LABOUR360 — SECURITY & DATA PROTECTION OVERVIEW For procurement, security review and vendor assessment use. Full URL: https://labour360.com/security -------------------------------------------------------------------- 1. POPIA RESPONSIBILITIES -------------------------------------------------------------------- Labour360 processes employee and case data captured by customers in the platform as an operator under POPIA (Act 4 of 2013) — the customer remains the responsible party. For data submitted directly to us (contact/demo forms, account registration), Labour360 acts as the responsible party. Full detail: our POPIA notice (https://labour360.com/popia) and Data Processing Agreement, available on request. -------------------------------------------------------------------- 2. HOSTING LOCATION -------------------------------------------------------------------- - Application layer: Vercel - Database: AWS RDS (PostgreSQL) - Documents & evidence: Amazon S3, eu-west-1 (Ireland) -------------------------------------------------------------------- 3. CROSS-BORDER DATA PROCESSING -------------------------------------------------------------------- Document storage is hosted in the EU (AWS eu-west-1). Where AI features are enabled, relevant case text is sent to our AI partner, Anthropic, for that request only. This is treated as a cross-border transfer subject to POPIA's requirements. -------------------------------------------------------------------- 4. ENCRYPTION IN TRANSIT AND AT REST -------------------------------------------------------------------- - In transit: all application, API and file-transfer traffic is served over HTTPS/TLS. - At rest: documents and evidence in Amazon S3 are encrypted using AWS server-side encryption (AES-256) by default. - Database-level encryption-at-rest configuration: documented in our full security pack, available on request. -------------------------------------------------------------------- 5. TENANT SEPARATION -------------------------------------------------------------------- Every record (employees, cases, documents, audit entries) is scoped to an organizationId at the data-access layer. Queries are filtered by organization in the service and repository layers before reaching the database. -------------------------------------------------------------------- 6. ROLE-BASED ACCESS -------------------------------------------------------------------- Access is enforced by role and by module. Roles include Super Admin, Admin, HR Manager, HR Officer, Finance Manager, Finance Officer, Legal Officer, Training Manager and User, each resolving to a defined access level (full / read-only / none) per module. Sensitive administrative actions are additionally restricted at the API layer. -------------------------------------------------------------------- 7. AUDIT LOGGING -------------------------------------------------------------------- Every create, update and delete against a tracked entity is logged with the action, entity, before/after values, acting user, organization, IP address, user agent and timestamp. Default retention: 365 days per organization, configurable on request. -------------------------------------------------------------------- 8. BACKUP AND RECOVERY -------------------------------------------------------------------- Runs on managed AWS RDS and Amazon S3 infrastructure, which provide durability and recovery capabilities at the infrastructure layer. Specific RPO/RTO figures: documented in our full security pack, available on request. -------------------------------------------------------------------- 9. DATA RETENTION -------------------------------------------------------------------- Personal information is retained only as long as necessary for the purpose collected, or as required by applicable law, then deleted or anonymised. Audit logs default to 365-day retention per organization. -------------------------------------------------------------------- 10. EMPLOYEE ACCESS CONTROLS -------------------------------------------------------------------- Employees see only what their role and organization entitle them to. No cross-organization or cross-role visibility by default; where self-service is enabled, individuals see only their own records. -------------------------------------------------------------------- 11. INCIDENT RESPONSE -------------------------------------------------------------------- Reported security incidents are investigated; where personal information is affected, impacted customers are notified per contractual and POPIA obligations. Full process and notification timelines: documented in our security pack and DPA, available on request. -------------------------------------------------------------------- 12. SUB-PROCESSORS -------------------------------------------------------------------- - Vercel — application hosting - AWS (RDS + S3, eu-west-1) — database and document storage - Anthropic — AI-assisted features (opt-in only) - Google — optional Google sign-in (opt-in only) Up-to-date list maintained in our DPA, available on request. -------------------------------------------------------------------- 13. DATA EXPORT AND DELETION -------------------------------------------------------------------- Documents and evidence can be downloaded by authorised users at any time. Employee and organization records can be deleted by an authorised administrator. Full organization-level export or deletion requests (e.g. at offboarding) can be made via security@labour360.com and are actioned per your agreement. -------------------------------------------------------------------- 14. AI DATA USAGE POLICY -------------------------------------------------------------------- AI features are opt-in per organization. When used, relevant case text is sent to Anthropic's API to generate a response; this data is not used to train Anthropic's models. Organisations can optionally connect their own Anthropic API key so AI usage is billed and governed under their own account. AI OUTPUT IS NOT LEGAL ADVICE. It is a drafting and research aid grounded in your case evidence and referenced legislation, and does not replace a qualified labour law practitioner or registered CCMA representative. Review AI output before relying on it. -------------------------------------------------------------------- Questions or need a full security pack, DPA or vendor questionnaire completed? Contact security@labour360.com or via https://labour360.com/contact --------------------------------------------------------------------