Platone Mobile Privacy Policy

Privacy policy for the Platone mobile application, explaining what personal data is processed, why, and what rights you have.

Last updated: 19/09/2026

Version: 1.0

Applies to: Platone mobile application for iOS and Android (com.platone.mobile)

1. About this policy

Platone is a workforce application supplied to organisations that manage field-based work. It is not a consumer product. You will normally be using it because your employer, or an organisation that has engaged you as a contractor, has issued you with an account.

This policy explains what personal data the app collects, why it is collected, who it is shared with, how long it is kept and what rights you have. It is written to meet the requirements of the UK GDPR and the Data Protection Act 2018, Regulation (EU) 2016/679 (the EU GDPR) and the Irish Data Protection Act 2018, together with the Privacy and Electronic Communications Regulations 2003 in the UK and the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 in Ireland.

2. Who is responsible for your data

Your employer or engaging organisation is the data controller for the working data processed through the app. They decide which jobs are assigned to you, which forms and risk assessments you must complete, whether location tracking is enabled for your role, and how long records are kept. Questions about why you are being monitored, or requests to access or delete your working records, should be directed to them in the first instance.

PLATONE LTD ("we", "us") supplies and operates the app and the supporting platform, and acts as a data processor on your employer's instructions under a written contract that meets Article 28 of the UK and EU GDPR.

We act as an independent data controller for a limited set of data only: crash reports, diagnostic telemetry and support correspondence used to keep the app secure and working correctly, as described in section 3.8.

Our details:

  • Company: PLATONE LTD, registered in NORTHERN IRELAND under company number NI737282
  • Registered address: PLATONE LTD, UNIT 19, Antrim Enterprise Agency, 58 Greystone Road, Antrim, Northern Ireland, BT41 1JZ
  • Data protection contact: TEAM@PLATONE.CO.UK
  • Data Protection Officer: None
  • UK representative (if applicable): N/A
  • EU representative (if applicable): N/A
  • ICO registration number: N/A

3. Personal data the app processes

3.1 Account and identity data

When you sign in we process your username, your first name and surname, your internal user identifier, the roles and team assigned to you, the date and time of your last sign in, and the access and refresh tokens issued to your device. This data is held in an encrypted database on the device so that you can continue working without signal.

3.2 Work allocation data

The app receives the jobs assigned to you and the information needed to carry them out. This can include the site address and geographic coordinates, customer or site contact names and telephone numbers, access instructions, asset and equipment references, appointment windows, and the history of the visit. Some of this is personal data about third parties such as customers or occupants, and you must handle it in line with your employer's own policies.

3.3 Location data

Location is the most sensitive category the app handles, so it is described in full in section 4. In summary, the app records your position when you confirm departure and arrival, and records a continuing trail of position readings while you are travelling to a job you have accepted. Each reading consists of latitude, longitude and the date and time it was taken. Readings are stored on the device and uploaded to your employer's system.

3.4 Forms, risk assessments and work records

The app captures the answers you and, where relevant, the customer give in risk assessments and in pre-work and post-work forms. Depending on how your organisation has configured them, forms can include free text, numeric readings, dropdown and multiple choice answers, ratings, yes or no questions, tables of repeating readings, asset selection and a deliberate capture of your current location as an answer.

Free text fields can contain anything you type. Please do not enter personal data about yourself or others beyond what the job genuinely requires, and be aware that health information about you or another person is treated as special category data, which needs the additional protections described in section 5.

3.5 Signatures

The app captures handwritten signatures drawn on the screen, together with the printed name of the signatory where the form asks for it, and can capture several signatures for a single visit. Signatures are personal data of the person signing and are stored as images with the completed record.

3.6 Photographs and attached files

You can attach photographs taken with the camera or chosen from the device gallery. Images are compressed before upload.

Photographs frequently contain more than the subject of the picture. The app reads the technical metadata embedded in each image and stores it alongside the picture. Depending on your device settings, that metadata can include the exact GPS coordinates where the photograph was taken, the date and time it was taken, and the make, model and settings of the camera. Photographs may also incidentally capture people, vehicles, registration plates or documents in the background.

