Owner, or Data Protection Officer (DPO) requiring further information on our data governance framework or Data Processing Agreements (DPA), please contact our team:
- Email: hello@carematchuk.co.uk