SafeTrace is committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, and how we use it. We collect only what is necessary to provide the SafeTrace service and never sell your data to third parties.
01 Who We Are
SafeTrace is a corporate traveller safety platform operated by Aigis Ltd. We provide real-time safety monitoring tools for organisations with travelling employees, including SOS alerts, location check-ins, crisis communications, welfare checks and travel itinerary management.
For the purposes of data protection law, Aigis Ltd is the data controller for personal data collected through our platform. If you have questions about this policy, please contact us at privacy@aigishq.com.
02 What Data We Collect
We collect the following categories of personal data:
- Account information — your name, work email address and password when you register
- Company information — your company name, industry, size and region when your organisation signs up
- Location data — your GPS coordinates when you check in or trigger an SOS alert
- Usage data — check-in timestamps, SOS alert history and messages sent through the platform
- Device information — device type and operating system, collected automatically when you use the app
- Push notification token — a unique device identifier used to send safety alerts and messages to your device. This is collected when you grant notification permissions in the app.
- Emergency contact details — name, relationship and phone number of a nominated emergency contact, provided voluntarily by the employee through the app settings.
- Travel itinerary — destination, departure date and return date, provided voluntarily by the employee when starting a trip.
- Welfare check responses — response status and timestamp when an employee responds to a welfare check from their administrator.
We do not collect payment card information, passport details, or any sensitive personal data beyond what is listed above.
02b Lawful Basis for Processing
Under UK GDPR, we rely on the following lawful bases for processing your personal data:
- Legitimate interests — processing location data, SOS alerts and check-ins is necessary for the legitimate interests of your employer in fulfilling their duty of care obligations to travelling employees
- Contract — processing account and company information is necessary to provide the SafeTrace service under our Terms of Service
- Legal obligation — we may process data where required to comply with applicable laws and regulations
- Consent — emergency contact details and travel itineraries are provided voluntarily by employees and processed on the basis of their consent. Employees may withdraw this information at any time through the app settings.
03 How We Use Your Data
We use your personal data for the following purposes:
- To provide the SafeTrace service — processing check-ins, SOS alerts, and communications
- To enable your employer's security team to monitor your safety while travelling
- To send notifications related to your safety status
- To process welfare check requests and responses between employees and administrators
- To display emergency contact details to administrators in the event of an SOS alert
- To show travel itinerary information to administrators to support duty of care obligations
- To maintain and improve the platform
- To comply with legal obligations
We do not use your data for advertising, profiling, or any purpose unrelated to the SafeTrace service.
04 Location Data
Location data is central to the SafeTrace service. Here is exactly how it works:
- When we collect it — when you actively press Check In or trigger an SOS alert, or when you voluntarily enable the Live Tracking feature. Live Tracking continuously shares your location every 15 seconds while active. You can turn Live Tracking on or off at any time from the app home screen.
- What we collect — your GPS coordinates (latitude and longitude) at the moment you check in or send an SOS
- Who sees it — only your company's designated administrators (typically your Security or HR team) can see your location data
- How long we keep it — check-in location data is retained for 30 days. SOS alert data is retained for 12 months for audit purposes. Live tracking trail data is retained for 48 hours.
SafeTrace does not track your location when you are not actively using the app. Location is only captured when you choose to check in, activate Track Me, or when you trigger an SOS alert.
05 Data Sharing
We do not sell your personal data. We share data only in the following circumstances:
- Your employer — administrators of your company's SafeTrace account can see your check-in history, location data and SOS alerts
- Firebase (Google) — we use Google Firebase to store data and authenticate users. Firebase operates under Google's privacy standards and is GDPR compliant
- EmailJS — we use EmailJS to send SOS alert notifications, overdue check-in alerts and welfare check escalation notifications to administrators. EmailJS processes email addresses only for the purpose of delivering these alerts
- Google Maps — we use Google Maps to display employee locations on the live tracking map. Location coordinates are processed by Google Maps API in accordance with Google's privacy standards
- Vercel — our web dashboard and website are hosted on Vercel's infrastructure. Vercel may process IP addresses and request data as part of hosting services
- UK FCDO (GOV.UK) — when an employee checks in, their country is checked against the UK Foreign, Commonwealth & Development Office travel advisory API. Only the country name is shared with this service — no personal data is transmitted
- Legal requirements — we may disclose data if required by law, court order, or to protect the safety of individuals
We never share your data with advertisers, data brokers, or any third party for commercial purposes.
06 Data Storage and Security
All SafeTrace data is stored on Google Firebase servers located in the European Union (London and Belgium regions). We implement the following security measures:
- All data is encrypted in transit using TLS/SSL
- All data is encrypted at rest by Firebase
- Access to the admin dashboard requires authentication
- Firebase security rules restrict data access to authorised users only
- Passwords are hashed and never stored in plain text
- Automated daily backups of all data to Google Cloud Storage (London region)
07 Your Rights
Under UK GDPR you have the following rights regarding your personal data:
- Right of access — you can request a copy of all personal data we hold about you and check we are processing it lawfully
- Right to rectification — you can ask us to correct inaccurate or incomplete data, though we may need to verify the accuracy of the new data you provide
- Right to erasure — you can request deletion of your personal data where there is no good reason for us to continue processing it. Note that we may not always be able to comply for specific legal reasons, which we will notify you of at the time of your request
- Right to restrict processing — you can ask us to suspend or limit the processing of your personal data in certain circumstances
- Right to data portability — you can request your data in a structured, machine-readable format where processing is based on consent or contract
- Right to object — you can object to processing of your personal data where we are relying on legitimate interests as our legal basis
- Right to withdraw consent — where we rely on consent to process your data, you can withdraw that consent at any time. For example, employees can remove their emergency contact details at any time through the app Settings screen. This will not affect the lawfulness of processing carried out before withdrawal
To exercise any of these rights, contact us at privacy@aigishq.com. We will respond within 30 days. We may need to verify your identity before processing your request. You will not be charged a fee to exercise these rights unless your request is clearly unfounded or excessive.
08 Data Retention
We retain your personal data for the following periods:
- Account data — retained while your account is active and for 30 days after deletion
- Check-in data — retained for 30 days
- SOS alert data — retained for 12 months
- Messages — retained for 12 months
- Location history — retained for 48 hours
- Emergency contact details — retained while the employee account is active, or until removed by the employee
- Travel itineraries — cleared automatically when the employee ends their trip
- Company data — retained while the company account is active and for 30 days after cancellation
You can request early deletion of your data at any time by contacting us.
08b Data Breaches
In the event of a personal data breach, we will notify affected individuals and the Information Commissioner's Office (ICO) as required by law. Where a breach is likely to result in a high risk to your rights and freedoms, we will contact you directly as soon as reasonably practicable.
08c Cookies
Our website (aigishq.com) uses essential cookies to maintain your login session and ensure the dashboard functions correctly. We do not use cookies for advertising or tracking purposes.
By using our website, you consent to the use of these essential cookies. You can disable cookies in your browser settings, however this may affect the functionality of the dashboard.
09 Children's Privacy
SafeTrace is a professional business tool intended for use by adults in a corporate context. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has provided us with personal data, please contact us immediately at privacy@aigishq.com.
10 Changes to This Policy
We may update this privacy policy from time to time. When we make significant changes, we will notify users via email and update the "Last updated" date at the top of this page. Your continued use of SafeTrace after changes are posted constitutes acceptance of the updated policy.
```
11 Contact Us
If you have any questions about this privacy policy or how we handle your personal data, please contact us:
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.