Legal

# Data processing

How CubeHR handles the staff data your organisation puts into it, including health and absence records, and what our Article 28 terms commit us to.

Last updated 25 September 2026. Issued by Cube Systems Limited, trading as CubeHR, of Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP. Registered in England and Wales, company number [17220899](https://find-and-update.company-information.service.gov.uk/company/17220899). ICO registration number [ZC216972](https://ico.org.uk/ESDWebPages/Entry/ZC216972).

## 1 Who is responsible for what

When your organisation uses CubeHR to manage its people, you decide what staff data goes into it and what it is used for. You are the controller of that data, and Cube Systems Limited is your processor, acting only on your documented instructions.

If you hold some of that data as a processor yourself, for example as an HR consultancy or bureau running CubeHR for a client, we act as your sub-processor for it, and the commitments on this page cover it in the same way.

Separately, we are a controller for the small amount of data we need to run our own business, such as the details of your account contacts and our billing records. That is covered by our [privacy policy](/legal/privacy).

## 2 Our data processing agreement

This page is our data processing agreement under Article 28 of UK GDPR. It forms part of your contract with Cube Systems Limited, so you do not need to sign anything separately. Under it, we:

- process your data only on your documented instructions, which include using CubeHR as designed with the configuration you choose, and tell you if we believe an instruction breaks the law;
- make sure everyone with access to it is bound by confidentiality;
- maintain the technical and organisational measures described [below](#how-it-is-protected), as Article 32 requires;
- use sub-processors only under written contracts with equivalent obligations, and give you notice before any change;
- help you answer requests from staff exercising their rights, and with data protection impact assessments and any consultation with the ICO;
- notify you of a personal data breach affecting your data without undue delay;
- delete or return your data when the subscription ends, at your choice; and
- make available the information you need to demonstrate compliance, and allow for audits, including inspections, by you or an auditor you appoint.

If we are required by UK law to process your data other than on your instructions, we will tell you before we do, unless that law forbids it. To review these terms with your data protection lead, or to have your own agreement countersigned for a larger account, email [hello@cube-hr.co.uk](mailto:hello@cube-hr.co.uk).

## 3 Details of the processing

| Item | Detail |
| --- | --- |
| Subject matter | Provision of the CubeHR HR platform, its mobile app and its API. |
| Duration | For as long as your subscription or trial is live, plus the 30-day export window and the deletion period set out below. |
| Nature and purpose | Hosting, storing, organising, retrieving and sending staff records so your organisation can administer employment: records, holiday and absence, rotas, time and attendance, documents, onboarding, performance, training, expenses and equipment. |
| Data subjects | Your employees, workers and contractors, job applicants and leavers, and people they name, such as emergency contacts and dependants. |
| Personal data | Identity and contact details, employment terms, job history, pay and bank details, National Insurance numbers, working patterns, rotas and timesheets, clock-in times and, where you turn it on, location at clock-in, holiday and absence records, documents you upload, performance and training records, expenses, equipment issued, and user account and audit records. |
| Special category and criminal offence data | Health information in sickness records, fit notes, occupational health referrals and adjustments; equality monitoring data if you choose to collect it; and DBS check results, which are criminal offence data. |

## 4 What CubeHR holds

| Category | Examples |
| --- | --- |
| Staff records | Name, contact details, date of birth, address, emergency contacts, job title, department, manager, contract, salary history, bank details and National Insurance number. |
| Time and attendance | Rotas and shifts, clock-in and clock-out times by QR code, kiosk, mobile or timesheet, location at clock-in where geofencing is on, and overtime. |
| Holiday and absence | Holiday requests and balances, sickness absence, fit notes, return to work notes and occupational health referrals. |
| Documents | Contracts, policies and acknowledgements, right to work documents and share codes, DBS certificates, certificates and expense receipts. |
| Onboarding and development | Onboarding checklists, probation outcomes, reviews, objectives and training records. |
| Equipment | Assets issued to staff, such as laptops, phones and keys, and their return. |
| Account and security records | Users, roles and permissions, sign-in history, two-step verification settings, API keys and the audit trail of changes. |

Health, equality and DBS information needs more care than the rest of a staff record. You need a condition under Article 9 or Article 10 of UK GDPR and, for most employment purposes, a condition in Schedule 1 of the Data Protection Act 2018, which usually means keeping an appropriate policy document. Use CubeHR’s permissions to limit who can see these records. Our [GDPR and data protection](/legal/gdpr) page explains this in more detail.

