IronLock Back to Login

Privacy Policy

Effective date: 1 July 2026  ·  Last updated: 27 July 2026

This page explains, in plain terms, what information IronLock collects about security guards, why we collect it, and how we keep it safe. It covers both the IronLock mobile app used by guards and the IronLock admin dashboard used by supervisors. IronLock is used only in the United Kingdom, and we follow UK data protection law — the UK GDPR and the Data Protection Act 2018. If anything here is unclear, please ask your administrator and we'll be happy to explain.

1. Who This Applies To

IronLock is not a public app. Accounts are created only by an authorised security firm, and there is no public sign-up. This policy applies to:

  • Guards — security officers given an account and using the mobile app during their shifts.
  • Administrators — the people who run the web dashboard for the firm.

By using the IronLock app, you acknowledge that your information may be handled as described here.

2. Who Looks After Your Data

Two parties are involved in handling data:

  • The security firm that runs IronLock decides what data is collected and why. In legal terms this makes them the "Data Controller."
  • The team that built and hosts IronLock only handles data by following the firm's instructions. In legal terms this makes them the "Data Processor."

3. Why We Collect Data

We collect data for one simple reason: to make sure guards are safe, present, and alert during their shift, and to keep an honest record of what happened. The law calls this a "legitimate interest" — a fair and reasonable business need.

Just as important is what we don't do: we only collect location and photos while a guard is actually on shift. We never track anyone in their own time.

4. What We Collect

Type of informationWhat it isWhy we need it
Account details Name, staff/employee code, username, email, phone, and SIA licence details To set up and manage a guard's account and check their licence is valid
Current location Where the guard is right now, updated regularly while on shift To check the guard is inside their assigned area and to alert a supervisor if they leave it
Verification photos Live photos taken through the app camera, with the time and place they were taken To confirm the guard is really at the site
Welfare checks Whether the guard answered a timed code check, and how quickly To confirm the guard is awake and okay
Shift records Check-in, start and end times, early-end requests and their reasons, and shift events To keep an accurate attendance and compliance record
Security records Login attempts (with time), session details, and the device name/identifier of the phone signed in To keep accounts secure, enforce one-device sign-in, and maintain a trustworthy record
Push notification token An anonymous device token issued by Apple or Google To deliver photo requests, welfare checks and alerts to the right phone
We keep a guard's location for "now" only — not a history. IronLock stores just where a guard is at this moment, and it's replaced every time a new position comes in. There is no map of everywhere they've been during the shift. The system can show where a guard is now — not where they walked earlier.

5. What We Never Collect

  • No tracking off-shift — location is only recorded while a guard is working.
  • No sound or voice recording of any kind, and no reading of calls or messages.
  • No fingerprints or face scans — no biometric data, and no facial recognition on verification photos.
  • No location history or route trail.
  • No access to your contacts, photo gallery, or files.
  • No selling of personal information — ever, to anyone.

6. What the App Asks Permission For

The mobile app asks for these device permissions, and uses them only for the purposes below:

  • Location — to confirm a guard is inside their assigned site boundary while on shift, and to give a supervisor a last known position if something goes wrong.
  • Camera — to take live verification photos when the system asks for one. The app camera is used deliberately so an old picture can't be chosen from the gallery.
  • Notifications — to deliver welfare checks, photo requests, shift reminders and emergency alerts.
  • Internet access — to send shift data to the dashboard.

You can turn any of these off in your device settings, but doing so will stop the matching check from working and may be recorded as a missed check.

7. How We Use the Information

The information is used to:

  • Sign in authorised users and keep accounts secure.
  • Check that a guard is inside their assigned area.
  • Confirm, with a live photo, that a guard is really at the site.
  • Confirm, with a quick code check, that a guard is awake and responsive.
  • Record attendance and shift activity, and raise alerts to a supervisor when something needs attention.
  • Produce compliance reports for the security firm.

Photos are used only to verify shift attendance. They are never shared with outside parties and are never used to judge job performance.

8. Our Legal Basis

Under UK GDPR, we rely on one or more of the following:

  • Legitimate interests — keeping lone workers safe and keeping honest security records.
  • Performance of a contract — your employment or service agreement with the firm.
  • Legal obligation — records the firm is required to keep.
  • Vital interests — where someone's safety is at risk and a supervisor needs a last known location.

9. Who We Share It With

Personal information is only ever available to:

  • Your employer — the security firm running IronLock.
  • The administrators that firm authorises to use the dashboard.
  • The service providers that keep IronLock running: UK-based cloud hosting, and the push notification services that reach your phone — Google's for Android devices, and Google's passing the message to Apple's for iPhone devices.

