Our company is an ISO27001-certified supplier, with UK-hosted infrastructure for GDPR compliance, and an enclosed AI data environment that never trains on your data.
Data never leaves the country
Audited annually
Never trained on your data
Sense Workplace is a British-built platform. All data that passes through is processed and stored by UK-based infrastructure, and is never routed through US or EU data centres. This ensures everything from your HR records and your timesheet entries to your location data and your AI queries, remains safe, secure, and compliant.
All data stored and processed in British data centres, with no cross-border data transfer. Fully compatible with UK GDPR and NHS or government data frameworks.
Our annual third-party audit covers our platform, infrastructure and internal processes, to ensure they meet internationally-recognised security standards.
Our controls are designed and audited against SOC 2 Type II criteria for security, availability, and confidentiality – available on request for enterprise.
Annual independent pen-testing by CREST-certified testers, with results and remediation evidence available to enterprise customers (under NDA.)
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Location signals from hardware devices are encrypted before they leave the device.
Guaranteed uptime as a service level agreement, with a real-time status page, automatic failover, and 24/7 infrastructure monitoring. Credits if SLA is breached.
Collecting HR data and real-time location information is a significant responsibility, which is why we've built GDPR compliance into the platform's architecture. Here's how we protect your workers' rights while giving you the operational visibility you need.
Each worker tracked by Sense can see their own location history, check-in records, and whatever other data is stored about them, from directly within the Sense Workplace app.
Sense provides templates for worker notification consent documentation and DPIA (Data Protection Impact Assessment) records, designed by our team of Data Protection Officers.
Automate data retention, and set sensitive data such as location information to be auto-deleted after 30, 60, or 90 days, with audit logs retained for the periods required by UK law.
When an employee leaves, Sense supports GDPR right-to-erasure laws, with workflows that remove personal data while retaining anonymised operational records for compliance.
Sense AI runs in a closed, UK-hosted inference environment. Your data is used generate answers. It stays within your customer account, and is never used to train future models.
| What Sense AI does | Status |
|---|---|
| Reads your company's own documents to answer questions | ✓ Yes |
| Stores AI query logs for audit purposes | ✓ Yes |
| Operates in a closed, UK-hosted environment | ✓ Yes |
| Uses your data to train or improve models | ✗ Never |
| Shares query data with other customers' environments | ✗ Never |
| Routes queries through US or EU infrastructure | ✗ Never |
We know that enterprise procurement requires more than just a flashy sales demo. Our technical teams can work with you to provide everything your IT, security and legal teams need, including:
System architecture diagram, data flow documentation, and infrastructure spec.
Pre-completed SIG (Standardised Information Gathering) questionnaire.
Full certification and scope documentation, available under NDA.
Executive summary of latest pen test findings and remediation status.
Data Processing Agreement, sub-processor list, and DPIA template.
IT and security leads at comparable organisations available for reference calls.
If you have more questions, you can request more information, or even book a quick call with our DPO who will happily answer your questions.