WorkNest Secure
Schedules of Processing
Cyber Essentials
Processing description | Assessing customers for Cyber Essentials and/or Cyber Essentials Plus |
|---|---|
Processing purpose | To assess the customers against the Cyber Essentials requirements and audit them to help them gain Cyber Essentials Plus |
Processing duration | Duration of the contract |
Categories of personal data | Name, work email address, phone number. IP addresses are used in Cyber Essentials Plus audits |
Categories of data subjects | Customers and customers employees |
Information security standards | In accordance with ISO 27001:2022 Cyber Essentials and Cyber Essentials Plus security controls |
Authorised Sub-Processors
Name | Address | Country | Processing carried out |
|---|---|---|---|
IASME | IASME Consortium Ltd, Wyche Innovation Centre, Upper Colwall, Malvern, WR13 6P | UK data stored in UK | Cyber Essentials assessment and Cyber Essentials Plus audit report portal |
Monday.com | 1 Rathbone Square London, W1T 1FB, UK | US based on EU servers | Project management |
Qualys | 100 Brook Drive, Green Park, Reading, Berkshire, England, RG2 6UJ | US data stored in UK | Vulnerability scanning |
CHECK Testing
Description | Details |
|---|---|
Subject matter of the processing | Pen testing of CHECK applications |
Duration of the processing | Duration of the statement of work then stored in logs for 6 months thereafter. Report held for 6 years |
Nature and purposes of the processing | In order to pen test a customer’s environment the processing could entail but not limited to collection, recording, storage, disclosure by transmission, consultation and adaption |
Type of Personal Data | Email address, first name, last name, this list is not exhaustive as further personal data may be accessed dependant on the pen test requested by the customer |
Categories of Data Subject | Customer employees and customers customers |
Retention period(s) for Personal Data during the contract term and process for destruction of data at end of retention period/s | Duration of the statement of work. Logs are held for 6 months thereafter. The report is held in secure portal for up to 6 years containing minimal personal data |
Plan for return and destruction of the data once the processing is complete (unless legal requirement to preserve that type of data). | Once the statement of work completed and the report written the logs are uploaded to a secure file storage and after 6 months are deleted. Within secure portal the report and any associated data is deleted. The customer can export the report and associated data, and a customer may request this data deleted at any point. |
Sub-Processors | Cyndicate Labs: 661 High St, Kingswinford DY6 8AL |
Penetration Testing
Subject matter of the Processing | Support the customer journey whilst they undergo penetration testing. |
|---|---|
Duration of the Processing | For the duration of the contract |
Nature of the Processing | Collection, Recording and Storage |
Purpose of the Processing | To provide the services under the contract |
Categories of Personal Data (including special categories of data, where applicable) | Name, work email address, work phone number and business address |
Categories of data subjects | Customers and clients (including their staff) |
Information security standards | In accordance with ISO 27001:2022 Cyber Essentials and Cyber Essentials Plus security controls |
Authorised Sub-Processors
Sub-processor name | Sub-processor location | Processing Activity |
|---|---|---|
Worknest IT | UK – Cheshire | Office 365 |
Sales
Business Function | WorkNest Cyber Ltd and WorkNest Cyber Inc – Sales |
|---|---|
Information Assets | Zoho CRM; Zoho Sign; Pipedrive; Sybill |
Data Subjects | Customers and clients (including their staff) |
Categories of Data | Name, work email address, work phone number, job title, calls |
Categories of Special Category Personal Data / Criminal Convictions Data | None |
Purpose of Processing / Transfer | Collection, recording, organisation, storage, consultation, AI scanning, use and updating of customer and client contact information for the purposes of communication, relationship management and fulfilment of contractual obligations. |
Legal Basis | Contract, Legal Obligation, Legitimate Interest, Consent |
Companies in Controller Role | WorkNest Cyber Ltd; WorkNest Cyber Inc |
Companies in Processor Role | N/A |
Companies in Joint Controller Role | WorkNest Cyber Ltd; WorkNest Cyber Inc |
Recipients (other 3rd Parties) external to Group (Sub-processors) | Zoho CRM – Ireland / Amsterdam; Pipedrive; Sybill |
Location of Data | Zoho CRM – Ireland / Amsterdam; Pipedrive – US; Sybill – US |
Access | Sales, Client Implementation, Marketing, Finance and some SLT |
Retention Period | Contract length + 7 years |
Security Measures (High-Level) | In accordance with ISO 27001:2022, Cyber Essentials and Cyber Essentials Plus security controls |
Additional Information | None |












