Skip to main content

Privacy Policy

1. Who This Notice Is For

This notice is for:

  • customers buying or administering the GMS platform;
  • staff, contractors, and client contacts whose data may be stored in the platform;
  • people who contact GMS directly through sales, support, or our website.

2. Who We Are

Guard Management Systems Ltd ("GMS", "we", "us") provides guard management, incident logging, compliance, reporting, and related mobile and web software.

Company details:

  • Legal name: Guard Management Systems Ltd
  • Registered office: Unit 5 Evtol Trading Estate, Newport, NP20 2DR
  • Company number: 14761547
  • Data Protection Officer or privacy lead: Paul Green
  • Contact Address: [email protected]

3. When GMS Is The Controller And When We Are Not

3.1 When your employer or service provider uses GMS

If you are a guard, employee, contractor, client contact, visitor, or other individual whose data is entered into GMS by one of our customers, that customer usually decides why your data is being used. In those cases:

  • the customer is the data controller;
  • GMS is usually the data processor;
  • your first privacy contact should normally be that customer, not GMS.

3.2 When you deal with GMS directly

GMS is the controller for data we use for our own business purposes, such as:

  • sales conversations;
  • support requests;
  • billing and contracting;
  • security, fraud prevention, and service monitoring;
  • recruitment and supplier management.

4. What Data We May Handle

Depending on how you use the service, GMS may handle:

  • identity and contact details;
  • job role and employment-related details;
  • shift, patrol, check-in, lone-worker, and incident records;
  • site, client, and assignment information;
  • messages, notes, and operational communications;
  • uploaded documents, images, and reports;
  • device identifiers, push registration details, login records, and session information;
  • approximate or precise location data where mobile workflows require it;
  • support and diagnostic records.

Some customers may also use GMS for more sensitive categories of data, such as vetting, complaint, or incident evidence records. In those cases, the customer is responsible for the lawful basis and any additional transparency duties owed to the individual.

5. Why Data Is Used

Data may be used to:

  • provide the platform and mobile services;
  • authenticate users and maintain secure sessions;
  • create reports, workflows, audit trails, and operational outputs;
  • support lone-worker, emergency, patrol, or response functions;
  • provide customer support and troubleshooting;
  • maintain service integrity, security, and resilience;
  • meet legal, regulatory, contractual, and accounting requirements;
  • improve the product in a controlled and proportionate way.

6. Lawful Bases

Where GMS is the controller, we usually rely on one or more of the following lawful bases:

  • contract;
  • legitimate interests;
  • legal obligation;
  • consent, where the law specifically requires it.

Where a GMS customer is the controller, that customer is responsible for deciding and documenting the lawful basis for the personal data it puts into the platform.

7. Sharing

We do not sell personal data.

We may share data with:

  • the relevant customer and its authorised users;
  • hosting, infrastructure, communications, or support providers acting on our instructions;
  • professional advisers, auditors, insurers, or debt recovery providers where needed;
  • regulators, courts, police, or other public authorities where we are legally required to do so or where the law otherwise permits.

Sub processor information

  • Where sub-processors are used their privacy policies will be made available as an addendum to this document.

8. International Transfers

We will not transfer personal data outside the UK unless there is a lawful basis to do so and suitable safeguards are in place. All servers, both live and backup are located within the United Kingdom. We use Email services on servers located both in the United Kingdom and the European Union.

9. Security

We use a mixture of technical and organisational controls, including:

  • encrypted connections in transit;
  • encrypted storage media or encrypted drives for hosted data;
  • session and authentication controls;
  • role-based permissions;
  • logging and monitoring for security and support purposes.

Some authorised GMS personnel may be able to read hosted data where access is necessary for support, debugging, security, maintenance, or legal compliance.

10. Cookies

The GMS platform uses essential cookies for authentication, session continuity, security, and related service functions. The platform cannot operate properly without those cookies.

Please also read the separate cookie policy.

11. How Long Data Is Kept

Retention depends on:

  • whether GMS is acting as controller or processor;
  • the customer's instructions;
  • the relevant contract;
  • legal, tax, audit, insurance, security, and backup requirements.

Please see the retention schedule for the default position.

12. Your Rights

You may have rights to:

  • access your data;
  • correct inaccurate data;
  • erase data in some situations;
  • restrict or object to some processing;
  • complain to the ICO;
  • ask about international transfers and safeguards.

If the data sits in a GMS customer's account, please contact that customer first because they usually control the data and decide how those rights requests are handled.

If your request is about GMS's own business data, contact our designated privacy officer listed above.

13. Complaints

If you are unhappy with how your data has been handled, we would like the chance to address it first. You may also complain to the Information Commissioner's Office at https://www.ico.org.uk. Our ICO Application number is C1940679.

14. Changes To This Notice

We may update this notice from time to time to reflect changes to the service, the law, or our operations.

Version: 2026-05-22 v2