Trust & security
You're trusting us with people's details
Names, hours, time off, and sometimes a sick note. This page sets out what we actually do about that — specifically, so you can check it rather than take our word.
Separation
One business can never see another
Every business on miaHQ shares infrastructure but not data. Separation is enforced by the database itself rather than by application code, so a mistake in a page or an API route cannot leak another company’s people.
- Row-level security is enabled on all 85 tables — there is no table without it.
- Policies key off the signed-in employee’s own company, resolved inside the database.
- The privileged key that bypasses these rules is server-only and never reaches the browser.
Access
People see their own work, and not much else
miaHQ has five roles — owner, admin, manager, supervisor and team member. What each can reach is decided in the database, not just hidden in the interface.
- A team member sees their own hours, shifts and time off.
- A supervisor can be scoped to particular areas: they approve and assign for their own people and nothing wider.
- Only an owner can grant owner or admin rights — a database trigger refuses it from anyone else.
- Manager corrections to a clock-in are recorded with who changed what, and an approved week locks.
Our access
What protects our own way in
Supporting you sometimes means someone at miaHQ needs to open your account. That path is deliberately narrow, recorded, and protected by more than a password.
- Every miaHQ operations account needs a second factor to sign in — an authenticator app, not SMS, which can be intercepted or SIM-swapped.
- Opening a customer account from our side creates a recorded session: who did it, when, and the reason they gave.
- Because that operator has already proved a second factor, a support session carries that assurance with it rather than sidestepping the protections on your own account.
- If someone loses their phone they use a one-time recovery code issued when they set 2FA up — a reset is never weaker than the factor it replaces.
Records
Records that hold up after the fact
Some of what miaHQ stores is evidence — a fridge temperature, a medicine dose, a confirmation that someone read a policy. Those are written to be defensible later, not just displayed now.
- Checklist items snapshot their wording when a run is created, so renaming a list never rewrites what was already ticked.
- An acknowledgement cannot be altered once given — the database rejects the change.
- Animal medicine records have no delete path, because veterinary records must be retained.
- Announcement audiences are fixed at publication, so a leaver or new starter cannot move the number on a post that already went out.
Storage & transit
Where your data sits
Customer data is held in the EU and encrypted both in transit and at rest by the underlying platform.
- Hosted in eu-west-1 (AWS Ireland). Data does not leave the EEA in normal operation.
- All traffic is over TLS; the database is encrypted at rest.
- Documents attached to announcements sit in a private bucket and are served through short-lived signed links, checked against the reader’s access each time.
- Kiosk PINs are stored only as bcrypt hashes — we cannot read them back.
Data protection
Registered with the ICO
miaHQ is a product of Vivid Vision Designs Ltd, registered as a data controller with the UK Information Commissioner's Office. You don't have to take our word for it — the entry is on the ICO's public register, listed under miaHQ.
- Reference
- ZC203564
- Registered
- 20 July 2026
- Renews
- 19 July 2027
Sub-processors
Who else touches your data
miaHQ runs on a small number of other services. These are all of them.
| Service | What it does | What it sees | Where |
|---|---|---|---|
| Supabase | Database, authentication and file storage | All customer data — people, shifts, hours, checklists, announcements and attachments | EU (Ireland) |
| Vercel | Application hosting and delivery | Requests in transit; no customer records are stored here | EU/global edge |
| Resend | Transactional email | Recipient name and email address, and the content of the message sent | EU/US |
| Cal.com | Booking a setup call | Only what a prospect enters when booking — name, email, chosen time | EU |
| Amazon Web Services (SES) | Email delivery (an alternative to Resend) | Recipient name and email address, and the content of the message sent | EU/US |
| Stripe | Subscription billing and payments | Billing contact and subscription details; card data is handled by Stripe | Global |
| Xero | Payroll export (only if you connect it) | Employee identity mapping and approved hours | Global |
| Open-Meteo | Weather on the dashboard | A venue’s approximate coordinates. No personal data is sent | EU |
| Better Stack | Uptime monitoring of our systems | System status only. No personal data is sent | EU/US |
| Anthropic | The Mia AI assistant (only when a company turns it on) | The employee’s own chat messages and the scheduling data Mia looks up to answer them — capped and filtered so bank, pay, HR and contact details are never sent | US |
What we don’t claim
miaHQ is not yet certified to SOC 2 or ISO 27001, and we would rather say so than display a badge we have not earned. The infrastructure we build on — Supabase and Vercel — is independently certified, but that is their audit and not ours. If a formal certification is a condition of your buying miaHQ, tell us and we will talk about the timeline honestly.
Ready for a calmer way to run your team?
miaHQ is in early access with a small group of shift-based businesses. Leave your details and we'll be in touch.
No growth tax. No charge for your staff. Every feature in every plan.
