Back to Login
This page explains, in plain terms, what information IronLock collects about security guards, why we collect it, and how we keep it safe. It covers both the IronLock mobile app used by guards and the IronLock admin dashboard used by supervisors. IronLock is used only in the United Kingdom, and we follow UK data protection law — the UK GDPR and the Data Protection Act 2018. If anything here is unclear, please ask your administrator and we'll be happy to explain.
IronLock is not a public app. Accounts are created only by an authorised security firm, and there is no public sign-up. This policy applies to:
By using the IronLock app, you acknowledge that your information may be handled as described here.
Two parties are involved in handling data:
We collect data for one simple reason: to make sure guards are safe, present, and alert during their shift, and to keep an honest record of what happened. The law calls this a "legitimate interest" — a fair and reasonable business need.
Just as important is what we don't do: we only collect location and photos while a guard is actually on shift. We never track anyone in their own time.
| Type of information | What it is | Why we need it |
|---|---|---|
| Account details | Name, staff/employee code, username, email, phone, and SIA licence details | To set up and manage a guard's account and check their licence is valid |
| Current location | Where the guard is right now, updated regularly while on shift | To check the guard is inside their assigned area and to alert a supervisor if they leave it |
| Verification photos | Live photos taken through the app camera, with the time and place they were taken | To confirm the guard is really at the site |
| Welfare checks | Whether the guard answered a timed code check, and how quickly | To confirm the guard is awake and okay |
| Shift records | Check-in, start and end times, early-end requests and their reasons, and shift events | To keep an accurate attendance and compliance record |
| Security records | Login attempts (with time), session details, and the device name/identifier of the phone signed in | To keep accounts secure, enforce one-device sign-in, and maintain a trustworthy record |
| Push notification token | An anonymous device token issued by Apple or Google | To deliver photo requests, welfare checks and alerts to the right phone |
The mobile app asks for these device permissions, and uses them only for the purposes below:
You can turn any of these off in your device settings, but doing so will stop the matching check from working and may be recorded as a missed check.
The information is used to:
Photos are used only to verify shift attendance. They are never shared with outside parties and are never used to judge job performance.
Under UK GDPR, we rely on one or more of the following:
Personal information is only ever available to:
Push notification services carry only a short prompt — never the contents of your records. We do not sell, rent, or trade personal information, and we do not use it for advertising.
We use industry-standard protections, but no system that sends or stores data electronically can be promised to be perfectly secure.
If a guard loses connection, the app keeps working: photos and welfare answers are held on the phone and sent up once the connection returns. Anything held on the phone is stored in the app's own private storage and is only used to complete the shift record. Once it has been safely received, the dashboard clearly marks it as having happened while offline, with the time it actually happened — not the time it arrived.
The security firm, as Data Controller, sets these periods and may keep records for longer where the law or a contract requires it.
This is deliberate. A security record that quietly renamed or blanked the person it refers to would no longer be a truthful record, and the firm is required to be able to show who was working, where, and when.
It also means that removing a guard from the roster is not, by itself, an erasure of their personal data. If someone asks for their personal data to be erased, the security firm handles that as a separate request and decides, record by record, what can be deleted and what must be kept for legal or contractual reasons — then tells the person the outcome.
Under UK law, you can ask to:
Requests should go to your employer or system administrator, who will respond within the time limits set by UK law. Some records must be retained to meet legal and compliance obligations, and where that applies you'll be told which ones and why.
The first time a guard logs into the app, they see a short, plain-English notice explaining what is collected and why. The app also clearly tells guards when their location is being recorded (only while on shift) and that a photo check may be requested during a shift.
IronLock is a professional tool for licensed security personnel and is not intended for anyone under 18. We do not knowingly collect information from children.
IronLock is built for firms operating in the United Kingdom, and personal data is hosted in the UK. If that ever needs to change, appropriate safeguards required by UK data protection law will be put in place first, and this policy will be updated.
The security firm registers its data handling with the UK's data protection regulator, the Information Commissioner's Office (ICO). If you're ever unhappy with how your data has been handled, you can contact the ICO at ico.org.uk.
We may update this policy from time to time as the system or the law changes. When we make an important change, the "Last updated" date at the top will change too.
If you have any questions about your data or this policy, please get in touch through your usual administrator. This policy works alongside our Terms & Conditions.