Security & compliance

Built to be asked about

Staffly handles national ID numbers, salary data and employment documents. Here is what has actually been done about that.

Security settings in Staffly: language, changing your password and two-factor authentication.
Data

Where your data lives

Staffly runs on Google Cloud in the EU. Application logic runs in europe-west1 (Belgium), and data is processed within the EU/EEA.

  • Data processed within the EU/EEA
  • A data processing agreement can be signed
  • Sub-processors disclosed on request
  • Your data is yours - including if you leave
The audit log in Staffly with timestamp, user, action and outcome for every event.
Access

Who can see what

Access is governed at three levels: which modules the company has, which rights the user has, and what the individual role may see.

  • Role-based access: sales, finance, recruitment, full access
  • Read-only office users
  • Two-factor by SMS can be required at login
  • Portal users only ever see their own data
  • Enforcement happens on the server too, not just in the browser
Sensitive data

National ID and documents

National ID numbers are stored encrypted and only revealed when a user with the right actively asks. Documents are encrypted on upload.

  1. 1National ID encrypted in the database
  2. 2Sensitive files encrypted on upload
  3. 3Consent captured separately at registration
  4. 4Export and deletion of personal data can be handled
  5. 5Access to sensitive fields appears in the audit log
Traceability

Audit log with export

Actions are logged with user, timestamp, action and what changed. The log can be filtered and exported when someone asks.

  • Filter by date, user, action and object
  • See what changed, and why
  • Export to CSV
  • History per employee, order and customer
Mobile

The phone is an entry point too

The app locks with biometrics and an app lock, because a phone in a crew room is a different threat than a PC in an office.

  • Face ID or fingerprint before the app opens
  • App lock after inactivity
  • Two-factor at login
  • The same role-based access as in the browser

In short

EU/EØS

Data processed in the EU.

Databehandleraftale

Can be signed.

Kryptering

National ID and sensitive files.

To-faktor

SMS at login.

Rollestyring

Access per role and module.

Revisionslog

With filtering and export.

Questions from your IT or procurement?

Send them over and we will answer specifically - including the dull ones.