Privacy Notice
Last updated: 13th August 2026
1. Who We Are
The Sentry Devices Ltd (“we”, “us”, “our”), of 173 King Street, Ramsgate, Kent, CT11 8PN, is registered with the Information Commissioner's Office (“ICO”), registration number ZB520206.
We wear two different hats depending on the data in question, and it matters which one applies to you:
- We are the data controller for account and billing data connected to a Business Customer's subscription (see section 3.1) and for data collected through our marketing website.
- We are only a data processor for the operational data your workers generate by using the Sentry app (see section 3.2). Your employer (the Business Customer that holds your licence) is the controller of that data, not us, and this Notice does not set out their privacy practices. Ask your employer for their own privacy notice covering your use of the app.
This Notice explains what personal data we collect, why, and what rights you have, whether you're visiting our website, using the Sentry app as a worker, or managing a Business Customer account as an Administrator.
We update this Notice from time to time in response to changes in the law, our processing practices, or the services we offer. When we make changes, we update the date at the top of this document.
2. The Sentry App and Portal
The Sentry app and business administration portal are hosted on our behalf by a UK-based hosting provider, under a written data processing agreement. Our hosting provider stores this data securely but does not decide how or why it's used.
Once a Business Customer's Administrator sets up their account and staff begin using the app, we do not have access to the operational data staff generate: check-ins, location sharing, alarms and alerts, and incident reports. That data is only accessible by the Business Customer, who is responsible for it under their own data protection policies. Panic alarm video sits apart even from that: it is not visible to the Business Customer's Administrators either, only to the individual worker who recorded it, unless that worker chooses to share it further themselves (see section 3.2). We can see a limited set of account-level information about the subscription itself, see section 3.1.
Storing this data on our hosting provider's servers, even though we never access or view it, still counts as “processing” it under UK GDPR, which defines processing broadly to include storage and hosting, not just active use. That's why sections 3.2, 4 and 6 below still apply to it, and why we still need a data processing agreement with each Business Customer in respect of it, even though we can't see it ourselves.
3. What Personal Data We Process
3.1 Data we control ourselves
Website visitors and enquiries: name, email address, phone number, the content of your enquiry, and technical/browsing information collected automatically (see Cookies, below).
Business Customer accounts: the company name, the name and email address of the Administrator who set up the account, the number of app licences purchased, the number of Users, the number of active licences, licences remaining, and any promotional codes used.
Billing: payment and billing information processed via Stripe, and any business name and address you give us so we can send you VAT invoices and receipts.
3.2 Data we process only on behalf of a Business Customer
This data is generated by workers using the app once their employer has set up an account. We store it, but only the Business Customer can access or make decisions about it (one exception is panic alarm video, see below). We're a processor here, not a controller, and this Notice doesn't set the rules for how it's used. It includes:
- check-in times and status;
- location data shared through the app;
- alarms and alerts, and any nominated personal contacts (friends or family) a worker adds to receive them;
- incident reports submitted through the app;
- video automatically recorded when a panic alarm is activated. This is stored on the worker's own device and, for 30 days, on our hosting provider's servers, so the worker can access it by an automatically emailed link if their phone is lost or no longer available to them. This video is only accessible to the worker who recorded it, not to their employer's Administrators through the portal, unless the worker chooses to share it themselves. See section 10 for when the 30-day period may be extended;
- data belonging to friends or family given a free additional licence by a User (see section 6): we have no visibility of this at all beyond knowing a licence has been allocated; the User who allocated it is responsible for it.
4. How We Use the Data We Control, and Our Legal Basis
This table covers the data described in section 3.1 only. Data described in section 3.2 is used as instructed by the relevant Business Customer, under their own lawful basis. Ask your employer's Administrator if you want to know theirs.
| Purpose | Lawful basis |
|---|---|
| Setting up and administering a Business Customer's subscription and licences. | Performance of our contract with the Business Customer. |
| Sending VAT invoices and receipts. | Performance of our contract with you, and compliance with our legal obligations. |
| Responding to enquiries made via our website, email, or social channels. | Our legitimate interest in responding to enquiries. |
| Business management, forecasting, and improving our services. | Our legitimate interest in managing and developing our business. |
| Website analytics and improving the visitor experience. | Your consent (cookies), and our legitimate interest in optimising our website. |
| Processing subscription payments. | Performance of our contract with you. |
| Preventing and detecting crime, including fraud. | Compliance with our legal obligations. |
Where we rely on legitimate interests, we've considered that interest against your rights and have concluded ours does not override yours. You can ask us for more detail on this balancing test at any time.
5. Storing Data on Behalf of Business Customers
Because the Service involves a worker's location and, where a panic alarm is used, video footage, it sits within the ICO's guidance on monitoring workers, but the responsibility for that monitoring sits with the Business Customer, not with us. Each Business Customer is responsible for making sure their own staff are properly informed about this monitoring, for example through an employment contract, a lone-working policy, or a specific notice, before the app is used. We are contractually required to only use this data as the Business Customer instructs, to keep it secure, and not to access it ourselves.
6. Cookies and Analytics
Our website uses cookies to improve your experience and understand how visitors use our site. On your first visit, our cookie banner asks for your permission before any optional cookies are set. You can accept or decline at any time using the Cookie Settings link in the footer.
We use a third-party website analytics tool to collect anonymised data about how visitors interact with our website, including pages visited, time on site, and general geographic region. We do not use this for advertising or remarketing. Analytics cookies are optional and only activated with your consent.
