Legal

GDPR Compliance at Native Keeper

How Native Keeper supports compliance with the UK GDPR and EU GDPR, including sensitive HR data, international transfers, and data subject rights.

Last updated: 10 June 2026

Overview

Quick answer for procurement teams: Native Keeper is operated by NeonStack Ltd, a UK company. We process employee and workforce data under the UK GDPR and EU GDPR. We sign a DPA with every paying customer, maintain a public Sub-processors list, support international transfers via SCCs and the UK IDTA, handle Special Category and Criminal-Offence Data on a lawful basis, and provide self-service tools for data subject rights. Skip to the Compliance Checklist or download our DPA.

What this page covers

The General Data Protection Regulation (GDPR) and its UK equivalent (UK GDPR) set the global benchmark for how Personal Data must be collected, processed, and protected. If you're using Native Keeper to hold records about employees, workers, contractors, or applicants — anywhere in the world — data protection law applies, and we're part of how you stay compliant.

This page explains:

Who we are and where we fit in the GDPR picture

What we do to comply with GDPR ourselves

How we handle sensitive HR data — including Special Category and Criminal-Offence Data

What we provide to you so you can comply with your obligations

What you (the customer) remain responsible for

How to get the documents your procurement team will ask for

If you just need the documents, jump to Resources. For everything else, read on.

1. Who plays what role under GDPR

GDPR distinguishes between Controllers (who decide why and how data is processed) and Processors (who process data on a Controller's behalf, under instruction).

In a typical Native Keeper scenario, the roles look like this:

Scenario

Controller

Processor

What this means

You add an employee's record to Native Keeper. Their DBS certificate is uploaded and tracked.

You (our customer)

Native Keeper

You decide what to collect, why, and what to do with it. We process it on your behalf under our DPA.

You sign up for a Native Keeper account. We collect your billing email and account details.

Native Keeper

—

We are the Controller for your own account data, governed by our Privacy Policy.

An employee whose records you hold in Native Keeper wants to exercise GDPR rights over their data.

You

Native Keeper

Your employee's rights are exercised against you as their employer. We help you respond using our self-service tools.

This distinction matters because GDPR places different obligations on each role. Our Data Processing Agreement sets out our obligations as Processor in detail.

2. Where Native Keeper sits geographically

Detail

Information

Legal entity

NeonStack Ltd, company number 16933096

Country of establishment

United Kingdom (England and Wales)

Registered office

The North Colchester Business Centre, 340 The Crescent, Colchester, England, CO4 9AD

Trading name

Native Keeper

ICO registration

[ICO REGISTRATION NUMBER — PENDING]

Primary supervisory authority

UK Information Commissioner's Office (ICO)

EU Representative (Art. 27)

Not currently appointed. Will be appointed before offering the Service at scale to EU Data Subjects.

Because we're established in the UK, we are subject to:

The UK GDPR

The Data Protection Act 2018

The Privacy and Electronic Communications Regulations (PECR)

When we serve customers and Data Subjects in the EEA, we additionally comply with the EU GDPR and apply appropriate safeguards for any cross-border transfer.

For customers and Data Subjects in other jurisdictions (United States, Canada, Australia, and elsewhere), we honour rights and obligations arising under applicable local data-protection law — see Section 8 below.

3.1 We have built our product to be privacy-respecting by design

GDPR Article 25 requires "data protection by design and by default". This shows up in Native Keeper as:

Access control by default. Employee records are visible only to Admin Users who have been explicitly granted access. No cross-customer visibility.

You own your data. Workforce records are yours. You can export them at any time and delete them permanently.

No reuse of workforce content for AI training. We do not use the content of employee records to train our or any third party's general-purpose AI models. See DPA, Section 9.

Customer-configurable retention. You set how long records persist — because HR data often has statutory retention obligations far longer than a typical SaaS retention window.

Encryption everywhere. All Customer Personal Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), including uploaded documents such as DBS certificates and Right to Work evidence.

Audit logs of admin actions available on supported plans.

Regional data residency available on supported plans — EU-only or UK-only storage.

3.2 We sign a DPA with every paying customer

Every customer on a paid plan automatically accepts our Data Processing Agreement at signup. The DPA includes:

Article 28 GDPR-compliant processing terms

EU Standard Contractual Clauses (SCCs) — Modules 2 and 3

UK International Data Transfer Addendum (IDTA)

Sub-processor general authorisation with 30-day prior notice for changes

72-hour breach notification commitment

Specific handling of Special Category and Criminal-Offence Data

Detailed Annexes covering processing purpose, data categories, and security measures

Enterprise customers requiring a counter-signed version can request one from legal@nativekeeper.com.

