DIANDOT HR · TRUST
Security & retention
A practical summary of the technical and organisational controls used for DianDot HR.
Last reviewed 29 August 2026
Access and application security
- Every HR record and mutation is scoped to the authenticated workspace; managers are additionally restricted by branch and explicit permission.
- Passwords are salted and hashed with PBKDF2-SHA256. Owner sessions use HttpOnly, Secure, SameSite cookies and expire after 12 hours.
- Repeated login, password-reset and verification failures are rate-limited and temporarily locked.
- Uploaded files use private object storage and authorised download routes; document request links are limited-lived and single-purpose.
- Automated tests exercise two real isolated D1 workspaces and reject cross-company reads and writes before release.
Backup and recovery
Active workspaces receive a daily database snapshot and copies of employee document objects. Backup runs record row and file counts and failures. Owners can trigger and review backups. Backup objects are retained for 35 days. Recovery is performed by an authorised operator into the same workspace and is validated before service is reopened.
Retention schedule
| Record | Normal retention |
|---|---|
| Active workspace HR records | While the account is active and as instructed by the customer |
| Deleted employee/workspace data | Removed from the live service; residual backup copies expire within 35 days |
| Authentication sessions | Until expiry, logout, password reset or account deletion |
| Verification and reset codes | 15 minutes or until used/replaced; expired records are operationally removable |
| Security error events | Up to 90 days |
| Billing records | For the account term and as required for tax, accounting and dispute obligations |
Incident response
Suspected incidents are contained, logged, assessed for affected workspaces and remediated. Customers are notified without undue delay when their personal data is affected. DianDot supports the customer with available facts so it can meet the UK GDPR 72-hour regulator deadline where applicable.
Requests and reporting
Workspace owners may request or create an export for access and portability work. Employees should contact their employer first. Security concerns and deletion or export requests may be sent to [email protected].