Privacy Policy
This policy explains how PeopleGem handles personal data under the UK GDPR and the Data Protection Act 2018, plainly and without the small print games.
Last updated 10 August 2026
1. Who we are
PeopleGem provides HR, rota scheduling, attendance, leave, UK payroll, workplace pensions, onboarding, Home Office right-to-work compliance, document management and a private, UK-hosted AI assistant to businesses in England & Wales. In this policy, “we”, “us” and “PeopleGem” refer to the provider of the PeopleGem platform.
If you have any question about this policy or about how your data is handled, please contact us at hello@peoplegem.io. [Company registration details available on request.]
2. Our two roles: controller and processor
Data protection law distinguishes between a data controller (who decides why and how personal data is processed) and a data processor (who processes it on a controller’s instructions). PeopleGem acts in both roles, depending on the data:
- We are the controller for the data relating to your account with us: the details of the person who signs up, billing and payment information, support correspondence, and information collected through our website.
- We are the processor for the employee and payroll personal data that our business customers put into the platform. Here, the customer is the controller: they decide what to record and why, and we process it only on their documented instructions in order to provide the service. This processing is governed by a data processing agreement (DPA).
If you are an employee of one of our customers and want to know how your data is used or want to exercise your rights, your employer is the controller and the first point of contact. We will support them in responding to your request.
3. The data we handle
Account and billing data (we are controller)
- Names, work email addresses and phone numbers of the people who administer the account.
- Company details, chosen plan, number of locations and add-ons.
- Billing and payment information (processed by our payment provider, so we do not store full card numbers).
- Support tickets and correspondence with our team.
Customer employee data (we are processor)
- Employee records, including names, contact details, dates of birth, addresses and emergency contacts.
- Pay, hours worked, timesheets, leave and absence, and pension details.
- Right-to-work, visa and BRP documents and expiry dates, used for Home Office compliance.
- Contracts, letters, certificates and other documents uploaded by the customer.
- Some of this is special category data or otherwise sensitive; we handle it accordingly (see Security).
Usage and website data (we are controller)
- Basic technical data such as IP address, device and browser type, and pages visited.
- Product usage needed to keep the service secure, reliable and improving.
- Cookies: we use essential cookies needed for the site and app to work (for example, to keep you signed in). Non-essential cookies are only set with your consent, which you manage through the cookie banner shown on our website.
4. Why we process it, and our lawful bases
Under UK GDPR we rely on the following lawful bases:
- Contract, to provide the service you or your employer signed up for, manage your account and take payment.
- Legitimate interests, to secure, support and improve the platform, prevent fraud and abuse, and communicate with you about the service, balanced against your rights.
- Legal obligation, where processing is required to meet payroll, tax and HMRC reporting duties, and other legal record-keeping requirements.
- Consent, for non-essential cookies and any optional marketing communications; you can withdraw consent at any time.
For employee and payroll data we process as a processor, the lawful basis is determined by the customer as controller, typically their own contractual and legal obligations as an employer.
5. Where your data is stored
- UK-hosted. The platform and its database are hosted in the United Kingdom.
- Your own cloud storage. Customers can connect their own Google Drive, OneDrive or Dropbox so that uploaded documents live in their cloud account, under their control, rather than being locked inside our system. Where you enable this, those files are governed by your agreement with that storage provider as well as this policy.
- Private, self-hosted AI. The PeopleGem-AI assistant runs on our own servers in the UK and answers from your own knowledge base. Your data is not sent to third-party AI models or external AI providers.
6. Sub-processors
To deliver the service we use a small number of trusted sub-processors, each bound by appropriate data protection terms. These include providers for:
- Infrastructure and hosting (UK-based).
- Payment processing for subscriptions.
- The HMRC Government Gateway for real-time payroll (RTI) filing.
- Workplace pension providers (for example NEST, The People’s Pension and NOW: Pensions) where you enable them.
- Messaging delivery over WhatsApp, SMS and email.
A current list of our sub-processors is available on request. Email hello@peoplegem.io.
7. How long we keep it
For employee and payroll data we process on a customer’s behalf, retention follows the customer’s own retention schedule as controller; our platform can delete data automatically on that schedule. Payroll and tax records are kept for the period required by law. Account and billing data is kept for as long as your account is active and for a reasonable period afterwards to meet our own legal and accounting obligations, after which it is deleted or anonymised.
8. Keeping your data secure
- Data is encrypted in transit, and sensitive personal details are encrypted at the field level in our database.
- Access is controlled by role, so people only see the data they need, including scoping accountants and branch admins to their remit.
- We maintain an audit trail of significant actions in the platform.
- We apply organisational and technical measures appropriate to the sensitivity of the data, and support two-factor authentication.
No system can be guaranteed perfectly secure, but we take our responsibilities seriously and will notify affected controllers of any personal data breach in line with our legal obligations.
9. International transfers
Personal data is primarily stored and processed in the United Kingdom. Where any transfer outside the UK is necessary, for example a sub-processor or a cloud-storage provider you choose to connect, we ensure an appropriate safeguard is in place, such as UK adequacy regulations or the International Data Transfer Agreement (or equivalent standard contractual clauses).
10. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure of your data in certain circumstances.
- Restriction of processing in certain circumstances.
- Portability, to receive your data in a portable format.
- Objection to processing based on legitimate interests, and to direct marketing at any time.
To exercise any of these where we are the controller, email hello@peoplegem.io. If you are an employee of one of our customers, please contact your employer as the controller; we provide them with the tools (including data-subject-access and erasure features) to respond.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority, at ico.org.uk, though we’d appreciate the chance to put things right first.
11. Changes to this policy
We may update this policy from time to time. When we make material changes we will update the “last updated” date above and, where appropriate, let you know in the app or by email.
See also our Terms of Service and our GDPR & data protection information. Questions? We’re at hello@peoplegem.io.