Privacy Notice
How Cross collects, uses, shares, secures, and retains personal data when delivering the platform.
Effective 1 September 2026
Who this notice covers
This notice explains how the Cross entity identified in the relevant account, order, or invoice handles personal data when providing the Cross platform. That entity is the controller for account administration, billing, product security, support, and direct service communications.
For worker, candidate, company-officer, and compliance records entered by a customer, the customer normally determines why the data is used and Cross acts as its service provider or processor. Customers must provide any additional workforce privacy information required by law.
Personal data we collect
- Account data: name, work email, authentication and security records, membership, role, and communication preferences.
- Company and sponsor data: Companies House identity, addresses, licence declarations, key contacts, and role-holder details.
- Worker and compliance data: employment, immigration, Certificate of Sponsorship, Right to Work, attendance, document, deadline, and change-notification information supplied by authorised users.
- Billing data: plan, subscription, invoices, payment status, and Stripe customer references. Cross does not store full card details.
- Technical data: IP address, shortened user agent, timestamps, security events, audit trails, device/browser information, and privacy-minimised usage events.
- Support and advisor data: messages, attachments, review findings, assignment events, and structured responses.
Where data comes from
We receive data from account holders, their organisations and authorised advisors; from Companies House public records; from Stripe subscription and payment events; and automatically from use of Cross. An organisation may also provide information about employees, candidates, directors, officers, and professional contacts.
How and why we use data
We process personal data to:
- create accounts, verify company authority, and provide the requested service;
- secure the platform, enforce permissions, prevent fraud, and maintain audit trails;
- process subscriptions, support billing recovery, and administer plans;
- deliver reminders, notifications, support, advisor assignment, reviews, and service communications;
- monitor reliability and improve Cross using privacy-minimised analytics; and
- comply with legal obligations and establish, exercise, or defend legal claims.
Depending on the context, our UK GDPR bases are performance of a contract, legitimate interests in operating and securing Cross, compliance with legal obligations, and consent where the law specifically requires it. Customers are responsible for identifying their own basis for workforce data they place in Cross.
International transfers
Some providers may process data outside the United Kingdom. Where UK data-protection law requires safeguards, we use an approved transfer mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to approved standard contractual clauses, together with appropriate supplementary measures.
How long we keep data
We keep data only as long as needed for the service, security, legal, accounting, and dispute purposes. Retention depends on the record and the customer relationship.
- Never-paid public onboarding drafts and placeholder company data are deleted after 90 inactive days.
- Raw privacy-minimised onboarding events are deleted after 90 days.
- Non-identifying daily onboarding aggregates may be retained for 24 months.
- Legal acceptances, billing records, security events, and compliance audit history may be retained longer where needed to demonstrate transactions, permissions, or legal compliance.
Security
Cross uses role- and tenant-based access controls, protected authentication tokens, private document storage, audited downloads, encryption in transit, provider controls, and operational monitoring. No online service can guarantee absolute security, so organisations must also manage user access, devices, exports, and credential hygiene.
Your rights
Depending on the circumstances, individuals may have rights to access, correct, erase, restrict, or object to processing; receive portable data; and withdraw consent. A person may also complain to the UK Information Commissioner’s Office. Workforce requests should usually be made first to the employer or organisation that controls the relevant workspace. Privacy questions and requests can be submitted through the support channel shown in Cross.
Changes to this notice
We may update this notice to reflect changes in the service, providers, or law. The current version and effective date appear above. Active customers may be notified of material changes; a policy update alone does not block ordinary portal access, though the current version must be acknowledged for initial Checkout, reactivation, and plan changes.

