Privacy notice
Last updated: 5 September 2026
This notice explains how Milo People handles personal information when you visit our website, contact us, hold an account, or use our workforce-management platform. It is intended to meet the transparency requirements of the UK GDPR and Data Protection Act 2018.
1. Who is responsible for your information?
For employee and workforce records entered into the platform by a customer, your employer or other subscribing organisation will normally be the data controller. Milo Peoplenormally acts as its data processor and processes those records on the customer's documented instructions.
Milo People acts as a controller for information used to run our own business and service, such as website enquiries, account administration, customer contacts, service-security logs, abuse prevention, billing administration and legal/compliance records. The contracting service operator is identified in the relevant customer agreement or order form.
2. Information we process
Depending on how the service is used, information may include:
- name, contact details, account identifiers, job title, workplace and role;
- working hours, rotas, attendance, clock-in/out records, absences and leave;
- employment, contract, pay, payroll and payslip information;
- right-to-work and identity-related information where supplied by your employer;
- bank details and National Insurance information where required for employment/payroll purposes;
- documents uploaded to an employee or company record;
- audit, access, device, security and diagnostic information;
- website enquiry details such as your name, email address and message.
Customers decide which workforce fields they use and must only collect information that is necessary for their employment and operational purposes.
3. Why information is used and lawful bases
Where we act as processor, the customer decides the purpose and lawful basis. Employers commonly rely on employment-law obligations, performance of employment contracts, legal obligations and legitimate interests, depending on the activity and circumstances.
Where we act as controller, we may process information because:
- it is necessary to perform a contract or take requested pre-contract steps;
- we have a legal obligation;
- it is necessary for legitimate interests such as service operation, fraud prevention, cybersecurity, customer support and service improvement, where those interests are not overridden by your rights;
- you have given consent where consent is the appropriate lawful basis.
4. Workforce monitoring and clocking
Rota, attendance and clocking features can amount to worker monitoring. The employer/controller is responsible for ensuring that monitoring is necessary, proportionate and transparent, for identifying an appropriate lawful basis, and for completing a data protection impact assessment where the proposed monitoring is likely to create a high risk to people's rights and freedoms.
5. How information is protected
We use tenant-aware access controls, row-level database security, role and permission checks, private document storage, audit logging and additional protection for sensitive information. National Insurance and bank values stored in dedicated sensitive-data fields use application-level encryption. Revealing full sensitive values is restricted to authorised roles and requires an MFA-backed session.
No online service can guarantee absolute security. We maintain controls intended to reduce risk and investigate suspected incidents. More information is available on our security page.
6. Who information may be shared with
Information may be shared with authorised personnel of the subscribing organisation and with service providers that support hosting, authentication, database, email, monitoring, support or other platform operations. We require service providers handling personal information to be subject to appropriate contractual and confidentiality obligations.
We may also disclose information where required by law, to establish or defend legal claims, or to protect the rights, security and integrity of users, customers or the service.
7. International transfers
Some suppliers may process information outside the United Kingdom. Where UK data protection law requires safeguards for an international transfer, the relevant controller will use an approved transfer mechanism or another lawful safeguard and assess the transfer as required.
8. How long information is kept
We do not keep personal information indefinitely. Customer workforce data is retained according to the customer agreement, customer instructions, configured retention rules and legal requirements. Our own controller records are kept only for as long as reasonably necessary for the purpose collected, including contractual, security, tax, dispute and regulatory requirements. Data is then deleted, anonymised or securely retained where a legal hold applies.
9. Your data protection rights
Depending on the circumstances, you may have rights to access your information, correct inaccurate information, request erasure, restrict processing, object to certain processing, receive portable data, and withdraw consent where processing is based on consent. Some rights are subject to legal exemptions.
For workforce information supplied by your employer, contact your employer first because it will normally be the controller. We assist customers with valid rights requests in accordance with our data processing obligations. Subject access requests are normally handled within one month, subject to the rules allowing an extension for complex or numerous requests.
10. Automated decision-making
The core workforce-management service is not intended to make solely automated decisions that produce legal or similarly significant effects about workers. If a customer configures or combines the service in a way that creates such decision-making, the customer is responsible for satisfying the applicable transparency and safeguards requirements.
11. Personal data breaches
We maintain an incident-response process. Where we act as processor, we notify the affected controller without undue delay after becoming aware of a personal data breach. The controller is responsible for assessing whether notification to the Information Commissioner's Office or affected individuals is required. Where notification to the ICO is required, UK GDPR generally requires it without undue delay and, where feasible, within 72 hours of awareness.
12. Cookies and local storage
We use storage technologies that are necessary for authentication, security, preferences and operation of the service. If we introduce non-essential analytics, advertising or similar technologies that require consent, we will provide the required choice before setting them.
13. Complaints
Please contact us first so we can try to resolve your concern. You also have the right to complain to the UK Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
14. Contact
Privacy and data-protection enquiries can be sent to the contact address shown on our website or in your customer agreement. If your request concerns workforce data, please identify your employer/subscribing organisation so it can be routed to the correct controller.
15. Changes to this notice
We may update this notice when the service, suppliers or legal requirements change. We will update the fixed revision date above when we make a material change rather than changing it automatically each day.