Privacy notice
ERA Contract Audit checks an employer's employment documents against the law. Two kinds of personal data pass through it: the name and work e-mail of the people who use an account, and whatever personal data the uploaded documents contain — a signed contract names an employee and their pay. For the first we are the controller. For the second the employer is the controller and we process the documents on its instructions, only to produce its report. That is why we ask for a template contract rather than signed copies.
Who is responsible
Data controller for this service: Armen Sarkisian, Komitas 57, 0032 Yerevan, Armenia. Questions about your data: privacy@vitersoft.com. You can also complain to the Information Commissioner's Office (ico.org.uk).
What is stored
- The company's name and size band, as typed on the form.
- The name, role and work e-mail of each person on the account, and the order they placed.
- The documents you upload, in private storage, and the text read from them in your browser.
- The findings, the reviewer's decisions and notes, and the published report with the sentences it quotes.
We do not store IP addresses. We do not use a language model or any other AI service: the checks are our own code.
How long
Uploaded documents and the text read from them are deleted automatically 30 days after upload. The published report stays until the account is deleted. The owner can delete the account from the settings page at any time: that removes the documents, the findings, the reports, the order and the people at once, and we count each of our tables and the storage afterwards to confirm nothing is left. An account that was ordered but never signed in to is removed automatically after 30 days. Sign-in links are stored only as a hash and removed within a day of expiring.
Who else sees it
- Cloudflare, Inc. (USA and EU) — runs the application.
- Supabase (EU, Frankfurt) — the database and the private file storage. Only our server can read them; the public keys hold no rights at all.
- Sendinblue SAS, 9-17 rue Salneuve, 75017 Paris, France (trading as Brevo) — sends sign-in links and the message that a report is ready. No message carries anything from your documents. Brevo puts an invisible image in every letter it sends, so it registers when a letter is opened; we cannot switch it off per message. The sign-in link itself is not rewritten.
- PostHog (EU, Germany) — counts how the tool is used: numbers and categories, no names, nothing from your documents.
- Our reviewer — a person working for us who reads your documents to check the findings.
Where a recipient processes data outside the UK or EEA, the transfer is covered by Standard Contractual Clauses.
Cookies
One: the sign-in cookie, which holds the account and the person and nothing else. The analytics run without cookies and without local storage, so there is no banner to click.
Your rights
Under UK GDPR you can ask for a copy of what we hold about you, have it corrected, or have it deleted — the last you can do yourself in settings. An employee whose details are in an uploaded document should ask their employer first; we act on its instructions. Write to privacy@vitersoft.com or hr@vitersoft.com and a person answers.