Privacy policy
Last updated: 2026-06-15
1. Who we are
Utility Guard is a construction field-management platform operated by Big S Web Design Sct Ltd (trading as Utility Guard) (“we”, “our”, “us”). Our registered office is at 59 Cornfoot Crescent, East Kilbride, G74 3zb, United Kingdom. For any questions about this policy, or to exercise your rights under UK GDPR, contact us at info@bigswebdesign.co.uk.
We are the “data controller” for personal data processed through the Utility Guard web app (app.utility-guard.co.uk), the mobile apps for iOS and Android, and the supporting API. Some employers (referred to here as “your organisation”) license Utility Guard to manage their workforce; in those cases your organisation is the data controller for the data they enter about you, and we act as their data processor.
If you have a concern about how your data is handled, you have the right to lodge a complaint with the UK Information Commissioner's Office at ico.org.uk/concerns.
2. What data we collect
The data we hold depends on whether you are an administrator, a field worker, or a third party (e.g. an emergency contact).
Account data
- Email address and a hashed password.
- Display name and role within your organisation.
- Session tokens (cookie on web, bearer token on mobile).
Worker profile data
- Full name, date of birth, home address, mobile number, email.
- UK National Insurance number.
- Emergency contact name, relationship, phone number, and address.
- Employment type, primary role, start date with the engaging company.
Compliance records (special category data)
- Photographs and metadata of competency cards (CSCS, NRSWA, EUSR, CPCS, NPORS, IPAF, first aid, asbestos awareness, etc.). These cards display your name, date of birth, photograph, and a reference number issued by an external body.
- Occupational medical records — the level of examination (e.g. working-at-heights, safety-critical), provider, examination date, expiry, and result. This is health data, a special category under UK GDPR Article 9.
- Drugs & alcohol screening records — method, reason, result, and date. Also special category data.
- Other supporting documents you or your employer upload.
Field-activity data
- Time tracking: clock-in and clock-out timestamps, project, metres dug, free-text notes, and a photograph captured on your phone at the start and end of each shift. The photos are stored with their EXIF location metadata where the device supplies it, and the clock-in/out request optionally includes latitude and longitude.
- Issues, daily logs, RAMS / permit sign-offs, toolbox talk attendance, inspection records, COSHH and manual-handling assessments, handovers — text content, attached photos, and digital signatures captured on a touch device.
- Comments and @-mentions you post.
Device & technical data
- Server-side request logs (IP address, user agent, timestamp).
- On iOS, an Apple Push Notification Service device token so we can send alerts (issue assignments, mentions, status changes). Android push notifications are not yet supported.
- A locally-cached copy of your accessible projects, issues, plans, and safety documents in the mobile app so the field-worker UI works offline.
3. Why we use it and the legal basis
We process your data on the following lawful bases under UK GDPR Article 6:
- Performance of a contract — managing your account, recording your shifts, tracking work assigned to you.
- Legitimate interests — keeping audit trails of who did what, sending operational push notifications and emails, detecting abuse of the platform.
- Legal obligation — keeping construction-industry compliance records (cards, medicals, RAMS sign-offs) for the periods required by UK health-and-safety regulations.
For special-category data (medicals, D&A screens), we rely on UK GDPR Article 9(2)(b) — processing necessary for carrying out obligations and exercising rights in the field of employment and social security law — together with Schedule 1, Part 1, paragraph 1 of the Data Protection Act 2018. Your employer's appropriate-policy document under that schedule applies.
4. Who we share it with
- Your organisation's administrators see your profile, compliance records, and field-activity. Other workers in the same organisation see only the bits relevant to shared work (your name and trade on a project, your sign-off on a shared RAMS, etc.).
- Our infrastructure providers:
- IONOS (UK) for the application server and database hosting.
- Apple, for delivery of push notifications to iOS devices via APNs.
- An email-delivery provider (Resend or an SMTP provider — currently {configured at deploy time}) for transactional emails like invites and password resets.
- Optional AI features. When you use an AI-assisted feature (e.g. extracting card details from a photograph), the relevant image or text is sent to a third-party model provider (currently Anthropic and OpenAI). These providers act as our processors. We do not enable these features by default; they are opt-in by your organisation's administrator.
- Law enforcement / regulators only where we are legally required to disclose.
We do not sell your data, use it for advertising, or share it with marketing networks.
5. International transfers
Our primary infrastructure is in the UK. Some third-party processors (Apple, the AI model providers, the email provider) may transfer your data to the United States or elsewhere. Where they do, we rely on the UK Government's adequacy regulations, the UK extension to the EU-US Data Privacy Framework, or the International Data Transfer Agreement as appropriate.
6. How long we keep it
Active account and field-activity data is kept for as long as your organisation maintains its licence with us. After the licence ends, we retain the data for a further 30 days to allow for export, then delete or anonymise it.
Compliance records (cards, medicals, D&A screens, RAMS sign-offs, permit approvals) are kept for the period required by UK construction-industry health-and-safety regulations, which can be up to 40 years for medical exposure records.
Server logs are retained for 30 days and used only for security incident investigation.
7. Your rights
Under UK GDPR you have the right to:
- Ask for a copy of the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data deleted, in cases where we don't have an overriding legal obligation to keep it.
- Restrict or object to certain processing.
- Receive your data in a portable format, for the data you provided directly.
- Withdraw any consent you previously gave, without affecting processing that took place before the withdrawal.
To exercise any of these rights, email info@bigswebdesign.co.uk. We respond within one calendar month. If your organisation is the controller for the relevant data, we will forward your request to them.
8. Security
Passwords are hashed with bcrypt before storage. Session tokens are random 256-bit values and expire. Sensitive endpoints require authentication. Database backups are encrypted. We restrict administrative access to named members of our team.
No system is perfectly secure. If we detect a personal data breach affecting your data, we will notify you and the ICO within the timeframes required by UK GDPR.
9. Cookies
The Utility Guard web app uses a single first-party session cookie (utilliti_session) to keep you signed in. We do not use third-party tracking cookies or advertising cookies. The mobile apps do not use cookies.
10. Children
Utility Guard is intended for use by adult construction-industry workers and the staff of the organisations employing them. We do not knowingly collect data from anyone under 18.
11. Changes to this policy
We may update this policy as the product evolves or the law changes. The “last updated” date at the top reflects the most recent change. Material changes will be communicated by email or in-app notice before they take effect.
12. Contact
For any questions about this policy or your data:
Big S Web Design Sct Ltd (trading as Utility Guard)
59 Cornfoot Crescent, East Kilbride, G74 3zb, United Kingdom
info@bigswebdesign.co.uk