GDPR, handled with you, not left to you
Looking after your team's personal data is a shared job: you decide what you collect and why, and PeopleGem gives you the tools to keep it safe and stay on the right side of UK GDPR, without needing a data-protection degree.
UK-hosted Encrypted personal data Self-hosted AI Your own cloud storage
The compliance work, built in
These aren't promises on a page. They're real parts of the product, there to make your day-to-day data duties simpler to meet.
Sensitive data encrypted, field by field
Personal details are encrypted at the field level, so the information most worth protecting stays protected, not just the database it lives in.
Retention that runs on schedule
Set how long each kind of record should be kept and let PeopleGem clear it down on time, so you keep data no longer than you need to, without a diary reminder.
Subject access & erasure, in a few clicks
When a member of staff asks for their data, or asks you to delete it, built-in DSAR and right-to-erasure tools help you respond properly and on time.
ROPA, consent & breach registers
Keep your record of processing activities, consent history and breach log in one place, the paperwork the ICO expects, ready when you need to show your working.
Right-to-work & visa tracking
Keep a clear right-to-work log and get warned before a visa or BRP expires, so you meet your Home Office duties and handle that data with care.
A full audit trail
Sensitive changes are logged, so you can see what happened, when and by whom. That is exactly the accountability UK GDPR asks you to be able to demonstrate.
Private, UK-hosted AI
PeopleGem-AI runs on our own UK servers and answers from your own knowledge base, so your people's data isn't sent off to a third-party AI model.
Your data in your own cloud
Connect your own Google Drive, OneDrive or Dropbox and keep documents in storage you control, and export or move your data any time, with no lock-in.
Sam Okafor
Right to work
Diego Alvarez
Visa expires in 21 days
Mia Turner
DBS check
Your data stays in the UK
Your people's information is hosted in the UK, the AI assistant runs on our own UK servers, and your documents can live in cloud storage you own. Fewer places for data to travel means fewer things to worry about.
Who does what
Being straight about this matters. Under UK GDPR you're the controller and PeopleGem is the processor, and here's honestly where each part sits.
What PeopleGem does
As your data processor
- Act as your data processor, handling personal data on your instructions, for the purposes you set.
- Build in strong security: field-level encryption, access controls, and an audit trail of sensitive changes.
- Give you the tools to meet your duties: DSAR, erasure, retention, ROPA, consent and breach registers.
- Keep our sub-processors transparent, and provide our Data Processing Agreement (DPA) and sub-processor list on request.
- Host your data in the UK and keep the PeopleGem-AI assistant self-hosted, so it stays in-country.
What stays with you
As the data controller
- Act as the data controller, deciding what personal data is collected and why.
- Establish the lawful basis for processing your staff's data, and tell them how it's used.
- Respond to your own people's requests. PeopleGem gives you the tools; the decision and the reply are yours.
- Choose your retention periods and settings to match your obligations and policies.
- Keep your account secure: manage who has access, and use strong sign-in and 2FA.
The rights your staff have, and how we help
UK GDPR gives every person rights over their own data. PeopleGem gives you a hand with each one, so responding is a task, not a scramble.
Access
Pull together a subject's personal data with the built-in DSAR tools, ready to share.
Rectification
Records are editable, so you can correct inaccurate or out-of-date details straight away.
Erasure
Right-to-erasure and scheduled retention help you delete data when it should go.
Restriction
Access controls and offboarding let you limit who can see or process a record.
Portability
Export your data in common formats, and keep documents in your own cloud from the start.
Objection
With a clear record of what's held and why, you can review and act on an objection with confidence.
The details, and where to find them
Is PeopleGem the controller or the processor?+
For your employees' data, you're the data controller and PeopleGem is your data processor, so we handle personal data on your instructions and give you the tools to meet your obligations. We don't claim any formal certification for that; we describe the practices we follow and are happy to talk them through.
Where can I read your privacy and terms?+
Our privacy notice lives at /privacy and our terms at /terms. They set out how we handle data and the agreement between us.
Can I get your DPA or a list of sub-processors?+
Yes. Email hello@peoplegem.io and we'll share our Data Processing Agreement and current sub-processor list.
Compliance you don't have to carry alone
Bring HR, payroll and rota into one place, with the encryption, retention and data tools that help you meet UK GDPR built right in. Start free, no card needed.