Trust Centre
Security and compliance, on the record.
We handle sensitive employee data for multi-site employers. This is how we protect it, and the evidence your due diligence team will ask for.
Last reviewed · 8 October 2026
Certified
Cyber Essentials
Penetration tested
26 July 2026
ICO registered
00014496640
Encrypted
AES-256 at rest
01 · Certification and testing
Checked by people who are not us.
Cyber Essentials certified. View our certificate on the Blockmark register.
Independently penetration tested, every year. Latest test 26 July 2026. Summary letter available under NDA.
Registered with the ICO. Registration number 00014496640.
02 · How we protect your data
Locked down by default.
Encryption. All personal data encrypted at rest (AES-256) and in transit (TLS 1.2 or higher).
Admin access. Two-factor sign-in on every Workplace Reporting staff account.
Access. Three roles: Super Admin, Admin and Manager. Each client sees only its own data, and managers see only their own sites.
Audit. Every access to health information logged, and logs kept for at least 12 months.
Infrastructure. Web application firewall, with admin access restricted behind a virtual firewall.
Backups. Automated daily backups.
Leaving. Your data returned in a machine-readable format, or deleted with written confirmation.
03 · Where your data is held
Clear about where it goes.
Absence records and transcripts. Stored in the UK and EEA.
Call audio. Stored in the EU, never publicly accessible, and deleted automatically after 5 days.
The voice line and notifications. Some processing by specialist providers in the US, covered by Standard Contractual Clauses and the UK IDTA.
Named sub-processors. Listed in our Data Processing Agreement and security pack, with 30 days notice of any change.
04 · AI and your data
Used to take the call, never to train a model.
No training. Call recordings, transcripts and absence records are never used to train AI models.
Callers are told. Every caller hears at the start that the line uses AI.
People decide. The AI records, summarises and flags. Your managers make every employment decision.
05 · GDPR and contracts
The paperwork, already done.
An Article 28 Data Processing Agreement, accepted at first login, with every acceptance timestamped.
A personal data breach reported to you within 48 hours, so you can meet the ICO's 72-hour deadline.
Absence reasons can include health information. Access is limited by role, and every view is logged.
06 · The line
Answered by us, not an overseas call centre.
Every call comes to one number, answered day or night.
Sensitive reasons such as bereavement or caring responsibilities are handled with care, and detail is limited in the general inbox email.
Recordings. Deleted automatically 5 days after the call.
Transcripts and absence records. Kept for as long as you are with us, so every employee's history stays complete when a trigger point or a hearing comes round. When you leave, they are returned to you or deleted, and we confirm it in writing.
07 · The company
A UK company that answers its own phone.
Workplace Reporting Ltd, registered in England and Wales. Company number 17267362. Carpenter Court, 1 Maple Road, Bramhall, Stockport, Cheshire, SK7 2DH.
Data protection and support: 0333 041 3226 · office@workplacereporting.co.uk
08 · The security pack
One PDF for your due diligence team.
Cyber Essentials certificate
Penetration test summary letter
Information security overview
Data Processing Agreement and sub-processor list
Ready answers to a standard supplier security questionnaire