Push notification services carry only a short prompt — never the contents of your records. We do not sell, rent, or trade personal information, and we do not use it for advertising.

10. How We Keep It Safe

  • Everything stays in the UK — the database, servers and photos are all hosted on UK-based systems. Personal data never leaves the UK.
  • Protected while sending — all data travels over a secure, encrypted (HTTPS) connection.
  • Protected while stored — data and photos are encrypted where they're kept.
  • Photos are private — they're held in private storage and only ever served to a signed-in administrator, never from a public web address.
  • Passwords are scrambled — stored using strong one-way hashing, never as plain text.
  • Access is by role — an account can only reach what its role allows, and access is logged.
  • Records can't be edited — once an event is logged it can't be changed or deleted, so the record stays honest.
  • Just for notifications — with the help of a Google service, we deliver alerts and reminders to the guard's app on both Android and iPhone (on an iPhone that service hands the message to Apple to deliver), without sharing any personal details.

We use industry-standard protections, but no system that sends or stores data electronically can be promised to be perfectly secure.

11. When the Signal Drops

If a guard loses connection, the app keeps working: photos and welfare answers are held on the phone and sent up once the connection returns. Anything held on the phone is stored in the app's own private storage and is only used to complete the shift record. Once it has been safely received, the dashboard clearly marks it as having happened while offline, with the time it actually happened — not the time it arrived.

12. How Long We Keep It

  • Shift history and events — kept as a permanent, unchangeable compliance record. These are never automatically deleted.
  • Verification photos — kept as part of the security record. After each calendar month ends, an administrator can download that month's photos as a backup file (a ZIP), and that backup file is available for 30 days.
  • Generated reports — the exported PDF/CSV files are cleared after 12 months by default; they can be regenerated at any time from the underlying records.
  • Alerts — kept indefinitely unless the firm sets its own limit. Alerts that are still open are never removed automatically.

The security firm, as Data Controller, sets these periods and may keep records for longer where the law or a contract requires it.

13. What Happens When a Guard Is Removed

Removing a guard hides them from the live system — it does not erase their data. When an administrator removes a guard, the account is deactivated, every signed-in device is signed out immediately, and the guard disappears from the roster, the shift picker and licence checks. Their details are kept exactly as they were so that past shifts, alerts, photos and reports still show who was genuinely on duty. The removal can be undone.

This is deliberate. A security record that quietly renamed or blanked the person it refers to would no longer be a truthful record, and the firm is required to be able to show who was working, where, and when.

It also means that removing a guard from the roster is not, by itself, an erasure of their personal data. If someone asks for their personal data to be erased, the security firm handles that as a separate request and decides, record by record, what can be deleted and what must be kept for legal or contractual reasons — then tells the person the outcome.

14. Your Rights

Under UK law, you can ask to:

  • See the information held about you.
  • Correct anything that's wrong.
  • Have your personal information deleted, where the firm isn't required to keep it.
  • Object to or limit how your data is used, in certain cases.
  • Get a copy of your data to take elsewhere, where that applies.

Requests should go to your employer or system administrator, who will respond within the time limits set by UK law. Some records must be retained to meet legal and compliance obligations, and where that applies you'll be told which ones and why.

15. Being Open With Guards

The first time a guard logs into the app, they see a short, plain-English notice explaining what is collected and why. The app also clearly tells guards when their location is being recorded (only while on shift) and that a photo check may be requested during a shift.

16. Age

IronLock is a professional tool for licensed security personnel and is not intended for anyone under 18. We do not knowingly collect information from children.

17. Data Leaving the UK

IronLock is built for firms operating in the United Kingdom, and personal data is hosted in the UK. If that ever needs to change, appropriate safeguards required by UK data protection law will be put in place first, and this policy will be updated.

18. Questions or Concerns

The security firm registers its data handling with the UK's data protection regulator, the Information Commissioner's Office (ICO). If you're ever unhappy with how your data has been handled, you can contact the ICO at ico.org.uk.

19. Updates to This Policy

We may update this policy from time to time as the system or the law changes. When we make an important change, the "Last updated" date at the top will change too.

20. Contact

If you have any questions about your data or this policy, please get in touch through your usual administrator. This policy works alongside our Terms & Conditions.

© 2026 IronLock. All rights reserved.
Privacy Policy · Terms & Conditions · Login