Privacy Policy
1. Who we are (Controller identity — UK GDPR Art-13(1)(a))
Recordme (“we”, “us”, “our”) is the data controller for personal data collected through this website and platform. Our registered company details, including our Companies House number, are published on our Imprint page. Our data protection contact is [email protected].
2. What personal data we collect
We collect and process the following categories of personal data:
- Account and identity data: name, email address, job title, employer organisation.
- Workforce records: employee onboarding information, working-time records, training completions, attendance and rota data, right-to-work documents, payroll data, return-to-work records, and incident reports — collected when your organisation uses Recordme for workforce compliance.
- Operational and food-safety records: temperature logs, allergen checks, pest-control records, checklist completions, audit records, and maintenance logs linked to specific sites and staff.
- Usage and technical data: IP address, browser type, pages visited, and error logs collected automatically to operate and improve the service.
- Communications data: the content of messages and support requests you send us.
Who the controller is for workforce and operational records: where your employer (or another organisation) uses Recordme to keep workforce, food-safety, or operational records about you, that organisation is the data controller of those records and Recordme processes them as its data processor under our Data Processing Agreement. Your employer’s own privacy notice governs that processing; this policy applies to the personal data for which Recordme is the controller (such as account, usage, and communications data).
3. Purposes and lawful bases (UK GDPR Art-13(1)(c)/(d))
We process personal data for the following purposes and lawful bases:
- Providing and operating the platform — necessary for the performance of our contract with you (UK GDPR Art-6(1)(b)).
- Workforce and food-safety compliance records — processed as your organisation’s data processor, on its documented instructions (UK GDPR Art-28). The underlying legal obligations these records satisfy — under the Food Safety Act 1990, Working Time Regulations 1998, RIDDOR 2013, and related regulations — rest on your organisation as controller, whose lawful basis is UK GDPR Art-6(1)(c).
- Improving the service and troubleshooting — legitimate interests in operating a reliable commercial service (UK GDPR Art-6(1)(f)). You may object to this processing at any time (see section 7), and you can contact [email protected] with any questions about this basis.
- Marketing communications — your consent, which you may withdraw at any time (UK GDPR Art-6(1)(a)).
- Special-category health data (where applicable in return-to-work or incident flows) — processing is necessary for the purposes of carrying out obligations in the field of employment law (UK GDPR Art-9(2)(b); Schedule 1, DPA 2018).
4. Retention periods (UK GDPR Art-13(2)(a))
We retain personal data for as long as necessary to fulfil the purpose for which it was collected and to comply with legal obligations:
- Food-safety records: minimum 5 years (FSA SFBB / HACCP minimum — Food Safety Act 1990 + UK Food Information Regulations).
- Working-time and attendance records: minimum 2 years (WTR 1998).
- Allergen records (PPDS labels / incident investigations): minimum 2 years (Natasha’s Law — Food Information (Amendment)(England) Regulations 2019; FIC 2014; FSA SFBB Pack §11 allergen records). Because of their life-safety significance, allergen declaration histories are kept as append-only records and may be retained beyond the statutory minimum under the applicable retention policy.
- Legionella (water-safety) records: minimum 5 years (ACOP L8).
- Workplace incident records (RIDDOR): minimum 3 years (Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 — SI 2013/1471, reg 12(1); HSE retention guidance). This covers injury reports, dangerous-occurrence reports, and occupational-disease reports notifiable to the Health and Safety Executive (HSE).
- Financial and payroll records: minimum 6 years (HMRC requirements).
- Right-to-work check evidence (immigration compliance): employment duration plus 2 years post-employment termination (Immigration, Asylum and Nationality Act 2006 — IDVT guidance; civil penalties for non-compliance up to £45,000 per worker for a first breach and £60,000 per worker for repeat breaches, in force since 13 February 2024).
