Privacy policy
Version of 15 September 2026
What personal information GuardPost collects about handlers, clients, site contacts, people who ask for private cover and visitors to the site — why, who sees it, how long we keep it, and your rights.
1. Who we are
1.1GuardPost is GUARDPOST CONNECTIONS LTD, a company registered in England and Wales with company number 17454609, whose registered office is at 21 Lockington Crescent, Dunstable, LU5 4ST. We decide how your personal information is used (we are its “controller”). Contact us about anything in this policy at support@guardpost.uk, or by post at our registered office.
1.2We are a small company and have not appointed a data protection officer.
2. Who this policy covers
2.1Handlers (K9 handlers and static guards with a GuardPost account), clients and the people who use GuardPost for them, site contacts whose details a client gives us, people who send a request for private cover, and anybody visiting guardpost.uk.
3. What we collect about handlers
3.1Your account: name, email address, mobile number, the town you are based in, your work type, and anything you add to your profile. If you turn on job alerts, your postcode, the map position we work out from it, and how far you will travel.
3.2Vetting: your documents and their details — SIA licence, public liability insurance, photographs of you (and your dog) and your photo ID, and for K9 handlers dog certification, microchip and transport details — plus anything a job asks for, such as a CSCS card, enhanced DBS certificate or BS 7858 screening. We record each check’s result, dates and who checked it.
3.3Right to work: the route you use and, for an online check, your share code and date of birth. We delete the share code and date of birth as soon as the check is decided, and keep the result, the method, any time limit and who checked.
3.4Work: jobs you apply for and are booked on; shift logs, including times, your location when you book on, check in, log an incident or book off, incident reports and photos, and your shift summaries; the selfie and licence photo taken when you book on; your reliability record, concerns raised about your shifts and your responses, inquiries, and reviews.
3.5Money and agreements: a self-billing agreement if you sign one (your typed name, when, your IP address, and your VAT status and number), invoices raised in your name, and whether you told us a client had not paid.
4. What we collect about clients, site contacts and private requests
4.1Clients: the name, email address and phone number of the people using the account; your business name and the details Companies House holds about it; jobs you post, including site address, access details, hazards, and the site and emergency contacts you give us; booking agreements (typed name, when, and IP address); sign-offs, concerns and reports; our fee invoices and payments; and your client record.
4.2Site contacts: the name and phone number a client gives us, which we pass to the handler booked for that site.
4.3Private cover requests: the name, email address, phone number, location and description you send us.
5. What we collect from everybody who visits
5.1Security records: sign-ins, access refused, and the IP address and browser used. For limiting sign-ups we keep a scrambled form of your IP address, not the address itself.
5.2Cookies: only the ones needed to keep you signed in and keep the site secure. We use no advertising or analytics cookies, so we do not ask for cookie consent.
6. Why we use it, and the law that allows it
6.1To provide GuardPost to you under our terms — accounts, job listings, introductions, bookings, shift records, invoices and notifications. (Contract.)
6.2To meet legal duties — the checks an employment agency must make before an introduction, keeping accounting records, and answering lawful requests from authorities. (Legal obligation.)
6.3To keep sites and people safe and GuardPost trustworthy — vetting and re-checking handlers, the reliability record, investigating concerns and sites left unattended, preventing fraud, noticing when a client and a handler who booked each other regularly suddenly stop (so we can check whether they are working together outside GuardPost), protecting our systems, and keeping evidence for claims and legal proceedings. (Our legitimate interests, which we balance against yours.)
6.4To send job alerts to your device, if you turn them on. You can turn them off at any time. (Consent.)
7. Criminal record information and photographs
7.1Some vetting involves criminal record information: an SIA licence is only issued after the SIA’s own criminal record check, and an enhanced DBS certificate or BS 7858 screening may contain criminal record details. Incident reports may describe suspected offences. We use this only where the Data Protection Act 2018 allows it, for example to meet regulatory requirements under the Private Security Industry Act 2001 and to prevent or detect unlawful acts, and only people who need it can open it.
