Legal

Privacy Policy

How Verbunk handles personal data, written so a worker can read it. Last reviewed 2026.

Before launch: this document states what the product actually does, checked against the schema. It still needs review by a qualified adviser in each operating jurisdiction, and the entity details in section 1 must be completed.

1. Who we are

Verbunk is operated by [legal entity name], registered at [registered address]. For anything in this document, including a request about your own data, write to [data protection contact].

When an agency uses Verbunk to staff its events, that agency decides what work you are offered and how long your records are kept. In data protection terms the agency is the controller and Verbunk is the processor acting on its instructions. Where we decide something ourselves — how the platform works, how long we keep our own logs — we are the controller.

2. This website

This page is part of the Verbunk marketing site, which is a different thing from the Verbunk product described in the rest of this document. What the site itself does is short enough to state completely.

The forms. If you send a staffing request, a demo request, a message, a checklist request, an invitation request or your address for our occasional insights, what you typed into that form is sent to Verbunk and stored so somebody can read it and reply. That is all of it: the fields on the form, and the time they arrived. Your IP address is used to limit how many submissions one connection can make in an hour and is not stored with what you sent. Nothing is shared with an advertising network, a tracking service or any other third party, because the site does not contact one — it loads no external font, script, image or pixel of any kind.

What we do with it. A person reads it and replies. Nothing here is automated: there is no confirmation email, no mailing platform and no scoring. Enquiries are kept while we are talking to you and for up to two years after the last contact, then deleted. If you would rather we deleted yours sooner, or would like a copy of it, write to the contact in section 1 and say so — there is not much of it and it is easy to find.

Accounts. The site does not create accounts and cannot sign you in. Until 19 August 2026 the sign-up pages asked for a password and the login page accepted one; neither could ever have worked, and both were removed. If you set a password on this site before that date it was never sent to Verbunk and was never on any Verbunk server — it stayed in your own browser. Clearing your browsing data for this site removes it. If you used the same password anywhere else, change it there.

Cookies. One, called vb_home. The home page exists in two versions and we count which one gets a better response; the cookie holds a single letter, a or b, so that a returning visitor sees the same one rather than a page that changes shape between visits. It lasts thirty days, it is readable only by this site, and it holds nothing that identifies you. It is not strictly necessary — it is there to test the page — so if you refuse or delete it the site works exactly as before, and you simply may be shown either version. What we keep from it is four running totals: how many people saw each version and how many clicked. There is no per-visitor record to keep.

3. What we hold about you

If you work shifts through Verbunk: your name and contact details, the roles and skills you list, your stated availability, the licences and certificates you upload with their expiry dates, the shifts you were offered, accepted, declined or worked, when you checked in and out, the hours approved and what you were paid.

If you use Verbunk on behalf of an agency or a client: your name, work contact details, your role, and a record of the actions you take in the product.

What we do not hold. We do not store your location. A geofenced check-in computes the distance to the venue and keeps the verdict and the accuracy of the reading — the coordinates themselves are never written down. We do not hold data about your health, beliefs, political opinions or anything else in the special categories, and the database refuses to store it rather than relying on a screen to prevent it.

4. Why we hold it, and on what basis

To offer you work and run the shift you accepted, which is the contract between you and the agency. To meet obligations that apply to us both, such as working-time limits and the checks a licence requires. To keep the service secure and prove what happened on the day, which is our legitimate interest in an accurate record — and yours, if a shift is ever disputed. Marketing only where you have asked for it, and you can stop it at any time without affecting your work.

5. Who can see what

Access is decided by role and enforced in the database, not by hiding buttons. Your agency sees what it needs to roster and pay you.

Clients see less than people expect. A client booking staff sees how ready their event is, which posts are filled and who has arrived — not your name against a licence expiry, not your reliability record, and not what you are paid. Two client accounts belonging to the same organisation cannot see each other's events.

Every time a client opens a record, that view is written down. It works both ways: it shows an agency who looked at what, and it lets us answer honestly if you ask whether anyone outside your agency has seen your details.

6. Automated decisions, and your right to a person

Verbunk ranks candidates for a shift and forecasts whether an event will be staffed. Every ranking comes with a plain-language explanation of why, and a human can always override it. Where a reliability score affects the work you are offered, you can challenge it: a named person reviews it, the outcome is recorded, and you are told what was decided.

No score is computed from anything you have not been told about, and the list of features used is published inside the product rather than kept internal.

7. How long we keep it

Records are kept on a published schedule rather than indefinitely. Pay and invoicing records are held for the period tax and employment law require. Attendance evidence and the signed delivery records that prove a shift happened are kept for the life of any dispute they might settle. Ranking and forecasting records are kept for a limited period and then removed. The schedule lives in the product and each entry states its reason.

8. Your rights

You can ask for a copy of your data, ask us to correct it, ask us to delete it, object to how we use it, or ask us to stop sending you messages. Verbunk has these built in rather than handled by email: an export produces everything held about you, and an erasure removes it.

Two honest limits. Where a record is evidence — an approved timesheet, a signed proof of delivery — erasing you replaces your name with a stable pseudonym and leaves the record standing, because deleting it would destroy somebody else's proof that a shift was worked and paid. And where a dispute or a legal obligation is live, a record can be held until it closes; that hold is recorded, has a reason, and ends.

If we get this wrong you can complain to your national data protection authority. We would rather you told us first.

9. Messages

You choose which messages you get and by which channel, and you can set quiet hours. Anything about a shift you have accepted still reaches you, because that is the job. Everything else you can switch off, and one link stops all of it.

10. Changes

If this policy changes in a way that affects you, we will say so in the product rather than quietly reposting the page.