Trust & Compliance

Last updated: 4 September 2026

Draft — for legal review. Sections marked below are placeholders only. Do not rely on this page as final contractual terms until reviewed and published by P-SaaS Ltd.

This page summarises how Sarge-P handles sensitive staffing data and compliance workflows. It is intended for venue and agency buyers evaluating a multi-year contract. For full privacy detail, see our Privacy Policy; for contractual terms, see Terms of Service.

Data roles

Sarge-P is used by venues, staffing agencies, and the staff they engage. Where a venue or agency inputs data about their own staff, that organisation is the data controller and is responsible for having a lawful basis to collect and use it. P-SaaS Ltd acts as a data processor on their behalf for that staff data.

P-SaaS Ltd is the data controller for account-holder and billing data, platform usage data, and visitors to our public marketing site.

[Placeholder — legal review required] Formal Data Processing Agreement (DPA) terms for processor relationships — to be supplied alongside signed contracts.

Payroll and agency spend

Sarge-P helps venues reconcile staffing costs from check-in and check-out records. Payroll figures and agency spend reports are derived from the shifts and scans you record in the platform — you remain responsible for verifying rates, hours, and invoices before payment.

  • Venue payroll exports: pay rates on staff profiles combined with event check-in/out scans produce CSV payroll reports for venue-employed staff, exportable by authorised venue admins.
  • Agency billing reports: agency rate cards and staffing allocations feed monthly agency spend summaries — hours, roles, and costs by agency and event for invoice reconciliation.
  • What we store: pay rates, role assignments, scan timestamps, and calculated figures used to generate exports — not your payroll provider or accounting system unless you choose to upload documents separately.

[Placeholder — legal review required] Retention periods for payroll and agency billing exports, and any integration with external accounting systems — to be confirmed with legal counsel.

Sensitive personal data

The platform may store the following categories of sensitive staffing data:

  • National Insurance numbers — encrypted at rest
  • Agency staff bank details for payment — encrypted at rest
  • Pay rates and payroll figures, exportable by authorised venue admins
  • A one-off location reading at sign-in/sign-out (and a single resume check while signed in) to confirm on-site attendance — not continuous tracking
  • Shift, attendance, holiday, and administrative records

Full categories and legal bases are listed in our Privacy Policy.

Security

  • Authentication: signed-in sessions use industry-standard credential hashing and JWT-based sessions. Sensitive actions are scoped to verified venue or agency membership in the database, not session claims alone.
  • Tenant isolation:venue and agency data is scoped by organisation membership — users cannot access another customer's roster, events, or staff records through normal platform use.
  • Encryption: dedicated application-layer encryption for National Insurance numbers and agency bank fields; data in transit protected by TLS.
  • Hosting: application and primary database hosted on Railway; object storage for uploaded briefing documents and images uses an S3-compatible provider.

[Placeholder — legal review required] Formal security questionnaire responses, penetration-test summaries, incident-response procedures, and any third-party certifications (e.g. ISO 27001, SOC 2) — to be supplied on request once available. Do not infer certifications from this page.

Sub-processors

We use the following sub-processors to operate the platform. We do not sell personal data. On the signed-in platform we do not use third-party analytics or advertising tracking. On the public marketing website, analytics or advertising technologies may be used only where a visitor has given consent via the cookie banner.

ServicePurpose
Railway (PostgreSQL)Primary database hosting
StripePayment processing and billing
ResendTransactional email (invites, reminders, billing)
CrispLive chat on the public marketing site only
Object storage (S3-compatible)Briefing documents, checklists, uniform and venue map images

[Placeholder — legal review required] Sub-processor change-notification process and international transfer safeguards — to be documented in the DPA.

Your data rights and retention

Staff and agency workers with queries about employment records held in Sarge-P should contact their employer or agency in the first instance. Under UK GDPR, data subjects may request access, correction, erasure, or portability — see our Privacy Policy for details and ICO contact information.

Personal data is retained while an account is active and for a further period where needed for legal obligations or dispute resolution.

Contact

Security or compliance enquiries — P-SaaS Ltd: [compliance contact email]