Back
    Legal

    Security & Compliance

    Workers Stay processes sensitive information about corporate clients, guests and property owners. We apply technical and organisational safeguards in line with ISO/IEC 27001 principles, OWASP ASVS and article 32 GDPR. This page describes our security programme in plain language.

    Last updated: 24 May 2026

    01

    Infrastructure

    The platform runs on EU-based cloud infrastructure with data primarily stored in Frankfurt, Germany. Databases live inside private networks, access uses short-lived tokens and all external traffic is encrypted with TLS 1.2+ and HSTS.

    We maintain redundant storage with automatic backups every six hours and daily point-in-time-recovery snapshots kept for 30 days.

    02

    Encryption

    • Data at rest: AES-256 in the database, hashed passwords (bcrypt/argon2id) and field-level encryption for sensitive data.
    • Data in transit: TLS 1.2 or higher with strong cipher suites, HSTS preload, automated certificate renewal.
    • Keys: managed in a KMS, rotated quarterly and audited on every access.
    03

    Access control

    We apply least privilege and role-based access control (RBAC) implemented through a dedicated `user_roles` table validated by server-side row-level security. Admin accounts require two-factor authentication and every access is logged immutably.

    Departing staff are de-provisioned within 4 hours. Third-party vendors only access systems through dedicated, auditable accounts.

    04

    Secure development lifecycle

    All code is reviewed before deployment. We run automated dependency scanning (SCA), static analysis (SAST), secret scanning and dynamic testing. No production change goes live without an automated test suite, manual review and immediate rollback capability.

    We follow OWASP Top 10 and OWASP API Security Top 10 as baselines and engage independent third parties for annual penetration tests.

    05

    Logging, monitoring and incidents

    All sensitive activity is centrally logged for 12 months. Anomalies trigger real-time alerts. We maintain a documented incident response plan with a 4-hour RTO and 30-minute RPO for critical services.

    Personal data breaches are reported to the supervisory authority within 72 hours per article 33 GDPR and affected data subjects are notified without undue delay.

    06

    Payments (PCI DSS)

    Workers Stay does not store full payment card data. All card handling takes place with our PCI DSS-certified provider Stripe. We are in scope for SAQ-A (lowest applicable level) and do not handle CHD or SAD in clear text.

    07

    Sub-processors

    We engage only sub-processors that meet equivalent security standards. A full and up-to-date list is available in our DPA. Changes are announced to corporate clients with at least 30 days' notice.

    08

    Responsible disclosure

    Security researchers are invited to report potential vulnerabilities to security@workersstay.com. We acknowledge within 48 hours, remediate based on CVSS priority and will not pursue legal action against reports made in good-faith research.

    09

    Data Processing Agreement (DPA)

    Corporate clients whose engagement involves the processing of personal data — booking forms, CRM integrations, lists of employees staying with us — are offered a written DPA before activation. Our standard DPA is aligned with article 28 GDPR and includes EU Standard Contractual Clauses (module 2 and 3 where applicable) for all sub-processors located outside the EEA. Request a copy of the current DPA at privacy@workersstay.com.

    10

    Sub-processors

    We engage a limited number of carefully vetted sub-processors. Each is bound by a written agreement that imposes equivalent data protection obligations. Current list:

    • Google LLC / Google Ireland Ltd — Google Workspace, Analytics, Ads, Maps (EU and US, SCCs).
    • Meta Platforms Ireland Ltd — Meta Pixel and CAPI (EU).
    • Supabase Inc. — application database and authentication (EU region, Frankfurt).
    • Stripe Payments Europe Ltd — card payments (EU, PCI DSS Level 1).
    • Resend, Inc. — transactional email (EU region).
    • Cloudflare, Inc. — DNS, WAF and edge delivery (global, SCCs).
    • PostHog Inc. — product analytics (EU region).

    We notify corporate clients in writing at least 30 days before a sub-processor is added or replaced.

    11

    Incident response and the 48-hour rule

    In the event of a confirmed incident affecting corporate client data we notify the affected client without undue delay and at the latest within 48 hours of confirmation. The notification includes the categories of data affected, likely consequences and the measures taken to mitigate. Personal data breaches are reported in parallel to the supervisory authority within 72 hours per article 33 GDPR.

    12

    Confidentiality and NDA

    All team members and contractors are bound by written confidentiality obligations that survive termination of their engagement. Mutual NDAs are available on request prior to commercial discussions.

    13

    Contact

    Security Office: security@workersstay.com. Data protection: privacy@workersstay.com. General contact: contact@workersstay.com. Postal address: Real Estate Ollopa11 Ltd, 128 City Road, London EC1V 2NX, United Kingdom.

    © 2026 Real Estate Ollopa11 Ltd — Workers Stay.
    Last updated: 24 May 2026
    Registered in England & Wales · Company No. 13697786 · Incorporated 22 October 2021 · 128 City Road, London EC1V 2NX, United Kingdom.

    Real Estate Ollopa11 LTD · Company no. 13697786 · Incorporated 22 October 2021 · 128 City Road, London EC1V 2NX

    © 2026 Workers Stay. All rights reserved.