1. Who we are
UberVisor Ltd. operates the UberVisor platform — a wallet, an issuer "Certify" tool, and a construction site companion app — together with the AWS-hosted backend services that serve them.
For your own account data (name, email, phone, login activity) we act as the controller. For credentials issued to you by a training provider, awarding body, or employer, that organisation is the controller and UberVisor acts as a processor under their instructions.
2. What we collect
- Your name and email address — used to sign you in and to send transactional emails (verification codes, two-factor codes, password resets, credential notifications).
- Phone number (optional) — used only for SMS-based account recovery and BLE-fallback session deep links. Leave it blank if you don't want SMS contact.
- Credentials issued to you, including any holder photo bound to a credential by the issuer.
- A device public key for proof-of-possession credentials — generated on your phone. We never see, store, or transmit the matching private key.
- Audit events that name you — issuance, revocation, presentation, and your own consent toggles. Retained as a legal record.
- Approximate location of verifier devices at the moment of a credential check, when an employer has enabled site check-in.
- Crash reports and aggregate usage telemetry (default-on, with a one-tap opt-out — see §6).
- If you join a waitlist on this website: your email address, a few details about the signup, and whether you asked for product news (see §10, The waitlist).
We do not collect: real-time GPS location of holders, contact-book data, social-media profiles, advertising identifiers, browsing history outside our apps, or biometric templates beyond a holder photo (which is treated as biometric-adjacent — see §5).
3. Lawful basis
We rely on the following UK/EU GDPR Article 6 (and where relevant Article 9) bases:
Account data — name, email, phone
Art. 6(1)(b) Contract. Needed to provide you with an account; you cannot use the app without it.
Credentials issued to you
Art. 6(1)(b) Contract Art. 6(1)(f) Legitimate interests. The issuer issued these to you in the context of certification. UberVisor processes them on the issuer's behalf as a processor.
Holder photo bound to a credential
Art. 6(1)(b) Contract Art. 9(2)(a) Explicit consent at capture. Treated as biometric-adjacent data. The photo is bound to the credential's signature via SHA-256 so it cannot be silently swapped. Deleted on account deletion.
Audit log entries
Art. 6(1)(c) Legal obligation. ISO/IEC 17024 §8.3 requires certifying bodies to keep records of issuance and revocation. These records survive account deletion in redacted form.
Product analytics — crash reports + usage stats
Art. 6(1)(f) Legitimate interests. On by default. Aggregated, non-identifying signals used to diagnose bugs and improve the apps. You have the right to object at any time under Article 21 — flip the toggle in Profile → Privacy & Data → Your data choices, and we stop processing immediately. We do not use this data for advertising or cross-site tracking.
Marketing emails
Art. 6(1)(a) Consent. Off by default. Switch on to opt in from Your data choices. Consent is specific, withdrawable, and we never pre-tick the box.
4. How we use Bluetooth (BLE)
Some credentials are presented over a short-range Bluetooth Low Energy handshake between your phone and the verifier device. This is a one-shot signal exchange at the moment of presentation — equivalent in scope to a contactless card tap.
- We do not record encounter history.
- We do not build movement patterns from BLE.
- The identifiers used on the BLE wire are ephemeral per session and not linkable back to you outside the verifier device's own audit log.
- On Android, the operating system requires the "fine location" permission to scan for BLE devices. We never read your actual GPS location and the permission is used only by the OS BLE scanner.
5. The holder photo
If your credential includes a photo, the issuer captured it during certification. The photo is stored in our private S3 bucket in eu-west-2, encrypted at rest, served only via signed short-lived URLs, and bound to the credential's cryptographic signature so a verifier can detect tampering.
Photos are deleted on account deletion. Issuers can revoke their own copy independently.
6. Your rights
Under UK and EU GDPR you have the right to:
- Access — get a copy of everything we hold about you (Art. 15).
- Rectify — correct inaccurate data (Art. 16).
- Erase — delete your account and personal data (Art. 17). Credential records are retained in redacted form per ISO/IEC 17024 §8.3 (a documented Art. 17(3)(b) exemption for legal compliance).
- Restrict processing — pause processing while we resolve a dispute (Art. 18).
- Portability — receive your data in a portable, machine-readable format (Art. 20).
- Object — to legitimate-interests processing, including product analytics (Art. 21).
- Withdraw consent — for anything we do on the basis of consent (Art. 7(3)).
The wallet, certify, and construction apps each include a Privacy & Data screen (Profile → Privacy & Data) where every one of these rights can be exercised self-service — most actions happen the moment you tap. If a flow fails, or you would rather speak to a human, email privacy@ubervisor.app. We respond within 30 days as required by Article 12(3); typically same week.
7. Where your data lives
Every UberVisor resource runs in AWS Europe (London) — eu-west-2. No personal data is replicated, cached, or processed outside the United Kingdom by us.
Sub-processor exceptions are listed in §9. None of them are routinely passed personal data; where they are (e.g., wallet pass delivery), the data leaves only after you have explicitly added the credential to that platform's wallet.
8. Retention
- Wallet profile and photos — kept while your account is active; deleted on account deletion.
- Credential records — kept for the certification scheme's validity period, typically up to seven years, per ISO/IEC 17024 §8.3.
- Audit log — seven years (TTL enforced at the database level).
- Data exports — generated on demand and deleted from our servers after seven days.
