Privacy & Cookie Policy
Last updated: 2 July 2026
This notice explains how Recon Systems Ltd ("we", "us") processes personal data on the Recon platform, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
123 Cherry Blossom Lane
1. Who is responsible for your data
Recon is a multi-organisation intelligence and incident management platform. Responsibility for personal data is split:
- We are the controller for platform account data: your registration details, user account, login and security records, support tickets and contact messages.
- Each subscribing organisation is the controller for the intelligence content its staff record on the platform (suspect records, incidents, vehicle records and banning orders). We process that content on the organisation's behalf, as its processor, under a data processing agreement. Each organisation must have its own lawful basis for recording this information, which it declares to us on registration.
2. What we collect and why
| Data | Purpose | Lawful basis |
|---|---|---|
| Registration details (organisation identity and address, contact name, email, phone, job title, SIA licence or police force where applicable, stated purpose and lawful basis, data protection officer, IP address of the application) | Assessing and approving access to the platform | Contract; legitimate interests (vetting access to sensitive data) |
| Account data (name, email address, role, password stored as a one-way hash, two-factor authentication secrets, notification and appearance preferences, profile photo if you add one) | Operating your account | Contract |
| Security records (the IP addresses of your three most recent logins, with approximate location derived from the IP; an audit trail of actions taken in the platform) | Account security, fraud prevention, and accountability required for a platform holding sensitive data | Legitimate interests; legal obligation (security of processing, Art. 32) |
| Support tickets and contact form messages (including the IP address of contact form submissions, used for rate limiting) | Responding to you and preventing abuse | Contract; legitimate interests |
| Private messages between users | Delivering the messaging feature. Messages are end-to-end encrypted — we store only ciphertext and cannot read message content. | Contract |
3. Criminal offence data
Intelligence content recorded by subscribing organisations may include personal data relating to criminal convictions and offences or suspected offences. Under Article 10 UK GDPR and the Data Protection Act 2018, each organisation may only record such data where it has an appropriate lawful basis and a condition for processing (for example, preventing or detecting unlawful acts). Organisations declare their basis on registration and are contractually required to keep it under review.
Platform safeguards for this data include: strict tenant isolation (an organisation can only see its own records), role-based access control, per-user watermarking of images so any leaked copy is traceable, a full audit trail of access and changes, encrypted storage, and short-lived signed links for images.
4. Cookies
We use only strictly necessary cookies. No advertising, analytics or tracking cookies are set, so no cookie consent banner is required.
| Cookie | Purpose | Lifetime |
|---|---|---|
__Host-CRDSESS | Keeps you signed in (session cookie) | Until you sign out or the session expires |
5. Who we share data with
We do not sell personal data. We use a small number of service providers (processors) to run the platform:
- Cloudflare — image storage (R2) and bot protection on public forms (Turnstile). Images are only reachable via short-lived signed links.
- ipinfo.io — approximate geolocation of login IP addresses, used solely for account security review by administrators.
- Email delivery providers — to send account and notification emails.
- Apple, Google and Mozilla push services — to deliver push notifications if you enable them. Notification payloads are encrypted in transit to your device.
- DVLA — where an organisation looks up a vehicle registration, the registration number is submitted to the DVLA Vehicle Enquiry Service.
Where a provider processes data outside the UK, transfers are protected by UK adequacy regulations or the provider's international data transfer safeguards (such as the UK Addendum to the EU Standard Contractual Clauses).
6. How long we keep data
- Account data — for the life of your account. When an account is deleted, personal details are removed; content the user authored is retained by the controlling organisation with authorship detached.
- Login IP history — only your three most recent logins are kept.
- Audit trail — retained for a limited period for security and accountability, then automatically deleted (default 2 years).
- API sessions — access tokens expire after 90 days and are then purged.
- Registration applications — refused applications are deleted automatically after 6 months.
- Intelligence content — retention is set by the controlling organisation in line with its own retention policy; contact the organisation for details.
7. Security
All traffic is encrypted in transit (TLS). Passwords are stored as strong one-way hashes and two-factor authentication is available on every account. Private messages are end-to-end encrypted. Access to intelligence content is restricted by organisation and role, watermarked, and audit-logged.
8. Your rights
You have the right to access, rectify, erase, restrict, object to, and port personal data we hold about you as controller. Signed-in users can exercise the two most common rights directly from their profile page:
- Download my data — an immediate machine-readable export of the personal data linked to your account (Articles 15 and 20).
- Request account deletion — sends a verified erasure request to the platform administrators (Article 17).
If you believe a subscribing organisation holds intelligence about you (for example a record or banning order), your request should be directed to that organisation, which is the controller of that content. If you contact us instead, we will pass your request to the relevant organisation without undue delay.
To exercise any other right, email [email protected] or use our contact form. We respond within one month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
9. Changes to this notice
We will update this page when our processing changes and revise the "Last updated" date above. Significant changes will be announced to account holders by email or in-app notice.