3.7 Camera and code scanning

The camera is also used to scan QR codes and barcodes. The video preview is processed on the device only in order to decode the symbol, and is not recorded or transmitted.

3.8 Device, diagnostic and usage data

To keep the app stable and secure we and our suppliers collect:

  • Crash and error reports through Sentry, including the error, the point in the code where it happened, the app version, the device model and operating system version, and, at the moment an error occurs, a screenshot of the screen you were on. That screenshot can contain whatever was visible at the time, including customer details, form answers or a signature.
  • Usage analytics through Microsoft Azure Application Insights, covering screens visited, events raised, errors and the address of the server your organisation connects to. These records are labelled with your username, so they are not anonymous and are attributable to you.
  • A performance sample of a small proportion of sessions, used to identify slowness in the app.
  • Local diagnostic logs written to the device and viewable inside the app. These are held on the device and are only sent to us if you or your employer supply them in support of a problem report.

We use this data to fix defects, investigate security incidents and improve the product. We do not use it for advertising, we do not sell it, and the app contains no advertising software and no third party tracking for marketing purposes.

3.9 Device unlock and authentication

You may be able to unlock an active session with a fingerprint or with face recognition. That check is performed entirely by your device's operating system. The app never receives, stores or transmits your fingerprint or facial data; it is told only whether the check succeeded. Where a PIN is used instead, it is held on the device.

3.10 Maps

Map screens load map tiles from OpenStreetMap. When a map is displayed your device's IP address and the area of the map you are viewing are visible to the tile provider, in the same way as visiting any website. Please see the OpenStreetMap Foundation privacy policy at https://osmfoundation.org/wiki/Privacy_Policy.

3.11 Data we do not collect

The app does not collect contacts, calendar entries, call logs, messages, browsing history, audio recordings, video recordings, advertising identifiers or payment details, and it does not scan the files on your device beyond the images you choose to attach.

4. Location tracking explained

Because location tracking of workers has a significant effect on privacy, we set out plainly how it works.

When tracking runs. Tracking starts when you accept a job and begin travelling to it, and stops when you arrive, when the job is completed, cancelled or forwarded to someone else, or when tracking is otherwise ended in the app. The app is not designed to record your location before your first job of the day, between the end of one job and the acceptance of the next, or after your working day has finished.

What is recorded. Latitude, longitude and a timestamp, recorded at short intervals while a journey is in progress, so that progress towards site can be shown accurately. Readings are held on the device and uploaded to your employer's system when a connection is available. You can see what is still waiting to upload in the app.

Background collection. So that a journey is recorded correctly when the screen is locked or another app is in use, the app requests permission to access location in the background. On Android a permanent notification is displayed while tracking is active, so it is always visible when a journey is being recorded. On iOS the system status indicator performs the same function.

Who sees it. Your location record is available to authorised schedulers, supervisors and administrators within your employer's organisation.

Your control. Location permission is requested when it is first needed and can be withdrawn at any time in your device settings, under Settings then Privacy and Security then Location Services on iOS, or Settings then Location or the app's permissions on Android. If permission is refused or withdrawn, journey tracking and some location dependent form questions will not work, and your employer may not be able to allocate certain work to you. Refusing permission does not disable the rest of the app.

Employment context. Your employer's decision to use location tracking, and how they use the resulting records, is governed by their own staff privacy notice and their contract with you. If you have concerns about location monitoring during your working day, you should discuss them with your employer.

5. Why we process your data, and our lawful basis

Where we process personal data as a data processor for your employer, your employer is responsible for establishing the lawful basis under Article 6 of the UK and EU GDPR (and Article 9 for any health data entered into forms). In a workplace context that basis is typically Article 6(1)(b) (performance of a contract) or Article 6(1)(f) (legitimate interests of the employer in managing work and ensuring worker safety).

