We regularly review how we can most securely store your data. We protect it in three key dimensions:
We store only necessary information, as collected by you. Individual logins mean that your team members can keep their details accurate and up to date, ensuring that you meet your legal obligations as an employer.
We encrypt your data both at rest and in transit, and our site and storage processes are architected for security. See Security Measures for specific details.
We have extensive internal access controls and regulations for the Charlie team, who only have access to data under limited conditions, and have all been security checked. Within our software you are able to set account roles for all employees to restrict access to sensitive materials.
We follow the principles of the General Data Protection Regulation of May 2018. We have a designated Data Protection Officer, and accountability and privacy are principles that are designed into both our software and policies.
Our core compliance with the act means we:
Have full awareness of where any of your data is being held & when outside the EU, ensuring appropriate compliance is in place
Ensure that only those who require access to your data are able to & we have the highest level of protection against unauthorised access
Ensure you have the right to view, amend, export or delete any information that we hold on your behalf, including anything held by 3rd party services
Ensure that consent is given during the sign up process for all that use Charlie and allowing you to withdraw this at anytime
You’re able to review the exact standards we hold ourselves to via our Privacy Policy.
Our Data Protection Officer is on hand should you have any concerns or issues, they can be contacted at [email protected]
Based on our self-assessment and that of our external Data Protection Officer we are currently compliant.
Ben Branson-Gateley. You can contact them via [email protected].
No.
Our retention periods are defined by you, you have full control of what data is held on our system and are free to remove or amend it at any time.
Within the EU.
Yes, this is defined by our commitment to ISO 27001 compliance and the controls we have in place internally for that. You can read more about our security measures here.
Of course – please email [email protected].
Yes we do.
Yes we do – you can read about the majority of our controls here.
Yes we do – you can download it here.