Privacy & Cookie Policy

Last updated: 2 July 2026

This notice explains how Recon Systems Ltd ("we", "us") processes personal data on the Recon platform, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

123 Cherry Blossom Lane

1. Who is responsible for your data

Recon is a multi-organisation intelligence and incident management platform. Responsibility for personal data is split:

2. What we collect and why

DataPurposeLawful basis
Registration details (organisation identity and address, contact name, email, phone, job title, SIA licence or police force where applicable, stated purpose and lawful basis, data protection officer, IP address of the application) Assessing and approving access to the platform Contract; legitimate interests (vetting access to sensitive data)
Account data (name, email address, role, password stored as a one-way hash, two-factor authentication secrets, notification and appearance preferences, profile photo if you add one) Operating your account Contract
Security records (the IP addresses of your three most recent logins, with approximate location derived from the IP; an audit trail of actions taken in the platform) Account security, fraud prevention, and accountability required for a platform holding sensitive data Legitimate interests; legal obligation (security of processing, Art. 32)
Support tickets and contact form messages (including the IP address of contact form submissions, used for rate limiting) Responding to you and preventing abuse Contract; legitimate interests
Private messages between users Delivering the messaging feature. Messages are end-to-end encrypted — we store only ciphertext and cannot read message content. Contract

3. Criminal offence data

Intelligence content recorded by subscribing organisations may include personal data relating to criminal convictions and offences or suspected offences. Under Article 10 UK GDPR and the Data Protection Act 2018, each organisation may only record such data where it has an appropriate lawful basis and a condition for processing (for example, preventing or detecting unlawful acts). Organisations declare their basis on registration and are contractually required to keep it under review.

Platform safeguards for this data include: strict tenant isolation (an organisation can only see its own records), role-based access control, per-user watermarking of images so any leaked copy is traceable, a full audit trail of access and changes, encrypted storage, and short-lived signed links for images.

4. Cookies

We use only strictly necessary cookies. No advertising, analytics or tracking cookies are set, so no cookie consent banner is required.

CookiePurposeLifetime
__Host-CRDSESSKeeps you signed in (session cookie)Until you sign out or the session expires

5. Who we share data with

We do not sell personal data. We use a small number of service providers (processors) to run the platform:

Where a provider processes data outside the UK, transfers are protected by UK adequacy regulations or the provider's international data transfer safeguards (such as the UK Addendum to the EU Standard Contractual Clauses).

6. How long we keep data

7. Security

All traffic is encrypted in transit (TLS). Passwords are stored as strong one-way hashes and two-factor authentication is available on every account. Private messages are end-to-end encrypted. Access to intelligence content is restricted by organisation and role, watermarked, and audit-logged.

8. Your rights

You have the right to access, rectify, erase, restrict, object to, and port personal data we hold about you as controller. Signed-in users can exercise the two most common rights directly from their profile page:

If you believe a subscribing organisation holds intelligence about you (for example a record or banning order), your request should be directed to that organisation, which is the controller of that content. If you contact us instead, we will pass your request to the relevant organisation without undue delay.

To exercise any other right, email [email protected] or use our contact form. We respond within one month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

9. Changes to this notice

We will update this page when our processing changes and revise the "Last updated" date above. Significant changes will be announced to account holders by email or in-app notice.