PRIVACY NOTICE · UPDATED 27 SEPTEMBER 2026

Your information and workplace records.

This notice covers the CheckControl website, workplace service and Check control iPhone app. It explains what happens to your account and to work you have already submitted.

1. Who operates CheckControl

CheckControl is a trading name of JOSHCURTIS-PRODUCTIONS. LTD, registered in England and Wales under company number 16990327. Registered office: C/O Clever Accounts Ltd, Brookfield Court Selby Road, Garforth, Leeds, England, LS25 1NB. Contact support@checkcontrol.org about privacy, support or a data request.

2. Your organisation and your account

Your organisation decides which workplace checks to assign, what information staff should record, who may access its records and the workplace purposes for retaining them. CheckControl stores and displays those records to provide the service to the organisation. CheckControl also handles account, security, billing and support information to operate its own service. Your organisation’s employment or workplace privacy notice may explain additional uses of its records. You can contact your manager or CheckControl about a request concerning those records.

3. Information we handle

Account information includes your name, work email address, account identifier, organisation, site access, job role, shifts and notification choices. Workplace information includes assigned checks, answers, measurements, completion times, written notes, issue reports, acknowledgements and photos you choose to upload. We also handle sign-in and security events, support correspondence, and organisation billing identifiers where billing is enabled. Notification registration uses a device or browser push identifier. Avoid including unrelated personal information, patient details or other sensitive information in notes or photos.

4. Why information is used

We use information to authenticate individual users, control access, assign work, record completed checks, show issues and evidence to authorised colleagues, deliver requested notifications, respond to support requests, maintain service security and administer organisation subscriptions. For CheckControl’s own processing, service and billing administration supports performance of a contract where you are a party to it; providing the organisation’s requested service, preventing abuse and responding to support requests serve legitimate interests in operating and protecting the service. Applicable legal obligations may require particular accounting or security disclosures. Optional marketing relies on the choices offered when it is collected. Your organisation is responsible for identifying and explaining the appropriate lawful basis for its workplace processing. Optional notification permissions and marketing choices can be withdrawn.

5. The iPhone app and your permissions

Camera access is used when you choose to take an evidence photo. The system photo picker shares only the images you select. Microphone access and voice-note recording are not part of this app. Notification permission is optional and can be changed in iPhone Settings; delivery preferences and a connection test are in Profile, then Notifications & email. Notification messages may contain workplace information, so consider your lock-screen preview settings. Face ID or the device passcode is handled by iOS; CheckControl does not receive your biometric information. The app does not use advertising trackers or sell your information to advertisers.

6. Saved work and offline use

After you load your workspace online, the app can store assigned work, draft answers and selected photos on your iPhone. Queued routines are sent when a usable connection returns with the app open. New assignments, account changes and issue-report sending need a connection. Profile, then Offline & saved work, shows pending work. Signing out clears that account’s saved local work after the app’s warning. Account deletion also clears local work after the server confirms the deletion. Uninstalling the app alone does not delete your server account or submitted workplace records.

7. Who receives information

Authorised members of your organisation can access workplace information according to their role and site permissions. Service suppliers process information needed for hosting, storage, authentication, communication, support and billing. These include OpenAI Sites and Cloudflare for the hosted service, database and file storage; Clerk for web account authentication where used; Resend for service email; Google Workspace for business email; Apple Push Notification service for iPhone alerts; and Stripe when your organisation uses online billing. Configured support and founder-assistance features can use OpenAI and Anthropic to process support messages and context made available to those features. The iPhone app does not include an advertising SDK. An organisation may separately export or share its reports; recipients of those copies are responsible for their own handling of them.

8. Processing locations

The service uses suppliers that operate internationally, so processing may take place outside the United Kingdom. We do not promise UK-only storage or processing. The relevant supplier services, locations and transfer arrangements depend on the processing involved. Contact support@checkcontrol.org for information about the suppliers and arrangements relevant to your organisation. This notice does not claim that a particular transfer safeguard or hosting region has been independently certified.

9. Retention of workplace records

Submitted checks form part of the organisation’s operational record. Deleting a staff app account or removing someone from a team does not automatically erase submitted checks, reports, photos or notes. The organisation’s continuing operational and audit purposes, its retention instructions and settings, and any applicable legal requirements determine how long those records are needed. There is no single fixed retention period for all organisations or all kinds of check. We do not assert that every submitted record is legally required to be retained, and a possible future need does not automatically override a valid data-rights request.

10. Evidence expiry and other retention settings

Evidence can expire independently of the check outcome. The service’s usual initial evidence-retention setting is 90 days; organisation settings can differ. Report evidence associated with open or in-progress reports, or reports explicitly kept, has exceptions to scheduled expiry. Expired day reports can also be removed according to their expiry and keep status. Account deletion does not change these existing settings. The service is not a promise of permanent evidence storage; organisations should export records they need and confirm suitable retention arrangements. Security sign-in-attempt cleanup uses two days, notification-delivery history uses 180 days, and raw website-measurement events use 35 days. These are scheduled cleanup settings, not a guarantee that every storage copy disappears at the same instant. Provider logs and backups may have separate service-specific lifecycles; contact us about copies relevant to a deletion request.

11. Deleting your staff app account

Open Profile, then Delete my account, and confirm with your current password. This removes your CheckControl password, recovery access, sessions and notification registrations. Your name and email are removed from the retained staff profile and check attribution, which displays “Deleted staff member”. Your app’s saved local work is cleared after confirmation. Submitted employer checks, reports and evidence remain visible to the organisation under its access controls. Written content and photos can still identify someone, so replacing the profile name is not complete anonymisation or erasure of workplace records. Returning staff must receive a new invitation and a separate account; historical checks are not reassigned to that new account.

12. Your rights and requests

Depending on the information and reason for processing it, you may request access, correction, erasure, restriction or portability, or object to processing. Where processing relies on consent, you may withdraw it. For workplace records, identify your organisation when contacting support@checkcontrol.org so the request can be considered with the appropriate organisation. We may need to verify your identity before disclosing or changing information. Retention requests and erasure requests need to be assessed against the applicable rights and any actual obligation to keep the records; account deletion is not a promise that every workplace record will be erased. You can raise a concern with the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint, or your local data-protection authority.

13. Website measurement

Public sales pages use a random first-party browser token to estimate page views, unique browsers and the path into Stripe Checkout. We store only a one-way hash of that token, the page path, event type and event time for these figures, not the visitor’s IP address, user-agent string, query string or form contents. Checkout completion is matched using a one-way hash of the Stripe Checkout session identifier. Global Privacy Control and Do Not Track disable this browser token and public-page event recording. The token expires after 30 days and raw events are scheduled for deletion after 35 days. These website figures are not an identified-person count and are separate from the native iPhone app.

If you allow Google Ads measurement on a sales page, a Google tag uses advertising cookies to recognise an ad click. We tell Google Ads only when Stripe has confirmed a new CheckControl subscription trial, using a non-reversible transaction identifier to prevent duplicate conversions. Google may receive browser and ad-click information. We do not send your name, email, check answers or photos in this conversion event. The Google tag does not load if you decline, have not chosen, or signal Global Privacy Control or Do Not Track. This choice is stored in your browser and can be changed here: .

14. Changes and contact

We update this notice when service practices change and show the update date above. Contact support@checkcontrol.org if you need help understanding it, exercising a right or confirming your organisation’s retention arrangements. See also the service terms.

? Help & Support