Strictly necessary cookies are set without consent because they're required for the website to function (for example, to remember your cookie preference). No personal data is stored via strictly necessary cookies.
We can only store cookies on your device without consent where they are strictly necessary for the site to work. For all other cookies, we need your consent first.
7. Who We Share Your Data With
We don't sell, rent, or trade your personal data. We work with a small number of carefully selected processors who act on our instructions and are contractually required to protect your data in line with UK GDPR. We describe them by category below rather than by name, as we're not legally required to name them individually, only to describe the categories of recipient and where they're based:
| Category | Purpose | Data processed |
|---|---|---|
| Our hosting provider (UK-based) | Hosting the Sentry app and business portal, including 30-day storage of panic alarm video, on our behalf. | The operational data described in section 3.2 (check-ins, location, alerts, incident reports, panic alarm video). We do not access this data ourselves. |
| Our website analytics provider (US-based) | Website analytics: understanding how visitors use our site. | Anonymised browsing data. Only activated with consent. |
| Our website hosting provider (US-based) | Hosting our marketing website. | Standard web server logs (IP address, browser type, pages requested), retained briefly for security. |
| Our transactional email provider (US-based) | Sending confirmation emails when you submit an enquiry or book a demo. | Name, email address, and enquiry content. |
| Our payment processor (US-based) | Payment processing for subscriptions, and generating VAT invoices/receipts we forward to you. | Payment card and billing data. We don't store or see your full card details, plus your business name and address if you provide it. |
8. International Transfers
Our hosting provider, which hosts the operational app data described in section 3.2, is UK-based, so this data is not transferred outside the UK.
We only share data with US-based providers in three limited ways: website analytics, sending transactional emails, and payment processing for your subscription (see section 7 for all three).
For all three, we rely on appropriate safeguards recognised under UK data protection law, such as the UK-US Data Bridge (the UK extension to the EU-US Data Privacy Framework) or the UK International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, depending on the provider's certification. You can ask us for details of the specific safeguard used for any of them.
The Apple App Store and Google Play Store are used only so that customers can download and subscribe to the app. We don't share personal data with them ourselves. Any data they collect, such as your app-store account or purchase history, is collected directly by them under their own privacy policies, and is outside our control.
9. Your Rights
These rights apply to the data we control ourselves (section 3.1). If you're a worker and want to exercise a right over your check-in, location, alert, incident report, or panic alarm video data, that request should go to your employer, as they control that data. We'll help them fulfil it where we're able to as their processor.
Under UK GDPR, you have the right to:
- request access to the personal data we hold about you;
- request that we correct or update inaccurate or incomplete data;
- request a portable, machine-readable copy of data you've given us;
- request erasure of your data where there's no good reason for us to keep it;
- request that we restrict processing your data in certain circumstances;
- object to processing based on our legitimate interests.
Some of these rights aren't absolute and are subject to conditions under data protection law. To exercise any of them, or to withdraw consent at any time, email privacy@thesentry.co.uk. There's no fee unless your request is clearly unfounded or excessive.
You also have the right to complain to the Information Commissioner's Office if you're unhappy with how we've handled your data, see ico.org.uk.
10. Data Retention
Data we control (section 3.1): we keep it for as long as necessary to administer the subscription and for a reasonable period afterwards to meet our contractual and legal obligations, such as tax record-keeping for VAT invoices.
Data we process on a Business Customer's or User's behalf (section 3.2): panic alarm video is kept on our hosting provider's servers for 30 days as standard. If the police or another authority formally ask us to preserve a specific video for longer, for example as part of an investigation, we may instruct our hosting provider to retain it beyond 30 days, and will tell the relevant Business Customer or account holder where we're able to. We still do not access the footage ourselves. Any onward disclosure of it to the police happens either because we're legally required to (for example, by a court order), or under the exemptions in the Data Protection Act 2018 that allow disclosure for the prevention or detection of crime. Other operational data (check-ins, location, alerts, incident reports) is retained in line with the Business Customer's own instructions and retention schedule. Ask your employer if you want to know how long they keep it.
11. Security
We use appropriate technical and organisational measures to protect your data against unauthorised access, loss, or disclosure, including encryption in transit, access controls, and contractual security requirements for our processors.
12. Children
The Sentry is built for business use, and we expect most Users to be adults. But children may come to use the app in two ways, and it's worth being clear about both:
- As a worker aged 16 or over, added by a Business Customer in an industry where that's a genuine, lawful working relationship (for example, event staffing).
- As a friend or family member given one of a User's free additional licences (see section 6), which carries no minimum age. We have no visibility of these individuals at all, including their age. The adult User who allocated the licence is responsible for making sure this is appropriate, including getting a parent or guardian's consent where needed, particularly for a child under 13.
We don't market the Service directly to children, and a child never signs up to it themselves, they're always added by an adult, either a Business Customer or a User. Downloading the app itself also goes through Apple's or Google's own app store, which applies its own age-rating and parental control framework to the download, as an additional layer outside our control. If we became aware that we held data directly identifying a child in the account/billing data we control (section 3.1), we'd delete it promptly; in practice we don't expect to, since that data is about the Business Customer's account, not individual workers.
13. Contact Us
For anything data protection related, email privacy@thesentry.co.uk. For general enquiries, email info@thesentry.co.uk or visit thesentry.co.uk.
The Sentry Devices Ltd, 173 King Street, Ramsgate, Kent, CT11 8PN.