A procurement-friendly summary of how Labour360 handles POPIA responsibilities, hosting, encryption, tenant separation, access control and AI data usage. Only claims we can stand behind technically are included here — anything more specific is available in our full security documentation on request.
Labour360 processes employee and case data that our customers capture in the platform as an operator under the Protection of Personal Information Act 4 of 2013 (POPIA) — the customer remains the responsible party and determines the purpose and means of processing.
For information submitted directly to us (contact forms, demo requests, account registration) Labour360 acts as the responsible party.
Full detail is set out in our POPIA notice and available in a Data Processing Agreement (DPA) on request.
The application layer runs on Vercel. The database runs on AWS RDS (PostgreSQL). Uploaded documents and evidence (disciplinary files, ISO evidence, case attachments) are stored in Amazon S3, in the eu-west-1 (Ireland) region.
Document storage is hosted in the EU (AWS eu-west-1). Where a customer enables AI-assisted features, the relevant case text is sent to our AI processing partner, Anthropic, for that request only — this is a cross-border transfer and only the data needed to generate the response is sent.
We treat all cross-border processing as subject to POPIA's cross-border transfer requirements.
All application, API and file-transfer traffic is served over HTTPS/TLS — there is no unencrypted path to the platform.
Documents and evidence stored in Amazon S3 are encrypted at rest using AWS server-side encryption (AES-256), applied by default to every object.
Database-level encryption-at-rest configuration is documented in our security overview, available on request.
Labour360 is multi-tenant by design: every record — employees, cases, documents, audit entries — is scoped to an organizationId at the data-access layer. Every query is filtered by organization in the service and repository layers before it reaches the database, so one customer's data is never returned in another customer's request.
Access is enforced by role and by section: user roles (Super Admin, Admin, HR Manager, HR Officer, Finance Manager, Finance Officer, Legal Officer, Training Manager, User, and others) each resolve to a defined access level — full, read-only or none — per module (disciplinary, ISO, employees, payroll, documents, and more).
Sensitive administrative actions (e.g. managing labour agencies) are additionally restricted to specific roles at the API layer, not just hidden in the UI.
Every create, update and delete against a tracked entity is written to an audit log capturing the action, entity, before/after values, the acting user, organization, IP address, user agent and timestamp.
Audit logs are retained for 365 days by default and are themselves scoped per organization; retention can be configured per organization on request.
Our database runs on managed AWS RDS infrastructure, and our document store runs on Amazon S3, both of which provide durability and recovery capabilities at the infrastructure layer.
Specific backup frequency, recovery point and recovery time objectives are documented in our full security overview, available on request.
Personal information is retained only for as long as necessary for the purpose it was collected, or as required by applicable labour, tax or other law, after which it is deleted or anonymised.
Audit logs default to a 365-day retention window per organization, with configurable cleanup.
Employees access only what their role and organization entitle them to see — there is no cross-organization or cross-role visibility by default. Where employee self-service is enabled, individuals see their own records only.
We investigate reported security incidents and, where personal information is affected, notify impacted customers in line with our contractual and POPIA obligations.
Our full incident response process and notification timelines are documented in our security overview and DPA, available on request.
We use a small set of sub-processors to deliver the platform: Vercel (application hosting), Amazon Web Services / AWS RDS and S3 (database and document storage, eu-west-1), Anthropic (AI-assisted features, only when enabled), and Google (optional Google sign-in, only when a customer enables it).
An up-to-date sub-processor list is maintained in our DPA, available on request.
Documents and evidence can be downloaded from the platform at any time by authorised users. Employee and organization records can be deleted by an authorised administrator.
For a full organization-level data export or deletion (e.g. at offboarding), contact us and we will action the request under the timelines in your agreement.
AI-assisted features (the legal intelligence assistant, risk analysis, drafting) are opt-in per organization. When used, the relevant case text is sent to Anthropic's API to generate a response — this data is not used to train Anthropic's models.
Organisations can optionally connect their own Anthropic API key, so AI usage is billed and governed under their own account rather than Labour360's.
AI output is a drafting and research aid, not legal advice — see the limitation below.
Labour360's AI features (risk analysis, document drafting, legal research assistance) are a drafting and research aid grounded in your case evidence and referenced legislation. They do not constitute legal advice, do not replace a qualified labour law practitioner or registered CCMA representative, and outputs should be reviewed by a competent person before being relied on or acted upon.
Request our full security documentation, DPA or a completed vendor questionnaire and we'll get it to your team.