Privacy
Last updated: 15 July 2026
Tech Guarding Ltd (Tech Guarding) respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, store, share, retain and delete personal data when you use our website, onboarding hub, TechGuard mobile app, guard operations systems, account services, and support channels.
Important information and who we are
Purpose of this Privacy Policy
This privacy policy aims to give you information on how Tech Guarding collects and processes your personal data through your use of our public website, Hub onboarding platform, TechGuard mobile app, operational dashboards, application forms, support channels, account deletion workflows, and related services.
The website, Hub and TechGuard app are not intended for children, and we do not knowingly collect data relating to children.
You must read this privacy policy and any other privacy policy or fair processing policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy policy supplements other notices and privacy policies and is not intended to override them.
Controller
Tech Guarding Ltd is the controller and responsible for your personal data (collectively referred to as Tech Guarding, "we", "us" or "our" in this privacy policy).
Tech Guarding Ltd is registered with the UK Information Commissioner’s Office (ICO) under registration reference ZC184746.
We have appointed a data privacy manager who is responsible for overseeing questions in relation to this privacy policy. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact the data privacy manager using the details set out below.
Contact details
If you have any questions about this privacy policy or our privacy practices, please contact our data privacy manager in the following ways:
Full name of legal entity: Tech Guarding Ltd
Email address: [email protected]
Account deletion and app support email: [email protected]
Postal address: 32 Eyre Street, Sheffield, S1 4QZ
Telephone number: 01147004052
You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
Changes to the privacy policy and your duty to inform us of changes
We keep our privacy policy under regular review. This version was last updated on 15 July 2026.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
Third-party Links
This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.
The data we collect about you
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
- Identity Data includes first name, and last name, company / business name.
- Contact Data includes email address and phone number.
- Financial Data includes bank account, payment, invoicing, payroll, expenses, credit control and other billing information where you are a client, supplier, worker, employee, contractor or other business contact.
- Transaction Data includes details of services requested or supplied, contracts, work records, invoices, payments to and from you or your organisation, and related accounting records.
- Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our website, Hub, app and services.
- Usage Data includes information about how you use our website, products and services.
- Profile Data includes your role, account profile, application profile, services requested, onboarding progress, preferences, feedback, survey responses and records of your interactions with our website, Hub, app and services.
- Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
- Account and Authentication Data includes account identifiers, login records, authentication tokens, multi-factor authentication status, trusted device records, session records, audit logs, account deletion requests and account support records.
- Onboarding and Screening Data includes applicant profile data, date of birth, place of birth, National Insurance number, preferred work areas, identity and right to work documents, SIA licence details, address history, employment and education history, referees, DBS and criminal record declarations, financial integrity declarations, credit reference and affordability check information, credit commitments, payment history, public record information, Companies House directorship information, sanctions, politically exposed person and regulatory screening information, declarations, review notes and compliance evidence.
- Guard Operations Data includes shift check-in and check-out records, patrol records, photo proof images, proof codes, incident reports, incident attachments, welfare checks, panic alarm records, shift exports, manager review activity, notes and operational status updates.
- Location Data includes GPS latitude, longitude, accuracy, address labels derived from coordinates, location unavailable reasons, a recent location refreshed while the app is open and in use (in the foreground) and cached on your device to speed up captures, and location data included in shift, patrol, panic alarm, welfare, incident and photo proof records where the relevant feature is used and permission is granted or operationally required. When you are off shift, or the app is closed, your location is not collected or tracked.
- Camera, Photo and File Data includes photos and patrol proof videos (including their audio) captured or uploaded for shift proof, patrol proof, incident evidence and onboarding documents, plus file names, file types, file sizes, storage paths, thumbnails and related metadata.
- Device, Storage and Offline Data includes app and browser storage used for authentication state, redirect state, cookie preferences, cached location data, queued offline shift actions, diagnostic data and similar information stored in localStorage, sessionStorage, cookies or IndexedDB.
- Notification and Device Data includes a push notification token, the app version and your device platform (for example, Android or iOS), used to deliver alerts to the control room and to operate and support the app.
- On-device security data: if you enable biometric unlock (fingerprint or face) or an app passcode to lock the TechGuard app, these are handled only on your device by its operating system and are never sent to, or stored on, our servers.
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.
Some information we process may be sensitive or receive additional protection under data protection law. This includes identity documents, right to work evidence, DBS and criminal record declarations, sanctions and fraud screening information, financial integrity information, credit reference and affordability information, panic alarm and welfare information, location data, and incident evidence. We only collect and use this information where it is needed for employment screening, security operations, legal or regulatory compliance, safeguarding, contractual obligations, legitimate business interests, or where you have provided consent. Where information is special category data or criminal offence data, we also rely on an additional condition or authorisation under data protection law, such as employment and social security obligations, substantial public interest, legal claims, safeguarding, explicit consent where appropriate, or another condition that applies to the specific check or record.
