Who We Are
This Privacy Policy explains how Trident HR Ltd collects, uses and protects personal data. It covers personal data we handle in our capacity as a controller — for example, when you visit our website, contact us about our services, or hold an account with us — and explains separately how personal data is handled within our Trident Command software platform and mobile app, where in most cases we act as a processor on behalf of our business clients.
Trident HR Ltd is the data controller for personal data collected through this website.
What Data We Collect
We may collect and process the following personal data when you use our website or contact us:
- Your name
- Email address
- Phone number (if provided)
- Preferred consultation date, time and format (video or telephone)
- Any information you choose to include in your enquiry or message
Through our website, we do not collect sensitive (special category) personal data, and we do not carry out automated decision-making or profiling. Where we provide our Trident Command software platform to client organisations, special category data such as sickness and absence information may be processed on the client's behalf — this is explained in “The Trident Command Platform and Mobile App” below.
How We Collect Data
We collect personal data when you:
- Submit a consultation booking request via our website
- Submit a general enquiry via our contact form
- Contact us directly by email or telephone
- Communicate with us regarding our services
How We Use Your Data
We use the personal data you provide to:
- Respond to your enquiry or booking request
- Arrange and confirm consultation appointments
- Provide information about our services
- Communicate with prospective or existing clients
- Maintain business records as required
Lawful Basis for Processing
Under UK GDPR, we process personal data on the following lawful bases:
- Legitimate interests — responding to enquiries and running our business operations
- Consent — where you have specifically provided consent for a particular use
- Contract — where processing is necessary to take steps prior to entering into or fulfilling a contract
How We Store and Protect Your Data
Your personal data is stored securely. We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss or disclosure.
Data submitted via our contact and booking forms is transmitted securely and processed by our email delivery service provider (Resend, Inc.) solely for the purpose of delivering that communication to us.
Sharing Your Data
We do not sell, rent or trade your personal data.
Your data may be shared only where:
- Required by law or a regulatory authority
- Necessary to deliver our services — for example, with IT infrastructure or email service providers who process data on our behalf under appropriate data processing agreements
Any third parties with whom we share data are required to handle it in accordance with applicable data protection law.
How Long We Keep Your Data
We retain personal data only for as long as necessary for the purposes for which it was collected, including:
- To respond to and follow up on enquiries
- To meet legal, regulatory or contractual obligations
- To maintain appropriate business records
Enquiry data is typically retained for up to 2 years from last contact. You may request deletion at any time.
Cookies
Our website may use essential cookies required for the site to function correctly. We do not use cookies for advertising, tracking or profiling purposes without your consent.
You can manage cookie preferences through your browser settings.
The Trident Command Platform and Mobile App
This section explains how personal data is handled within Trident Command — our HR software platform — and the Trident Command mobile app (together, “the Platform”). It applies in addition to the rest of this policy.
Our role: processor, not controller
When a business subscribes to Trident Command, that business (your employer, “the Client”) decides what employee data is held and why. Under UK data protection law, the Client is the data controller for the personal data of its workforce held in the Platform. Trident HR Ltd acts as the data processor, handling that data only on the Client's documented instructions and under a written Data Processing Agreement.
This means that if you are an employee using the app provided by your employer, your employer is responsible for the personal data held about you. Requests to access, correct or delete your workforce data should be directed to your employer in the first instance. We will assist your employer in responding to any such request.
Trident HR Ltd remains the data controller for limited data we determine the purpose of ourselves — for example, account administrator contact details, billing information, support correspondence, and security and audit logs.
What the Platform processes
Depending on the modules your employer uses and the features you access, the Platform may process:
- Identity and contact data — name, work email, work phone number, job title, department, profile photograph
- Personal contact data, where held — personal phone, personal email, home address, date of birth
- Emergency contact details
- Attendance and working time — clock-in and clock-out records, timecards, flexi balances, rotas
- Absence data — holiday requests and entitlement, sickness records, fit notes and related health information
- Location data — precise device location at the moment of clocking in or out, used to confirm attendance against your employer's designated work location
- Performance data — reviews, goals and one-to-one records
- Documents you sign or acknowledge through the app
- Wellbeing check-ins you choose to submit
- Support requests you raise through the app
- Account identifiers and technical data necessary to operate the service securely
Special category (sensitive) data
Sickness and absence records, fit notes and wellbeing information are special category data concerning health under Article 9 of the UK GDPR. This data receives additional protection. Your employer, as controller, is responsible for identifying its lawful basis under Article 6 and its condition for processing under Article 9 — typically employment, social security and social protection obligations under Article 9(2)(b), supported by an appropriate policy document under Schedule 1 of the Data Protection Act 2018. We process this data strictly on your employer's instructions and apply role-based access controls so that it is visible only to authorised people within your organisation.
Location data
The app requests access to your device location only to verify your location at the moment you clock in or out, against the work location set by your employer. Location is not tracked continuously, is not collected in the background, and is not used for any other purpose. You can decline the location permission; clocking in by location will then be unavailable, but the rest of the app remains usable.
Biometric app lock
If you enable the optional app lock, Face ID or Touch ID is used to unlock the app. This biometric check is performed entirely on your device by your device's operating system. We never receive, see or store your biometric data.
Sign-in
Sign-in is handled through Microsoft 365 single sign-on or, where enabled, email and password. Authentication is processed by our identity provider on our behalf.
Who processes data on our behalf (sub-processors)
We use the following sub-processors to deliver the Platform. Each is bound by a data processing agreement and processes data only on our instructions:
- Supabase — database, authentication and file storage (data hosted in the European Union, Ireland)
- Microsoft — email delivery, calendar integration and single sign-on
- Resend — transactional email delivery
- Apple Push Notification service and Expo — delivery of mobile push notifications
- Vercel — application hosting
Personal data within the Platform is hosted in the United Kingdom and the European Economic Area. Where any processing involves a transfer of personal data outside the UK, we rely on an appropriate safeguard such as UK adequacy regulations or the International Data Transfer Agreement.
How long Platform data is kept
Workforce data is retained for as long as your employer's subscription requires it, and in line with your employer's own retention decisions as controller. When a subscription ends, data is returned to, or deleted on the instruction of, the Client, subject to any legal retention obligations.
Security
The Platform applies encryption in transit and at rest, role-based access controls, tenant isolation between client organisations, and audit logging. Trident HR Ltd holds Cyber Essentials certification.
Your Rights
Under UK data protection law, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your personal data
- Object to or restrict processing of your data
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with the Information Commissioner's Office (ICO)
To exercise any of these rights, please contact us at admin@tridenthr.co.uk. We will respond within one calendar month.
Where Trident HR acts as a processor on behalf of your employer (see “The Trident Command Platform and Mobile App”), please direct requests about your workforce data to your employer, who is the controller. We will support them in responding.
You also have the right to complain to the ICO at ico.org.uk or by calling 0303 123 1113.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The latest version will always be published on this page with an updated date.
Contact Us
If you have any questions about this Privacy Policy or how we handle your personal data, please contact:
Trident HR Ltd
Technology House, 3 Newton Place, Glasgow, G3 7PR
admin@tridenthr.co.uk
0330 133 6933