Trust Centre

Security and compliance, on the record.

We handle sensitive employee data for multi-site employers. This is how we protect it, and the evidence your due diligence team will ask for.

Last reviewed · 8 October 2026

Certified

Cyber Essentials

Penetration tested

26 July 2026

ICO registered

00014496640

Encrypted

AES-256 at rest

01 · Certification and testing

Checked by people who are not us.

  • Cyber Essentials certified. View our certificate on the Blockmark register.

  • Independently penetration tested, every year. Latest test 26 July 2026. Summary letter available under NDA.

  • Registered with the ICO. Registration number 00014496640.

02 · How we protect your data

Locked down by default.

  • Encryption. All personal data encrypted at rest (AES-256) and in transit (TLS 1.2 or higher).

  • Admin access. Two-factor sign-in on every Workplace Reporting staff account.

  • Access. Three roles: Super Admin, Admin and Manager. Each client sees only its own data, and managers see only their own sites.

  • Audit. Every access to health information logged, and logs kept for at least 12 months.

  • Infrastructure. Web application firewall, with admin access restricted behind a virtual firewall.

  • Backups. Automated daily backups.

  • Leaving. Your data returned in a machine-readable format, or deleted with written confirmation.

03 · Where your data is held

Clear about where it goes.

  • Absence records and transcripts. Stored in the UK and EEA.

  • Call audio. Stored in the EU, never publicly accessible, and deleted automatically after 5 days.

  • The voice line and notifications. Some processing by specialist providers in the US, covered by Standard Contractual Clauses and the UK IDTA.

  • Named sub-processors. Listed in our Data Processing Agreement and security pack, with 30 days notice of any change.

04 · AI and your data

Used to take the call, never to train a model.

  • No training. Call recordings, transcripts and absence records are never used to train AI models.

  • Callers are told. Every caller hears at the start that the line uses AI.

  • People decide. The AI records, summarises and flags. Your managers make every employment decision.

05 · GDPR and contracts

The paperwork, already done.

  • An Article 28 Data Processing Agreement, accepted at first login, with every acceptance timestamped.

  • A personal data breach reported to you within 48 hours, so you can meet the ICO's 72-hour deadline.

  • Absence reasons can include health information. Access is limited by role, and every view is logged.

06 · The line

Answered by us, not an overseas call centre.

  • Every call comes to one number, answered day or night.

  • Sensitive reasons such as bereavement or caring responsibilities are handled with care, and detail is limited in the general inbox email.

  • Recordings. Deleted automatically 5 days after the call.

  • Transcripts and absence records. Kept for as long as you are with us, so every employee's history stays complete when a trigger point or a hearing comes round. When you leave, they are returned to you or deleted, and we confirm it in writing.

07 · The company

A UK company that answers its own phone.

Workplace Reporting Ltd, registered in England and Wales. Company number 17267362. Carpenter Court, 1 Maple Road, Bramhall, Stockport, Cheshire, SK7 2DH.

Data protection and support: 0333 041 3226 · office@workplacereporting.co.uk

08 · The security pack

One PDF for your due diligence team.

  1. Cyber Essentials certificate

  2. Penetration test summary letter

  3. Information security overview

  4. Data Processing Agreement and sub-processor list

  5. Ready answers to a standard supplier security questionnaire