UK GDPR Statement
Last updated: 14 May 2026
GuardFlow is fully committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Roles
For personal data uploaded by tenants (staff, applicants, customer contacts), GuardFlow acts as a processor and the tenant company acts as the controller. For account, billing and platform-usage data, GuardFlow acts as the controller.
Data subject rights
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object
- Rights related to automated decision-making — GuardFlow does not perform solely-automated decisions with legal effects.
Signed-in users can download their data, correct their details and ask for their account to be deleted directly from their account page or the Companion app. Otherwise, submit a request at support@guardflowapp.com. We respond within 30 days. A deletion removes the login and personal data straight away, except records the retention periods below still require, which are held out of everyday use and deleted when their period ends.
Retention
These are the default retention periods. Each customer, as controller, can change them but never below a legal minimum, and nothing is deleted automatically, and no deletion request is carried out without a person reviewing it, until the customer has recorded legal sign-off.
| Records | Default period | Why |
|---|---|---|
| Payroll, tax and pension recordsPayslips, P45 and P60 forms, RTI submissions, pay runs and pension contributions. | 6 years after the end of the tax year | HMRC requires PAYE records for at least 3 years after the end of the tax year they relate to. National Minimum Wage records must be kept for 6 years, so 6 years is the safe default. |
| Timesheets and clock in and out recordsShifts worked, clock in and out times and locations, timesheets and attendance corrections. | 6 years from the date of the record | The Working Time Regulations 1998 require 2 years. These records also evidence pay, so the 6 year National Minimum Wage rule usually applies too. |
| Clock in verification photosSelfies and override photos taken when an officer clocks in or out. | 6 months from the date of the record | No statute sets a period. The photos exist to settle attendance disputes, so a short period suits the UK GDPR data minimisation principle. |
| Live location trailGPS points recorded while an officer is on duty with location tracking on. | 1 year from the date of the record | No statute sets a period. The clock in location stays with the attendance record; this only covers the tracking trail between clock in and clock out. |
| Leavers' contact details, bank details and photosHome address, phone numbers, emergency contacts, bank details and profile photo of someone who has left. | 1 year after the person leaves | No statute sets a period. Bank details are only needed to pay the final wages, and contact details only to reach the person. GuardFlow's GDPR pack commits to removing these 12 months after someone leaves. |
| Leavers' identity and tax detailsLegal name, date of birth, National Insurance number and National Insurance evidence of someone who has left, which their pay and tax records rely on. | 7 years after the person leaves | Payroll and tax records may need to identify the person for 6 years after the last tax year they were paid in, and the Limitation Act 1980 allows most claims for 6 years. |
| Right to work evidenceCopies of passports, visas, residence permits and share code checks. | 2 years after the person leaves | Home Office guidance: keep copies for the whole employment and for 2 years after it ends. |
| SIA licence and BS 7858 screening filesSIA licence checks, driving licence and proof of address copies, credit checks, references, employment history and other vetting records. | 7 years after the person leaves | No statute sets a period. BS 7858 and ACS assessors expect screening files to be kept after employment ends. Confirm the period with your assessor. |
| Employment contracts and HR fileSigned contracts and other HR file documents of someone who has left. | 6 years after the person leaves | No statute sets a period. The Limitation Act 1980 allows contract claims for 6 years, so employers commonly keep contracts for 6 years after employment ends. |
| DBS certificate informationCopies of DBS certificates and the information on them. | 6 months after the decision | The DBS Code of Practice says certificate information should be kept no longer than 6 months after the recruitment decision, unless there is a dispute. The date, reference and outcome of the check can be kept longer. |
| Incident reports and the occurrence bookIncident reports, evidence, patrol exceptions and the occurrence book. | 6 years from the date of the record | The Limitation Act 1980 allows most claims for 6 years (3 years for personal injury). RIDDOR accident records must be kept for at least 3 years. |
| Unsuccessful job applicantsApplications, CVs and notes for people who were not hired. | 6 months after the decision | ICO recruitment guidance: keep only as long as needed. 6 months covers the time limit for an Equality Act claim. |
| Audit logThe record of who did what in GuardFlow, including every deletion and anonymisation. | 7 years from the date of the record | Kept as evidence of how personal data was handled. The log is append-only and nobody can remove entries early. |
| Control room messagesMessages between officers and the control room, and their attachments. | 7 years from the date of the record | Kept as an operational record. Each message carries its own retention date, and legal hold stops removal. |
Each company using GuardFlow is the controller of its staff data and sets its own periods in Settings, within these legal minimums. These periods are defaults based on UK law and guidance. They are not legal advice. Your company should confirm them with its own adviser before switching on automatic deletion. GuardFlow deletes nothing automatically unless the company has recorded that sign-off and switched automatic deletion on. A deletion request follows the same periods: records a period still requires are held out of everyday use until it ends, then deleted.
International transfers
All production data is hosted in Switzerland (Zurich), which the UK recognises as providing an adequate level of data protection. Where a sub-processor is outside the UK, the EEA or Switzerland, we rely on UK Addendum / Standard Contractual Clauses.
Sub-processors
We use the following sub-processors to deliver the service:
- Supabase — database, authentication and file storage (Switzerland, Zurich region).
- Stripe — payment processing for subscriptions and invoices (PCI-DSS Level 1; transfers under SCCs where applicable).
- Resend — delivery of transactional email (account, compliance and billing notifications).
- Cloudflare — CDN and edge delivery, with data localisation.
- Lovable — application hosting and build platform.
We keep this list current. Customers can request advance notice of changes to sub-processors at support@guardflowapp.com.
Breach notification
We notify affected controllers without undue delay and within 72 hours where feasible, providing details of the breach, likely consequences and remediation.
DPO
Data Protection Officer: support@guardflowapp.com