Where your data lives, and how to check it

Your own database and your own application service, encrypted in transit and at rest, hosted in the UK. Every claim below is one you can check.

Data privacy

Your employee data sits in its own database, encrypted, and reachable only by your organisation.

Reliability

Built on AWS, with high availability. Anyone on your team can reach it from a browser.

Compliance

We meet UK GDPR and the Data Protection Act 2018. The data processing agreement sets out how.

How we protect your data.

Encryption, access controls and where your data physically sits. Each one is set out below with what backs it.

Complete data isolation

Your data is stored in a protected location unique to your organisation. Each customer gets their own isolated application service, meaning your data is processed completely separately from other organisations.

This applies to everything: timesheets, employee records, custom exporters, and more. No one outside your organisation can access any of your data.

  • Dedicated database per organisation
  • Isolated application services
  • Role-based access controls

End-to-end encryption

All data is encrypted using well-established protocols. We use TLS 1.2+ for data in transit and AES-256 for data at rest, the same standards used by banks and government agencies.

User credentials are additionally protected using secure hashing algorithms, ensuring passwords are never stored in plain text and are inaccessible even to our team.

  • TLS 1.2+ for all connections
  • AES-256 encryption at rest
  • Secure password hashing

UK data centre security

Your data is hosted entirely within the UK on Amazon Web Services (AWS) London region infrastructure. This means your data never leaves the UK and is subject to UK data protection laws.

AWS secures the buildings themselves: 24/7 surveillance, biometric access controls and continuous monitoring, under their own ISO 27001 and SOC 2 certifications. Those are AWS's certificates and cover their facilities - the certification of Chinchill.hr is ours, and is set out below.

  • UK-only data residency (London region)
  • 24/7 physical security & monitoring
  • AWS-certified data centre facilities

AWS Partner expertise

We are a recognised partner on the AWS Partner Network, which gives us access to AWS training and support.

  • AWS Partner Network member
  • AWS-certified engineers

Independently certified

Fat Potato Limited holds ISO 27001 and Cyber Essentials Plus. The scope of both covers the development and operation of Chinchill.hr, and the production AWS estate this platform runs on sat inside both assessed boundaries.

  • ISO 27001: information security management
  • Cyber Essentials Plus: independently tested technical controls
  • Both scoped to this platform, not just the company

5

controls, and what backs each one

Built for UK businesses.

These are the obligations that apply to a system holding UK employee data, and what each one means here.

  • UK GDPR compliant

    Full compliance with UK General Data Protection Regulation requirements.

  • Data Protection Act 2018

    Adherence to all requirements of the UK Data Protection Act.

  • Clear data processing

    Transparent DPA outlining exactly how we process your data.

  • Data subject rights

    Full support for access, rectification, erasure, and portability requests.

  • Appointed DPO

    Dedicated Data Protection Officer overseeing compliance.

  • UK data residency

    All data stored and processed within UK borders.

6

obligations, and how each is met

Your people's data stays your data.

Questions about security?

We're happy to answer any questions about how we protect your data. Book a demo or get in touch with our team.