Legal

Guard HQ Privacy Policy

Last updated: 30 June 2026

Effective date: 30 June 2026

This page explains how Guard HQ collects, uses, stores, and protects personal data when you use our B2B workforce platform, when we provide security services directly, and when you visit our website.

1. Introduction

This Privacy Policy explains how Guard HQ Ltd ("Guard HQ", "we", "us", or "our") collects, uses, stores, and protects personal data when you use:

  • the Guard HQ mobile application ("App") on iOS and Android; and
  • our website at https://guardhq.co.uk ("Website").

Guard HQ operates in two ways: we provide a business-to-business (B2B) workforce platform for security companies, and we also deliver security services directly—employing or contracting guards and serving client sites ourselves. Your relationship with us (and who controls your data) depends on which of these applies to you.

We are committed to protecting your privacy and handling personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data controller contact

Guard HQ Ltd
1 Old Hall Street
Liverpool
Merseyside
L3 9HP
United Kingdom

Email: support@guardhq.co.uk

Website: https://guardhq.co.uk

2. Who this policy applies to

This policy applies if you are:

  • a security company administrator registering or managing a company account on our B2B platform;
  • a guard using the App for shifts, reports, leave, and payslips—whether employed or contracted by your security company or by Guard HQ when we provide security services directly;
  • a client viewing site activity, shifts, and reports—whether your organisation uses the platform through another security company or receives security services from Guard HQ;
  • a sub-administrator with delegated access;
  • a site contact or representative for premises where Guard HQ provides security services; or
  • a visitor to our Website.

3. Our role: controller and processor

Guard HQ operates both as a B2B workforce platform for other security companies and as a security services provider in our own right. Our data protection role depends on the situation:

SituationOur role
Data we process to run the platform and our security services business (e.g. company registration, support, billing, security logs)Data controller
Workforce and operational data entered by another security company on the platform (guards, clients, sites, rotas, reports, chats, payslips)Data processor on behalf of that security company
Guards, sub-admins, and workforce data where Guard HQ employs or contracts staff to deliver security servicesData controller
Client and site data where Guard HQ is contracted to provide security services (including shift reports and incident records shared with the client)Data controller (and, where applicable, joint controller with the client for operational reporting at protected sites)

If you use the App through another security company: that company is usually the data controller for your employment and operational data. Requests about that data should normally be made to them first. We will assist them as required by law in our processor role.

If Guard HQ is your employer or security services provider: we are the data controller for your employment, assignment, and operational data. Contact us directly at support@guardhq.co.uk for data subject requests.

Companies registering on the App may optionally provide their own privacy policy URL during signup.

4. Personal data we collect

We collect personal data depending on your role, whether you interact with us as a platform user or as part of our direct security services, and how you use the App.

4.1 Account and identity data

  • Full name
  • Email address
  • Password (stored in hashed/secure form — never in plain text)
  • Phone number
  • Account role (admin, guard, client, sub-admin)
  • Account status (active, inactive, suspended)

4.2 Company registration data (admins)

  • Company name
  • Company registration number
  • Country
  • Business address
  • Support email
  • Optional company privacy policy URL

4.3 Employment and workforce data (guards and sub-admins)

  • Date of birth
  • Home address
  • National Insurance number
  • Driving licence number
  • Hourly rate or yearly salary
  • Security ranks and licence/badge details (e.g. SIA Door Supervisor, badge number and expiry)
  • Assigned sites

4.4 Client data

  • Name, email, phone
  • Site name and address
  • Assigned site visibility

4.5 Site and operational data

  • Site name, code, type, address
  • Site coordinates (latitude/longitude, where provided)
  • Emergency contact number
  • Assigned guards and clients
  • Hourly rates and site requirements (e.g. driving licence required)

4.6 Shift and reporting data

  • Shift assignments, confirmations, start/end times, and status
  • Patrol records and site checklist responses
  • Handover notes
  • Incident details (type, time, location, description, actions taken, police diary reference)
  • Photos and images captured or uploaded as evidence (via camera or photo library)

4.7 Payroll data

  • Payslip period, gross pay, net pay, payment status
  • Payslip PDFs (where generated or shared)

4.8 Leave and holidays

  • Leave request dates, reasons/comments, and approval status
  • Company and site holiday records

4.9 Communications

  • In-app chat messages (including sender name, role, timestamp, and context such as user, site, or sub-admin conversation)

4.10 Quotes and commercial requests

  • Quote reference, site, dates, guard requirements, ranks, notes, quoted amounts, and status

4.11 Activity and audit data

  • Logs of key actions within a company account (e.g. user changes, rota updates, shift events) for administrative and security purposes

4.12 Technical and device data

  • Device type, operating system, and app version
  • Authentication tokens and session information
  • Locally stored app preferences (via device storage)
  • Internet connectivity data necessary to operate the App
  • Error and diagnostic data from our hosting providers where enabled

We do not intentionally collect data from children. The App is intended for business and workforce use by adults.

5. How we collect personal data

We collect data when you:

  • register or sign in to the App;
  • are added or managed by your company administrator;
  • are engaged by Guard HQ as a guard or sub-admin for security services we deliver;
  • enter into or manage a security services contract with Guard HQ as a client or site representative;
  • complete shift reports, upload photos, submit leave requests, or send chats;
  • use password reset or account deletion request features;
  • contact us at support@guardhq.co.uk; or
  • interact with our Website.

We may also receive data from your company administrator when they create or update your account, or from client organisations when we onboard sites for security services.