3.3 We publish a current list of Sub-processors

Every third party that may Process Customer Personal Data on our behalf is listed at nativekeeper.com/legal/sub-processors, with their purpose, location, and the safeguards applied to international transfers.

You can subscribe to email notifications and receive 30 days' prior notice of any addition or replacement.

3.4 We handle international transfers properly

For data leaving the UK or EEA, we use:

EU Standard Contractual Clauses (SCCs) — Commission Decision (EU) 2021/914

UK International Data Transfer Addendum (IDTA) issued by the ICO

EU-US Data Privacy Framework for certified US recipients (Vercel, Stripe, Resend, and others where certified)

Adequacy decisions where applicable

Supplementary technical measures including end-to-end encryption, key isolation, and access restrictions

Regional data residency (data stored exclusively within a chosen region) is available on supported plans — contact legal@nativekeeper.com.

3.5 We meet our obligations as a Processor

GDPR Obligation

How we meet it

Process only on documented instructions (Art. 28(3)(a))

Defined in your account settings, the DPA, and our Terms of Service

Confidentiality of personnel (Art. 28(3)(b))

Written confidentiality agreements; access on a need-to-know basis

Security of processing (Art. 32)

Encryption in transit (TLS 1.2+) and at rest (AES-256); RBAC; MFA; monitoring. See our Security page.

Engaging sub-processors (Art. 28(2) & (4))

General authorisation with 30 days' notice; binding flow-down terms

Assistance with Data Subject requests (Art. 28(3)(e))

Self-service tools + manual support

Assistance with security, breach notification, DPIAs (Art. 28(3)(f))

Documented incident response; DPIA support; security questionnaire on request

Deletion or return of data on termination (Art. 28(3)(g))

Export and delete tools in-product; 30-day free export window on termination

Demonstrate compliance (Art. 28(3)(h))

This page; our DPA; security questionnaires; certifications (in progress)

3.6 We respond to Data Subject rights requests

Whether you're a Native Keeper account holder or an individual whose records are held in the Service by an employer, we support the full range of rights:

Right of access

Right to rectification

Right to erasure ("right to be forgotten")

Right to restriction of processing

Right to data portability

Right to object

Right to withdraw consent

Rights related to automated decision-making

How to exercise these depends on whether we hold your data as Controller or Processor. Full details are in our Privacy Policy, Section 10 and Section 11.

3.7 We notify of breaches within 72 hours

If we become aware of a Personal Data Breach affecting Customer Personal Data, we notify affected customers without undue delay and in any event within 72 hours, with all the information GDPR Art. 33 requires. Details in our DPA, Section 5.4.

4. How we handle sensitive HR data

Native Keeper is designed to hold employment records. Depending on how you use the Service, that may include:

Special Category Personal Data (Art. 9 UK/EU GDPR): health data, sickness absence records, disability information, trade-union membership, ethnic origin (for equality monitoring), and — in future — biometric data.

Criminal-Offence Data (Art. 10 UK/EU GDPR): DBS certificates, other background-check results, and spent-conviction disclosures.

We take this responsibility seriously and build for it.

4.1 What we do

Same encryption, same controls, same audit as all Customer Personal Data. Sensitive documents are stored in the same encrypted environment with the same access controls as any other record.

No routine access by our team. Native Keeper personnel do not access the content of your workforce records in the ordinary course of providing the Service. Any access for troubleshooting or security purposes is logged and requires justification.

Access limited to Admin Users you designate. You control who in your organisation can see which records.

Audit logs of admin actions available on supported plans.

No use of sensitive data for AI training, profiling, or any purpose other than what you instruct.

4.2 What you are responsible for

Because you are the Controller of the data you upload, you are responsible for:

Having a lawful basis under Article 9 to Process Special Category Data (typically the "employment, social security and social protection" condition, which requires an appropriate policy document in the UK)

Having a lawful basis under Article 10 to Process Criminal-Offence Data (typically a condition under Schedule 1 DPA 2018 for UK Controllers)

Providing appropriate privacy notices to your workforce

Complying with any consultation, information, or notification obligations you owe to workers, works councils, or trade unions

Determining appropriate retention for each category of data, in line with your local statutory obligations

Our DPA Section 4 sets this out in full.

5. What we provide to help you comply

As our customer, GDPR makes you (the Controller) responsible for compliance, but we give you the tools and documentation to actually achieve it.

