Data protection

Data Protection & UK GDPR Statement

A public summary of GGK Technologies' approach to UK GDPR, customer data, security, retention and data-protection responsibilities.

Public document
Version 1.0
Effective September 2026

Garden Gate Keeper (GGK) is an incident, accident and near-miss reporting and management platform for organisations. This statement explains GGK's approach to UK GDPR, including the different roles GGK and its customers have when personal information is processed through the service.

1. About this statement

This public statement describes GGK Technologies' data-protection approach at a practical, high level. It supports customer due diligence and complements GGK's Privacy Notice and Data Retention & Deletion Policy. It does not replace a customer organisation's own privacy information and does not disclose confidential security architecture or internal operational records.

The detailed Record of Processing Activities (ROPA), internal data map, supplier assessments, backup design and security-control records are maintained internally rather than published on the website.

2. Controller and processor roles

Situation Normal role What this means
Customer incident, accident and near-miss records Customer = Data Controller
GGK = Data Processor
The customer determines why the information is collected, the applicable lawful basis, relevant special-category condition and appropriate retention requirements. GGK processes the information to provide the service and on the customer's instructions.
GGK's own business information GGK = Data Controller For website enquiries, prospective-customer information, customer contacts, account administration, service security and similar business records, GGK determines its own processing purposes and responsibilities.

3. Information that may be processed

4. Health and other special-category information

Incident-management records can contain information concerning an individual's health, including injuries, treatment, affected body parts, health consequences and other medical information. Health information is Special Category Personal Data under UK data-protection law.

Where GGK processes this information for a customer, the customer remains responsible for identifying the appropriate Article 6 lawful basis and Article 9 condition. GGK processes the information only as required to provide the service, in accordance with customer instructions and applicable contractual requirements.

5. UK GDPR principles

6. Why personal information is processed

Personal information may be processed to report and manage incidents, identify affected persons and witnesses, record injury and treatment information, manage investigations and audit history, produce reports and dashboards, support health and safety and regulatory requirements, administer user accounts and security, provide customer support, and respond to business enquiries.

7. Lawful bases

When GGK acts as Data Controller, relevant lawful bases may include contract, legal obligation and legitimate interests. Consent may be used where appropriate and legally required. When GGK acts solely as Data Processor for customer incident information, the customer determines the applicable lawful basis.

8. Security and access controls

GGK takes reasonable technical and organisational measures designed to protect personal information against unauthorised access, accidental loss, destruction, alteration, unauthorised disclosure and misuse.

9. Retention and deletion

Retention of customer incident information is primarily determined by the customer. When a customer's service ends, GGK intends to provide a reasonable opportunity to export required information. Customer information held in active production systems is normally scheduled for deletion within 90 days of termination, unless another contractual arrangement, legal requirement or retention hold applies.

Deleted information may remain temporarily in historical backups until those backups reach the end of their normal retention cycle.

10. Service providers, sub-processors and international transfers

GGK reviews external suppliers that may process personal information on its behalf and maintains an internal sub-processor register. Appropriate contractual and data-protection terms are used where required.

The core GGK application and SQL database are hosted on GGK-controlled infrastructure in the United Kingdom. Some supporting services, such as email delivery or business communications, may involve processing in other jurisdictions. Where an international transfer is relevant, GGK uses an appropriate mechanism or safeguard required by UK data-protection law.

11. Individual rights and requests

Depending on the circumstances, individuals may have rights including access, correction, deletion, restriction, data portability, objection and rights relating to automated decision-making and profiling. If information has been entered into GGK by an employer or another organisation, that organisation will normally be the Data Controller and should normally be contacted first.

12. Personal data breaches

GGK maintains procedures for identifying, assessing and responding to suspected personal-data breaches. Where GGK acts as Data Processor and becomes aware of a relevant breach affecting customer data, GGK will notify the customer without undue delay in accordance with applicable law and contractual requirements.

13. Accountability, privacy by design and review

14. Customer responsibilities

Customers using GGK remain responsible for their own compliance obligations where they are the Data Controller, including determining lawful bases, Article 9 conditions, access permissions, retention requirements, legal holds and the privacy information provided to affected individuals.

15. Questions, concerns and complaints

Questions about GGK's approach to data protection can be submitted through the GGK contact form. Individuals also have the right to raise concerns with the Information Commissioner's Office (ICO).

16. Changes to this statement

GGK may update this statement to reflect changes to the service, suppliers, legal requirements or the way personal information is processed. The latest public version will be made available through the GGK Technologies website.

Last updated: September 2026
Version 1.0