Information we process
The system may process information needed to operate and support the workforce, including:
- Candidate and Worker identity, account, contact, profile, work-history, preference and emergency-contact information;
- National Insurance, bank and payment, HMRC, payroll and wage information where the relevant Candidate or payroll route is in use;
- Right to Work, PONI and proof-of-address evidence, together with identity and duplicate-account checks;
- site photo or CCTV notice acknowledgement where that notice applies; the system does not collect facial templates, face geometry or other biometric identifiers;
- attendance scan-in and scan-out records, including QR or PIN attendance method information where used;
- availability submissions, shift bookings, attendance corrections, and review outcomes;
- absence or reporting information where it is used for operational review;
- welfare or safeguarding information where it is reported and authorised staff need it for their role;
- worker document/resource access and announcement or attachment visibility where relevant;
- bug or issue reports, including optional screenshots uploaded by users;
- admin, client, and worker account access metadata where relevant to security, audit, or troubleshooting;
- reports, exports, and client-visible reporting outputs where authorised.
Medical and night-work health information and criminal declarations are available only in controlled synthetic demonstration routes. Real-person use remains disabled until the separate approvals, notices and operational safeguards for those routes are complete.
Layered privacy information is shown before the related account, identity, Right to Work, National Insurance and payroll information is collected.
Why we use this information
Information is used only for appropriate system and workforce purposes, including:
- workforce operations and attendance management;
- shift planning, availability review, and booking administration;
- payroll readiness, timesheet review, reconciliation, and attendance dispute review;
- client read-only reporting where applicable and authorised;
- support, audit, security, troubleshooting, and system improvement.
Who may see information
Information is available only through the access routes and roles provided by the system. Authorised People Solutions admin, payroll, operations and support users may access information needed for their work. Workers may view their own relevant records, resources and announcements. Authorised client portal users may see limited read-only client reporting where applicable.
Payroll information is limited to payroll-authorised users. Right to Work, PONI, proof-of-address and other compliance information is limited to the applicable authorised reviewers. Welfare, safeguarding, health and criminal information has narrower role-based access.
Client access does not grant admin write access, worker-management actions, payroll controls or system-administration rights. Support or admin reviewers may see submitted issue reports according to the system's access rules.
Reports, documents and screenshots
Issue reports and screenshots
Submitting an issue report is a support activity. Screenshots are optional and may contain personal, payroll, client or operational information visible on the page. Avoid uploading unnecessary sensitive information and crop or redact screenshots where practical. Screenshots are reviewed only by authorised system or admin users according to the system's access rules.
Documents and announcements
Worker documents, resources, announcements and announcement attachments may be made available through authenticated system routes. Direct storage access should not be used as the normal way to access these files.
Reports and exports
Reports and exports may contain worker identifiers and operational data. They should be used only for authorised operational, payroll, support, audit and client-reporting purposes.
Retention
An incomplete Candidate account and application follow a fixed schedule from account creation. Reminders are sent on days 5, 10 and 13, and the complete account and application are deleted after 15 calendar days, on day 15. Activity does not restart that schedule. Accounts with submitted applications and Worker-linked accounts are excluded from this deletion. An active Candidate-scoped legal hold pauses deletion while reminders continue.
Issue-report content and optional screenshots are retained for 12 months from their original creation unless an active legal hold pauses disposal. After disposal, value-free audit information may be retained for six years. Other records follow their approved category-specific retention periods and hold controls.
Your rights
You can ask People Solutions for information about your data-protection rights, including access, correction, restriction, objection or deletion where the law applies.
Candidate account creation and Candidate application review do not make a solely automated identity, clearance, merge or readiness decision. Automated checks can route a possible match or expired evidence for authorised human review.
Security
The system uses practical safeguards such as authenticated access, role-based access controls, protected file serving, password hashing and limited client visibility. These safeguards reduce risk, but no system can promise absolute security.
Contact
For questions about this notice, attendance records, system access or support requests, contact People Solutions at support@ps.endera.co.uk.