A breach with bank details and NI numbers is reportable to the ICO within 72 hours and can result in fines up to ยฃ17.5m. We treat your team's data accordingly.
AES-256 across the whole database. Bank sort codes, account numbers and NI numbers have an additional field-level encryption layer using a separate master key in Supabase Vault โ even a leaked database key wouldn't expose them.
Every table is locked down at the database. Staff can never query other staff's data, managers see only their site, payslips are HR-confidential. 59 RLS policies covering 26 tables โ bypassed by no UI bug.
Every sensitive action โ login, payslip view, bank update, RTW sign-off โ recorded with actor + IP + timestamp. Append-only at the database trigger level: nobody, including us, can edit or delete entries. Used for tribunal defence.
You are the Controller, we are the Processor. DPA available on request. Subject access requests, erasure requests and data exports supported within 30 days.
Registered with the Information Commissioner's Office under the Data Protection Fee. Registration number visible on this page once active.
UK government-backed certification proving baseline cyber-security controls. Renewed annually.
Retention rules baked in: PAYE 3 years, RTW 2 years post-employment, employment contracts 6 years (Limitation Act 1980), audit log 6 years.
The third-party services we use to operate WorkHive. Full list in our Sub-processor list.
If we ever detect a security incident:
Full plan documented in our Breach Response Plan.
Found something? Email security@workhive.co.uk. We respond within 24 hours.
Need our DPA, sub-processor list, or other compliance documentation for your own records? Email security@workhive.co.uk โ we respond within 1 working day.