Non-Automated Decision Making and Profiling
We may use automated systems and tools to support certain business processes, such as risk assessment, fraud prevention, affordability checks, identity verification, screening, compliance checks or record management. These tools may analyse personal data using predefined criteria or rules to generate indicators, scores or recommendations.
We do not make decisions that have a legal or similarly significant effect on individuals based solely on automated processing. Automated screening, fraud, sanctions, PEP, right to work, SIA licence, DBS, credit reference, affordability or similar checks may help flag issues, inconsistencies or records that need review, and may influence the speed or level of review applied to an application or request. Individuals will not be automatically rejected or subject to an adverse onboarding or screening decision without meaningful human involvement. A human reviewer cross-checks the results and makes the final decision before an onboarding or screening outcome is approved or rejected.
If you fail to provide personal data
Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.
How is your personal data collected?
We use different methods to collect data from and about you, including through:
- Direct interactions: You may give us personal data by filling in website, Hub, onboarding, support, account deletion or mobile app forms; creating an account; signing in; uploading documents; taking or uploading photos; submitting shift, patrol, welfare, panic alarm or incident records; corresponding with us by email, telephone, post, social media or support channels; or giving us feedback.
- Automated technologies or interactions: As you interact with our website, Hub or app, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see the Cookies section of this policy for further details.
- App permissions and local device features: The TechGuard app may request camera, microphone, location and notification permissions. Camera access is used for proof photos and incident evidence. The microphone is used only while recording patrol proof videos so those clips can include audio (recording falls back to silent video if microphone access is declined). Location access is used for shift, patrol, alarm, welfare and incident records. To make these captures fast and accurate, while the app is open and in use it may also refresh your device location in the foreground at short intervals and look up the matching address (a reverse-geocoding lookup performed using Google Maps Platform — see the service providers and other recipients named under ‘Disclosures of your personal data’ below), caching the most recent result on your device. The app does not track your location in the background, when it is closed, or while you are off shift. Offline shift actions may be stored locally and synced when your device reconnects.
- Third parties or publicly available sources: We may receive personal data from referees, previous employers, education providers, clients, site managers, regulators, public registers, SIA licence checks, right to work checks, Companies House, sanctions and watchlist sources, DBS or DBS partner workflows, credit reference agencies and financial screening providers including Creditsafe and TransUnion, cloud hosting and storage providers, authentication providers, email delivery providers, bot protection providers, geocoding providers, analytics providers and other service providers that support our website, Hub, app, screening and security operations.
How we use your personal data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we need to comply with a legal obligation.
- Where processing is necessary to perform a contract with you, a client, an employer or a prospective employer, or to take steps before entering into a contract.
- Where processing is necessary to protect vital interests, including responding to panic alarms, welfare checks, urgent safety incidents or emergency situations.
- Where you have consented to us processing your data.
Purposes for which we will use your personal data
We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table below:
Purpose/Activity |
Type of data |
Lawful basis for processing including basis of legitimate interest |
|---|---|---|
|
To manage our relationship with you which will include:
|
|
|
|
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) |
|
|
|
To provide, manage and administer security services and business relationships, including client onboarding, quotations, contracts, service delivery, invoicing, payment administration, credit control, supplier administration, payroll support, expenses, accounting, audit and tax records. |
|
|
|
To deliver and develop relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you. |
|
|
|
To deliver advertising and marketing updates including those regarding our platform, launch date etc. |
|
|
|
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences. |
|
|
|
To make suggestions and recommendations to you about goods or services that may be of interest to you. |
|
|
|
To confirm your country location to determine whether we are able to provide you our Services. |
|
|
|
To create, authenticate and manage accounts across the Hub, TechGuard app and related services, including login, cross-domain authentication, multi-factor authentication, session management, account recovery and account deletion requests. |
|
|
|
To administer onboarding, employment screening, credit reference and affordability checks and BS 7858-aligned compliance workflows, including identity, right to work, SIA licence, address, employment, education, referee, DBS, criminal record, financial integrity, Companies House, sanctions, PEP, fraud and declaration checks. |
|
|
|
To operate the TechGuard mobile app, including shift check-in and check-out, patrol proof, photo proof, offline action queueing, shift history, session activity, exports and operational reporting. |
|
|
|
To respond to panic alarms, welfare checks, urgent incidents, security events and operational safety workflows, including notifying authorised control room, management or client personnel where required. |
|
|
|
To protect our systems, users, clients and business, including fraud prevention, abuse prevention, audit logging, role-based access control, data integrity checks, troubleshooting, testing, maintenance and support. |
|
|
|
To process access, correction, restriction, portability, objection, withdrawal of consent, account deletion and erasure requests, and to preserve relevant records where this is necessary for a specific legal or regulatory obligation, an active investigation, or an actual or reasonably anticipated legal claim. |
|
|
Marketing
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. Consent may be withdrawn at any time. When you give consent, details on how to change your mind will be provided, and you can also contact us to change records of your consent.
