Trust & Compliance
Last updated: 4 September 2026
Draft — for legal review. Sections marked below are placeholders only. Do not rely on this page as final contractual terms until reviewed and published by P-SaaS Ltd.
This page summarises how Sarge-P handles sensitive staffing data and compliance workflows. It is intended for venue and agency buyers evaluating a multi-year contract. For full privacy detail, see our Privacy Policy; for contractual terms, see Terms of Service.
Data roles
Sarge-P is used by venues, staffing agencies, and the staff they engage. Where a venue or agency inputs data about their own staff, that organisation is the data controller and is responsible for having a lawful basis to collect and use it. P-SaaS Ltd acts as a data processor on their behalf for that staff data.
P-SaaS Ltd is the data controller for account-holder and billing data, platform usage data, and visitors to our public marketing site.
[Placeholder — legal review required] Formal Data Processing Agreement (DPA) terms for processor relationships — to be supplied alongside signed contracts.
Payroll and agency spend
Sarge-P helps venues reconcile staffing costs from check-in and check-out records. Payroll figures and agency spend reports are derived from the shifts and scans you record in the platform — you remain responsible for verifying rates, hours, and invoices before payment.
- Venue payroll exports: pay rates on staff profiles combined with event check-in/out scans produce CSV payroll reports for venue-employed staff, exportable by authorised venue admins.
- Agency billing reports: agency rate cards and staffing allocations feed monthly agency spend summaries — hours, roles, and costs by agency and event for invoice reconciliation.
- What we store: pay rates, role assignments, scan timestamps, and calculated figures used to generate exports — not your payroll provider or accounting system unless you choose to upload documents separately.
[Placeholder — legal review required] Retention periods for payroll and agency billing exports, and any integration with external accounting systems — to be confirmed with legal counsel.
Sensitive personal data
The platform may store the following categories of sensitive staffing data:
- National Insurance numbers — encrypted at rest
- Agency staff bank details for payment — encrypted at rest
- Pay rates and payroll figures, exportable by authorised venue admins
- A one-off location reading at sign-in/sign-out (and a single resume check while signed in) to confirm on-site attendance — not continuous tracking
- Shift, attendance, holiday, and administrative records
Full categories and legal bases are listed in our Privacy Policy.
Security
- Authentication: signed-in sessions use industry-standard credential hashing and JWT-based sessions. Sensitive actions are scoped to verified venue or agency membership in the database, not session claims alone.
- Tenant isolation:venue and agency data is scoped by organisation membership — users cannot access another customer's roster, events, or staff records through normal platform use.
- Encryption: dedicated application-layer encryption for National Insurance numbers and agency bank fields; data in transit protected by TLS.
- Hosting: application and primary database hosted on Railway; object storage for uploaded briefing documents and images uses an S3-compatible provider.
[Placeholder — legal review required] Formal security questionnaire responses, penetration-test summaries, incident-response procedures, and any third-party certifications (e.g. ISO 27001, SOC 2) — to be supplied on request once available. Do not infer certifications from this page.
Sub-processors
We use the following sub-processors to operate the platform. We do not sell personal data. On the signed-in platform we do not use third-party analytics or advertising tracking. On the public marketing website, analytics or advertising technologies may be used only where a visitor has given consent via the cookie banner.
| Service | Purpose |
|---|---|
| Railway (PostgreSQL) | Primary database hosting |
| Stripe | Payment processing and billing |
| Resend | Transactional email (invites, reminders, billing) |
| Crisp | Live chat on the public marketing site only |
| Object storage (S3-compatible) | Briefing documents, checklists, uniform and venue map images |
[Placeholder — legal review required] Sub-processor change-notification process and international transfer safeguards — to be documented in the DPA.
Your data rights and retention
Staff and agency workers with queries about employment records held in Sarge-P should contact their employer or agency in the first instance. Under UK GDPR, data subjects may request access, correction, erasure, or portability — see our Privacy Policy for details and ICO contact information.
Personal data is retained while an account is active and for a further period where needed for legal obligations or dispute resolution.
Contact
Security or compliance enquiries — P-SaaS Ltd: [compliance contact email]