• Trust Centre
  • Data Security & GDPR

We take your data as seriously as you do.

It’s one of your organisation’s biggest priorities, so it’s one of our greatest responsibilities.

  • UK GDPR & DPA 2018

  • Bank-level encryption

  • UK & EU data residency

DS-security-posture dashboard

2FA

on a private cluster, with permissions granted only where needed

Daily

vulnerability scanning, with quarterly audits and risk assessments

UK & EU

data residency across Microsoft Azure and Amazon AWS regions

Key features

Key features

We combine industry-standard best practice measures with our technology expertise, all wrapped around our understanding of your specific business and culture. This ensures the highest level of security, so you can focus your efforts instead on the people management and business initiatives that drive value. That’s an HR headache taken care of.

Advanced Encryption

Uses firewalls, HTTPS, and bank-level encryption to secure data and communications.

Secure Authentication

Authenticates over SSL/TLS and stores data in an encrypted form.

Segregated Data Protection

Segregates and tokenizes sensitive data for added security.

Access Control Measures

Restricts data access with two-factor authentication and strict permissions.

Continuous Security Monitoring

Performs regular scans, audits, and updates to maintain security.

DS-encryption-layers dashboard displaying encryption layers

How we look after your data

Storage, security and privacy.

  • Employing firewalls, HTTPS, and bank-level encryption to secure networks, communications, and data for a higher level of security and privacy
  • Authenticating over SSL/TLS (Transport Layer Security) and tokenising and storing data in an encrypted data store
  • Segregating and tokenizing all sensitive data, adding an extra layer of data protection
DS-access-permissions displayed on a dashboard

How we look after your data

Secure access controls.

  • Storing data in a private cluster that’s only accessible via two-factor authentication, for added physical and technical protection
  • Maintaining a permissions-led regime that grants access only to those employees who need to see customer data for valid reasons
DS-security-activity-log shown on a dashboard

How we look after your data

Data kept up-to-date.

  • Staying up-to-the-minute on security updates to software libraries and applying any patches or bug fixes as needed to protect from threats
  • Performing daily vulnerability scanning and assessment, as well as quarterly audits and risk assessments on services and data stores, to ensure we’re adhering to our internal security policy requirements
  • Maintaining internal security policies, including network security, logical access, credentialing, passwords, and data classification
  • Working with consultants and outside counsel to ensure our processes and controls are consistent with best practices
DS-data-processing-agreement dashboard

How we look after your data

A contracted commitment.

  • Representing in our customer documentation that we will maintain a security programme consistent with industry standards
  • Ensuring all clients are protected by a Data Processing Agreement
DS-data-residency-map showing Azure and AWS locations

Data storage location

Your data stays in the UK and EU.

All HR Duo data, including biometric data, is stored in either Microsoft Azure Data Centre UK South region or Amazon AWS EU-West-1 Data Centre.

  1. Biometric data included
  2. Regional data centres only

GDPR with HR Duo

Your data, handled lawfully.

HR Duo is designed to support full compliance with UK and EU data protection laws, including the UK GDPR and Data Protection Act 2018. HR Duo processes personal data under clearly defined legal bases:

CONTRACTUAL NECESSITY

Delivering your services

To deliver HR software, payroll, and workforce management services.

CONSENT

Marketing & cookies

For marketing, cookies, and optional communications. You can withdraw consent at any time.

LEGITIMATE INTEREST

Running & improving

To run and improve the HR platform.

LEGAL OBLIGATION

Where the law requires

Where required by law, such as responding to legal authorities.

No selling or misuse of data.

HR Duo does not sell or share personal data with third parties for commercial gain. Data is only shared where necessary to deliver services or meet legal requirements. Any third-party processors are bound by strict data protection agreements.

  • Every client protected by a Data Processing Agreement

Security you can rely on

An HR headache, taken care of.

See how HR Duo keeps your workforce data secure and compliant — while you focus on the people management and business initiatives that drive value.

FAQs

Where is my data stored?

All HR Duo data, including biometric data, is stored in either the Microsoft Azure Data Centre UK South region or the Amazon AWS EU-West-1 data centre — keeping your data within UK and EU regions.

How is my data encrypted?

We use firewalls, HTTPS and bank-level encryption to secure networks, communications and data. Authentication runs over SSL/TLS, and data is tokenised and stored in an encrypted data store, with sensitive data further segregated.

Who can access customer data?

Data is held in a private cluster accessible only via two-factor authentication. We maintain a permissions-led regime that grants access only to those employees who need to see customer data for valid reasons.

Is HR Duo GDPR compliant?

HR Duo is designed to support full compliance with UK and EU data protection laws, including the UK GDPR and Data Protection Act 2018. We process personal data under clearly defined legal bases, and every client is protected by a Data Processing Agreement.

Do you sell or share my data?

No. HR Duo does not sell or share personal data with third parties for commercial gain. Data is only shared where necessary to deliver services or meet legal requirements, and any third-party processors are bound by strict data protection agreements.

How do you stay ahead of new threats?

We stay up to the minute on security updates and apply patches as needed, perform daily vulnerability scanning plus quarterly audits and risk assessments, and work with consultants and outside counsel to keep our processes consistent with best practice.