Skip to content
E-DOB

Legal

Privacy Policy

Last updated: 22 June 2026. This document is maintained centrally by Ffon Solutions Limited.

Privacy Policy

Effective date: 15 June 2026 Last updated: 15 June 2026

This Privacy Policy explains how Ffon Solutions Limited, trading as GuardDog Digital ("we", "us", "our"), processes personal data in connection with E-Dob, our SaaS incident reporting and management platform for organisations, available at eu.e-dob.uk.

E-Dob is provided as a database and workflow platform for the recording, management, and processing of an organisation's incident log and daily occurrence records. The customer organisation determines what data is entered into the platform, who may access it, how it is used, and how long it is retained.

We act as a data processor in relation to personal data uploaded to, stored in, or otherwise processed through the platform by our customers. We act as a data controller only in respect of limited personal data that we process for our own purposes, including account administration, billing, website administration, service operation, security, and compliance.

1. Categories of personal data

We may process the following categories of personal data:

  • User account data — name, email address, role, authentication credentials, login timestamps, and two-factor authentication settings.
  • Incident report data — personal data included in incident reports created by customers, which may relate to staff, service users, visitors, members of the public, contractors, or other individuals involved in an incident.
  • Public statement submissions — content submitted by members of the public at a customer's invitation, including any contact details provided.
  • Billing data — subscription, invoicing, payment, and account administration data.
  • Technical and security data — IP addresses, device and browser information, access logs, audit logs, and security event logs.
  • Medical report data — where enabled, special category health data relating to individuals involved in medical incidents, including patient name, date of birth, contact details, incident narrative, injury details, clinical status, treatment information, hospital attendance, and associated media files.

2. Purposes of processing

We process personal data for the following purposes:

  • to provide, maintain, and support the E-Dob platform;
  • to host, store, organise, and make available customer data at the customer's instruction;
  • to administer user accounts and access permissions;
  • to monitor, secure, and improve the platform;
  • to respond to support requests and troubleshoot technical issues;
  • to manage billing, invoicing, and account administration;
  • to comply with legal and regulatory obligations;
  • to process medical reports where a customer enables that feature and instructs us to do so.

3. Controller and processor roles

Where we process personal data on behalf of a customer, that customer acts as the data controller and we act as the data processor.

In that capacity:

  • the customer determines the purposes and means of processing;
  • the customer determines what data is entered into the platform;
  • the customer determines access permissions and retention settings;
  • the customer is responsible for its own privacy notices, lawful basis, and responses to data subject requests in relation to controller-managed data;
  • we process data only on the customer's documented instructions, except where required by applicable law.

Where we process personal data for our own purposes, we act as an independent data controller.

4. Lawful bases for processing

Where we act as a controller, we rely on the following lawful bases under the UK GDPR, as applicable:

  • Contract — for the provision of the E-Dob service and related account administration;
  • Legitimate interests — for platform security, abuse prevention, fraud detection, service improvement, and business administration, provided that those interests are not overridden by the rights and freedoms of data subjects;
  • Legal obligation — where processing is required to comply with applicable law;
  • Consent — where a member of the public voluntarily submits a statement and consent is the appropriate lawful basis for that submission.

Where we act as a processor, our processing is carried out in accordance with our agreement with the relevant customer and on that customer's instructions.

4.1 Special category data

Where your organisation uses the Medical Reports feature, E-Dob may process special category health data under Article 9 UK GDPR. The applicable Article 9 condition depends on the customer's use case and must be confirmed by the customer’s Data Protection Officer or legal adviser.

Possible Article 9 conditions may include:

  • Explicit consent — where valid and appropriate for the processing activity;
  • Health or social care — where processing is necessary for preventive or occupational medicine, the assessment of working capacity, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems and services.

The customer organisation, as controller, is responsible for ensuring an appropriate Article 9 condition applies and for any related notices, records, or consents required by law.

5. Data retention

We retain personal data only for as long as necessary for the purposes for which it is processed, subject to any applicable legal, regulatory, contractual, or operational requirements.

In summary:

  • Account data is retained for the duration of the subscription and for a limited period thereafter for reactivation, administration, and dispute handling.
  • Security and audit logs are retained for a limited period for security, monitoring, troubleshooting, and abuse prevention.
  • Incident data is retained in accordance with the customer's instructions, configuration, and applicable legal or regulatory requirements.
  • Billing and accounting records are retained for as long as required for tax, accounting, and contractual purposes.
  • Medical report data is retained for the period defined in our Data Retention Policy or as required by the customer's regulatory obligations, including where applicable RIDDOR or CQC requirements.