6. Device permissions

The App may request access to:

PermissionPurpose
CameraCapture photographic evidence for shift reports and incident records
Photo librarySelect existing images to attach to reports
InternetSync data, authenticate users, and deliver app functionality
Phone diallerOpen your device’s phone app to call emergency or site contacts (we do not record calls)

You can manage permissions in your device settings. Some features will not work without the relevant permission.

We do not use your camera or photos for advertising or unrelated profiling.

7. How we use personal data and lawful bases

Under UK GDPR, we rely on the following lawful bases:

PurposeLawful basis
Creating and managing accountsContract (Art. 6(1)(b))
Delivering rotas, reports, chat, leave, and payslipsContract / Legitimate interests
Workforce administration by your company (platform use)Contract / Legitimate interests (processor role)
Employing guards and delivering contracted security servicesContract / Legitimate interests / Legal obligation
Security, fraud prevention, and audit loggingLegitimate interests (Art. 6(1)(f))
Legal and regulatory complianceLegal obligation (Art. 6(1)(c))
Responding to support and deletion requestsLegitimate interests / Legal obligation
Improving reliability and fixing errorsLegitimate interests

Where we process special category data (if any arises in incident reports, such as health-related information), we will do so only where permitted by law — typically with explicit consent, employment law obligations, or the establishment/exercise of legal claims, as applicable.

8. Who we share personal data with

We may share personal data with:

8.1 Your organisation on the platform

When you use Guard HQ through another security company, admins, sub-admins, and authorised clients within that organisation can access data according to their role and permissions.

8.2 Clients and sites where Guard HQ provides security services

When Guard HQ delivers security services directly, we may share relevant operational data—including shift records, patrol reports, and incident information—with authorised contacts at the client sites we protect, in line with our contract and legitimate security needs.

8.3 Service providers (sub-processors)

We use trusted third parties to host and operate the App, including:

  • Google Firebase (authentication, cloud database, file storage) — Google Privacy Policy
  • Cloud infrastructure and support tools as needed

We require processors to protect data under written agreements consistent with UK GDPR Article 28.

8.4 Legal and safety disclosures

We may disclose data where required by law, court order, or regulatory authority, or to protect rights, safety, and security.

We do not sell your personal data.

9. International transfers

Our service providers may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as:

  • UK International Data Transfer Agreement (IDTA);
  • UK Addendum to EU Standard Contractual Clauses; or
  • an adequacy decision recognised by the UK.

You may request more information about transfers by contacting us.

10. Data retention

We keep personal data only as long as necessary for the purposes described in this policy, including:

Data typeTypical retention
Active account dataFor the life of the account and company subscription
Shift reports, incidents, and audit logsAs required for operations, legal claims, and industry record-keeping (typically up to 6–7 years where employment/security records apply)
Chat messagesTypically 12–24 months unless longer retention is required
Payslips and payroll recordsAs required by UK tax and employment law — typically up to 6 years
Support correspondenceTypically 3 years

When data is no longer needed, we delete or anonymise it securely.

Account deletion: You may request deletion via the App ("Delete Account"). If you use the platform through another security company, also contact your company administrator. If Guard HQ is your employer or security services provider, contact support@guardhq.co.uk directly. Some data may be retained where required by law or for legitimate business purposes (e.g. completed shift records, SIA and employment records).

11. Security

We implement appropriate technical and organisational measures, including:

  • encrypted connections (HTTPS/TLS);
  • access controls and role-based permissions;
  • secure authentication;
  • restricted access to production systems; and
  • regular review of security practices.

No method of transmission or storage is 100% secure. Please use a strong password and keep your device secure.

12. Your rights (UK GDPR)

If we are the controller of your data, you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion in certain circumstances
  • Restrict processing — in limited cases
  • Data portability — receive your data in a structured format where applicable
  • Object — to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent

To exercise these rights, contact support@guardhq.co.uk. We respond within one month, extendable where permitted by law.

If your data is controlled by another security company on the platform, contact them first; we will assist them as their processor. If Guard HQ is your employer or the provider of security services at your site, contact us directly.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):

Information Commissioner's Office

https://ico.org.uk

Telephone: 0303 123 1113

13. Marketing and tracking

  • The App is not designed for cross-app tracking or behavioural advertising.
  • We do not use your workforce data for third-party marketing.
  • If we send service or product updates by email, you can opt out of non-essential marketing at any time.

14. Children

The App is not intended for individuals under 18. We do not knowingly collect data from children. Contact us if you believe a child has provided data.

15. Third-party links

The App or Website may link to third-party sites (including a company's own privacy policy). We are not responsible for their privacy practices.

16. Changes to this policy

We may update this policy from time to time. We will post the updated version at https://www.guardhq.co.uk/privacy and update the "Last updated" date. For material changes, we may notify you in the App or by email.

17. Contact us

For privacy questions, data subject requests, or account deletion:

Guard HQ Ltd

1 Old Hall Street
Liverpool
Merseyside
L3 9HP
United Kingdom

Email: support@guardhq.co.uk

Website: https://guardhq.co.uk

Appendix: Summary for app store listings

Data linked to you: Name, email, phone, employment details, location-related site data, photos, messages, payroll information.

Data not used for tracking: As declared in our Apple Privacy Nutrition Label.

Purpose: App functionality, workforce management, security services delivery, account management, and security.

This document is provided for operational use. Have it reviewed by a qualified UK data protection adviser before publication on your website or app stores.