StaffingAudit
← Back to home

Privacy & data handling

Last updated · July 2026

You're sending us documents that can include criminal record information (DBS certificates), health information, and other sensitive personal data. This page sets out exactly what we do with it, in plain terms.

What we collect

When you send a worker's compliance file for review, we receive whatever you include — typically a DBS certificate, training or registration certificates, references, and right-to-work evidence. Verifying a certificate against a registration or check-service record requires the certificate holder's details (name, certificate/registration number) to be present — this can't be removed without preventing the check itself. If you prefer, you can label the file with your own internal worker reference alongside the required details, so you can match it to your own records.

What we do with it

Where it's held

Document storage and hosting are UK/EU-based, with access restricted to the review process. Where AI-assisted tools are used as part of the review, processing may occur under standard data protection safeguards (such as UK GDPR-compliant transfer mechanisms); we do not claim this specific step occurs exclusively on UK/EU infrastructure.

Who sees it

Only the individual(s) at StaffingAudit conducting the review. We do not sell, share, or use your documents or worker data for any purpose beyond producing your report.

Your rights

Under UK GDPR, you can ask us what data we hold, ask us to delete it, or ask us to stop processing it at any time. Contact us at hello@staffingaudit.co.uk and we'll respond within statutory timescales.

ICO Registration: ZC184040
Data controller: SYLOQ Limited, registered in England & Wales, No. 16971248
Contact: hello@staffingaudit.co.uk

Changes to this policy

If this policy changes, we'll update the date at the top of this page. Material changes affecting how we handle documents already submitted will be communicated directly.