Infrastructure
The platform runs on EU-based cloud infrastructure with data primarily stored in Frankfurt, Germany. Databases live inside private networks, access uses short-lived tokens and all external traffic is encrypted with TLS 1.2+ and HSTS.
We maintain redundant storage with automatic backups every six hours and daily point-in-time-recovery snapshots kept for 30 days.
Encryption
- Data at rest: AES-256 in the database, hashed passwords (bcrypt/argon2id) and field-level encryption for sensitive data.
- Data in transit: TLS 1.2 or higher with strong cipher suites, HSTS preload, automated certificate renewal.
- Keys: managed in a KMS, rotated quarterly and audited on every access.
Access control
We apply least privilege and role-based access control (RBAC) implemented through a dedicated `user_roles` table validated by server-side row-level security. Admin accounts require two-factor authentication and every access is logged immutably.
Departing staff are de-provisioned within 4 hours. Third-party vendors only access systems through dedicated, auditable accounts.
Secure development lifecycle
All code is reviewed before deployment. We run automated dependency scanning (SCA), static analysis (SAST), secret scanning and dynamic testing. No production change goes live without an automated test suite, manual review and immediate rollback capability.
We follow OWASP Top 10 and OWASP API Security Top 10 as baselines and engage independent third parties for annual penetration tests.
Logging, monitoring and incidents
All sensitive activity is centrally logged for 12 months. Anomalies trigger real-time alerts. We maintain a documented incident response plan with a 4-hour RTO and 30-minute RPO for critical services.
Personal data breaches are reported to the supervisory authority within 72 hours per article 33 GDPR and affected data subjects are notified without undue delay.
Payments (PCI DSS)
Workers Stay does not store full payment card data. All card handling takes place with our PCI DSS-certified provider Stripe. We are in scope for SAQ-A (lowest applicable level) and do not handle CHD or SAD in clear text.
Sub-processors
We engage only sub-processors that meet equivalent security standards. A full and up-to-date list is available in our DPA. Changes are announced to corporate clients with at least 30 days' notice.
Responsible disclosure
Security researchers are invited to report potential vulnerabilities to security@workersstay.com. We acknowledge within 48 hours, remediate based on CVSS priority and will not pursue legal action against reports made in good-faith research.
Data Processing Agreement (DPA)
Corporate clients whose engagement involves the processing of personal data — booking forms, CRM integrations, lists of employees staying with us — are offered a written DPA before activation. Our standard DPA is aligned with article 28 GDPR and includes EU Standard Contractual Clauses (module 2 and 3 where applicable) for all sub-processors located outside the EEA. Request a copy of the current DPA at privacy@workersstay.com.
Sub-processors
We engage a limited number of carefully vetted sub-processors. Each is bound by a written agreement that imposes equivalent data protection obligations. Current list:
- Google LLC / Google Ireland Ltd — Google Workspace, Analytics, Ads, Maps (EU and US, SCCs).
- Meta Platforms Ireland Ltd — Meta Pixel and CAPI (EU).
- Supabase Inc. — application database and authentication (EU region, Frankfurt).
- Stripe Payments Europe Ltd — card payments (EU, PCI DSS Level 1).
- Resend, Inc. — transactional email (EU region).
- Cloudflare, Inc. — DNS, WAF and edge delivery (global, SCCs).
- PostHog Inc. — product analytics (EU region).
We notify corporate clients in writing at least 30 days before a sub-processor is added or replaced.
Incident response and the 48-hour rule
In the event of a confirmed incident affecting corporate client data we notify the affected client without undue delay and at the latest within 48 hours of confirmation. The notification includes the categories of data affected, likely consequences and the measures taken to mitigate. Personal data breaches are reported in parallel to the supervisory authority within 72 hours per article 33 GDPR.
Confidentiality and NDA
All team members and contractors are bound by written confidentiality obligations that survive termination of their engagement. Mutual NDAs are available on request prior to commercial discussions.
Contact
Security Office: security@workersstay.com. Data protection: privacy@workersstay.com. General contact: contact@workersstay.com. Postal address: Real Estate Ollopa11 Ltd, 128 City Road, London EC1V 2NX, United Kingdom.