AdminHQ

Security & Data Protection

Last updated: 19 August 2026

These are the commitments AdminHQ makes about how it handles your data. They sit alongside our Privacy Notice, which explains what we collect and why.

1. Controller and processor roles

For your own account details you are the data subject and we are the controller. For the employee records you enter, you are the controller and we act as processor on your instructions — we only process that data to run the service for you.

2. Access controls

Every record is scoped to the account that created it and enforced at the database level, so one business cannot read another’s employees, records or submissions. Employee links are single-purpose, tokenised and expire after 30 days. They only allow a renewal date to be submitted for approval — they never expose your dashboard.

3. Encryption

All traffic between your browser and AdminHQ is encrypted with HTTPS/TLS, and data is encrypted at rest. AdminHQ does not accept or store document uploads, so no certificates or files are held in the service.

4. Sub-processors

We use a small number of providers to run the service: our hosting and database provider (application hosting and database), our email provider (expiry reminders and account emails), and Paddle (our Merchant of Record for payments, invoicing and tax). Payment card details are handled entirely by Paddle and never reach our systems. We will update this page before adding a new sub-processor that handles personal data.

5. Retention and deletion

We keep your data for as long as your subscription is active. You can delete individual employees at any time, and deleting your account from Settings removes your records immediately. If your subscription ends, we hold your data for 90 days so you can return, then permanently delete it. Activity logs are removed after 24 months. Invoice records held by Paddle are retained by them for the period required by law.

6. Your responsibilities

Use a strong, unique password, keep employee links private, and remove employees who have left. See our Acceptable Use Policy for the full list.

7. Incidents

If we become aware of a personal data breach affecting your data we will notify you without undue delay, describe what happened and what we are doing about it, so you can meet your own reporting duties.

8. Reporting a vulnerability

If you believe you have found a security issue, email support@adminhq.app with enough detail for us to reproduce it. Please do not test against other customers’ data or publish the issue before we have had a chance to fix it.