Last updated · July 2026
You're sending us documents that can include criminal record information (DBS certificates), health information, and other sensitive personal data. This page sets out exactly what we do with it, in plain terms.
When you send a worker's compliance file for review, we receive whatever you include — typically a DBS certificate, training or registration certificates, references, and right-to-work evidence. Verifying a certificate against a registration or check-service record requires the certificate holder's details (name, certificate/registration number) to be present — this can't be removed without preventing the check itself. If you prefer, you can label the file with your own internal worker reference alongside the required details, so you can match it to your own records.
Document storage and hosting are UK/EU-based, with access restricted to the review process. Where AI-assisted tools are used as part of the review, processing may occur under standard data protection safeguards (such as UK GDPR-compliant transfer mechanisms); we do not claim this specific step occurs exclusively on UK/EU infrastructure.
Only the individual(s) at StaffingAudit conducting the review. We do not sell, share, or use your documents or worker data for any purpose beyond producing your report.
Under UK GDPR, you can ask us what data we hold, ask us to delete it, or ask us to stop processing it at any time. Contact us at hello@staffingaudit.co.uk and we'll respond within statutory timescales.
ICO Registration: ZC184040
Data controller: SYLOQ Limited, registered in England & Wales, No. 16971248
Contact: hello@staffingaudit.co.uk
If this policy changes, we'll update the date at the top of this page. Material changes affecting how we handle documents already submitted will be communicated directly.