7.2Photographs of your face are compared by a person, never by face-matching software. We do not use biometric data.
8. Decisions made automatically
8.1Some decisions happen without a person: a document stops counting on its expiry date; a reliability score below 60 stops a handler applying for work; and a site reported or admitted as left unattended stops a handler taking new work until we decide. Job alerts are matched automatically by distance and eligibility.
8.2You can ask a person at GuardPost to review any of these decisions, explain your side and challenge it, by emailing support@guardpost.uk.
9. Who can see it
9.1Clients see what they need to choose and work with a handler: once a handler is fully vetted, their name, photograph, town, profile, reliability score, reviews, the state and expiry of each check, and their SIA licence and dog certification numbers. A client who books a handler also sees their mobile number, their shift logs and book-on selfie, and is told whether a licence photo was taken — only the handler and GuardPost can see the licence photo itself.
9.2Handlers see a client’s business name and client record, and, once booked, the site address, access details and site contacts.
9.3K9 Securex, a separate security company, receives private cover requests so it can reply to them. It decides what to do with them under its own privacy notice.
9.4Our service providers handle information for us under contract and only on our instructions: Vercel (hosts the website, running in London), Neon (our database, in London), Cloudflare (stores uploaded documents and photos, in the EU), Resend (sends our emails), Google (our support mailbox, and job alerts on Chrome and Android), and postcodes.io (turns a postcode into a map position — it receives the postcode only). If you turn on job alerts, your browser’s own push service (Google, Apple, Mozilla or Microsoft) delivers them. We check client businesses on the public Companies House register.
9.5We also share information when the law requires it — for example with the SIA, the police or HMRC — and with insurers, lawyers and courts when needed for a claim or legal proceedings. If GuardPost’s business is sold, information would pass to the buyer under this policy.
10. Information outside the UK
10.1We keep our database in London and documents in the EU, which UK law treats as adequately protected. Some of our providers are owned by US companies and may access information from outside the UK. Where they do, we rely on the UK’s adequacy regulations — including the UK extension to the EU–US Data Privacy Framework for certified companies — or the UK’s approved international data transfer agreement or addendum.
11. How long we keep it
11.1Book-on selfies and licence photos: 30 days. Right-to-work share codes and dates of birth: deleted as soon as the check is decided.
11.2Right-to-work records (the result, method, any time limit and who checked): 2 years after you stop working through GuardPost.
11.3Vetting documents: until 6 months after your account closes, unless they are needed for a claim or dispute that is still open.
11.4Shift logs, bookings, reports, incident records, concerns, inquiries, reliability records, messages, agreements and invoices: 6 years after the booking they relate to ends, because they may be needed as evidence or for accounting.
11.5Private cover requests: 12 months. Security records: 12 months. Sign-up limiting records: about an hour. Job alert subscriptions: until you turn alerts off or your browser tells us the subscription has ended. Account details: while your account is open, then with the records above.
12. How we protect it
12.1Everything travels encrypted, and our providers store it encrypted. Documents are kept in private storage that is never publicly accessible, and every time GuardPost staff open one it is logged. Staff accounts need a second sign-in step. Uploads are checked for harmful content before they are stored, and nobody signs in with a password — we send one-time links instead.
13. Your rights
13.1You can ask for a copy of your personal information, for it to be corrected, for it to be deleted, for its use to be restricted, to object to our using it, and for information you gave us in a form you can take elsewhere. Some rights have limits — for example, we cannot delete records we must keep for legal reasons or for a claim.
13.2Email support@guardpost.uk. We will answer within one month, and there is normally no charge.
13.3Where we rely on your consent, you can withdraw it at any time.
14. Complaints
14.1If you are unhappy with how we use your information, tell us first and we will try to put it right. You can also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.
15. Children, and changes to this policy
15.1GuardPost is not for anybody under 18.
15.2If we change this policy we will publish the new version here with its date, and tell account holders about important changes by email.
Questions about this document: support@guardpost.uk