Dextro Trust & Privacy Center

Enterprise-grade security.
Total transparency.

As a Healthcare Recruitment Agency handling sensitive candidate files and Right-to-Work documents, your candidates' data is protected by best-in-class UK infrastructure and strict data processing agreements.

How your data flows securely

A documented, encrypted pipeline from your agency to our Operations Desk.

Secure Magic Links

You drop candidate details via WhatsApp. We instantly generate an encrypted portal for secure upload.

UK Hosted Infrastructure

Supabase & Vercel (London). AES-256 Encryption, Row Level Security (RLS).

Authorised Operators

Strictly authenticated access. Nigeria operations protected by IDTA safeguards.

Technical & Organisational Measures (TOMs)

We enforce strict engineering and personnel protocols to ensure client data is securely managed.

Encryption & Storage

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. We utilize Supabase (PostgreSQL) running on UK-hosted cloud infrastructure to ensure data sovereignty.

Row Level Security (RLS)

We implement strict Row Level Security (RLS) policies. This means that at the database level, queries are strictly constrained by tenant IDs to ensure complete data isolation between accounts.

Secure Architectures

We utilize cryptographically secure UUIDs for all resource endpoints. Our application is hosted on Vercel's global edge network, providing built-in DDoS protection, automatic SSL, and high availability.

Personnel Security

Our remote operators undergo identity verification and reference checks. We enforce a strict Clean Desk Policy and utilize operational workspace policies that prohibit the local storage or downloading of any client files.

Vulnerability Management

Our infrastructure undergoes automated dependency scanning and regular security reviews aligned with UK Cyber Essentials and ICO guidelines to proactively address vulnerabilities.

Continuous Monitoring

All authentication events and database queries are continuously logged. Access logs are actively monitored to ensure only authorized personnel interact with client endpoints.

Our Data Protection Framework

We provide complete transparency before you even start your pilot.

1. Data Processing Agreement (DPA)

Under UK GDPR, you remain the Data Controller. Dextro acts exclusively as a Data Processor. We only process candidate information upon your direct instructions, strictly for the purpose of chasing and verifying compliance. We execute a standard DPA with all clients prior to onboarding.

2. International Data Transfers

Our operations adhere strictly to UK GDPR Chapter V on international data access. Because our human administration operations are based in Nigeria, we execute a full Data Processing Addendum incorporating the UK International Data Transfer Addendum (IDTA). Our operators work directly inside your provisioned UK tenant environment via encrypted endpoints with zero local file caching.

3. Subprocessor Register

We partner only with industry-leading, ISO 27001-certified infrastructure providers. Our core subprocessors include:

  • Supabase: Database and Auth (AWS London)
  • Vercel: Hosting and Edge Network
  • Resend: Transactional Email

4. Incident Response & DSARs

In the unlikely event of a data breach, we commit to a prompt GDPR-compliant notification to the Data Controller. Furthermore, if a candidate submits a Data Subject Access Request (DSAR) directly to us, we immediately route that request to you (the Controller) for instruction, rather than acting independently.

5. Data Retention & Deletion

Automated Document Purging. Once a candidate's compliance pack is complete, the required documents are synced back to your agency's OneDrive. We permanently purge candidate data from Dextro's systems via automated routines 30 days after verification completion to minimize your risk footprint.

6. Strict Operational Boundaries

We manage the administration; you manage the risk. We do not make hiring decisions, clinical judgements, or provide regulated safeguarding advice. If a DBS certificate is flagged, or a candidate document is unclear, our team immediately escalates the file to your team for review.

Compliance Resources

Download our standardized Data Processing Agreement and our full Technical & Organisational Measures document for your procurement team.

Speak to our DPO

Have specific questions about how we handle International Transfers or UK GDPR compliance? Contact our Data Protection Officer directly.

privacy@dextrohq.com →

Ready to test the workflow?

Experience the security and efficiency of a managed compliance desk.

Start Dextro Risk-Free