Where we act as a data controller for crash reports, diagnostic telemetry and support records, our lawful basis is Article 6(1)(f) (our legitimate interest in operating a secure, reliable and functional mobile application and meeting our contractual obligations to your employer). Where a crash report incidentally captures sensitive information visible on screen, our basis for processing that element is Article 9(2)(f) (establishment, exercise or defence of legal claims) or Article 9(2)(g) (substantial public interest in ensuring software security), supported by safeguards including access restricted to engineering personnel and short retention periods.

6. Who your data is shared with

Working data captured in the app is transmitted directly to your employer's system or to the cloud infrastructure hosted on their behalf.

To operate the app platform, we use the following infrastructure and service providers, acting as sub-processors under contract:

Supplier Purpose Data involved
Microsoft Azure Cloud hosting, database services and Application Insights telemetry Working data in transit, usage analytics labelled with username
Functional Software, Inc. (Sentry) Crash reporting and error diagnostics Crash reports, error details, device details, screenshots at error moment
OpenStreetMap Foundation Map tile rendering IP address and map region viewed during tile requests

A current list of our sub-processors is available at https://www.platone.co.uk/privacy-policy/. Customers under contract are notified of changes in accordance with their agreement.

We do not sell personal data, do not pass it to advertising networks, and do not disclose it to third parties except where required by law, court order or regulatory instruction.

7. International transfers

Working data is hosted in the UK. Crash reporting uses Sentry's European data region.

Where any supplier processes data outside the UK or the European Economic Area (EEA), transfers are protected by UK International Data Transfer Agreements (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), or by an adequacy decision such as the EU-U.S. Data Privacy Framework and its UK Extension.

8. How long data is kept

Working data on the device is retained only for as long as needed to deliver it to your employer's system and support offline working, after which local copies are purged in accordance with storage management rules. Your employer determines how long working records are retained on their central systems.

Our own diagnostic data is retained for 90 days for crash reports and 90 days for usage analytics, after which it is deleted or aggregated so that it no longer identifies you.

9. How your data is protected

Data stored on the device is held in an encrypted local database using industry standard encryption algorithms. Data in transit between the device and cloud servers is protected using TLS 1.2 or higher. Access to central platform infrastructure is restricted to authorised engineering staff using multi-factor authentication and role-based access controls.

No system is completely secure. Please report any suspected compromise of your account or your device to your employer and to us at TEAM@PLATONE.CO.UK without delay.

10. Your rights

Under data protection law you have rights including subject access, rectification, erasure, restriction of processing, data portability and objection. Because your employer is the controller for your working records, requests relating to job history, completed forms, signatures, photographs or location records should be submitted to your employer. We will assist your employer in responding to your request where required by our agreement with them.

For the diagnostic data we control ourselves, contact TEAM@PLATONE.CO.UK. We will respond within one month, which can be extended by up to two further months for complex requests, and we will tell you if that happens. We do not charge a fee unless a request is manifestly unfounded or excessive.

11. Complaints

If you are unhappy with how your data has been handled, please raise it with your employer or with us at TEAM@PLATONE.CO.UK first. You also have the right to complain to a supervisory authority:

  • In the UK: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, website ico.org.uk
  • In Ireland: Data Protection Commission (DPC), 21 Fitzwilliam Square South, Dublin 2, D02 RD28, telephone +353 (0)1 7650100 / 1800 437 737, website dataprotection.ie

12. Children

The app is intended exclusively for professional workforce use and is not directed at or offered to children. We do not knowingly collect personal data from persons under 16 years of age.

13. Permissions the app requests

Depending on the features enabled by your organisation, the app may request device permissions including Location (for journey tracking and location-based forms), Camera (for taking job photographs and scanning codes), Photo Library (for attaching images), and Biometrics / Face ID / Fingerprint (for quick session unlock). You can review and manage permissions in your device settings at any time.

14. Changes to this policy

We may update this policy as the app changes. The current version is always available at https://www.platone.co.uk/privacy-policy/ and in the app under Settings. Where a change materially affects how your data is used, we will tell your organisation in advance and, where appropriate, display a notice in the app.

15. Contact

Questions about this policy or our data protection practices can be sent to TEAM@PLATONE.CO.UK.