TacDesk Privacy Policy
Last updated: 21 September 2026
1. About this policy
TacDesk ("TacDesk", "we", "us", "our") provides a workforce management platform used by licensed security companies in the United Kingdom to manage their on-the-ground operations. This Privacy Policy explains how we collect, use, share and protect personal information when you use the TacDesk mobile app or any TacDesk-hosted web portal provided by your employer.
Two things to understand up front:
- The TacDesk app is only available to employees and contractors of security companies that subscribe to TacDesk. It is not a consumer app.
- Your employer (the security company that issued your TacDesk account) is the data controller for almost all the personal information processed about you while you use the app — your name, shift records, location while on duty, reports you submit, and so on. TacDesk processes that information on your employer's behalf as a data processor under a written agreement with them. If you have questions about why your employer uses TacDesk, what they can see, or how long they keep your data, please contact your employer directly. TacDesk is a controller only for the limited information described in section 4.
If you have received an email from us and do not use TacDesk: this policy is also our notice to you. We hold a small amount of business contact information about you — see section 4 for what, section 5 for why, section 6 for the legal basis, and section 9 for how long. Section 11 explains how to object.
2. Who we are
TacDesk is a trading name of Michael Bryce, operating as a sole trader in the United Kingdom.
Contact: info@tacdesk.co.uk
3. Information we collect
3.1 Account information
- Name, work email address, phone number
- Job role (Guard, Supervisor, Manager, Administrator)
- Username and a hashed password (we never store passwords in plain text)
- Optional profile photo
- The employer (security company) you work for
3.2 Location information
The app records your device's location in two ways:
Foreground location (while the app is open) — when you use a feature that needs your location, such as clocking in, completing a patrol checkpoint, or scanning an NFC tag at a site.
Background location — for lone-worker safety:
- We record your location periodically while you are clocked in to a shift, even if the app is in the background, your screen is locked, or your phone is in your pocket.
- This is required because security guards routinely work alone, often at night, on remote sites. Your dispatcher needs to be able to verify you are at your assigned post during scheduled check-calls, and locate you immediately if you miss a check-call or trigger a duress alarm.
- Background tracking starts when you clock in and stops automatically when you clock out. You can clock out at any time.
- While background tracking is active, the app shows a persistent notification so it is always clear to you that your location is being recorded.
- Your location is shared with your employer's dispatch and management team. It is not shared with other guards, and it is not shared with your employer's clients.
3.3 Operational data
Records created during your work:
- Clock-in / clock-out timestamps and locations
- Patrol checkpoints scanned (NFC tag IDs, QR codes, GPS waypoints)
- Incident reports, patrol reports, check-call logs, vehicle defect reports
- Photos, notes, and voice notes attached to those reports
- Messages sent and received within the app
3.4 Voice notes and AI-drafted reports
The app lets you dictate a short spoken account of something that has happened, instead of typing it. The recording is then turned into a draft report which you check, correct and sign off. How it works:
- You have to hold the button down. Recording only happens while you are pressing and holding. It stops the moment you let go. The app never listens in the background, never records ambiently, and cannot be left running.
- Each recording is capped at two minutes, and the app shows a recording indicator that cannot be switched off while it is running.
- What you say may include other people. When you describe an incident you will usually be describing members of the public — someone refused entry, someone involved in an incident, a bystander. That information is personal data about them, and your employer is the controller for it, in the same way it is for anything you write in a typed report or capture on a body-worn camera. Your employer is responsible for telling people that recording may take place at its sites.
- The recording is transcribed and drafted automatically. At the end of your shift the audio is converted to text by a speech-to-text provider, and the text is turned into a draft report by an AI provider. Both are listed as sub-processors in section 7. No decision about you is made by that process — it produces a draft, and a person (you) signs it.
- The audio is deleted once you sign off. And if a recording never becomes a report at all — because it was made by mistake, or the transcription did not complete — it is still deleted, on a fixed clock, once a manager at your employer has been told about it. What we will not do is delete a recording nobody has been told about: in the rare case where we cannot get that alert to anyone at your employer, the recording is held and the problem escalated rather than quietly destroyed. See section 9 for the exact periods, the one exception, and what happens in that case.
