HomeGuides › Security and Data Protection — WorkerRecord

Security and data protection

How we protect your documents and your workers' data

You're uploading sensitive compliance documents — insurance certificates, DBS disclosures, medical records, professional registrations. Here is a plain English summary of how that data is protected.

Your documents are private

Documents uploaded to WorkerRecord are stored on private, encrypted storage. There are no public URLs for any document. Every download is authenticated — a document can only be accessed by a signed-in member of your team. If you were to share a URL with someone outside your account, it would not work.

Access is limited to your account

WorkerRecord is used by many companies, but data is completely isolated between them. Your documents, workers, and compliance records are accessible only to your team. Every action that accesses your data — downloads, approvals, exports — checks that the person making the request belongs to your account.

Payments are handled by Stripe

Card details never pass through our servers. Payment information is captured directly by Stripe — a PCI DSS Level 1 certified payment processor — and only a subscription reference is stored on our side. We never see or store card numbers or CVVs.

UK GDPR compliance

WorkerRecord processes personal data on behalf of its customers. We are a data processor under UK GDPR; you are the data controller. This relationship is governed by our Data Processing Agreement, which covers your rights, our obligations, sub-processor details, and breach notification procedures.

Data is stored on servers in the UK and European Economic Area. No personal data is transferred outside the UK/EEA without appropriate safeguards.

Connections are encrypted

All connections to WorkerRecord use HTTPS. The application enforces this with HTTP Strict Transport Security — browsers will refuse to connect over an unencrypted connection.

If you are procuring on behalf of a larger organisation and need a full technical security overview — covering authentication controls, file validation, HTTP security headers, injection prevention, incident response procedures, and the complete sub-processor list — we can provide that document on request.

Request the full security document

For procurement teams and data protection officers who need specifics, we have a detailed technical security overview available on request. Contact us and we'll send it within one working day.

Request security document

Official sources

HSE ↗ SIA ↗ DVSA ↗ CQC ↗ Environment Agency ↗ Traffic Commissioners ↗
About this guide: Our content is reviewed with the help of industry professionals and draws on primary sources including DVSA, SIA, CQC, Environment Agency, and HSE publications. Regulations change — we recommend verifying current requirements directly with the relevant authority before making compliance decisions.