Last updated 2026-08-29.
Cairn Workforce ("Cairn", "we", "us", "our") provides a workforce management platform (the "Platform") for security companies — rota scheduling, timesheets, compliance tracking (SIA licences, right-to-work), incident reporting, and payroll support.
Cairn Workforce Ltd is a company incorporated in Scotland. Registered office: Office 639, 18 Young St, UNIT LGE, Edinburgh, EH2 4JB, Scotland.
Data protection registration: registered with the UK Information Commissioner's Office, registration reference ZC230954.
Contact for privacy queries: info@cairnworkforce.co.uk
This policy explains how Cairn collects, uses, and protects personal data when a client security company (the "Client") uses the Platform to manage its own staff ("Officers"). It applies to:
For the personal data of a Client's staff (Officers), the Client is the data controller and Cairn is the data processor, acting on the Client's instructions under a Data Processing Agreement (see the separate DPA workstream — not yet executed).
What this means in practice: if you are an Officer and have a question about how your data is used, your first point of contact should usually be your employer (the Client company), not Cairn directly — though we will always help route a request correctly.
For Client company account holders' own data (their name, email, login activity, billing details), Cairn is the controller.
| Category | Examples | Collected from |
|---|---|---|
| Account details | Name, email, role, login/session data | Account holder, at registration or invite |
| Identity & compliance | Date of birth, address, postcode, SIA licence number/type/expiry, right-to-work document type/expiry, uploaded ID/licence photos | Officer, during onboarding |
| Emergency contact | Contact name, phone, relationship | Officer, during onboarding |
| Employment | Job role, pay rate, start/end date, site assignment | Client company (manager) |
| Shift & attendance | Rota assignments, shift offers/acceptances, clock-in/out times, GPS location at clock-in (where enabled) | Generated by Platform use |
| Payroll | Hours worked, pay rate, calculated gross pay | Generated by Platform use, from the above |
| Incidents & performance | Incident reports, performance notes, disciplinary records | Client company (manager), Officer (incident reports) |
| Billing | Company billing contact, Direct Debit mandate reference (not full bank details — held by our payment processor, GoCardless) | Client company, via GoCardless |
We do not collect more than the above without updating this policy — see the data minimisation principle in our internal Data Retention Policy (e.g. raw DBS check data is deliberately not collected; SIA licence verification is used instead).
Special category data (none is deliberately collected — the Platform does not ask for health, biometric, or similar data) is out of scope of normal use; if this changes, this policy will be updated with an explicit lawful basis under UK GDPR Article 9.
Cairn uses the following subprocessors to run the Platform. None of them use Platform data for their own purposes beyond providing their service to us.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting, authentication, file storage | UK (London region, where configured) |
| Vercel | Application hosting / serverless compute | UK region, where configured |
| Resend | Transactional email (invites, password resets, notifications) | USA — see §7 |
| GoCardless | Direct Debit payment processing for Client subscriptions | UK |
We do not sell personal data, and do not share it with any party outside this list except where required by law, or with the Client's own explicit instruction (e.g. exporting their own staff data).
Supabase, Vercel, and GoCardless are configured to process and store data in the UK. Resend, our transactional email provider (invites, password resets, notifications), processes data in the USA — confirmed via Resend's own published subprocessor list, which shows its infrastructure providers (Amazon Web Services, Vercel Inc., PlanetScale, Snowflake, Supabase Inc.) are all US-based. This transfer is covered by the Standard Contractual Clauses in Resend's own Data Processing Addendum, which extend to transfers from the UK, EEA, and Switzerland. If this changes — a new subprocessor, or a change to an existing one's processing location — we'll update this policy to describe the transfer safeguard in place at the time.
Retention periods are set out in our internal Data Retention Policy, summarised here:
| Category | Retention after employment ends |
|---|---|
| Core identifying details (DOB, address, emergency contact) | 3 months |
| Name, employee number | 6 years |
| SIA licence & right-to-work records | 2 years |
| Payroll, timesheets, expenses | 6 years |
| Incident reports, performance/disciplinary records | 6 years |
| Training records | 2 years |
| Leave/absence records | 2 years |
| Notifications | 90 days (not tied to employment) |
| GPS/location data | 90 days (not tied to employment) |
At the end of each period, we anonymise the relevant fields rather than deleting the whole record, so that the Client's own historic reports (payroll, incident, disciplinary) remain intact without identifying the individual. This runs automatically on a daily schedule. Full detail and rationale: internal Data Retention Policy document.
Under UK GDPR, you have the right to:
To exercise these rights, contact your employer (the Client company) if you're an Officer, or Cairn directly for account-holder data. A manager at your employer can action a right-to-erasure request directly from your staff profile once your employment has ended; other requests (access, portability, rectification) are currently handled manually.
You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) if you believe your data has been mishandled.
Data is encrypted in transit (HTTPS) and at rest (via Supabase's managed Postgres). Access to Client data is scoped by row-level security so one Client company cannot see another's data. Compliance documents (SIA badge photos, right-to-work proof) are stored in a private, non-public storage bucket.
We'll update this policy as the Platform and its data practices evolve, and note the date of the most recent change at the top of the document. Material changes affecting Client companies will be communicated directly.
Cairn · Security Workforce Management