3.5 Device and technical information
- Device model, operating system version, app version
- A push-notification token issued by Google Firebase Cloud Messaging (Android devices) or by Apple Push Notification service (iOS devices)
- IP address and approximate location derived from IP, for security and audit logging
- Crash logs and basic diagnostic information
3.6 Information from third parties
If your employer integrates TacDesk with another system (e.g. payroll or scheduling software), we may receive limited information from that system — typically just enough to match you to the right TacDesk account.
4. Information for which TacDesk is the controller
For the following, TacDesk is the data controller (not your employer):
- Information about your employer's account with us (billing, contracts) — this is about the company, not about you personally
- Aggregate, de-identified usage statistics that we use to improve the product
- Support correspondence you send directly to TacDesk (e.g. emailing
info@tacdesk.co.uk) - Business contact information about prospective customers — name, job title, employer and a business email address or phone number, for people who are not TacDesk users. We hold this about named individuals at UK security companies so that we can tell their organisation about the product. See section 5 for where this comes from and how we use it, section 6 for the legal basis, and section 9 for how long we keep it.
5. How we use the information
Where your employer is the controller, the purposes are:
- Operating the service — clocking you in and out, recording shifts, tracking lone-worker safety, delivering messages, and generating the reports your employer is contractually required to provide to its own clients
- Lone-worker safety — monitoring background location during your shift so your employer can respond to missed check-calls or duress events
- Workforce management — producing attendance, patrol and incident records, including transcribing dictated voice notes and drafting reports from them for you to check and sign
- Compliance — meeting your employer's regulatory obligations (e.g. SIA licensing, BS 7858, BS 7499, HSE lone-worker guidance)
Where TacDesk is the controller (section 4), the purposes are:
- Providing and maintaining the platform for your employer
- Improving the product using aggregate or anonymised data
- Security and fraud prevention
- Complying with our own legal obligations
We do not use data collected through the TacDesk app for marketing or advertising, and the app itself contains no advertising and no advertising trackers.
Contacting prospective customers. Separately from the app, we contact people who are not TacDesk users to tell them about the product — for example, a manager or director at a UK security company who has not signed up. We obtain their business contact information (name, job title, employer, business email or phone number) from public sources such as the Companies House register, and from third-party B2B contact-enrichment providers (for example Apollo, Snov and GetProspect). We only use this to contact people in their professional capacity at a corporate entity — we do not run this kind of outreach against sole traders or individuals contacted in a personal capacity. We do not use it for any other purpose, and we do not use it to build a profile of you beyond identifying you as a contact at that company. See section 6 for the legal basis, section 9 for how long we keep it, and section 11 for how to object — if you tell us you do not want to hear from us, we stop and do not contact you again.
App Tracking Transparency (iOS). The TacDesk iOS app does not engage in tracking as defined by Apple's App Tracking Transparency framework. We do not link your activity in TacDesk with data collected by other apps or websites for advertising or measurement purposes, and we do not share your data with third-party data brokers. As a result, the app does not display the App Tracking Transparency permission prompt.
6. Legal bases under UK GDPR
When TacDesk processes data on your employer's behalf, your employer is responsible for the lawful basis. Typically your employer relies on:
- Performance of a contract (your employment contract)
- Legitimate interests (running their security business, meeting client SLAs, ensuring lone-worker safety)
- Legal obligations (record-keeping, health and safety)
When TacDesk processes data as a controller, we rely on:
- Performance of a contract (our contract with your employer)
- Legitimate interests (running, securing and improving the platform)
- Legal obligations
Where we contact a prospective customer's business contact to tell them about TacDesk, we rely on legitimate interests (Article 6(1)(f) UK GDPR) — reasonable, proportionate business-to-business marketing directed at a named decision-maker at a corporate entity, using their business contact details only, for a product relevant to their organisation. You have the right to object to this processing at any time, free of charge, and if you do we will stop and will not contact you again — see section 11.
