Last updated: 2026-08-20

Privacy policy

Cue HR (Dorset, United Kingdom), operated by Kamila Matczak, is the data controller for the personal data described in this document.

This policy explains what personal data Cue HR collects, why we hold it, and what rights you have under UK GDPR and the Data Protection Act 2018. It applies to visitors to cuehr.co.uk, prospective clients using the contact form, and users of the client portal (both admin and client roles).

What we collect

Marketing site: minimal - no analytics cookies by default. Server logs record IP and user agent for security and rate-limit enforcement (retention: 30 days).

Contact form: name, email, company, employee count, message, submission timestamp, source IP. Stored to respond to your enquiry.

Client portal accounts: name, work email, encrypted password hash, organisation, role, locale preference, two-factor status, last-login timestamp.

Employee records (managed by clients): full name, contact email, phone, job title, employment type, start/end dates, probation dates, right-to-work status + evidence dates, notes. Data provided by the client organisation.

HR case records: case type, timeline notes, stage changes, attached documents. Client-organisation scoped, admin-only visibility.

Tickets and messages: message content, timestamps, sender, ticket status transitions.

Uploaded documents: file content stored privately in Vercel Blob storage, downloaded only through authenticated proxy after access-scope check.

Audit log: every write action (login, doc upload/download, ticket reply, case update) with actor, IP, timestamp, and target entity, kept indefinitely for compliance.

Legal basis for processing

  • Contract (Art. 6(1)(b) UK GDPR): to provide the services you or your employer signed up for.
  • Legitimate interests (Art. 6(1)(f)): security logging, rate limiting, audit trail for tribunal defence.
  • Consent (Art. 6(1)(a)): for marketing communications (opt-in only; you can unsubscribe at any time).
  • Legal obligation (Art. 6(1)(c)): tax and employment records retained per HMRC and statutory requirements.
  • Special category data (employee sickness, health records): processed under Art. 9(2)(b) - employment law obligations of the employer.

Retention

Contact-form submissions: kept until resolved plus 12 months.

Client portal accounts: for the duration of the contract, plus 6 years after termination (HMRC and tribunal defence window).

Employee records: for the duration of employment plus 6 years after termination.

HR case records: 6 years after case closure.

Uploaded documents: same as the record they attach to.

Audit log: 6 years minimum, indefinite for security-critical events.

Server logs: 30 days.

Who we share data with

Sub-processors we use to run the service:

  • Vercel Inc. (hosting, edge network) - EU region (Frankfurt) for compute, US-based company.
  • Neon Inc. (Postgres database) - EU region (Frankfurt).
  • Upstash Inc. (rate-limit + notification cache) - EU region (Frankfurt).
  • Resend Inc. (transactional email) - EU region for sending, US-based company.

International transfers to the US rely on the UK-US Data Bridge and Standard Contractual Clauses where required. We do not sell personal data. We do not use it to train AI models.

Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you (subject-access request).
  • Have inaccurate data corrected.
  • Have your data erased (subject to legal-retention limits - e.g., HMRC 6-year rule).
  • Restrict or object to processing.
  • Data portability where processing is by consent or contract.
  • Withdraw consent for marketing at any time.
  • Complain to the Information Commissioner’s Office (ICO): https://ico.org.uk.

Security

Passwords are hashed with argon2id (OWASP 2023 moderate parameters). TOTP secrets encrypted at rest with AES-256-GCM. Recovery codes stored as SHA-256 hashes. Sessions are HttpOnly, SameSite=Lax, 14-day rolling expiry, invalidated on password reset.

HTTPS enforced via HSTS. Content Security Policy is nonce-based (no unsafe-inline scripts). Every write action is audit-logged with actor, IP, and target.

Documents are stored privately in Vercel Blob and served only through an authenticated proxy that checks organisation membership before streaming.

Data protection enquiries and subject-access requests: dpo@cuehr.co.uk. Postal address: Cue HR, Dorset, United Kingdom.

Cue HR - Senior HR for UK SMEs, in English and Polish