Promotional offers from us
We may use your Identity, Contact, Technical, Usage and Profile Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you (we call this marketing).
You will receive marketing communications from us if you have requested information from us.
Third-party marketing
We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.
Opting out
You can ask us to stop sending you marketing messages at any time by using any available marketing preference settings, following the opt-out links on any marketing message sent to you, or contacting us at any time.
If you opt out of receiving marketing messages, this does not stop us using personal data provided through a service relationship or other transaction. We may still send service, account, operational, safety, legal or administrative messages where they are needed for those non-marketing purposes.
Cookies
We use essential cookies and similar technologies for security, authentication, account sessions, preferences, cookie consent, cross-subdomain sign-in and service reliability. Where optional analytics or marketing technologies are used, including Google Analytics / Google tag on the public website and Meta / Facebook Pixel where deployed, we will seek consent where required and process the resulting Technical Data and Usage Data for measurement, service improvement and marketing effectiveness. The TechGuard app and Hub may also use browser or device storage, including localStorage, sessionStorage and IndexedDB, for authentication state, redirect state, cookie preferences, cached location context and offline shift actions. You can set your browser to refuse all or some cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies or local storage, some parts of the website, Hub or app may become inaccessible or may not function properly.
We use Cloudflare Turnstile on forms and other protected flows to help distinguish genuine visitors from automated bots and abuse. When Turnstile is loaded or used, Cloudflare may process information about your browser, device and interaction with the protected page for bot detection, blocking and service improvement. Cloudflare's processing is described in its Turnstile Privacy Addendum and main privacy policy.
Change of purpose
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.
If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Disclosures of your personal data
We may share your personal data with the parties set out below for the purposes set out in the table [Purposes for which we will use your personal data] above. · External Third Parties as set out in the ‘Glossary’ section.
Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy policy.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. Where a third party acts as our processor, we do not allow it to use your personal data for its own purposes and permit processing only for specified purposes and in accordance with our instructions. A separate controller is responsible for its own processing under data protection law.
We may share Financial Data, Transaction Data and related Identity and Contact Data with banks, payment providers, payroll and accounting providers, professional advisers, insurers, auditors, HM Revenue & Customs, regulators and other authorities where this is needed for payment, payroll, accounting, tax, insurance, audit, debt recovery, legal, regulatory or business administration purposes.
Our public website uses analytics and tag services, including Google Analytics / Google tag and Meta / Facebook Pixel where deployed, to understand website usage and improve our website and marketing. These providers may receive Technical Data, Usage Data and cookie or similar identifiers where the relevant technology is active. Our cookie policy gives more detail about the cookies and similar technologies used on the public website.
Credit Reference and Affordability Checks
To help us assess applications, prevent fraud, and meet our legal and regulatory obligations, we may obtain information about you from credit reference agencies (CRAs). We obtain this information via Creditsafe, which uses its data partner TransUnion to supply consumer credit and identity data.
Creditsafe Business Solutions Limited is authorised and regulated by the Financial Conduct Authority (FCA Firm Reference Number: 742313). TransUnion International UK Limited is authorised and regulated by the Financial Conduct Authority (FCA Firm Reference Number: 737740).
The information we receive may include data relating to your identity, credit commitments, payment history, and public record information. This data is used solely for legitimate business purposes, including creditworthiness assessment, identity verification, and fraud prevention, in accordance with applicable data protection laws.
Further information about how Creditsafe and TransUnion process your personal data can be found in their respective privacy notices: Creditsafe Transparency Notice | Customers & Suppliers and TransUnion Bureau Privacy Notice.
Service providers and other recipients used by the TechGuard app. The TechGuard guard app and the Tech Guarding Hub use the organisations below. Their legal roles depend on the service they provide: some act as processors on our instructions, while others act as separate controllers for the personal data they receive.