7. Sharing your information
Your information is shared with:
- Your employer — the dispatch, supervisor, manager and administrator users at the security company that issued your TacDesk account. What each role can see is determined by your employer's configuration.
- Sub-processors that help us run the service:
- Google LLC / Firebase Cloud Messaging — to deliver push notifications to Android devices
- Apple Inc. / Apple Push Notification service (APNs) — to deliver push notifications to iOS devices
- Apple Inc. / App Store Connect and TestFlight — for iOS app distribution and crash diagnostics
- Our hosting provider (Amazon Web Services, London region) — to store and serve the data
- ElevenLabs — to convert dictated voice notes into text. Audio is sent for transcription only.
- Anthropic PBC — to turn that transcript into a draft report for you to check and sign. Our contract with them requires that transcripts are not used to train their models.
- Xero — accounting and invoicing. Only your employer's billing contact details and their invoice and payment records are shared. No guard records, location data, reports or body-worn video are sent to Xero.
- Email service providers — to send transactional emails (password resets, account notifications)
- Authorities, when required by law — e.g. a valid court order or police request. We require a lawful basis before disclosing.
- In a business transfer — if TacDesk is acquired, your data may transfer to the acquiring entity, subject to the same protections set out here.
We do not sell your personal information. We do not share it with advertisers, data brokers, or profiling services.
8. International transfers
Personal data is stored on servers in the United Kingdom. Some sub-processors process data outside the UK/EEA — Google Firebase and Apple Push Notification service for push notifications, ElevenLabs and Anthropic (both United States) for voice note transcription and report drafting, and Xero for accounting and invoicing. Xero receives billing contact and invoice data only. Where this happens, we rely on the UK International Data Transfer Agreement, the EU Standard Contractual Clauses with the UK Addendum, or another lawful transfer mechanism.
9. Data retention
- Account data: retained while your employer's TacDesk account is active.
- Location history: retained for the period configured by your employer — typically 90 days for routine location pings, longer where a shift includes an incident or duress event that may be needed for legal or insurance purposes.
- Operational records (clock-ins, patrols, incidents, reports): retained for the period your employer specifies, normally driven by their clients' contractual requirements (often 12-24 months).
- Voice note recordings and their raw transcripts: deleted when you sign off the report they produced, plus a short fixed grace period of 7 days in case the report has to be reopened. This period is fixed and your employer cannot extend it. The one exception is that a manager can mark a specific recording as evidence for a particular incident — for example where a report is disputed. A recording marked that way is kept with that incident record and follows the incident's retention period instead. Nothing is kept as evidence automatically; it takes a deliberate act by a named person, and it is logged.
- Voice notes that never became a report: occasionally a recording is never turned into a report — it was made in error, or the transcription did not complete. Because nobody has read it, and the recording is the only copy of what was said, it is not deleted on the ordinary clock above. Instead, three days after it was made it appears in a "needs attention" list for a manager at your employer, who is alerted; you see it in your own list too. The manager can deal with the report, delete the recording straight away, or mark it as evidence as described above. If none of those things happens, the recording is deleted automatically — 30 days after it was made, or 14 days after the manager was first alerted, whichever is the later of the two. In normal running that is 30 days. Deletion is preceded by 24 hours' notice in that list and is logged. If a recording's own date is missing or unreadable, it goes into the manager's list immediately, and the 30-day period runs from the day it appears there rather than from a date we cannot rely on; the 14-day period still runs from when a manager was first alerted. In practice that means such a recording is kept for at least 30 days from the day it appears in the list. The clock only starts once someone has been told. If we cannot deliver that alert to anyone at your employer — for example because there is no working manager contact on the account — the recording is not deleted. It is held, securely and unread, and we escalate the problem until someone can be told. We would rather keep a recording longer than destroy an account of an incident that nobody has ever been told exists. This is rare, it is logged, and it is the only situation in which one of these recordings is kept beyond the periods above.
- After your account is closed: we delete or anonymise your personal data on instruction from your employer. Your employer may be legally or contractually required to retain certain records (e.g. attendance records) for a longer period; in that case, those records are retained securely and used only for that purpose.
- Backups: data may persist in encrypted backups for up to 30 days after deletion.
