Who We Are
This Privacy Policy explains how Trident HR Ltd collects, uses and protects personal data. It covers personal data we handle in our capacity as a controller — for example, when you visit our website, contact us about our services, or hold an account with us — and explains separately how personal data is handled within our Trident Command software platform and mobile app, where in most cases we act as a processor on behalf of our business clients.
Trident HR Ltd is the data controller for personal data collected through this website.
What Data We Collect
We may collect and process the following personal data when you use our website or contact us:
- Your name
- Email address
- Phone number (if provided)
- Preferred consultation date, time and format (video or telephone)
- Any information you choose to include in your enquiry or message
Through our website, we do not collect sensitive (special category) personal data, and we do not carry out automated decision-making or profiling. Where we provide our Trident Command software platform to client organisations, special category data such as sickness and absence information may be processed on the client's behalf — this is explained in “The Trident Command Platform and Mobile App” below.
How We Collect Data
We collect personal data when you:
- Submit a consultation booking request via our website
- Submit a general enquiry via our contact form
- Contact us directly by email or telephone
- Communicate with us regarding our services
Prospective Clients and Business Contacts
We sometimes identify organisations that may benefit from our services and contact a named person there directly, by telephone or by email. If you have heard from us and did not previously contact us, this section explains where your data came from and what your rights are.
What we collect
Business contact information only: your name, job title, work email address, work telephone number, your employer, and the fact that your organisation has publicly advertised a role or otherwise indicated a need for HR support. We do not collect personal contact details, financial information, or any special category data about you.
Where it comes from
Publicly available sources — job advertisements published by your organisation, your organisation's own website, and the public register at Companies House. We do not purchase contact data, and we do not use data brokers or list vendors.
Why we use it
To make you aware of HR services relevant to a need your organisation has itself made public. We rely on legitimate interests under Article 6(1)(f) of the UK GDPR. We have carried out a legitimate interests assessment for this activity and will provide a copy on request.
How long we keep it
Where no engagement follows, prospect records are deleted after 24 months. Where you ask us not to contact you again, we keep only enough information to make sure we honour that.
Your right to object
You have an absolute right to object to direct marketing. Tell us on the call, reply to any email from us, or contact info@tridenthr.co.uk. We will stop contacting you and record your objection permanently. No account, portal or form is required.
We screen our calling list against the Telephone Preference Service and the Corporate Telephone Preference Service before we call.
We do not sell, rent or trade prospect contact data, and we do not share it with any third party for their own purposes. Calling and introductory emails may be carried out on our behalf by a contracted supplier acting only on our documented instructions under a written data processing agreement.
How We Use Your Data
We use the personal data you provide to:
- Respond to your enquiry or booking request
- Arrange and confirm consultation appointments
- Provide information about our services
- Communicate with prospective or existing clients
- Maintain business records as required
Lawful Basis for Processing
Under UK GDPR, we process personal data on the following lawful bases:
- Legitimate interests — responding to enquiries, direct business-to-business marketing, and running our business operations
- Consent — where you have specifically provided consent for a particular use
- Contract — where processing is necessary to take steps prior to entering into or fulfilling a contract
How We Store and Protect Your Data
Your personal data is stored securely. We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss or disclosure.
Data submitted via our contact and booking forms is transmitted securely and processed by our email delivery service provider (Resend, Inc.) solely for the purpose of delivering that communication to us.
Sharing Your Data
We do not sell, rent or trade your personal data.
Your data may be shared only where:
- Required by law or a regulatory authority
- Necessary to deliver our services — for example, with IT infrastructure or email service providers who process data on our behalf under appropriate data processing agreements
Any third parties with whom we share data are required to handle it in accordance with applicable data protection law.
How Long We Keep Your Data
We retain personal data only for as long as necessary for the purposes for which it was collected, including:
- To respond to and follow up on enquiries
- To meet legal, regulatory or contractual obligations
- To maintain appropriate business records
Enquiry data is typically retained for up to 2 years from last contact. You may request deletion at any time.
Cookies
Our website may use essential cookies required for the site to function correctly. We do not use cookies for advertising, tracking or profiling purposes without your consent.
You can manage cookie preferences through your browser settings.
The Trident Command Platform and Mobile App
This section explains how personal data is handled within Trident Command — our HR software platform — and the Trident Command mobile app (together, “the Platform”). It applies in addition to the rest of this policy.