- Bounced or complained email addresses — held on the SES suppression list to prevent further sends to known-bad addresses.
- Waitlist email addresses — if you didn't ask for product news: until we've emailed you that the product has launched, or 24 months after you joined, whichever comes first. If you did: for as long as you stay subscribed, with a request to re-confirm every 24 months. See §10.
9. Sub-processors
- Amazon Web Services (Europe Region, London — eu-west-2). Cloud infrastructure: DynamoDB, S3, KMS, AppSync, API Gateway, Cognito, Lambda, SES, SNS. Operating under AWS's UK/EU Data Processing Addendum and Standard Contractual Clauses where applicable.
- Expo (EAS Updates). Used to deliver over-the-air app updates. Expo's servers see only request metadata (IP address, device model, bundle hash) when your app checks for an update. We do not transmit wallet data to Expo.
- Apple and Google (Wallet pass delivery). When you add a credential to Apple Wallet or Google Wallet, the signed pass leaves UberVisor and lands in your platform wallet. From that point Apple or Google's privacy policies apply to that copy of the credential.
10. This website: cookies, fonts, server logs and the waitlist
This site sets no cookies. It runs no analytics scripts, no advertising pixels and no cross-site tracking.
The typeface is loaded from Google Fonts, so your browser also asks Google's servers for it. Google receives your IP address as part of that request and handles it under its own privacy policy.
Server logs
Like almost every website, the servers that deliver these pages keep a record of each request. We keep that log. Here is what that involves:
- What is in it: the date and time, the page you asked for (including any tag on the link, such as
utm_source=linkedin), the page that linked you here, your browser's user-agent string, your IP address, and the country Amazon CloudFront works out from that address. There are no cookies in it, because the site sets none.
- What we use it for: counting visits (how many, which pages, and which links brought people here) and diagnosing problems with the site. Nothing else. We do not use it to identify you, to build a profile of you, or to follow you to other sites.
- Who gets it: only us. It is kept in a private Amazon Web Services storage bucket in London (eu-west-2), which AWS runs for us as our processor. It is not shared with or sold to anyone else.
- How long we keep it: 90 days. After that it is deleted automatically.
The pages reach you through Amazon CloudFront, a network of servers that handles each request on its way through, usually at a location near you. The log itself is kept in London.
Art. 6(1)(f) Legitimate interests: running the site and knowing whether people can find it. You can object at any time (Art. 21) by emailing privacy@ubervisor.app. If you want to see what the log holds about you, tell us your IP address and roughly when you visited. The log has no name or email address in it, so that is the only way we can find your lines.
The waitlist
Some pages have a "Join the waitlist" form for products that are not generally available yet. Under the email field there is a box for product news. It starts unticked, it stays unticked unless you tick it, and you can join the waitlist without it.
- What we keep: your email address, when you joined, which page's form you used, which product the form was about (at the moment, UberVisor for Construction), whether you ticked the product-news box, when you answered, and the exact wording that was next to the box. We also keep a code calculated from your address; it lets the unsubscribe link in our emails find your entry without the link containing your address. Nothing else. The service that receives the form keeps no record of your IP address or your browser.
- What we use it for: two things, and the second only if you ticked the box.
- To email you about the product you joined the waitlist for, for example when a pilot cohort opens or when it launches.
- If you ticked the box: occasional news about UberVisor products.
We do not add you to any other mailing list, and we do not share or sell your address.
- Where it is kept: in a database in Amazon Web Services' London region (eu-west-2), which AWS runs for us as our processor. When you join, we get an email telling us that someone signed up. That email does not contain your address.
- How long we keep it:
- If you didn't tick the box: until we've emailed you that the product has launched, or 24 months after you joined, whichever comes first. The 24-month limit is enforced by the database, which deletes the entry automatically.
- If you ticked the box: for as long as you stay subscribed. Every 24 months we will ask you to confirm that you still want the emails. If you don't confirm, we delete your address.
In both cases the database keeps a rolling backup for 35 days, so a deleted address can remain in that backup for up to 35 days before it is gone completely.
- Unsubscribing: every email we send about the waitlist or product news has an unsubscribe link, and many email apps also show an Unsubscribe button that does the same thing. Unsubscribing deletes your address completely, from the waitlist and from product news, and we don't keep a note of it. You can also email privacy@ubervisor.app with the subject "Remove me from the waitlist". If you'd like to stay on the waitlist but stop product news, email the same address and we'll untick it for you.
Art. 6(1)(a) Consent, for both uses: you asked to join the waitlist by submitting the form, and you asked for product news by ticking the box. You can withdraw consent at any time (Art. 7(3)) in the ways described above. Withdrawing does not affect anything we did before you withdrew.
11. Children
UberVisor is a workplace platform. We do not knowingly collect data from anyone under 16. Account creation in all three apps is gated by an age 16+ confirmation on first run, in line with UK ICO age-assurance guidance and GDPR Article 8.
12. Changes to this notice
If we materially change how we handle data we will publish the new notice version and prompt you to acknowledge it on next app launch (the same flow used at first-run). Past versions remain on file; ask privacy@ubervisor.app if you need a copy of a previous version.
13. Contact & complaints
For any privacy question, data-subject request, or to raise a concern: privacy@ubervisor.app.
You also have the right to lodge a complaint with the UK Information Commissioner's Office: ico.org.uk/concerns.