- Prospective customer business contact information: if we have not yet contacted you, we delete your record 6 months after we obtained it, unless we contact you before then. If we have contacted you and you have not replied, we delete your record 12 months after our last contact with you. If you tell us to stop contacting you, we keep a minimal record of that request indefinitely, so that we do not contact you again, and delete everything else we held about you.
If you cannot reach your employer to action a deletion request, contact info@tacdesk.co.uk and we will work with you and your employer to resolve it.
10. Account closure and deletion
TacDesk accounts are issued and managed by your employer — the security company that subscribes to TacDesk on your behalf. You cannot self-create a TacDesk account, and accordingly account closure is handled by your employer's administrator. To close your account, contact your employer directly. If your employer is unreachable or has ceased trading, email info@tacdesk.co.uk and we will work with you to action the closure.
This arrangement is consistent with Apple's App Store Review Guideline 5.1.1(v), which permits employer or administrator-managed account deletion for business apps where the user did not create the account themselves.
11. Your rights
Under UK GDPR you have the right to:
- Access the personal data held about you
- Rectify inaccurate or incomplete data
- Erase your data in certain circumstances ("right to be forgotten")
- Restrict or object to processing
- Data portability — receive your data in a portable format
- Withdraw consent where processing is based on consent
Because your employer is the data controller for most of your data, please address these requests to your employer first. We will support your employer in fulfilling them. If you cannot reach your employer or they have ceased trading, contact info@tacdesk.co.uk.
You also have the right to complain to the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
12. Security
We protect your data using:
- TLS 1.2+ encryption in transit
- Encryption at rest for databases and backups
- Role-based access control within the platform
- Audit logging of administrative actions
- Regular security updates and vulnerability scanning
- Two-factor authentication available for management roles
No system is completely secure. If we ever suffer a breach likely to result in a high risk to your rights, we will notify your employer, and where required by law, you and the ICO, without undue delay.
13. Permissions used by the mobile app
The app requests these permissions only when needed for the features described above:
- Location (foreground and background) — for clock-ins, patrols, and lone-worker safety
- Camera — for incident report photos and profile photos
- Photos / media / files — for attaching photos to reports
- Notifications — for push alerts (shift reminders, dispatcher messages, duress broadcasts)
- NFC — for scanning patrol checkpoint tags
- Phone — to display caller ID for in-app dispatcher calls (where supported)
- Microphone — for optional dictated voice notes attached to reports. The microphone is only active while you are pressing and holding the record button (section 3.4).
You can revoke any permission in your device settings. Revoking the location permission will prevent you from clocking in or completing GPS-based patrols.
14. iOS Live Activities and lock-screen content
When you are on shift or on patrol, the iOS app displays a status banner on your lock screen and in the iPhone Dynamic Island summarising your current state — for example, shift duration, client name, and whether a check-call is due. This information is generated and updated locally on your device using data already collected for the purposes described in section 3. It is not transmitted to additional third parties beyond those listed in section 7. You can hide lock-screen Live Activities at any time in iOS Settings → Face ID & Passcode → Live Activities, or by disabling Live Activities for TacDesk individually.
15. Children
TacDesk is a workforce platform for licensed security professionals and is not intended for, marketed to, or available to anyone under 18.
16. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via the app and/or email at least 14 days before they take effect. The "Last updated" date above will always reflect the most recent version.
19 August 2026: we removed a statement in section 7 describing the deletion and model-training terms that apply to our speech-to-text provider. That statement did not accurately describe our arrangement with that provider. Nothing about how the service works has changed, no protection has been withdrawn from anyone, and no voice notes had been transcribed at the time of this change.
21 September 2026: sections 1, 4, 5, 6 and 9 were corrected to describe our use of business contact information for sales outreach to prospective customers, which a previous version of this policy incorrectly said we do not do. This is a correction to bring the policy in line with a practice that was already happening, not a change in what we do.
17. Contact us
For privacy questions or to exercise your rights, email info@tacdesk.co.uk.
You may also contact the Information Commissioner's Office (ico.org.uk) directly without going through us first.