Privacy Policy
Last updated: 14 May 2026
GuardFlow ("we", "us", "our"), operated by FORGEAI STUDIO LTD (trading as NovaStack), is committed to protecting the privacy of all users of our security workforce management platform.
1. Who we are
GuardFlow is a SaaS product provided by FORGEAI STUDIO LTD (trading as NovaStack), a company registered in England and Wales. We act as a data processor on behalf of our customers (security firms) for personal data they upload, and as a data controller for account/billing data.
2. Information we collect
- Account data: name, email, phone, role, employer.
- Operational data: shift records, clock-in/out times and locations, timesheets.
- Compliance data: SIA licence numbers, right-to-work documents, DBS check details, training certificates.
- Photographs: profile photos, clock-in verification images, and patrol or incident photo evidence.
- Technical data: IP address, browser type, device info, log files.
3. How we use your information
- To provide and maintain the service.
- To verify identity, SIA licence, and right-to-work status.
- To process payroll data and generate invoices.
- To send service notifications and compliance reminders.
- To meet legal and regulatory obligations.
4. Lawful basis (UK GDPR)
We rely on: (a) contract — to deliver the service; (b) legal obligation — to retain employment, tax and SIA records; (c) legitimate interests — to operate, secure and improve the platform; (d) consent — for optional marketing.
5. Sharing
We share data only with: your employer (the tenant); our sub-processors under contract — Supabase (database, authentication & storage), Stripe (payments), Resend (transactional email), Cloudflare (CDN & edge delivery) and Lovable (application hosting platform), as listed in our UK GDPR Statement; and authorities where legally required (HMRC, SIA, police). We never sell personal data.
6. Retention
We keep personal data only as long as the law requires or the purpose needs. The default periods below apply unless your employer has set different ones. Where the law sets a minimum, they cannot choose a shorter period.
| Records | Default period | Why |
|---|---|---|
| Payroll, tax and pension recordsPayslips, P45 and P60 forms, RTI submissions, pay runs and pension contributions. | 6 years after the end of the tax year | HMRC requires PAYE records for at least 3 years after the end of the tax year they relate to. National Minimum Wage records must be kept for 6 years, so 6 years is the safe default. |
| Timesheets and clock in and out recordsShifts worked, clock in and out times and locations, timesheets and attendance corrections. | 6 years from the date of the record | The Working Time Regulations 1998 require 2 years. These records also evidence pay, so the 6 year National Minimum Wage rule usually applies too. |
| Clock in verification photosSelfies and override photos taken when an officer clocks in or out. | 6 months from the date of the record | No statute sets a period. The photos exist to settle attendance disputes, so a short period suits the UK GDPR data minimisation principle. |
| Live location trailGPS points recorded while an officer is on duty with location tracking on. | 1 year from the date of the record | No statute sets a period. The clock in location stays with the attendance record; this only covers the tracking trail between clock in and clock out. |
| Leavers' contact details, bank details and photosHome address, phone numbers, emergency contacts, bank details and profile photo of someone who has left. | 1 year after the person leaves | No statute sets a period. Bank details are only needed to pay the final wages, and contact details only to reach the person. GuardFlow's GDPR pack commits to removing these 12 months after someone leaves. |
| Leavers' identity and tax detailsLegal name, date of birth, National Insurance number and National Insurance evidence of someone who has left, which their pay and tax records rely on. | 7 years after the person leaves | Payroll and tax records may need to identify the person for 6 years after the last tax year they were paid in, and the Limitation Act 1980 allows most claims for 6 years. |
| Right to work evidenceCopies of passports, visas, residence permits and share code checks. | 2 years after the person leaves | Home Office guidance: keep copies for the whole employment and for 2 years after it ends. |
| SIA licence and BS 7858 screening filesSIA licence checks, driving licence and proof of address copies, credit checks, references, employment history and other vetting records. | 7 years after the person leaves | No statute sets a period. BS 7858 and ACS assessors expect screening files to be kept after employment ends. Confirm the period with your assessor. |
| Employment contracts and HR fileSigned contracts and other HR file documents of someone who has left. | 6 years after the person leaves | No statute sets a period. The Limitation Act 1980 allows contract claims for 6 years, so employers commonly keep contracts for 6 years after employment ends. |
| DBS certificate informationCopies of DBS certificates and the information on them. | 6 months after the decision | The DBS Code of Practice says certificate information should be kept no longer than 6 months after the recruitment decision, unless there is a dispute. The date, reference and outcome of the check can be kept longer. |
| Incident reports and the occurrence bookIncident reports, evidence, patrol exceptions and the occurrence book. | 6 years from the date of the record | The Limitation Act 1980 allows most claims for 6 years (3 years for personal injury). RIDDOR accident records must be kept for at least 3 years. |
| Unsuccessful job applicantsApplications, CVs and notes for people who were not hired. | 6 months after the decision | ICO recruitment guidance: keep only as long as needed. 6 months covers the time limit for an Equality Act claim. |
| Audit logThe record of who did what in GuardFlow, including every deletion and anonymisation. | 7 years from the date of the record | Kept as evidence of how personal data was handled. The log is append-only and nobody can remove entries early. |
| Control room messagesMessages between officers and the control room, and their attachments. | 7 years from the date of the record | Kept as an operational record. Each message carries its own retention date, and legal hold stops removal. |
Each company using GuardFlow is the controller of its staff data and sets its own periods in Settings, within these legal minimums. These periods are defaults based on UK law and guidance. They are not legal advice. Your company should confirm them with its own adviser before switching on automatic deletion. GuardFlow deletes nothing automatically unless the company has recorded that sign-off and switched automatic deletion on. A deletion request follows the same periods: records a period still requires are held out of everyday use until it ends, then deleted.
7. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, and to lodge a complaint with the ICO (ico.org.uk).
Signed-in users can exercise the main rights themselves: download a copy of their data, correct their details, and ask for their account and personal data to be deleted, from their account page on the web or in the Companion app. Their employer must act on a deletion request within one month, or explain the lawful reason it cannot. A deletion request does not remove records the law still requires, such as a National Insurance number for HMRC or right to work copies for the Home Office: those are held out of everyday use until their period in the table above ends, then deleted. If the person is still owed pay, the deletion waits until their final pay has been made and their P45 issued.
8. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Access is role-based and audit-logged. We use row-level security to ensure tenants can only access their own data.
9. Contact
Data Protection Officer: support@guardflowapp.com