- Return-to-work fitness assessments (food-safety health data) ⚠ Special-category data (UK GDPR Art-9 health data) — food-handler symptom-exclusion records (gastrointestinal symptoms, skin conditions, injuries, exclusion dates, and clinical notes) are health data under UK GDPR Art-9. Processing is necessary under Art-9(2)(b) (carrying out obligations in the field of employment law) and Art-9(2)(h) (purposes of preventive or occupational medicine and assessment of the working capacity of the employee), in conjunction with the Food Safety Act 1990 and the FSA Safer Food Better Business (SFBB) food-handler fitness-to-work requirements. Retained for 6 years from the employment end date (HMRC overlap — the most stringent applicable window per our retention policy). These records are protected by database-enforced row-level tenant isolation, changes to them are recorded in an append-only audit trail, and access is restricted to authorised personnel through role-based permissions.
- Audit log records (accountability evidence, security investigations) — retained indefinitely while the service remains in operation. This is our retention policy for accountability and security evidence: it supports our accountability obligations under the UK GDPR Art-5(2) accountability principle and overlaps the Companies Act 2006 6-year minimum for financial records, but the indefinite period is a policy choice, not a statutory mandate. Audit logs are append-only records and may contain your name, user ID, and the actions you performed. See the ICO accountability guidance and our Data Processing Agreement for further detail on our security and access controls for audit data.
- Account data: retained for the duration of the contract; we will delete it within 90 days of account closure, subject to the above minimum retention obligations.
5. Recipients and sharing (UK GDPR Art-13(1)(e))
We share personal data with the following categories of recipient, all of whom are bound by data-processing agreements: cloud infrastructure providers (EU-hosted); error-monitoring and logging providers (technical data, with personal data scrubbed before transmission); payment processors (billing data only); and email delivery providers (communications data only). We do not sell personal data. The full named list — with processing regions and transfer mechanisms per provider — is published on our Sub-processors page.
6. International transfers (UK GDPR Art-13(1)(f))
Where data is processed outside the UK or EEA, we ensure appropriate safeguards are in place — either an adequacy decision, or the UK International Data Transfer Agreement (IDTA) / Standard Contractual Clauses. Details are available on request at [email protected].
7. Your rights (UK GDPR Arts-13(2)(b), 15–22)
You have the following rights in relation to your personal data:
- Access (Art-15): request a copy of data we hold about you.
- Rectification (Art-16): correct inaccurate or incomplete data.
- Erasure (Art-17, “right to be forgotten”): request deletion where data is no longer necessary or consent is withdrawn, subject to legal retention obligations.
- Restriction (Art-18): restrict processing in certain circumstances.
- Portability (Art-20): receive your data in a machine-readable format.
- Objection (Art-21): object to processing based on legitimate interests or direct marketing.
- Automated decision-making (Art-22): we do not make solely automated decisions that produce significant legal effects.
To exercise any right, email [email protected] or use Settings → Privacy within the platform. We will respond within one calendar month (UK GDPR Art-12(3)).
8. Right to complain (UK GDPR Art-13(2)(d))
You have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113. We would however appreciate the opportunity to address your concerns before you contact the ICO — please email [email protected] first.
9. Business customers — Data Processing Agreement
Where you access the Recordme platform on behalf of a business and Recordme processes personal data as your data processor (UK GDPR Art-28), our controller-processor relationship is governed by the Data Processing Agreement (DPA). The DPA covers all eight mandatory Art-28(3) elements including processing instructions, confidentiality, security measures, sub-processor authorisation, data subject rights assistance, breach notification, data deletion, and audit rights.
10. Cookies
For information about cookies and tracking technologies, see our Cookie Policy.
11. Children’s data (UK GDPR Art-8)
Recordme is a business-to-business compliance platform for adult professionals in the hospitality sector. The service is not directed at, and is not intended for use by, children under the age of 13 (or such other minimum age as UK GDPR Art-8 specifies for the relevant information society service). We do not knowingly collect personal data from children. If you believe a child has submitted personal data through our platform, please contact us immediately at [email protected] and we will delete that data promptly.
Last reviewed: 29 July 2026, for consistency with current UK law, by Claude Fable 5 (AI) — not a solicitor. Independent solicitor review is planned before we scale beyond our pilot phase. For questions contact [email protected].