As a Healthcare Recruitment Agency handling sensitive candidate files and Right-to-Work documents, your candidates' data is protected by best-in-class UK infrastructure and strict data processing agreements.
A documented, encrypted pipeline from your agency to our Operations Desk.
You drop candidate details via WhatsApp. We instantly generate an encrypted portal for secure upload.
Supabase & Vercel (London). AES-256 Encryption, Row Level Security (RLS).
Strictly authenticated access. Nigeria operations protected by IDTA safeguards.
We enforce strict engineering and personnel protocols to ensure client data is securely managed.
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. We utilize Supabase (PostgreSQL) running on UK-hosted cloud infrastructure to ensure data sovereignty.
We implement strict Row Level Security (RLS) policies. This means that at the database level, queries are strictly constrained by tenant IDs to ensure complete data isolation between accounts.
We utilize cryptographically secure UUIDs for all resource endpoints. Our application is hosted on Vercel's global edge network, providing built-in DDoS protection, automatic SSL, and high availability.
Our remote operators undergo identity verification and reference checks. We enforce a strict Clean Desk Policy and utilize operational workspace policies that prohibit the local storage or downloading of any client files.
Our infrastructure undergoes automated dependency scanning and regular security reviews aligned with UK Cyber Essentials and ICO guidelines to proactively address vulnerabilities.
All authentication events and database queries are continuously logged. Access logs are actively monitored to ensure only authorized personnel interact with client endpoints.
We provide complete transparency before you even start your pilot.
Under UK GDPR, you remain the Data Controller. Dextro acts exclusively as a Data Processor. We only process candidate information upon your direct instructions, strictly for the purpose of chasing and verifying compliance. We execute a standard DPA with all clients prior to onboarding.
Our operations adhere strictly to UK GDPR Chapter V on international data access. Because our human administration operations are based in Nigeria, we execute a full Data Processing Addendum incorporating the UK International Data Transfer Addendum (IDTA). Our operators work directly inside your provisioned UK tenant environment via encrypted endpoints with zero local file caching.
We partner only with industry-leading, ISO 27001-certified infrastructure providers. Our core subprocessors include:
In the unlikely event of a data breach, we commit to a prompt GDPR-compliant notification to the Data Controller. Furthermore, if a candidate submits a Data Subject Access Request (DSAR) directly to us, we immediately route that request to you (the Controller) for instruction, rather than acting independently.
Automated Document Purging. Once a candidate's compliance pack is complete, the required documents are synced back to your agency's OneDrive. We permanently purge candidate data from Dextro's systems via automated routines 30 days after verification completion to minimize your risk footprint.
We manage the administration; you manage the risk. We do not make hiring decisions, clinical judgements, or provide regulated safeguarding advice. If a DBS certificate is flagged, or a candidate document is unclear, our team immediately escalates the file to your team for review.
Download our standardized Data Processing Agreement and our full Technical & Organisational Measures document for your procurement team.
Have specific questions about how we handle International Transfers or UK GDPR compliance? Contact our Data Protection Officer directly.
privacy@dextrohq.com →Experience the security and efficiency of a managed compliance desk.
Start Dextro Risk-Free