Legal · PNC UNIQUE LTD
Security & Retention
Last updated: February 2026
This document describes the technical and organisational measures we apply to protect data processed through the PNC Absence Notifications Portal, and how long we keep it.
1. Data at rest
- All Portal data is stored in an encrypted MongoDB Atlas cluster hosted in the EU region.
- Database volumes are encrypted at rest using AES-256.
- Automated daily backups are retained for 30 days on an encrypted, isolated backup service.
2. Data in transit
- All traffic between browsers, the application and the database is encrypted with TLS 1.2 or above.
- HSTS is enforced on production hostnames.
- Session tokens are issued over HTTPS only and are short-lived.
3. Access control
- Named accounts for all supervisors and administrators; no shared logins.
- Role-based access: contractors, supervisors and administrators only see the data required for their role.
- Passwords are stored as salted, one-way bcrypt hashes; the plaintext is never recorded.
- Administrative access to production infrastructure is limited to authorised PNC personnel and is auditable.
4. Audit trail
Every submission, approval, rejection and cancellation is recorded with the identity of the actor, a UTC timestamp and (where applicable) the reason provided. Audit records are immutable to standard Portal users and are retained per the schedule below.
5. Retention schedule
- Absence notifications and associated audit trail — retained for 6 years after the end of the contractor's engagement, in line with statutory limitation periods under the Limitation Act 1980.
- Contractor and supervisor records — retained for 6 years after end of engagement.
- Authentication and access logs — retained for 12 months.
- Email delivery logs (Resend) — retained for 12 months.
- Database backups — rolling 30-day window.
After the retention period expires, records are deleted or irreversibly anonymised.
6. Incident response
- We monitor error rates, authentication failures and unusual access patterns.
- Any personal-data breach that is likely to result in a risk to individuals' rights is reported to the ICO within 72 hours of PNC becoming aware of it, and to affected individuals where required.
- Post-incident, we conduct a root-cause review and document remediation actions.
7. Sub-processors
- MongoDB Atlas — database hosting (EU region).
- Resend — transactional email.
- Emergent — application hosting.
All sub-processors are bound by written data-processing agreements including confidentiality, security and audit rights.
8. Contact
Security concerns or suspected incidents should be reported immediately to admin@pncunique.com or on 0333 090 5024.
