Legal

Privacy policy

This policy explains what personal data Ubique Group Limited collects, why, how long we keep it, and what you can do about it. It is written in plain English on purpose.

Last updated: 15 September 2026. Controller: Ubique Group Limited, 71-75 Shelton Street, London WC2H 9JQ, company number 12348871.

1. Who we are

Ubique Group Limited ("Ubique", "we", "us") is registered in England and Wales under company number 12348871. Our registered office is 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. We are registered with the UK Information Commissioner's Office (ICO) as a data controller and have appointed a Data Protection Officer, who you can reach at privacy@ubiquehq.co.uk.

Ubique provides employer of record, contractor management, global payroll, PEO and VEO services through the platform at ubiquehq.co.uk. Where we provide services under contract to a client, our roles are set out in the Data Processing Agreement: we act as controller for employment records we are required to keep by law, and as processor for the client's HR data.

2. Who this policy covers

This policy applies to four groups of people:

  1. Clients: the people who represent a company using Ubique, such as administrators, finance contacts and hiring managers.
  2. Employed team members: people employed by Ubique, a Ubique entity or a local employment partner on behalf of a client, and Ubique's own employees.
  3. Contractors: independent contractors engaged and paid through the platform.
  4. Website visitors: anyone who visits ubiquehq.co.uk, uses our free tools or contacts us.

3. What data we collect

3.1 Clients

Name, work email, job title, phone number, company details, billing contact and payment information (bank details or card tokens held by our payment provider), login credentials, and records of how you use the platform, including audit logs of actions taken in your account.

3.2 Employed team members

Because we or our partner are the legal employer, we hold what any employer must hold: name, date of birth, nationality, home address, contact details, identity documents and right-to-work evidence, tax identifiers and social security numbers, bank details, salary, contract terms, time off, expenses, performance-related information shared by the client, emergency contacts, and, where local law requires it, information about health (for sick leave), family (for parental leave or dependants' benefits) and trade union membership. We collect these from you, from the client, and from authorities and benefits providers.

3.3 Contractors

Name, business name, address, tax identifiers, bank details, contract terms, invoices and payment history, and the answers you give in the Misclassification Risk Check if you use it.

3.4 Website visitors

Anything you type into a form (demo requests, contact, newsletter), the inputs you enter into Ubique Atlas and Ubique Calculator (not linked to you unless you sign up), and basic server logs: IP address, browser, pages requested and timestamps.

4. Why we use it and on what basis

Under the UK GDPR and the EU GDPR we must have a lawful basis for each use. These are ours:

  1. Performance of a contract: running your account, employing team members, paying contractors, running payroll, providing support. This covers most of what we do.
  2. Legal obligation: tax withholding and reporting, social security enrolment, right-to-work checks, keeping employment records for statutory periods, responding to lawful requests from authorities, anti-money-laundering checks on clients.
  3. Legitimate interests: securing the platform, preventing fraud, improving the product using aggregated usage data, sending existing clients information about related services, and defending legal claims. We balance these against your rights and you can object at any time.
  4. Consent: marketing emails to people who are not yet clients, and any optional add-ons that need it. You can withdraw consent at any time by using the unsubscribe link or emailing us.
  5. Employment law and substantial public interest: for special category data such as health or trade union membership, we rely on the employment law conditions in Article 9(2)(b) GDPR and Schedule 1 of the UK Data Protection Act 2018.

For residents of California, the CCPA gives you equivalent rights. We do not sell personal information and we do not share it for cross-context behavioural advertising.

5. Who we share it with

  • Your employer or client: if you are an employed team member or contractor, the client company sees the information it needs to manage you day to day: contract terms, salary, leave, expenses, documents you upload. It does not see your bank details or identity documents.
  • Local employment partners: in the 120 countries where a vetted partner is the legal employer, the partner receives the data needed to employ and pay you, under a contract that binds it to this policy and the DPA.
  • Subprocessors: hosting (Amazon Web Services, Ireland and Frankfurt), e-signature, transactional email, payment and foreign exchange providers. The current list is on the security page and in the DPA.
  • Benefits brokers and immigration partners: only if the client buys the add-on, and only the data needed to enrol you or process your application.
  • Authorities: tax authorities, social security bodies, courts and regulators where we are legally required to.
  • Professional advisers: auditors, lawyers and insurers, under confidentiality.

We do not sell personal data. We do not share it with advertisers.

6. International transfers

Platform data is stored in the EU (Ireland and Frankfurt). Because we employ people in 160 countries, employment and payroll data must reach the country where the person works. Where that country is outside the UK and the European Economic Area and has no adequacy decision, we use the EU Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum, supported by a transfer risk assessment. Copies of the clauses in use for a given country are available to clients on request.

7. How long we keep it

  • Client account data: for the life of the contract and 6 years after it ends, for tax and limitation purposes.
  • Employment records: for the statutory retention period in the country of employment, typically between 5 and 10 years after employment ends. We cannot delete these early, even at the client's request.
  • Payroll and tax records: as required by the relevant tax authority, usually 6 to 10 years.
  • Contractor records: 6 years after the last payment.
  • Right-to-work documents: 2 years after employment ends, or longer where local law requires.
  • Website enquiries and demo requests: 24 months from last contact.
  • Server logs: 12 months.

8. Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or give it to you in a portable format. You can withdraw consent where we rely on it. You can also complain to the ICO (ico.org.uk) or your local supervisory authority, though we would rather you told us first.

Email privacy@ubiquehq.co.uk. We acknowledge within 2 business days and respond within one month. If you are employed through Ubique, some records cannot be deleted during the statutory retention period; we will tell you which and why.

9. Cookies

This website sets essential cookies only: a session cookie when you log in and a cookie that remembers whether you have dismissed a notice. There are no analytics, advertising or tracking cookies on ubiquehq.co.uk, which is why there is no cookie banner. The platform at app level uses the same essential cookies plus one for your MFA device trust, which expires after 30 days.

10. Security

Ubique is SOC 2 Type II audited. Data is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher. MFA is mandatory for every user. Access is role-based and logged. Full details, including our subprocessor list and responsible disclosure policy, are on the security page. If we suffer a personal data breach that affects you, we will tell you and the relevant client within 48 hours of confirming it.

11. Changes and contact

We update this policy when the law or our services change. Material changes are announced to clients by email 30 days in advance and the "last updated" date at the top changes. Older versions are available on request.

Data Protection Officer, Ubique Group Limited, 71-75 Shelton Street, London WC2H 9JQ. Email privacy@ubiquehq.co.uk. Phone +44 20 3318 0450.

Questions about your data?

The DPO answers within two business days.