Tools in the product

Capability

What it lets you do

Self-service data export

Export all workforce data in CSV or JSON format, with attached files, in response to portability requests or for your own records

Self-service record deletion

Permanently delete individual records in response to erasure requests

Configurable retention

Set retention rules per record type to reflect statutory HR retention requirements

Access control per Admin User

Grant granular access rights so only authorised staff can see sensitive records

Audit logs

See who in your organisation accessed or modified records (on supported plans)

Regional data residency

Store workforce data exclusively within the EEA, the UK, or another supported region (on supported plans)

Compliance-expiry reminders

Automated notifications for upcoming document expiries so you never miss a legal deadline

Inspection-ready exports

Generate audit-friendly reports for regulator inspections or internal reviews

Documents we provide

Document

Where

Data Processing Agreement (DPA)

/legal/dpa — auto-accepted at paid signup; counter-signed version available on request

Sub-processors list

/legal/sub-processors — public, with email subscription for changes

Privacy Policy

/legal/privacy

Security overview

/legal/security

Standard Contractual Clauses

Incorporated into the DPA

UK IDTA

Incorporated into the DPA

Security questionnaire response

Available on request via legal@nativekeeper.com for enterprise procurement teams

Support for your compliance work

DPIA support — if you need information for a Data Protection Impact Assessment, contact legal@nativekeeper.com and we'll provide what's reasonably required.

Custom contractual terms — enterprise customers can negotiate variations to the DPA where required.

Audit access — satisfied through certifications (in progress) and on-request information.

6. What you remain responsible for

GDPR responsibility doesn't shift to us just because we provide the tools. As the Controller of the data you upload to Native Keeper, you are responsible for:

Identifying a lawful basis for each collection of Personal Data (typically contract of employment, legal obligation, or legitimate interest for employers)

Identifying additional lawful bases for Special Category and Criminal-Offence Data (Article 9 and Article 10)

Maintaining an appropriate policy document where required by DPA 2018 Schedule 1 for UK Controllers relying on conditions such as the "employment, social security and social protection" condition

Providing privacy notices to your workforce and applicants — including disclosing Native Keeper as your Processor

Not collecting more data than you need (data minimisation)

Honouring Data Subject rights requests from your workforce, using the tools we provide

Configuring appropriate retention for each record type in line with your statutory obligations

Consulting with workers, works councils, or trade unions where required in your jurisdiction

Conducting a DPIA where required (large-scale processing of Special Category or Criminal-Offence Data typically triggers this)

Reporting any breaches you become aware of to your supervisory authority within 72 hours where required

Complying with employment law in each jurisdiction where you operate — this is beyond data-protection law and we can't do it for you

If any of this is unfamiliar, the ICO's guide for organisations at ico.org.uk/for-organisations is the best free UK resource. EEA Controllers should consult their national supervisory authority.

7. Compliance Checklist

A one-page summary you can paste into your own procurement review.

Native Keeper compliance summary

Item

Status

Established in a jurisdiction with strong data-protection law

✅ United Kingdom

Registered with a supervisory authority

✅ ICO registration [PENDING]

Signs a GDPR Art. 28 Data Processing Agreement

✅ With every paying customer

DPA incorporates EU SCCs and UK IDTA

✅ Modules 2 and 3 + UK Addendum

DPA covers Special Category and Criminal-Offence Data

✅ Art. 9 and Art. 10 handling built in

Maintains a public list of Sub-processors

✅ /legal/sub-processors

30 days' notice of Sub-processor changes

✅ With subscription option

Encryption in transit

✅ TLS 1.2+

Encryption at rest

✅ AES-256 including uploaded documents

Multi-factor authentication on employee access

✅

Self-service data export

✅

Self-service record deletion

✅

Configurable retention per record type

✅

Access controls per Admin User

✅

Audit logs (on supported plans)

✅

Breach notification within 72 hours

✅

Does not use workforce data to train AI

✅

Does not sell Personal Data

✅

Regional data residency available

✅ On supported plans

SOC 2 Type II report

🟡 In progress

ISO 27001 certification

🟡 Roadmap

Appointed DPO

❌ Not currently required (Art. 37)

Appointed EU Representative

🟡 Will appoint as required (Art. 27)

8. Other jurisdictions

Native Keeper serves customers globally. Depending on where you and your workforce are located, additional data-protection laws may apply. We aim to comply with each of them and provide the tools and safeguards you need to comply with your own obligations under them.

