Last updated: 2026-08-20

Data protection

Cue HR (Dorset, United Kingdom), operated by Kamila Matczak, is the data controller for the personal data described in this document.

This page describes how Cue HR positions itself under UK GDPR - who is controller, who is processor, what technical and organisational measures apply, and how a data-breach would be handled.

Controller vs processor

For personal data of contact-form submitters and portal users (name, email, account activity) Cue HR is the data controller.

For personal data of a client organisation’s employees stored in the portal (employee records, RTW evidence, case notes, uploaded documents), the client organisation is the controller and Cue HR is the processor acting on documented instructions.

A written data-processing agreement (DPA) is signed at commercial onboarding for every client; a template is available on request.

Technical measures

  • Encryption in transit: TLS 1.2+ enforced, HSTS with 180-day max-age.
  • Encryption at rest: Neon Postgres (AES-256), Vercel Blob (AES-256), 2FA secrets AES-256-GCM with an app-managed key.
  • Passwords hashed with argon2id (OWASP moderate parameters).
  • Session cookies HttpOnly, SameSite=Lax, 14-day rolling, invalidated on password reset.
  • Nonce-based Content Security Policy; no unsafe-inline scripts.
  • Rate limiting on every auth surface + contact form.
  • Full audit log on every write action.
  • Documents served through an authenticated proxy that verifies org membership before streaming (no publicly guessable file URLs).

Organisational measures

Admin role is limited to Kamila Matczak and Łukasz Matczak. Both use unique per-user accounts and 2FA-enabled logins. Sub-processor access is governed by their own SOC 2 / ISO 27001 controls.

Backups are covered by Neon’s built-in point-in-time recovery (7-day window on the current plan, extendable). We keep two snapshot branches at each launch milestone for rapid rollback.

Data-breach response

A confirmed personal-data breach triggers the following: contain the breach, assess scope and severity, notify affected client organisations without undue delay, and notify the ICO within 72 hours where the breach is likely to result in risk to individuals. Where the risk is high, affected individuals are also notified. A written incident record is retained for at least 5 years.

Sub-processors

Current sub-processors:

  • Vercel Inc. - hosting + edge network, EU (Frankfurt) for compute.
  • Neon Inc. - Postgres database, EU (Frankfurt).
  • Upstash Inc. - rate-limit + notification cache, EU (Frankfurt).
  • Resend Inc. - transactional email, EU for sending.

We will publish updates here before onboarding any new sub-processor that handles personal data.

DPO contact: dpo@cuehr.co.uk. A signed copy of the DPA template is available on request.

Cue HR - Senior HR for UK SMEs, in English and Polish