## 5 Where it is held

Your data is stored in the United Kingdom:

- application servers, databases and backups in UK data centres operated by Crushed Ice, part of Crushed Ice Group; and
- uploaded documents, photos and receipts in Amazon S3, and system email sent through Amazon SES, both in the AWS London region.

Files are delivered to signed-in users through Amazon CloudFront over short-lived links. If someone opens a file from outside the UK, CloudFront may serve it from a location near them, under the UK Addendum to the standard contractual clauses in the AWS data processing addendum. We do not otherwise transfer your data outside the UK, and we will not start to without telling you first as set out under [sub-processors](#sub-processors).

## 6 How it is protected

### Access and permissions

- Role-based permissions, so your administrators decide who can see and change which records.
- Two-step verification for sign-in, and individual accounts for everyone who uses the system.
- Your data kept separate from other customers’ data, and access by our staff limited to the named people who need it to run and support the service, with that access logged.

### Audit and integrations

- An audit trail of changes to personnel records, recording who changed what and when.
- API access through keys you create and can revoke individually.

### Encryption and resilience

- Encryption in transit with TLS.
- Encryption at rest for sensitive fields, such as bank details and National Insurance numbers, and for uploaded document copies.
- Passwords stored only as salted hashes. The password itself is never kept.
- Regular backups held in the UK, with tested restore procedures.

Security is reviewed as the product changes. We will tell you before we make a change that materially reduces the protection applied to your data.

## 7 Sub-processors

You give general authorisation for us to use sub-processors. Each one is named on our [sub-processors](/legal/sub-processors) page with what it does, what it processes and where, and works under a written contract imposing the same obligations we owe you.

We give customers at least 30 days’ notice by email before adding or replacing one, and you can object on reasonable data protection grounds during that period. If we cannot resolve a reasonable objection, you may end the affected part of the service without penalty.

## 8 Requests from your staff

Requests from your employees to see, correct or delete their data should be made to you, as the controller. CubeHR gives your administrators the tools to answer them: search, export, correction and deletion of individual records, and exports for subject access requests. We will help you extract anything you cannot export yourself.

If an employee contacts us directly, we will not answer the request ourselves unless you ask us to. We will tell them to approach you and let you know it happened, without undue delay and at no charge.

## 9 Breach notification

If we become aware of a personal data breach affecting your data, we will notify your account contact without undue delay, and in any event within 48 hours, so that you can meet the 72-hour deadline for reporting to the ICO under Article 33.

We will tell you what happened, the categories and approximate number of people and records affected, the likely consequences and what we are doing about it, and keep you updated as we learn more. Reporting to the ICO and telling your staff is your decision as controller. We will support it and will not obstruct it.

## 10 Audit and assurance

We will answer reasonable security questionnaires and provide documentation of our measures. Where you need an on-site or third-party audit, we will agree scope and timing with you in advance. Audits are limited to once in any 12-month period unless a breach or a regulator requires otherwise.

## 11 When a subscription ends

You can export your data at any time in structured, machine-readable formats, not only at the end. When a subscription ends:

- your account stays available for export for 30 days;
- we then delete your data from live systems within a further 60 days, including uploaded documents and the audit trail, and confirm in writing when we have; and
- copies in backups expire on their normal rotation within 90 days after that, and are not restored in the meantime.

If you would rather we returned the data to you in a particular format first, tell us before the export window closes. We keep only what the law requires of us, such as invoices, which our [privacy policy](/legal/privacy) covers.

## 12 Contact

Data protection enquiries go to [hello@cube-hr.co.uk](mailto:hello@cube-hr.co.uk), or by post to Cube Systems Limited, Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP. We aim to respond within five working days. We are registered with the Information Commissioner’s Office under number ZC216972.

Other policies

- [All legal documents](/legal)
- [Privacy policy](/legal/privacy)
- [Cookie policy](/legal/cookies)
- [Terms of service](/legal/terms)
- [Sub-processors](/legal/sub-processors)
- [GDPR and data protection](/legal/gdpr)

Questions about any of this? Email [hello@cube-hr.co.uk](mailto:hello@cube-hr.co.uk), call [01234 672 617](tel:+441234672617) or write to us at the address above.

---

**URL:** https://cube-hr.co.uk/legal/data-processing
