Security and Data Storage Statement

Last updated: 20.07.2026

Overview

Armaris is a safer recruitment platform for organisations working with vulnerable adults and children. This statement explains the controls used to protect customer data, support inspection-ready audit trails, and help organisations meet their responsibilities when storing recruitment, identity, DBS, right to work and sponsorship records.

Armaris acts as a Data Processor. Each organisation registered within the platform is the Data Controller for the data held in their account — they decide what is collected and why. Armaris handles that data only on the client’s instructions.

Security is reviewed as the service evolves, and operational access is limited to what is required to provide, support and maintain the platform.

Data Ownership

Each organisation registered within Armaris is the Data Controller for the data held in their account. Armaris acts as the Data Processor, handling that data only on the client’s instructions and never using it for any purpose beyond delivering the platform.

If Armaris is asked to remove data it processes on a client’s behalf, this will receive a response within 30 days. Client data is retained for as long as the subscription remains active, or for the duration of any referral programme, in accordance with the relevant written agreement.

What We Hold

All data processed through Armaris is stored within the UK. On behalf of client organisations, Armaris stores the following:

  • Personal details and contact information for employees and applicants
  • Copies of identity documents, such as passports and driving licences
  • DBS certificate numbers (DBS checks are processed by Aaron’s Department, an official DBS umbrella body; Armaris stores the certificate number and outcome as part of the recruitment record)
  • National Insurance numbers
  • Right to work share codes and supporting records
  • Overseas DBS check certificates
  • Recruitment documentation such as references, right to work records, qualifications, and contracts (depending on plan tier)
  • Organisational account and user data
  • A timestamped activity log for each account

Armaris operates as a secure digital storage and workflow platform. The platform does not make decisions based on the data it holds — document review, verification and approval decisions are made by the client organisation’s authorised users.

Payments are handled by Stripe, a PCI DSS Level 1 certified provider. Armaris does not store card details.

Subprocessors

Armaris engages the following subprocessors:

  • Audacia Consulting Limited — platform development and technical support services, under a written data processing agreement
  • Aaron’s Department — DBS umbrella body responsible for processing DBS check applications on behalf of client organisations
  • Stripe — payment processing (PCI DSS Level 1 certified)
  • Microsoft Azure — cloud infrastructure, hosting, and encrypted storage

Encryption

All data transmitted to and from the Armaris platform is encrypted in transit using TLS 1.2 or above. Data stored within the platform — including documents, records and database content — is encrypted at rest using AES-256 encryption. File storage is FIPS 140-2 compliant. Encryption is managed through Microsoft Azure’s enterprise-grade infrastructure.

Further technical details of the encryption implementation are available to clients and procurement teams on request.

Security Controls

The following controls are applied across the platform to reduce risk and keep sensitive recruitment records controlled, traceable and available when needed:

  • Role-based access across employee, verifier, and administrator levels — users only see information relevant to their role
  • A complete, timestamped audit trail of all core editing actions, including document uploads, check completions, status changes, and user actions, recording who performed each action and when
  • Where a user account is deleted, their name is replaced with ‘Deleted User’ in standard records to support data minimisation. The underlying user ID is retained to allow the original identity to be retrieved where necessary — for example in safeguarding investigations or regulatory inquiries
  • Operational and administrative access is limited, monitored and used only where required to operate or support the service
  • Independent penetration testing carried out annually by Precursor Security, and following any major feature release that affects the platform’s API
  • Runtime configuration for environment-specific values

Data Retention

Client data is retained for as long as the subscription remains active. Following account closure, client data will be retained for a period of 30 days before permanent deletion, unless a shorter period is requested. Data can be exported before deletion.

Payment history is retained after account closure for accounting and legal purposes.

Customers are responsible for applying their own retention schedules and legal requirements within the platform. Armaris provides a central place to manage and review those records.

Leaving the Platform

When a client leaves the platform and a request is received by Armaris to remove their data, this will receive a response within 30 days. Data can be exported in full before deletion. Following account closure, data will be retained for 30 days before permanent deletion, unless a shorter period is requested. Payment history is retained afterwards for accounting purposes.

Incident Response

If a data breach occurs that is likely to put individuals at risk, Armaris will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of it, in line with UK GDPR requirements, and will inform affected organisations without undue delay.

Compliance and Certifications

Armaris operates under the UK GDPR and the Data Protection Act 2018. Relevant service tiers meet CQC and Ofsted requirements, and the platform follows the DBS Code of Practice.

Armaris was developed in collaboration with Audacia Consulting Limited, a UK software development company certified to:

  • Cyber Essentials
  • Cyber Essentials Plus
  • ISO 27001 — Information Security Management
  • ISO 9001 — Quality Management

ICO Registration Number: ZC200700

Your Rights

You have the right to access, correct, delete, restrict, or export your data, and to object to how it is processed. To exercise any of these rights, contact Armaris directly using the details below.

Contact

For data protection, security or privacy queries:

Email:

Registered address: 38 Freemans Way, Harrogate, HG3 1DH

ICO Registration Number: ZC200700