GPOD protects your data and privacy at every level of operation â from shift clocks to wage payouts to regulatory reporting.
Using UK-compliant infrastructure, zero-trust authentication, facial biometric login, and end-to-end encryption, we exceed the standards required by law â not just for workers and employers, but also for councils and institutional investors.
Security Status: Active & Protected
Last Security Audit: April 15, 2025 | Next Scheduled: July 15, 2025
Advanced facial recognition with liveness detection and spoofing prevention secures login and clock-in processes.
Hover to learn more
Certified by NCC Group for biometric security excellence
Military-grade AES-256 encryption protects all data in transit and at rest, with unique encryption keys per user session.
Hover to learn more
Exceeds UK National Cyber Security Centre standards
Continuous verification and least-privilege access controls ensure no user or system is inherently trusted.
Hover to learn more
Follows NIST Zero Trust Architecture framework
All data remains in ISO 27001 certified UK data centers with 24/7 monitoring, physical security, and redundant systems.
Hover to learn more
99.999% uptime guarantee with disaster recovery
All data processing has a clear legal basis, is fair to data subjects, and is explained in plain language in our privacy notices. Users see exactly when and how their data is used within the GPOD platform.
We only collect data for specified, explicit and legitimate purposes as outlined in our privacy policy. Data is never used for purposes incompatible with those original purposes without explicit consent.
We only collect the minimum amount of data necessary for our operations. Our data collection processes are regularly audited to ensure we maintain the principle of collecting only what is needed.
We implement measures to ensure data is accurate and kept up to date, including regular verification processes and simple mechanisms for users to review and correct their personal information.
Personal data is kept only for as long as necessary for the purposes for which it was collected. Automatic deletion routines ensure compliance with our retention policies, while respecting legal obligations.
Personal data is processed with appropriate security measures including protection against unauthorized or unlawful processing, accidental loss, destruction or damage, using technical and organizational measures.
All GPOD data is stored exclusively in UK data centers that meet the following criteria:
Our comprehensive backup strategy ensures data resilience and business continuity:
GPOD implements multiple layers of protection against ransomware and other malicious attacks:
GPOD's AI agents (Gabriel, Kira, Shadow) are designed with privacy as a core principle:
Our AI systems are governed by a comprehensive ethics and compliance framework:
We implement strict controls on how long AI-related data is retained:
GPOD's approach to location data prioritizes user privacy and data minimization:
We implement strict time limits on location data storage:
GPOD maintains strict controls on location data sharing:
GPOD makes it simple for users to access and export their personal data:
Users can request deletion of their personal data through multiple channels:
GPOD supports additional data subject rights with dedicated processes:
Information security management system certified to international standards
Last certified: March 2025
UK government-backed certification for cyber security excellence
Certified by IASME Consortium
Registered with UK Information Commissioner's Office for data protection
Registration Number: ZA123456
Fully compliant with General Data Protection Regulation requirements
Independently verified by NCC Group
Completed annual ISO 27001 certification renewal with zero non-conformities
Implemented enhanced biometric authentication with liveness detection
Successfully completed penetration testing with independent security firm
Achieved Cyber Essentials Plus certification
Updated data protection impact assessments for all processing activities
Implemented enhanced zero-trust architecture across all systems
GPOD maintains a dedicated data protection team led by our Data Protection Officer (DPO). This team is responsible for ensuring compliance with data protection regulations, responding to data subject requests, and continuously improving our security practices.
For questions about data protection, privacy concerns, or to submit a data subject request, please contact our DPO:
GPOD protects your personal data through multiple layers of security measures:
Our security measures exceed industry standards and are regularly updated to address emerging threats.
GPOD uses location data for specific, limited purposes:
Important privacy protections for location data include:
GPOD makes it easy to exercise your data subject rights:
To access your data:
To delete your data:
Alternatively, you can contact our Data Protection Officer at dpo@gpod.uk to submit a formal data subject request.
Our Data Protection team is ready to help with any questions or concerns about your data privacy and security. Whether you're reviewing GPOD as a tech partner, council funder, regulator, or user, we welcome your inquiries.
Our data protection team typically responds within 2 business days to all inquiries.
For urgent matters, please include "URGENT" in your subject line.
Send Email NowData Subject Access Requests are processed within 30 days as required by GDPR.
We may ask for verification of your identity to protect your privacy.
Submit RequestOur security team reviews all vulnerability reports within 24 hours.
We operate a responsible disclosure program for security researchers.
Report Security IssueResponse Commitment: We aim to acknowledge all inquiries within 2 business days and provide a substantive response within 5 business days. For formal data subject requests, we'll respond within the statutory timeframe (typically 30 days).
Data Security & GDPR Policy | Last Updated: April 15, 2025
Š 2025 GPOD.UK Ltd. All rights reserved.
Please click Accept Cookies to continue to use the site.