Data Protection & UK GDPR Statement
A public summary of GGK Technologies' approach to UK GDPR, customer data, security, retention and data-protection responsibilities.
Garden Gate Keeper (GGK) is an incident, accident and near-miss reporting and management platform for organisations. This statement explains GGK's approach to UK GDPR, including the different roles GGK and its customers have when personal information is processed through the service.
1. About this statement
This public statement describes GGK Technologies' data-protection approach at a practical, high level. It supports customer due diligence and complements GGK's Privacy Notice and Data Retention & Deletion Policy. It does not replace a customer organisation's own privacy information and does not disclose confidential security architecture or internal operational records.
The detailed Record of Processing Activities (ROPA), internal data map, supplier assessments, backup design and security-control records are maintained internally rather than published on the website.
2. Controller and processor roles
| Situation | Normal role | What this means |
|---|---|---|
| Customer incident, accident and near-miss records | Customer = Data Controller GGK = Data Processor |
The customer determines why the information is collected, the applicable lawful basis, relevant special-category condition and appropriate retention requirements. GGK processes the information to provide the service and on the customer's instructions. |
| GGK's own business information | GGK = Data Controller | For website enquiries, prospective-customer information, customer contacts, account administration, service security and similar business records, GGK determines its own processing purposes and responsibilities. |
3. Information that may be processed
- Names, contact details, email addresses, employee or user information, departments and workplace/site information.
- Incident location, date and time, reporting-person details, impacted-person details and witness information.
- Incident descriptions, accident and near-miss information, investigation notes, findings, status history and attachments or evidence.
- Injury or harm information, affected body parts, medical treatment information and first-aider information.
- User-account information, roles, permissions, login/security information, IP address, session information, access records and audit logs.
- Website enquiry information, organisation details, correspondence, customer administration and support information.
4. Health and other special-category information
Incident-management records can contain information concerning an individual's health, including injuries, treatment, affected body parts, health consequences and other medical information. Health information is Special Category Personal Data under UK data-protection law.
Where GGK processes this information for a customer, the customer remains responsible for identifying the appropriate Article 6 lawful basis and Article 9 condition. GGK processes the information only as required to provide the service, in accordance with customer instructions and applicable contractual requirements.
5. UK GDPR principles
- Lawfulness, fairness and transparency.
- Purpose limitation.
- Data minimisation.
- Accuracy.
- Storage limitation.
- Integrity and confidentiality.
- Accountability.
6. Why personal information is processed
Personal information may be processed to report and manage incidents, identify affected persons and witnesses, record injury and treatment information, manage investigations and audit history, produce reports and dashboards, support health and safety and regulatory requirements, administer user accounts and security, provide customer support, and respond to business enquiries.
7. Lawful bases
When GGK acts as Data Controller, relevant lawful bases may include contract, legal obligation and legitimate interests. Consent may be used where appropriate and legally required. When GGK acts solely as Data Processor for customer incident information, the customer determines the applicable lawful basis.
8. Security and access controls
GGK takes reasonable technical and organisational measures designed to protect personal information against unauthorised access, accidental loss, destruction, alteration, unauthorised disclosure and misuse.
- Access is restricted through user accounts, roles and permissions.
- Security and audit information is maintained to help detect and investigate suspicious or unauthorised activity.
- Core application and database services are operated on GGK-controlled infrastructure in the United Kingdom.
- Backups are maintained for business continuity and disaster recovery.
- GGK personnel access customer information only where reasonably necessary for support, maintenance, security, service integrity or legal obligations.
9. Retention and deletion
Retention of customer incident information is primarily determined by the customer. When a customer's service ends, GGK intends to provide a reasonable opportunity to export required information. Customer information held in active production systems is normally scheduled for deletion within 90 days of termination, unless another contractual arrangement, legal requirement or retention hold applies.
Deleted information may remain temporarily in historical backups until those backups reach the end of their normal retention cycle.
10. Service providers, sub-processors and international transfers
GGK reviews external suppliers that may process personal information on its behalf and maintains an internal sub-processor register. Appropriate contractual and data-protection terms are used where required.
The core GGK application and SQL database are hosted on GGK-controlled infrastructure in the United Kingdom. Some supporting services, such as email delivery or business communications, may involve processing in other jurisdictions. Where an international transfer is relevant, GGK uses an appropriate mechanism or safeguard required by UK data-protection law.
11. Individual rights and requests
Depending on the circumstances, individuals may have rights including access, correction, deletion, restriction, data portability, objection and rights relating to automated decision-making and profiling. If information has been entered into GGK by an employer or another organisation, that organisation will normally be the Data Controller and should normally be contacted first.
12. Personal data breaches
GGK maintains procedures for identifying, assessing and responding to suspected personal-data breaches. Where GGK acts as Data Processor and becomes aware of a relevant breach affecting customer data, GGK will notify the customer without undue delay in accordance with applicable law and contractual requirements.
13. Accountability, privacy by design and review
- GGK maintains internal records of processing activities and a data map.
- New features and significant changes are considered from a data-minimisation and privacy-by-design perspective.
- New suppliers and material changes to processing, hosting, transfers or data categories are reviewed.
- High-risk processing is assessed to determine whether a Data Protection Impact Assessment is required.
- Policies and registers are reviewed periodically and following significant changes.
14. Customer responsibilities
Customers using GGK remain responsible for their own compliance obligations where they are the Data Controller, including determining lawful bases, Article 9 conditions, access permissions, retention requirements, legal holds and the privacy information provided to affected individuals.
15. Questions, concerns and complaints
Questions about GGK's approach to data protection can be submitted through the GGK contact form. Individuals also have the right to raise concerns with the Information Commissioner's Office (ICO).
16. Changes to this statement
GGK may update this statement to reflect changes to the service, suppliers, legal requirements or the way personal information is processed. The latest public version will be made available through the GGK Technologies website.
