Workforce's primary application and customer database are hosted in Render's Frankfurt region.
Trust & compliance
Trust & compliance
Aludel builds Workforce for organisations that need to make sensitive operational decisions with confidence. This page sets out where customer data is hosted, the independent assurance held by our infrastructure provider, and the commitments we make to customers.
Hosted on infrastructure certified to ISO/IEC 27001:2022 and examined under SOC 2 Type II.
We offer a Data Processing Agreement to every customer.
Shared responsibilities
For personal data entered into Workforce by a customer, the customer ordinarily acts as data controller and Aludel acts as data processor. We process that data to provide, secure, support and maintain the service, following the customer's documented instructions and the terms of our Data Processing Agreement.
Aludel Limited is the data controller for information used to manage its own website enquiries, customer relationships, accounts and legal obligations. Our privacy notice explains these activities and the rights available to individuals.
Hosting and data residency
Workforce's primary application service and customer database are hosted with Render in Frankfurt, Germany. This provides a named EU hosting location for customer data stored by the application.
Data residency describes the primary hosting location. Render is a US-headquartered provider, and limited service, security or support processing may involve international transfers. Where required, these transfers are protected using recognised safeguards, including contractual protections.
Independent infrastructure assurance
Workforce is hosted on Render infrastructure covered by the following independent assurance:
ISO/IEC 27001:2022
Render's information security management system supporting the Render Platform is certified to ISO/IEC 27001:2022. The certificate reviewed by Aludel is valid until 7 November 2027, subject to ongoing surveillance audits.
SOC 2 Type II
Render's controls were independently examined against the security, confidentiality and availability trust services criteria for the period 1 October 2024 to 30 September 2025.
Independent security testing
Render commissions independent penetration testing and maintains security, vulnerability management and incident response programmes.
These certifications and reports apply to Render and the scope stated in its audit documents. They do not mean that Aludel itself is ISO 27001 certified or has completed its own SOC 2 examination.
Security controls
Our approach combines safeguards in Workforce with controls provided by the hosting environment.
- Access control: role-based access separates standard users, customer administrators and Aludel system administrators.
- Authentication: production sessions use secure, HTTP-only cookies and expire after eight hours. Password reset invalidates existing sessions.
- Tenant separation: customer records are scoped by organisation within the application and access-controlled at the service layer.
- Data minimisation: Workforce is designed for staff planning information, not medical records or sickness and absence reasons.
- Resilience: Render maintains backup, business continuity, disaster recovery, vulnerability management and incident response controls within its audited environment.
- Review: access, software changes and infrastructure controls are reviewed as part of ongoing service operation.
Data protection commitments
Aludel supports customers in meeting their obligations under the UK GDPR and Data Protection Act 2018. Our customer terms can include a Data Processing Agreement covering processing instructions, confidentiality, security, assistance with individual rights, incident handling, subprocessors, audits, international transfers, and deletion or return of data when services end.
Workforce is not designed for special category data. Customers should not enter health information, medical details, sickness or absence reasons, or other special category information into free-text fields. If a proposed use changes the nature or risk of processing, we will work with the customer to assess the appropriate safeguards before that use begins.
Request a Data Processing AgreementIncident and breach notification
If we become aware of a personal data breach affecting customer data, we will notify the affected customer without undue delay. We will provide the information reasonably available to help the customer understand the nature and likely consequences of the incident, the data affected, and the measures taken or proposed in response.
We will continue to provide material updates as the investigation develops and cooperate with the customer's reasonable regulatory and data-subject notification obligations.
Subprocessors
We use the following organisations to help provide Workforce. They process personal data only for the stated service.
Render Services, Inc.
Cloud application and database hosting
- Primary location
- Frankfurt, Germany
- Data involved
- Customer account, workforce planning and service data
- Assurance
- ISO/IEC 27001:2022; SOC 2 Type II
University of St Andrews
Hosted Conjure optimisation service
- Location
- United Kingdom
- Data involved
- Staff identifiers (excluding names), roles, skills, contracted hours, availability, shift preferences, planning constraints and job metadata needed to calculate a roster
- Purpose
- Running optimisation jobs and returning roster assignments
Account email delivery
- Service
- Email infrastructure
- Data involved
- Recipient email address and the content and delivery metadata of account verification and password-reset messages
- Purpose
- Sending essential service and account-security emails
Customers are informed of material changes to this list in accordance with their Data Processing Agreement.
Questions
Need more detail for procurement?
Contact us for our Data Processing Agreement, security information, or help with a supplier assessment.
Contact data protection