Legal
Privacy Policy
Written in plain English, because knowing what happens to safety data shouldn’t need a lawyer.
This policy explains what personal data Not A Lone Worker collects, why, who we share it with, and the rights you have over it. Not A Lone Worker is a service provided by TNS365, a company registered in England & Wales. In this policy “we”, “us” and “our” mean TNS365 operating the Not A Lone Worker service.
Who the data controller is
For the account holder’s own account details, TNS365 is the data controller. For the personal data of the workers a customer monitors (their names, phone numbers, check history and location on check-in), the customer is the controller and we act as a data processor on their behalf, handling that data only to run the check-in and escalation service they’ve configured. Questions either way can go to hello@notaloneworker.com.
What we collect
- Account details — the name, work email, and organisation of the people who administer an account, plus login credentials (passwords are stored only as a secure hash).
- Worker details — the name and phone number (and optionally email) of each worker set up to receive check-ins. This is the minimum needed to send a check and know who it was for.
- Check history — the record of each welfare check: when it was sent, on what channel, whether and how the worker responded, any AI voice-call outcome, and every escalation and acknowledgement that followed.
- Location — a worker’s GPS location is captured only when they actively tap a check-in or raise an SOS/panic. We do not track workers continuously or in the background; location is a snapshot taken at the moment they confirm safe or ask for help.
- Voice-call content — when our AI caller (“Zoe”) phones a worker who has gone quiet, the conversation is processed to determine a safe-or-distress outcome. Free-text SMS replies are similarly interpreted to understand the worker’s response.
- Technical data — standard server logs (IP address, browser, timestamps) needed to run the service securely and diagnose faults.
Why we use it, and our lawful basis
We process this data to deliver the safety service: to send scheduled check-ins, interpret responses, make AI voice calls when a worker is quiet, run the escalation ladder, and keep the audit trail that demonstrates an employer’s duty of care. Our lawful bases under UK GDPR are performance of a contract (running the service the customer signed up for) and the legitimate interests of employers and workers in worker safety. Where a customer relies on consent from their workers, obtaining and recording that consent is the customer’s responsibility as controller.
Who we share it with (our processors)
We don’t sell personal data and we don’t share it for advertising. We use a small set of trusted sub-processors purely to operate the service:
| Processor | What they handle |
|---|---|
| Twilio | Sending check-in SMS and placing the AI voice calls. |
| OpenAI | Powering the AI voice conversation (“Zoe”) and interpreting free-text SMS replies to read safe or distress. |
| Stripe | Processing subscription billing. Card details go directly to Stripe — we never see or store them. |
| Mailgun | Sending email check-ins, escalation emails and account notifications. |
| Cloudflare | Security, DNS and content delivery in front of the service. |
Each processor is bound by a data-processing agreement and may only use the data to provide their service to us. Where a processor operates outside the UK/EU, transfers are covered by appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses.
Where your data is stored
The Not A Lone Worker application and its database are hosted in the UK/EU. Worker and check data lives within UK/EU data centres. The sub-processors above may process limited data (for example, an SMS in transit) under the transfer safeguards described above.
How long we keep it
Check history and audit records exist to prove duty of care, so we retain them for as long as an account is active and for a reasonable period afterwards to meet the customer’s own record-keeping needs. When an account is closed, we delete or anonymise personal data once it is no longer needed, subject to any legal retention obligations. A customer can ask us to remove a specific worker’s data at any time.
Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased where there’s no overriding reason to keep it;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw any consent you have given.
If you’re a worker being monitored, the first point of contact is usually your employer (the controller), but you can also reach us and we’ll help. To exercise any right, email hello@notaloneworker.com. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.
Security
Access to the console requires a login, and account sign-in is protected with two-factor authentication. Data is encrypted in transit, passwords are stored only as secure hashes, and access to production systems is restricted to the people who operate the service.
Changes to this policy
We may update this policy as the service evolves. When we make a material change we’ll update the date at the top and, where appropriate, let account holders know.
Contact
Not A Lone Worker, a service of TNS365. Email hello@notaloneworker.com for any privacy question or to exercise your rights.