← Back to Cairn

Privacy Policy

Last updated 2026-08-29.


1. Who we are

Cairn Workforce ("Cairn", "we", "us", "our") provides a workforce management platform (the "Platform") for security companies — rota scheduling, timesheets, compliance tracking (SIA licences, right-to-work), incident reporting, and payroll support.

Cairn Workforce Ltd is a company incorporated in Scotland. Registered office: Office 639, 18 Young St, UNIT LGE, Edinburgh, EH2 4JB, Scotland.

Data protection registration: registered with the UK Information Commissioner's Office, registration reference ZC230954.

Contact for privacy queries: info@cairnworkforce.co.uk

2. Scope

This policy explains how Cairn collects, uses, and protects personal data when a client security company (the "Client") uses the Platform to manage its own staff ("Officers"). It applies to:

  • Client company staff (managers/administrators) who hold an account.
  • Officers whose employment/compliance/shift data the Client stores on the Platform.

3. Our role: processor, not controller

For the personal data of a Client's staff (Officers), the Client is the data controller and Cairn is the data processor, acting on the Client's instructions under a Data Processing Agreement (see the separate DPA workstream — not yet executed).

What this means in practice: if you are an Officer and have a question about how your data is used, your first point of contact should usually be your employer (the Client company), not Cairn directly — though we will always help route a request correctly.

For Client company account holders' own data (their name, email, login activity, billing details), Cairn is the controller.

4. What data we collect

CategoryExamplesCollected from
Account detailsName, email, role, login/session dataAccount holder, at registration or invite
Identity & complianceDate of birth, address, postcode, SIA licence number/type/expiry, right-to-work document type/expiry, uploaded ID/licence photosOfficer, during onboarding
Emergency contactContact name, phone, relationshipOfficer, during onboarding
EmploymentJob role, pay rate, start/end date, site assignmentClient company (manager)
Shift & attendanceRota assignments, shift offers/acceptances, clock-in/out times, GPS location at clock-in (where enabled)Generated by Platform use
PayrollHours worked, pay rate, calculated gross payGenerated by Platform use, from the above
Incidents & performanceIncident reports, performance notes, disciplinary recordsClient company (manager), Officer (incident reports)
BillingCompany billing contact, Direct Debit mandate reference (not full bank details — held by our payment processor, GoCardless)Client company, via GoCardless

We do not collect more than the above without updating this policy — see the data minimisation principle in our internal Data Retention Policy (e.g. raw DBS check data is deliberately not collected; SIA licence verification is used instead).

5. Lawful basis for processing

  • Contract — processing Officer employment/compliance/shift data is necessary for the Client to perform its employment contract with the Officer, and for Cairn to provide the Platform under its contract with the Client.
  • Legal obligation — retaining right-to-work and SIA licence records supports the Client's own legal obligations (illegal working checks, SIA licensing requirements).
  • Legitimate interests — Cairn's legitimate interest in operating, securing, and improving the Platform (e.g. diagnosing bugs, preventing abuse), balanced against individuals' rights.
  • Consent — where explicitly asked for and not otherwise covered above (e.g. optional push notification opt-in).

Special category data (none is deliberately collected — the Platform does not ask for health, biometric, or similar data) is out of scope of normal use; if this changes, this policy will be updated with an explicit lawful basis under UK GDPR Article 9.

6. Who we share data with (subprocessors)

Cairn uses the following subprocessors to run the Platform. None of them use Platform data for their own purposes beyond providing their service to us.

SubprocessorPurposeLocation
SupabaseDatabase hosting, authentication, file storageUK (London region, where configured)
VercelApplication hosting / serverless computeUK region, where configured
ResendTransactional email (invites, password resets, notifications)USA — see §7
GoCardlessDirect Debit payment processing for Client subscriptionsUK

We do not sell personal data, and do not share it with any party outside this list except where required by law, or with the Client's own explicit instruction (e.g. exporting their own staff data).

7. International transfers

Supabase, Vercel, and GoCardless are configured to process and store data in the UK. Resend, our transactional email provider (invites, password resets, notifications), processes data in the USA — confirmed via Resend's own published subprocessor list, which shows its infrastructure providers (Amazon Web Services, Vercel Inc., PlanetScale, Snowflake, Supabase Inc.) are all US-based. This transfer is covered by the Standard Contractual Clauses in Resend's own Data Processing Addendum, which extend to transfers from the UK, EEA, and Switzerland. If this changes — a new subprocessor, or a change to an existing one's processing location — we'll update this policy to describe the transfer safeguard in place at the time.

8. How long we keep data

Retention periods are set out in our internal Data Retention Policy, summarised here:

CategoryRetention after employment ends
Core identifying details (DOB, address, emergency contact)3 months
Name, employee number6 years
SIA licence & right-to-work records2 years
Payroll, timesheets, expenses6 years
Incident reports, performance/disciplinary records6 years
Training records2 years
Leave/absence records2 years
Notifications90 days (not tied to employment)
GPS/location data90 days (not tied to employment)

At the end of each period, we anonymise the relevant fields rather than deleting the whole record, so that the Client's own historic reports (payroll, incident, disciplinary) remain intact without identifying the individual. This runs automatically on a daily schedule. Full detail and rationale: internal Data Retention Policy document.

9. Your rights

Under UK GDPR, you have the right to:

  • Access — ask what personal data we (or, for Officer data, the Client as controller) hold about you.
  • Rectification — ask for inaccurate data to be corrected.
  • Erasure — ask for data to be deleted, subject to our legal retention obligations above.
  • Restriction — ask us to limit how we use your data in certain circumstances.
  • Portability — ask for your data in a portable format, where applicable.
  • Objection — object to processing based on legitimate interests.

To exercise these rights, contact your employer (the Client company) if you're an Officer, or Cairn directly for account-holder data. A manager at your employer can action a right-to-erasure request directly from your staff profile once your employment has ended; other requests (access, portability, rectification) are currently handled manually.

You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) if you believe your data has been mishandled.

10. Security

Data is encrypted in transit (HTTPS) and at rest (via Supabase's managed Postgres). Access to Client data is scoped by row-level security so one Client company cannot see another's data. Compliance documents (SIA badge photos, right-to-work proof) are stored in a private, non-public storage bucket.

11. Changes to this policy

We'll update this policy as the Platform and its data practices evolve, and note the date of the most recent change at the top of the document. Material changes affecting Client companies will be communicated directly.

Cairn · Security Workforce Management