Our role: processor, not controller
When a business subscribes to Trident Command, that business (your employer, “the Client”) decides what employee data is held and why. Under UK data protection law, the Client is the data controller for the personal data of its workforce held in the Platform. Trident HR Ltd acts as the data processor, handling that data only on the Client's documented instructions and under a written Data Processing Agreement.
This means that if you are an employee using the app provided by your employer, your employer is responsible for the personal data held about you. Requests to access, correct or delete your workforce data should be directed to your employer in the first instance. We will assist your employer in responding to any such request.
Trident HR Ltd remains the data controller for limited data we determine the purpose of ourselves — for example, account administrator contact details, billing information, support correspondence, and security and audit logs.
What the Platform processes
Depending on the modules your employer uses and the features you access, the Platform may process:
- Identity and contact data — name, work email, work phone number, job title, department, profile photograph
- Personal contact data, where held — personal phone, personal email, home address, date of birth
- Emergency contact details
- Attendance and working time — clock-in and clock-out records, timecards, flexi balances, rotas
- Absence data — holiday requests and entitlement, sickness records, fit notes and related health information
- Location data — precise device location at the moment of clocking in or out, used to confirm attendance against your employer's designated work location
- Performance data — reviews, goals and one-to-one records
- Documents you sign or acknowledge through the app
- Wellbeing check-ins you choose to submit
- Support requests you raise through the app
- Account identifiers and technical data necessary to operate the service securely
Special category (sensitive) data
Sickness and absence records, fit notes and wellbeing information are special category data concerning health under Article 9 of the UK GDPR. This data receives additional protection. Your employer, as controller, is responsible for identifying its lawful basis under Article 6 and its condition for processing under Article 9 — typically employment, social security and social protection obligations under Article 9(2)(b), supported by an appropriate policy document under Schedule 1 of the Data Protection Act 2018. We process this data strictly on your employer's instructions and apply role-based access controls so that it is visible only to authorised people within your organisation.
Location data
The app requests access to your device location only to verify your location at the moment you clock in or out, against the work location set by your employer. Location is not tracked continuously, is not collected in the background, and is not used for any other purpose. You can decline the location permission; clocking in by location will then be unavailable, but the rest of the app remains usable.
Biometric app lock
If you enable the optional app lock, Face ID or Touch ID is used to unlock the app. This biometric check is performed entirely on your device by your device's operating system. We never receive, see or store your biometric data.
Sign-in
Sign-in is handled through Microsoft 365 single sign-on or, where enabled, email and password. Authentication is processed by our identity provider on our behalf.
Who processes data on our behalf (sub-processors)
We use the following sub-processors to deliver the Platform. Each is bound by a data processing agreement and processes data only on our instructions:
- Supabase — database, authentication and file storage (data hosted in the European Union, Ireland)
- Microsoft — email delivery, calendar integration and single sign-on
- Resend — transactional email delivery
- Apple Push Notification service and Expo — delivery of mobile push notifications
- Vercel — application hosting
Personal data within the Platform is hosted in the United Kingdom and the European Economic Area. Where any processing involves a transfer of personal data outside the UK, we rely on an appropriate safeguard such as UK adequacy regulations or the International Data Transfer Agreement.
How long Platform data is kept
Workforce data is retained for as long as your employer's subscription requires it, and in line with your employer's own retention decisions as controller. When a subscription ends, data is returned to, or deleted on the instruction of, the Client, subject to any legal retention obligations.
Security
The Platform applies encryption in transit and at rest, role-based access controls, tenant isolation between client organisations, and audit logging. Trident HR Ltd holds Cyber Essentials certification.
Your Rights
Under UK data protection law, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your personal data
- Object to or restrict processing of your data
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with the Information Commissioner's Office (ICO)
To exercise any of these rights, please contact us at info@tridenthr.co.uk. We will respond within one calendar month.
Where Trident HR acts as a processor on behalf of your employer (see “The Trident Command Platform and Mobile App”), please direct requests about your workforce data to your employer, who is the controller. We will support them in responding.
You also have the right to complain to the ICO at ico.org.uk or by calling 0303 123 1113.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The latest version will always be published on this page with an updated date.
Contact Us
If you have any questions about this Privacy Policy or how we handle your personal data, please contact:
Trident HR Ltd
Technology House, 3 Newton Place, Glasgow, G3 7PR
info@tridenthr.co.uk
0330 133 6933