Privacy Policy
How NHR Solution handles personal data — both the data of people who visit this site, and the employee data our customers hold in the platform.
01Who we are and our role
NHR Solution provides HR, payroll, compliance and workforce software to UK businesses.
Our role under UK GDPR depends on whose data it is. For visitors to this website and people who contact us, we are the controller — we decide what to collect and why. For employee data our customers put into the platform, the customer is the controller and we are the processor: we hold and process it on their instructions, and we do not decide what goes in or how it is used.
That distinction matters in practice. If you are an employee of one of our customers and want to see or correct your record, the request goes to your employer, not to us. We will help them answer it.
02What we collect from website visitors
Contact and demo enquiries: your name, email address, telephone number if you give one, business name, employee-count band, sector, and what you wrote in the message. We collect these because you asked us to reply.
Trial sign-ups: the same, plus the plan you selected.
Technical information: pages visited, approximate location derived from IP address, browser and device type. Used to keep the service working and to understand which pages are useful. Page-visit measurement uses Google Analytics, and only if you accept optional cookies — see the cookie policy.
We do not buy contact lists, and we do not add enquirers to marketing email unless they ask to be added.
03Employee data held in the platform
When a customer uses NHR Solution, the platform can hold: identity and contact details; employment terms including job title, department, start date, hours and manager; pay and pension information; bank details where payroll is used; absence records including dates and reasons; leave requests and balances; attendance and clocking records; shift patterns; documents such as contracts, right-to-work evidence and certificates; training and certification records; performance notes, goals and review outcomes; expense claims and receipts; safety incident records; recruitment records for candidates; and anonymous wellbeing check-in responses.
Some of this is special category data under Article 9 — health information in absence reasons, occupational health reports, and anything revealing ethnicity, religion or trade union membership. It is held separately and access is restricted by role.
Wellbeing check-in responses carry no employee identifier by design. There is no technical route from a response back to a person, which is why team results are withheld below a minimum number of responses.
04Lawful basis
For website enquiries we rely on legitimate interests — you contacted us and expect a reply — and on consent where you have asked for marketing. Website analytics rely on consent, which you can withdraw at any time from the cookie policy.
For employee data in the platform, the lawful basis is the customer's to determine as controller. In most cases it will be performance of the employment contract, compliance with a legal obligation such as PAYE and working-time records, or legitimate interests.
Where a customer processes staff data through an AI feature, they should record their own lawful basis for doing so. Our assistant is given aggregate figures only; it is never given individual records, notes, or absence reasons.
05Who we share data with
Sub-processors: hosting, email delivery, error monitoring and payment processing. A current list is available on request, and we will give notice before adding or replacing one.
Website analytics: Google, which provides Google Analytics, receives page-visit data from visitors who have accepted optional cookies.
We do not sell personal data. We do not share it for advertising.
We disclose data where we are legally required to, and will tell the controller unless prohibited from doing so.
06Where data is held
Customer data is held in the United Kingdom or the European Economic Area.
Where any sub-processor operates outside those areas, transfers are covered by the UK International Data Transfer Agreement or the addendum to the EU standard contractual clauses, with a transfer risk assessment on file.
07How long we keep it
Website enquiries: 24 months from last contact, unless a commercial relationship begins.
Customer platform data: for the term of the subscription, then 30 days for retrieval, then deletion. A customer can delete their data at any point during the term.
Backups are retained for 35 days and then overwritten, so deletion completes within that window.
Employee records themselves carry statutory retention periods the customer must determine — payroll records for at least three years after the tax year, working time records for two, accident records for three. The platform does not delete records automatically, because getting that wrong is worse than keeping them.
08Your rights
You have the right to be informed, to access your data, to have inaccuracies corrected, to erasure in some circumstances, to restrict or object to processing, and to data portability.
To exercise a right over data we hold as controller, contact us. We will respond within one month; the deadline runs from when the request reaches anyone at the company, not when it reaches the right person.
To exercise a right over employee data held by your employer in the platform, contact your employer.
You can complain to the Information Commissioner's Office. We would prefer the chance to put it right first.
09Security
Access to customer data is restricted by role within the platform, and internally on a least-privilege basis. Data is encrypted in transit and at rest.
We do not hold card details. Payment is handled by a provider whose systems hold that data.
We do not currently hold an ISO 27001 certification or any other security accreditation, and this policy does not claim one.
