Back to Home

Security & GDPR Compliance

Last Validated: June 2026

At MapMyCare, we understand that handling sensitive health and behavioral data for vulnerable young people requires the absolute highest standard of security. Our architecture is built from the ground up to ensure your organizational data is siloed, encrypted, and compliant.

UK Data Residency (GDPR)

100% of MapMyCare data—including databases, backups, and secure media storage—is hosted exclusively in the EU West 2 (London) data center. Your data never leaves the UK, ensuring complete compliance with the UK GDPR regulations regarding data sovereignty.

Row Level Security (RLS)

Our database enforces strict Row Level Security. Cross-organizational data leakage is impossible at the database kernel level. Staff members can only view profiles assigned to their specific Care Home ID.

Secure Media Buckets

Resident profile images and media are stored in a locked bucket. Anonymous access is physically blocked. Only users possessing a cryptographically signed, unexpired JWT session token can upload or view images.

Encrypted Transit & Storage

All data is encrypted in transit using industry-standard TLS 1.2+ and encrypted at rest on the database servers.

Role-Based Access

MapMyCare employs strict role-based access. Care Home Managers have total control over authorizing staff emails. Unapproved email addresses are physically blocked from viewing any data.