WorkplaceHero
For IT teams and procurement

Security and data protection

The short version for IT teams, procurement reviewers and data protection leads: where your data lives, how it is protected, who can see it and what happens if something goes wrong. The full legal detail is in our privacy policy and terms.

Where your data lives

Your organisation's records, CPD logs and learner files are stored on managed cloud infrastructure in the European Union (EU Ireland region). The website is delivered from a global edge network, so pages load quickly wherever your staff are.

Our infrastructure providers are independently certified against SOC 2 Type II and ISO 27001:2022 and operate in line with UK GDPR and EU GDPR. We do not move your data outside the UK and EU.

How it is protected

Everything travels over an encrypted connection (TLS). Data at rest - the database and stored documents such as certificates and uploads - is encrypted by the underlying storage. Course materials, certificates and learner documents are handed out through short-lived signed links rather than public web addresses.

Access is protected by role-based permissions at the application layer and row-level security at the database layer, so even a bug cannot quietly hand one account's data to another.

Who can see what

Your staff's CPD log belongs to the learner. Personal reflections and notes are always private. Organisation managers see a summary of each member's activity (total hours, number of entries, last activity) and can only read full entries where that person has explicitly chosen to share them.

Individual learners can only see their own records. Staff and admin accounts are protected with multi-factor authentication.

If something goes wrong

We monitor the service continuously and investigate anything unusual. If a personal data breach affects your organisation, we will tell you without undue delay and within 72 hours of becoming aware of it, with the information you need to meet your own obligations under UK GDPR.

Retention and deletion

We keep personal data only as long as we need it. Certificates and assessment evidence are retained for the period required by awarding organisations and qualification regulators; routine logs are cleared on shorter cycles. The full schedule is in our privacy policy.

You can export everything we hold about you, or delete your account and its data, from My account at any time - no phone call required.

Governance and accountability

WorkplaceHero is registered with the Information Commissioner's Office as a data controller, registration number ZB616407. Our data protection contact is hello@workplacehero.co.uk.

We keep records of our processing activities and our retention schedule, review sub-processors before they are added, and can answer security and data protection questionnaires directly - email us and we will respond.

Sub-processors

These providers help us run the service and may handle personal data on our behalf. All are bound by written contracts that restrict what they may do with your data. We will give reasonable notice before adding or replacing a sub-processor.

ProviderWhat they do for usWhere
Lovable Cloud (Supabase)Database, accounts, authentication and file storage for the WorkplaceHero platformEuropean Union (Ireland region)
CloudflareDelivers the WorkplaceHero website from a global edge networkGlobal edge network, EU-first routing
Lovable managed emailDelivers transactional emails such as confirmations, invites and certificatesEuropean Union
Lovable AI gateway (leading model providers)Powers the in-app assistant and helps us review and improve course contentEuropean Union / United States, under Lovable's enterprise terms
StripeCard payments and invoicingEuropean Union and United States
KlarnaInstalment payment options on course checkoutsEuropean Union
Focus AwardsAwarding organisation for regulated qualifications - receives registration and assessment data for enrolled learnersUnited Kingdom
HighfieldCourse platform for Highfield e-learning courses; learners are set up on Highfield's own systemsUnited Kingdom

Data processing agreement

Organisations that need a signed agreement before enrolling staff can download our standard data processing agreement. It sets out our obligations as a processor under Article 28 of UK GDPR, including security measures, breach notification, assistance with data subject rights and deletion at the end of the contract. If your own DPA needs countersigning, email us and we will review it with you.

Download the DPA (PDF)

Report a security issue

If you have found a security problem in our website or platform, please tell us before going public so we can fix it. Email hello@workplacehero.co.uk with the details and we will acknowledge your report, investigate and keep you informed. We will not pursue legal action against good-faith researchers who respect other people's data and privacy.