Legal
Guard HQ Privacy Policy
Last updated: 30 June 2026
Effective date: 30 June 2026
This page explains how Guard HQ collects, uses, stores, and protects personal data when you use our B2B workforce platform, when we provide security services directly, and when you visit our website.
1. Introduction
This Privacy Policy explains how Guard HQ Ltd ("Guard HQ", "we", "us", or "our") collects, uses, stores, and protects personal data when you use:
- the Guard HQ mobile application ("App") on iOS and Android; and
- our website at https://guardhq.co.uk ("Website").
Guard HQ operates in two ways: we provide a business-to-business (B2B) workforce platform for security companies, and we also deliver security services directly—employing or contracting guards and serving client sites ourselves. Your relationship with us (and who controls your data) depends on which of these applies to you.
We are committed to protecting your privacy and handling personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data controller contact
Guard HQ Ltd
1 Old Hall Street
Liverpool
Merseyside
L3 9HP
United Kingdom
Email: support@guardhq.co.uk
Website: https://guardhq.co.uk
2. Who this policy applies to
This policy applies if you are:
- a security company administrator registering or managing a company account on our B2B platform;
- a guard using the App for shifts, reports, leave, and payslips—whether employed or contracted by your security company or by Guard HQ when we provide security services directly;
- a client viewing site activity, shifts, and reports—whether your organisation uses the platform through another security company or receives security services from Guard HQ;
- a sub-administrator with delegated access;
- a site contact or representative for premises where Guard HQ provides security services; or
- a visitor to our Website.
3. Our role: controller and processor
Guard HQ operates both as a B2B workforce platform for other security companies and as a security services provider in our own right. Our data protection role depends on the situation:
| Situation | Our role |
|---|---|
| Data we process to run the platform and our security services business (e.g. company registration, support, billing, security logs) | Data controller |
| Workforce and operational data entered by another security company on the platform (guards, clients, sites, rotas, reports, chats, payslips) | Data processor on behalf of that security company |
| Guards, sub-admins, and workforce data where Guard HQ employs or contracts staff to deliver security services | Data controller |
| Client and site data where Guard HQ is contracted to provide security services (including shift reports and incident records shared with the client) | Data controller (and, where applicable, joint controller with the client for operational reporting at protected sites) |
If you use the App through another security company: that company is usually the data controller for your employment and operational data. Requests about that data should normally be made to them first. We will assist them as required by law in our processor role.
If Guard HQ is your employer or security services provider: we are the data controller for your employment, assignment, and operational data. Contact us directly at support@guardhq.co.uk for data subject requests.
Companies registering on the App may optionally provide their own privacy policy URL during signup.
4. Personal data we collect
We collect personal data depending on your role, whether you interact with us as a platform user or as part of our direct security services, and how you use the App.
4.1 Account and identity data
- Full name
- Email address
- Password (stored in hashed/secure form — never in plain text)
- Phone number
- Account role (admin, guard, client, sub-admin)
- Account status (active, inactive, suspended)
4.2 Company registration data (admins)
- Company name
- Company registration number
- Country
- Business address
- Support email
- Optional company privacy policy URL
4.3 Employment and workforce data (guards and sub-admins)
- Date of birth
- Home address
- National Insurance number
- Driving licence number
- Hourly rate or yearly salary
- Security ranks and licence/badge details (e.g. SIA Door Supervisor, badge number and expiry)
- Assigned sites
4.4 Client data
- Name, email, phone
- Site name and address
- Assigned site visibility
4.5 Site and operational data
- Site name, code, type, address
- Site coordinates (latitude/longitude, where provided)
- Emergency contact number
- Assigned guards and clients
- Hourly rates and site requirements (e.g. driving licence required)
4.6 Shift and reporting data
- Shift assignments, confirmations, start/end times, and status
- Patrol records and site checklist responses
- Handover notes
- Incident details (type, time, location, description, actions taken, police diary reference)
- Photos and images captured or uploaded as evidence (via camera or photo library)
4.7 Payroll data
- Payslip period, gross pay, net pay, payment status
- Payslip PDFs (where generated or shared)
4.8 Leave and holidays
- Leave request dates, reasons/comments, and approval status
- Company and site holiday records
4.9 Communications
- In-app chat messages (including sender name, role, timestamp, and context such as user, site, or sub-admin conversation)
4.10 Quotes and commercial requests
- Quote reference, site, dates, guard requirements, ranks, notes, quoted amounts, and status
4.11 Activity and audit data
- Logs of key actions within a company account (e.g. user changes, rota updates, shift events) for administrative and security purposes
4.12 Technical and device data
- Device type, operating system, and app version
- Authentication tokens and session information
- Locally stored app preferences (via device storage)
- Internet connectivity data necessary to operate the App
- Error and diagnostic data from our hosting providers where enabled
We do not intentionally collect data from children. The App is intended for business and workforce use by adults.
5. How we collect personal data
We collect data when you:
- register or sign in to the App;
- are added or managed by your company administrator;
- are engaged by Guard HQ as a guard or sub-admin for security services we deliver;
- enter into or manage a security services contract with Guard HQ as a client or site representative;
- complete shift reports, upload photos, submit leave requests, or send chats;
- use password reset or account deletion request features;
- contact us at support@guardhq.co.uk; or
- interact with our Website.
We may also receive data from your company administrator when they create or update your account, or from client organisations when we onboard sites for security services.