Law / regime

How we support it

UK GDPR + DPA 2018

Compliant; primary framework we build to

EU GDPR

Compliant; DPA includes EU SCCs; EU data residency available

Swiss FADP

DPA and safeguards support Swiss transfers

CCPA / CPRA (California)

Compliant for California residents (see Privacy Policy Section 13)

Canadian PIPEDA

Data-protection controls consistent with PIPEDA principles

Brazilian LGPD

Data-protection controls consistent with LGPD principles

Australian Privacy Act

Data-protection controls consistent with Australian Privacy Principles

Other national and sub-national laws

We honour any right or obligation applicable to you or your workforce under your local law

If your jurisdiction has specific requirements not addressed here, contact legal@nativekeeper.com and we'll walk through them with you.

9. Resources

Resource

Link

Data Processing Agreement

/legal/dpa

Sub-processors list

/legal/sub-processors

Privacy Policy

/legal/privacy

Security overview

/legal/security

Terms of Service

/legal/terms

Cookie Policy

/legal/cookies

Acceptable Use Policy

/legal/acceptable-use

Accessibility Statement

/legal/accessibility

ICO (UK Supervisory Authority)

ico.org.uk

European Data Protection Board

edpb.europa.eu

10. Frequently Asked Questions

Are you GDPR compliant?

Native Keeper is operated in compliance with UK GDPR and EU GDPR obligations applicable to us as a Processor. We provide the contractual, technical, and operational mechanisms you need to use Native Keeper in a GDPR-compliant way. GDPR compliance is, however, a shared responsibility — see Section 6 above.

Can we hold DBS certificates and other criminal-offence data in Native Keeper?

Yes. Native Keeper is designed to hold such data, subject to your having a lawful basis under Art. 10 UK GDPR and (in the UK) a condition under Schedule 1 DPA 2018. Our DPA supports this processing. See DPA Section 4(e).

Can we hold sickness absence or health data?

Yes. Native Keeper supports Special Category Data under Art. 9 UK/EU GDPR, provided you have a lawful basis (typically the "employment, social security and social protection" condition in the UK). See DPA Section 4(d).

Will you sign our company's DPA instead of yours?

For enterprise customers, yes, we will review reasonable amendments to our standard DPA. For all other customers, our standard DPA — which is already designed to satisfy GDPR Art. 28 — is what we use. Contact legal@nativekeeper.com.

Where is data stored?

By default, in the EU (Frankfurt) for European customers and the United States for others. Regional data residency (EU-only, UK-only) is available on supported plans. See our Sub-processors page for full detail.

Can records be deleted on request?

Yes. You can permanently delete any record from your dashboard. Deleted data is removed from backups within 90 days.

Do you use our data to train AI?

No. We do not use Customer Personal Data — including workforce records or uploaded documents — to train any general-purpose AI model, either our own or any third party's. See DPA Section 9.

Do you sell personal data?

No. We never have and we never will. We do not share data for cross-context behavioural advertising.

What happens if there's a breach?

We notify affected customers within 72 hours of becoming aware of a Personal Data Breach, with full details as required by GDPR Art. 33. See DPA Section 5.4.

Can our employees exercise their GDPR rights against Native Keeper directly?

Because you are the Controller of your employees' data, your employees exercise their rights against you. We support you with self-service tools to fulfil those rights. If an individual is unable to reach you, they may contact us and we will help identify the correct Controller.

Are you certified to SOC 2 or ISO 27001?

SOC 2 Type II is in progress. ISO 27001 is on our roadmap. The current technical and organisational measures we apply are in DPA Annex 2 and on our Security page.

Are you also CCPA compliant?

Yes. See Privacy Policy, Section 13.

We're a US employer. Can we still use Native Keeper?

Yes. Native Keeper serves employers worldwide. Because we're a UK company processing data on your behalf, transfers of your workforce data to and within the UK are governed by SCCs and the safeguards described in our DPA. See Section 8.

We're a care provider / regulated employer. Does Native Keeper meet CQC / equivalent regulatory expectations for record-keeping?

Native Keeper provides encrypted storage, audit trails, access controls, retention configuration, and inspection-ready exports that many regulated employers use to meet record-keeping obligations. However, we don't hold a specific certification for any regulator. You remain responsible for confirming that Native Keeper meets your specific regulatory expectations. Contact us at legal@nativekeeper.com if you'd like documentation to support a regulator conversation.

Contact

For GDPR questions, DPAs, or anything privacy-related:

Email: legal@nativekeeper.com

Postal: NeonStack Ltd, The North Colchester Business Centre, 340 The Crescent, Colchester, England, CO4 9AD