- Google Maps Platform — receives device GPS coordinates to return a human-readable address (reverse geocoding) used to stamp proof captures. Under the Google Maps Platform data protection terms, Google acts as an independent controller for the personal data it receives. Its processing is also governed by Google’s privacy policy.
- Google / Firebase Cloud Messaging (FCM) — acts as a processor when it receives a device push token and notification content to deliver push notifications and alerts.
- Supabase / Lovable Cloud — acts as a processor in providing database, file storage and realtime services for the TechGuard backend and the Hub. The primary hosting region is Europe (Ireland), although Supabase and its authorised sub-processors may also process personal data in other countries as described under ‘International transfers’ below.
- Sentry — acts as a processor providing crash and error monitoring for the TechGuard app. When an app error occurs, Sentry may receive technical diagnostic details such as the error message, stack trace, app environment, and scrubbed request or breadcrumb context. We disable default personal-data collection and remove cookies, authentication headers, query strings, request bodies, direct user details and console breadcrumbs from the diagnostic event payload. A pseudonymous identifier or app record identifier may remain where needed to diagnose the error. Performance tracing and Session Replay are disabled, and Sentry is not used for product analytics, advertising or cross-app tracking. See Sentry’s privacy policy.
The Tech Guarding Hub is our own identity, single sign-on and onboarding platform, rather than a separate third-party sub-processor.
We do not sell your personal data, and we do not use your guard-app data for advertising. Apart from the scrubbed Sentry crash/error monitoring described above, the TechGuard app contains no third-party product-analytics, advertising, attribution or cross-app tracking software. Your guard evidence (photos, videos and reports) is not shared with other app users or made public. Where your managers or control room can see your shift status, location or reports, that visibility is limited to authorised personnel within Tech Guarding and, where applicable, the client or employing organisation you work for. A client or employing organisation is a separate legal entity and may act as an independent or joint controller for its use of those records. Its own privacy information should explain that processing. This disclosure is not a sale of your data. (Our public website separately uses cookies and analytics as described in the ‘Cookies’ section.)
International transfers
Some of our external third parties are based outside the UK, so their processing of your personal data will involve transferring data outside the UK.
The primary hosting region for the TechGuard backend and the Tech Guarding Hub is Europe (Ireland), within the EEA. Transfers from the UK to the EEA are made in reliance on the UK adequacy regulations. Hosting in Ireland does not prevent limited processing elsewhere: Supabase, Sentry and their authorised sub-processors may process personal data in other countries, and Google Maps Platform, Google / Firebase Cloud Messaging, Google Analytics / Google tag, Meta / Facebook Pixel where deployed, Creditsafe, TransUnion, Cloudflare Turnstile and other service providers may use global infrastructure, including infrastructure in the United States. This means that device location, push tokens, notification content, scrubbed app error diagnostics, website analytics data, credit reference and affordability check data, bot-protection data and related technical data may be processed outside the UK and EEA.
For a transfer of UK personal data to a US recipient that remains certified for the relevant data, we may rely on the UK Extension to the EU–US Data Privacy Framework. Where UK adequacy regulations do not cover a restricted transfer, we use an applicable safeguard such as the UK International Data Transfer Agreement or the UK Addendum to the European Commission’s Standard Contractual Clauses. Before relying on such a safeguard, we carry out the required data protection test (also known as a transfer risk assessment) and put in place any additional protections identified by that assessment. Where the EU GDPR separately applies, we use an applicable EU transfer mechanism, such as an adequacy decision, the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses.
Please contact us if you want further information about the mechanism that applies to a particular transfer or how to obtain a copy of the relevant safeguards.
Data security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. Where they process personal data on our behalf, they act only on our instructions and are subject to a duty of confidentiality.
For the TechGuard app specifically, personal data is encrypted in transit using HTTPS/TLS; proof photos and videos are stored in a private storage area that is not publicly accessible; and on mobile devices your login session is stored encrypted in the device’s secure keystore. Any biometric unlock or app passcode is held only on your device, as described above.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Data retention
How long will you use my personal data for?
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
Contact enquiries and service-assessment requests are normally kept for as long as needed to respond to the enquiry, manage the relationship and keep proportionate business records. Marketing preferences, opt-outs and consent records are kept for as long as needed to respect your choices and demonstrate compliance. Website analytics records are kept for the period set by the relevant analytics tool and are reviewed periodically.
Scrubbed TechGuard app crash and error diagnostics are kept for 30 days and then deleted in accordance with our Sentry project retention setting. They are used only to investigate errors, reduce crashes and maintain app reliability, not for advertising or cross-app tracking.
