GPOD protects your data and privacy at every level of operation â from shift clocks to wage payouts to regulatory reporting.
Using UK-compliant infrastructure, zero-trust authentication, facial biometric login, and end-to-end encryption, we exceed the standards required by law â not just for workers and employers, but also for councils and institutional investors.
Security Status: Active & Protected
Last Security Audit: April 15, 2025 | Next Scheduled: July 15, 2025
Advanced facial recognition with liveness detection and spoofing prevention secures login and clock-in processes.
Military-grade AES-256 encryption protects all data in transit and at rest, with unique encryption keys per user session.
Continuous verification and least-privilege access controls ensure no user or system is inherently trusted.
All data remains in ISO 27001 certified UK data centers with 24/7 monitoring, physical security, and redundant systems.
All data processing has a clear legal basis, is fair to data subjects, and is explained in plain language in our privacy notices. Users see exactly when and how their data is used within the GPOD platform.
We only collect data for specified, explicit and legitimate purposes as outlined in our privacy policy. Data is never used for purposes incompatible with those original purposes without explicit consent.
We only collect the minimum amount of data necessary for our operations. Our data collection processes are regularly audited to ensure we maintain the principle of collecting only what is needed.
We implement measures to ensure data is accurate and kept up to date, including regular verification processes and simple mechanisms for users to review and correct their personal information.
Personal data is kept only for as long as necessary for the purposes for which it was collected. Automatic deletion routines ensure compliance with our retention policies, while respecting legal obligations.
Personal data is processed with appropriate security measures including protection against unauthorized or unlawful processing, accidental loss, destruction or damage, using technical and organizational measures.
All GPOD data is stored exclusively in UK data centers that meet the following criteria:
Our comprehensive backup strategy ensures data resilience and business continuity:
GPOD implements multiple layers of protection against ransomware and other malicious attacks:
GPOD's AI agents (Gabriel, Kira, Shadow) are designed with privacy as a core principle:
Our AI systems are governed by a comprehensive ethics and compliance framework:
We implement strict controls on how long AI-related data is retained:
GPOD's approach to location data prioritizes user privacy and data minimization:
We implement strict time limits on location data storage:
GPOD maintains strict controls on location data sharing:
All third-party service providers undergo a rigorous security and compliance assessment:
GPOD implements multiple layers of API security to protect data in transit:
All third-party relationships involving personal data are governed by formal agreements:
GPOD makes it simple for users to access and export their personal data:
Users can request deletion of their personal data through multiple channels:
GPOD supports additional data subject rights with dedicated processes:
We have established a formal process for handling data subject requests:
GPOD maintains comprehensive documentation of all data processing activities:
We have implemented robust processes for security incident management:
GPOD generates regular compliance reports for internal and external stakeholders:
GPOD's security infrastructure is designed to meet the requirements of even the most security-conscious organizations:
We ensure compatibility with public sector security and procurement requirements:
GPOD meets the stringent security requirements of financial institutions:
GPOD provides clear, accessible information about data practices:
Users have access to transparent information about their data:
GPOD provides robust tools for managing consent preferences:
Information security management system certified to international standards
UK government-backed certification for cyber security excellence
Registered with UK Information Commissioner's Office for data protection
Fully compliant with General Data Protection Regulation requirements
Completed annual ISO 27001 certification renewal with zero non-conformities
Implemented enhanced biometric authentication with liveness detection
Successfully completed penetration testing with independent security firm
Achieved Cyber Essentials Plus certification
Updated data protection impact assessments for all processing activities
Implemented enhanced zero-trust architecture across all systems
GPOD maintains a dedicated data protection team led by our Data Protection Officer (DPO). This team is responsible for ensuring compliance with data protection regulations, responding to data subject requests, and continuously improving our security practices.
For questions about data protection, privacy concerns, or to submit a data subject request, please contact our DPO:
GPOD protects your personal data through multiple layers of security measures:
Our security measures exceed industry standards and are regularly updated to address emerging threats.
GPOD uses location data for specific, limited purposes:
Important privacy protections for location data include:
GPOD makes it easy to exercise your data subject rights:
To access your data:
To delete your data:
Alternatively, you can contact our Data Protection Officer at dpo@gpod.uk to submit a formal data subject request.
GPOD uses facial recognition technology for secure authentication and clock-in verification:
How it works:
Privacy safeguards:
GPOD maintains several key security certifications and compliance validations:
These certifications are maintained through regular audits and assessments, ensuring our security measures remain at the highest standards.
GPOD has a comprehensive data breach response plan that includes:
Our breach notification process includes clear, plain-language information about:
Our Data Protection team is ready to help with any questions or concerns about your data privacy and security. Whether you're reviewing GPOD as a tech partner, council funder, regulator, or user, we welcome your inquiries.
Response Commitment: We aim to acknowledge all inquiries within 2 business days and provide a substantive response within 5 business days. For formal data subject requests, we'll respond within the statutory timeframe (typically 30 days).
Data Security & GDPR Policy | Last Updated: April 15, 2025
Š 2025 GPOD.UK Ltd. All rights reserved.
Please click Accept Cookies to continue to use the site.