This policy sets out how the Company collects, uses, stores, secures and disposes of personal data in line with the UK GDPR and the Data Protection Act 2018. It applies to all personal data processed through the Mostlane Portal and related systems, covering employees, workers, contractors and customer contacts.
The Company is the data controller. Day-to-day responsibility sits with [name / role]. The Company is not required to appoint a statutory Data Protection Officer but has designated the above person as the point of contact for data protection matters.
The Company processes personal data: lawfully, fairly and transparently; for specified purposes only; limited to what is necessary; kept accurate; retained no longer than necessary; and kept secure.
| Category | Examples | Lawful basis |
|---|---|---|
| Staff records | Name, username, email, phone, permissions, pay rate | Contract; legal obligation |
| Working time | Clock in/out, timesheets, shifts, holiday | Legal obligation (Working Time Regs); contract |
| Employment documents | Contracts, letters, policies (in the staff documents area) | Contract; legal obligation |
| Job & site records | Job notes, photos, signatures, site & customer contacts | Contract; legitimate interests |
| Security data | Login history, IP address, device records, audit log | Legitimate interests (system security) |
Personal data is kept only as long as necessary for the purpose or as required by law, then deleted or anonymised.
| Record | Retention period | Reason |
|---|---|---|
| Payroll, pay & working-time records | 6 years after the tax year | HMRC / statutory |
| Holiday & shift history | 6 years | Working Time Regulations |
| Employment contracts & HR file | 6 years after leaving | Limitation Act / disputes |
| Job sheets, site photos, signatures | 6 years after job completion | Contract / liability |
| Login history, IP, device records, audit log | 12 months (auto-pruned) | Security; data minimisation |
| Unsuccessful applicants / leavers’ access | Access removed immediately on leaving | Data minimisation |
The portal automatically prunes its security audit log and login history at 12 months. Longer-retained records (payroll, HR, job history) are reviewed annually and deleted or anonymised once their period expires.
Individuals have the right to be informed, to access their data, to rectification, to erasure, to restrict or object to processing, and to data portability. The portal provides a one-click data export (access/portability) and erasure (anonymise & close) for each person, via My Documents (administrator function). Requests should be sent to [contact email] and will be answered within one month.
Any suspected breach must be reported immediately to [contact]. Where a breach is likely to result in a risk to individuals, it will be reported to the ICO within 72 hours of becoming aware, and affected individuals informed where the risk is high.
The Company uses the following processors, each under a data processing agreement. Where data is transferred outside the UK, an approved safeguard (UK adequacy or the International Data Transfer Agreement) applies.
| Processor | Purpose |
|---|---|
| Cloudflare | Hosting, database (D1), file storage (R2) |
| Resend | Transactional email (password / welcome) |
| Google Maps Platform | Mapping & geocoding of site addresses |
| PDFShift | Generating job-sheet PDFs |
| [others as applicable] |
This policy is reviewed at least every 12 months, or sooner if the law or our systems change materially.
Signed: [name] · Position: [role] · Date: [date]