Basic client, supplier, worker, employee, contractor, payment, payroll, invoicing, accounting and tax records are normally kept for up to six years after the end of the relevant relationship, transaction or financial year, unless a longer statutory period, regulatory requirement, contractual requirement, accreditation requirement or retention hold applies.
Retention of TechGuard guard-app data. Operational evidence generated through the guard app — shift check-in/out records, proof photos and videos, incidents, patrol events and panic alarm records — is retained while the relevant client contract or engagement is active and then, so that it remains available for security and site record-keeping, incident investigation, contractual and accounting requirements, insurance, and the establishment, exercise or defence of legal claims, for a further period of up to six years. That period reflects the six-year limitation period for bringing most contractual and civil claims in England and Wales under the Limitation Act 1980. At the end of it we delete or irreversibly anonymise the records, unless a longer statutory period, a specific client or accreditation requirement, or a retention hold (see below) applies. Where BS 7858 applies, the specific screening records covered by that standard are retained during the relevant employment and for seven years after the employment ends. Other applicant, onboarding and screening records are not automatically retained for seven years and are kept only for their applicable documented period.
At the end of an applicable retention period, we delete or irreversibly anonymise personal data unless, and only for so long as, continued retention is necessary to comply with a specific legal or regulatory obligation, respond to an active investigation, or establish, exercise or defend an actual or reasonably anticipated legal claim. Any retention hold is limited to the relevant records, access and other processing are restricted, and the need for the hold is reviewed periodically. The records are deleted or anonymised when the hold ends. If a hold affects an erasure request, we will explain the applicable grounds and your complaint rights unless the law prevents us from doing so.
Where you request deletion of your account (see ‘Your legal rights’ below), eligible account and app data is deleted without undue delay and normally within 30 days after we have verified the request, unless an applicable exception requires us to retain particular data. Location held on your device is short-lived (cached for minutes to hours), and offline queues hold data only until they have synced.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
Your legal rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data. These rights include:
- Request access to your personal data
- Request correction of your personal data
- Request erasure of your personal data
- Object to processing of your personal data
- Request restriction of processing your personal data
- Request transfer of your personal data
- Right to withdraw consent
If you wish to exercise any of the rights set out above, please contact us. Because the TechGuard app and the Tech Guarding Hub are separate systems, deletion comes in two scopes:
- Delete your personal guard-app data while keeping your Hub onboarding account. You can do this in the app (Profile → delete options). If you are not assigned to an organisation, this removes your whole guard-app account; if you are, your personal (non-organisation) data is removed. Records linked to your organisation are retained only where necessary under the criteria in ‘Data retention’ and are managed by the relevant controller.
- Delete your whole Tech Guarding Hub account. This disables your login, removes or anonymises your Hub identity data, and erases your personal guard-app data on the guard backend. Organisation-linked guard records are retained only where necessary under the criteria in ‘Data retention’ and are managed by the relevant controller. You can request this in the app (Profile → Delete account, which opens the link below) or directly at https://hub.techguarding.com/delete-account.
Some records are kept where this is necessary to comply with legal, contractual or accreditation requirements. BS 7858 is a British Standard rather than legislation. Where it applies, the specific screening records covered by the standard are retained during the relevant employment and for seven years after the employment ends, as described above.
No fee usually required
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
Time limit to respond
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Glossary
Lawful Basis
Legitimate Interest means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.
Comply with a legal obligation means processing your personal data where it is necessary for compliance with a legal obligation that we are subject to.
Third Parties
External Third Parties:
- Service providers acting as processors based in specific regions (such as Europe) who provide IT and system administration services.
- Professional advisers acting as processors or joint controllers including lawyers, bankers, auditors and insurers based in the United Kingdom who provide consultancy, banking, legal, insurance and accounting services.
- HM Revenue & Customs, regulators and other authorities acting as processors or joint controllers based in the United Kingdom who require reporting of processing activities in certain circumstances.
- Cloud hosting, database, storage, authentication, email, bot protection, geocoding, analytics, monitoring, support and security providers who help us operate the website, Hub, TechGuard app and related systems.
- Screening, verification and compliance providers, including providers used for SIA licence checks, right to work checks, Companies House checks, DBS or DBS partner workflows, Creditsafe, TransUnion, credit reference agencies, credit or financial screening, sanctions, fraud and watchlist checks.
- Referees, previous employers, education providers, clients, site managers, control room staff and authorised managers where this is needed for onboarding, employment screening, security operations, incident response, welfare checks or contractual service delivery.
Your Legal Rights
You have the right to:
Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:
- If you want us to establish the data's accuracy.
- Where our use of the data is unlawful but you do not want us to erase it.
- Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.
- You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use.
Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.