Home › Guides › Security and Data Protection — WorkerRecord

Security and data protection

Plain English. No marketing claims we can't back up.

You are uploading compliance evidence — insurance certificates, DBS disclosures, professional registrations, medical records. This page explains exactly how that data is protected, using only claims we can verify from our own codebase and infrastructure. If a claim appears below, it is true today.

Where your data lives

Files are stored in the EU — Stockholm (eu‑north‑1). Your data does not leave the EU at any point in normal operation, including when documents are read by our AI assistant (see below). Every connection to WorkerRecord uses HTTPS with HTTP Strict Transport Security (HSTS), so browsers will refuse to connect over an unencrypted connection.

How documents are encrypted

Documents are encrypted by WorkerRecord before they are written to storage, using a key that is not held by our cloud provider. This matters more than it might sound. Storage providers offer their own encryption at rest, but that decrypts transparently for anyone holding valid storage credentials — so it protects against a stolen disk, not against a compromised account. Because we encrypt in the application with a separate key, the contents of our storage bucket are unreadable ciphertext to anyone who obtains access to it.

Generated exports and recovery archives — which contain the same documents — are encrypted the same way, and are delivered through expiring signed links rather than public storage URLs.

AI-assisted document reading

When a document is uploaded, we can use an AI model to read its expiry date and suggest the document type, so your reviewer does not have to type them. This is switched off by default — you choose whether to enable it.

Who can see your documents

No document has a public URL. Every download is authenticated: a signed-in member of your team requests it, the application verifies that the document belongs to your account, and only then generates a temporary signed link. Guessing or sharing a link with someone outside your account will not work — both the authentication and the ownership check will fail.

Files are stored under a path that includes your account identifier and a UUID filename — meaning the original filename is never used on disk, and paths cannot be guessed. Uploaded files are also validated on file type before storage.

WorkerRecord is used by many companies. Data is completely isolated between accounts. Every read, write, and download checks that the person making the request belongs to your account. A cross-account probe returns a 404 — the same response as a missing record — so an attacker cannot confirm whether a document ID exists.

Deletion protection

When you remove a worker or delete a document, the record and its file are kept for 30 days before permanent deletion. This is a grace window — if a worker is removed by mistake, the records can be recovered within that period. After 30 days, the record and the file are permanently deleted.

GDPR erasure requests are processed immediately on request.

Your data is yours

You can export everything — your worker list, document status, and compliance history — as a CSV or ZIP file at any time from the Export page in your account. No request needed, no waiting, no fee. If you close your account, your export is available until the account is deactivated.

How long documents are kept

Most documents are kept for as long as you need them. Some are deliberately not: a DBS disclosure certificate is destroyed six months after it is approved, in line with the DBS Code of Practice, which asks that certificate information is not retained longer than necessary. The record of the check is kept — the date, the document type, and its reference — so you can still evidence to an inspector that the check was carried out. Only the certificate image is destroyed.

Right-to-work documents are treated the opposite way and are not automatically deleted, because the Home Office requires copies to be retained for the duration of employment plus two years.

Answering a subject access request

If one of your workers asks for the information held about them, you can export that worker's records and documents on their own — without disclosing anyone else's data. This is available from the worker's page in your account.

Payments

Card details never pass through our servers. Payment is captured directly by Stripe — a PCI DSS Level 1 certified processor — and only a subscription reference is stored on our side. We never see or store card numbers or CVVs.

UK GDPR

WorkerRecord processes personal data on behalf of its customers. We are a data processor under UK GDPR; you are the data controller. This relationship is governed by our Data Processing Agreement, which covers your rights, our obligations, sub-processor details, and breach notification procedures.

If you are procuring on behalf of a larger organisation and need a technical security overview, or a signed DPA before your procurement team will approve the purchase, contact us and we will provide it within one working day.

Questions about security?

Email hello@workerrecord.co.uk and we will respond within one working day. DPA requests, data subject access requests, and breach notifications can all go to the same address.

Official sources

HSE ↗ SIA ↗ DVSA ↗ CQC ↗ Environment Agency ↗ Traffic Commissioners ↗
About this guide: Our content is reviewed with the help of industry professionals and draws on primary sources including DVSA, SIA, CQC, Environment Agency, and HSE publications. Regulations change — we recommend verifying current requirements directly with the relevant authority before making compliance decisions.