Where we act as processor, deletion or return of customer data is carried out in accordance with the relevant customer agreement and documented instructions, subject to any legal obligation requiring retention.

6. Recipients and sub-processors

We disclose personal data only where necessary for the operation of the service, the provision of support, or compliance with law, including to approved sub-processors and service providers such as:

  • hosting and infrastructure providers;
  • storage and backup providers;
  • email delivery providers;
  • payment processors;
  • customer support and security tooling providers.

A current list of sub-processors is maintained in our Sub-processor List.

We do not sell personal data.

We may disclose personal data to law enforcement authorities, regulators, courts, or other public bodies where required or permitted by law.

7. International transfers

Our primary infrastructure is hosted in the UK/EU region (Laravel Cloud on AWS, eu-west-1 / London).

Where a customer enables optional AI-assisted features, limited incident text may be processed by Google (Gemini API), which is located in the United States. Any such transfer is made only where the customer has enabled the feature and only subject to appropriate safeguards, including Standard Contractual Clauses or equivalent transfer mechanisms where required by applicable law.

8. Data subject rights

Subject to the conditions and exemptions under the UK GDPR, individuals may have the following rights:

  • right of access;
  • right to rectification;
  • right to erasure;
  • right to restriction of processing;
  • right to data portability;
  • right to object to certain processing.

Where we act as processor in relation to customer-controlled data, we will ordinarily refer the request to the relevant customer and provide reasonable assistance to the extent required by our agreement and applicable law.

9. How to exercise your rights

To exercise your rights, or to raise a data protection query, please contact our Data Protection Officer at dpo@e-dob.uk.

General privacy queries may be sent to privacy@e-dob.uk.

If you are uncertain whether your request should be directed to us or to one of our customers, please contact us and we will assist in directing the request appropriately.

10. Personal data breaches

Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with applicable law.

Where we act as processor, we will notify the relevant customer without undue delay in accordance with our contractual obligations.

11. Customer responsibility

If you use the platform on behalf of your organisation, you are responsible for ensuring that your use of the platform complies with your organisation's privacy policy, records management requirements, and internal data governance arrangements.

In particular, the customer organisation is responsible for:

  • determining the lawful basis for its own processing;
  • deciding what incident data is entered into the platform;
  • deciding who may access that data;
  • setting and applying appropriate retention periods;
  • responding to data subject requests in relation to controller-managed data;
  • ensuring that individuals are informed where required by law;
  • ensuring an appropriate Article 9 condition applies where special category data is processed.

12. Data access and use

Ffon Solutions Limited is not responsible for how customers choose to access, review, disclose, or otherwise use data they upload to the platform, except to the extent required by applicable law, our contractual obligations, or our obligations as a data processor.

Access controls within the platform are administered by the customer and its authorised users. The customer remains responsible for ensuring that access is appropriate and properly authorised.

13. Governing law and jurisdiction

This service is governed by the laws of England and Wales, and the courts of England and Wales shall have jurisdiction, subject to any mandatory legal requirements to the contrary.

14. Contact details

Ffon Solutions Limited trading as GuardDog Digital Privacy queries: privacy@e-dob.uk Data Protection Officer: dpo@e-dob.uk

Medical Report Data (Special Category)

Where your organisation uses the Medical Reports feature, E-Dob processes special category data under UK GDPR Article 9, specifically health data relating to individuals involved in medical incidents.

  • Lawful basis (Article 9(2)): Processing is necessary for the purposes of preventive or occupational medicine, the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems and services (Article 9(2)(h) UK GDPR), or with the explicit consent of the data subject (Article 9(2)(a) UK GDPR) — the applicable basis depends on your organisation's specific use case and should be confirmed with your Data Protection Officer.
  • Data processed: Patient name, date of birth, phone number, incident narrative, injury details, clinical status, treatment information, hospital attendance, and associated media files.
  • Retention: Medical reports are retained for the period defined in our Data Retention Policy, or as required by your organisation's regulatory obligations (for example, Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 and Care Quality Commission requirements where applicable).
  • Your responsibilities: As the data controller, your organisation is responsible for ensuring an appropriate Article 9 lawful basis exists for processing medical data through E-Dob, and for obtaining any necessary consent or maintaining appropriate records.

Central copy: view on the E-DOB Trust Centre →

We use cookies

We use essential cookies to make E-DOB work, and optional analytics cookies to help us understand how the site is used. You can accept everything, reject non-essential cookies, or manage your preferences.

Read our Cookie Policy →