6. Device permissions
The App may request access to:
| Permission | Purpose |
|---|---|
| Camera | Capture photographic evidence for shift reports and incident records |
| Photo library | Select existing images to attach to reports |
| Internet | Sync data, authenticate users, and deliver app functionality |
| Phone dialler | Open your device’s phone app to call emergency or site contacts (we do not record calls) |
You can manage permissions in your device settings. Some features will not work without the relevant permission.
We do not use your camera or photos for advertising or unrelated profiling.
7. How we use personal data and lawful bases
Under UK GDPR, we rely on the following lawful bases:
| Purpose | Lawful basis |
|---|---|
| Creating and managing accounts | Contract (Art. 6(1)(b)) |
| Delivering rotas, reports, chat, leave, and payslips | Contract / Legitimate interests |
| Workforce administration by your company (platform use) | Contract / Legitimate interests (processor role) |
| Employing guards and delivering contracted security services | Contract / Legitimate interests / Legal obligation |
| Security, fraud prevention, and audit logging | Legitimate interests (Art. 6(1)(f)) |
| Legal and regulatory compliance | Legal obligation (Art. 6(1)(c)) |
| Responding to support and deletion requests | Legitimate interests / Legal obligation |
| Improving reliability and fixing errors | Legitimate interests |
Where we process special category data (if any arises in incident reports, such as health-related information), we will do so only where permitted by law — typically with explicit consent, employment law obligations, or the establishment/exercise of legal claims, as applicable.
8. Who we share personal data with
We may share personal data with:
8.1 Your organisation on the platform
When you use Guard HQ through another security company, admins, sub-admins, and authorised clients within that organisation can access data according to their role and permissions.
8.2 Clients and sites where Guard HQ provides security services
When Guard HQ delivers security services directly, we may share relevant operational data—including shift records, patrol reports, and incident information—with authorised contacts at the client sites we protect, in line with our contract and legitimate security needs.
8.3 Service providers (sub-processors)
We use trusted third parties to host and operate the App, including:
- Google Firebase (authentication, cloud database, file storage) — Google Privacy Policy
- Cloud infrastructure and support tools as needed
We require processors to protect data under written agreements consistent with UK GDPR Article 28.
8.4 Legal and safety disclosures
We may disclose data where required by law, court order, or regulatory authority, or to protect rights, safety, and security.
We do not sell your personal data.
9. International transfers
Our service providers may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as:
- UK International Data Transfer Agreement (IDTA);
- UK Addendum to EU Standard Contractual Clauses; or
- an adequacy decision recognised by the UK.
You may request more information about transfers by contacting us.
10. Data retention
We keep personal data only as long as necessary for the purposes described in this policy, including:
| Data type | Typical retention |
|---|---|
| Active account data | For the life of the account and company subscription |
| Shift reports, incidents, and audit logs | As required for operations, legal claims, and industry record-keeping (typically up to 6–7 years where employment/security records apply) |
| Chat messages | Typically 12–24 months unless longer retention is required |
| Payslips and payroll records | As required by UK tax and employment law — typically up to 6 years |
| Support correspondence | Typically 3 years |
When data is no longer needed, we delete or anonymise it securely.
Account deletion: You may request deletion via the App ("Delete Account"). If you use the platform through another security company, also contact your company administrator. If Guard HQ is your employer or security services provider, contact support@guardhq.co.uk directly. Some data may be retained where required by law or for legitimate business purposes (e.g. completed shift records, SIA and employment records).
11. Security
We implement appropriate technical and organisational measures, including:
- encrypted connections (HTTPS/TLS);
- access controls and role-based permissions;
- secure authentication;
- restricted access to production systems; and
- regular review of security practices.
No method of transmission or storage is 100% secure. Please use a strong password and keep your device secure.
12. Your rights (UK GDPR)
If we are the controller of your data, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion in certain circumstances
- Restrict processing — in limited cases
- Data portability — receive your data in a structured format where applicable
- Object — to processing based on legitimate interests
- Withdraw consent — where processing is based on consent
To exercise these rights, contact support@guardhq.co.uk. We respond within one month, extendable where permitted by law.
If your data is controlled by another security company on the platform, contact them first; we will assist them as their processor. If Guard HQ is your employer or the provider of security services at your site, contact us directly.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
13. Marketing and tracking
- The App is not designed for cross-app tracking or behavioural advertising.
- We do not use your workforce data for third-party marketing.
- If we send service or product updates by email, you can opt out of non-essential marketing at any time.
14. Children
The App is not intended for individuals under 18. We do not knowingly collect data from children. Contact us if you believe a child has provided data.
15. Third-party links
The App or Website may link to third-party sites (including a company's own privacy policy). We are not responsible for their privacy practices.
16. Changes to this policy
We may update this policy from time to time. We will post the updated version at https://www.guardhq.co.uk/privacy and update the "Last updated" date. For material changes, we may notify you in the App or by email.
17. Contact us
For privacy questions, data subject requests, or account deletion:
Guard HQ Ltd
1 Old Hall Street
Liverpool
Merseyside
L3 9HP
United Kingdom
Email: support@guardhq.co.uk
Website: https://guardhq.co.uk
Appendix: Summary for app store listings
Data linked to you: Name, email, phone, employment details, location-related site data, photos, messages, payroll information.
Data not used for tracking: As declared in our Apple Privacy Nutrition Label.
Purpose: App functionality, workforce management, security services delivery, account management, and security.
This document is provided for operational use. Have it reviewed by a qualified UK data protection adviser before publication on your website or app stores.