Data privacy
Your employee data sits in its own database, encrypted, and reachable only by your organisation.
Reliability
Built on AWS, with high availability. Anyone on your team can reach it from a browser.
Compliance
We meet UK GDPR and the Data Protection Act 2018. The data processing agreement sets out how.
How we protect your data.
Encryption, access controls and where your data physically sits. Each one is set out below with what backs it.
Complete data isolation
Your data is stored in a protected location unique to your organisation. Each customer gets their own isolated application service, meaning your data is processed completely separately from other organisations.
This applies to everything: timesheets, employee records, custom exporters, and more. No one outside your organisation can access any of your data.
- Dedicated database per organisation
- Isolated application services
- Role-based access controls
End-to-end encryption
All data is encrypted using well-established protocols. We use TLS 1.2+ for data in transit and AES-256 for data at rest, the same standards used by banks and government agencies.
User credentials are additionally protected using secure hashing algorithms, ensuring passwords are never stored in plain text and are inaccessible even to our team.
- TLS 1.2+ for all connections
- AES-256 encryption at rest
- Secure password hashing
UK data centre security
Your data is hosted entirely within the UK on Amazon Web Services (AWS) London region infrastructure. This means your data never leaves the UK and is subject to UK data protection laws.
AWS secures the buildings themselves: 24/7 surveillance, biometric access controls and continuous monitoring, under their own ISO 27001 and SOC 2 certifications. Those are AWS's certificates and cover their facilities - the certification of Chinchill.hr is ours, and is set out below.
- UK-only data residency (London region)
- 24/7 physical security & monitoring
- AWS-certified data centre facilities
AWS Partner expertise
We are a recognised partner on the AWS Partner Network, which gives us access to AWS training and support.
- AWS Partner Network member
- AWS-certified engineers
Independently certified
Fat Potato Limited holds ISO 27001 and Cyber Essentials Plus. The scope of both covers the development and operation of Chinchill.hr, and the production AWS estate this platform runs on sat inside both assessed boundaries.
- ISO 27001: information security management
- Cyber Essentials Plus: independently tested technical controls
- Both scoped to this platform, not just the company
Cyber Essentials Plus
Independently tested technical controls
Assessed by CYBERTEC
View the certificate
5
controls, and what backs each one
Built for UK businesses.
These are the obligations that apply to a system holding UK employee data, and what each one means here.
UK GDPR compliant
Full compliance with UK General Data Protection Regulation requirements.
Data Protection Act 2018
Adherence to all requirements of the UK Data Protection Act.
Clear data processing
Transparent DPA outlining exactly how we process your data.
Data subject rights
Full support for access, rectification, erasure, and portability requests.
Appointed DPO
Dedicated Data Protection Officer overseeing compliance.
UK data residency
All data stored and processed within UK borders.
6
obligations, and how each is met
Your people's data stays your data.
We only process it on your instruction.
Your documented instructions, and what the law requires. Nothing we decide on our own.
We never sell it, and never use it for advertising or unrelated profiling.
Our own analytics stop at aggregated, anonymous metrics, and that limit is written into the agreement rather than assumed.
It lives in London.
Your database and application service run in AWS's London region, and the agreement commits us to keeping your data in the UK or EU.
You get 30 days notice before we add a sub-processor.
And 14 days to object on data protection grounds.
You take it with you when you leave.
Your data stays available to export as CSV or JSON for 30 days after termination. We securely delete it within 90 days, and confirm that in writing on request.
Questions about security?
We're happy to answer any questions about how we protect your data. Book a demo or get in touch with our team.