Personal information we collect
We collect personal information in the following ways.
Personal information you provide
- Account information: your name, work email address, organisation, staff group, account status and assigned worker, responder or administrator role.
- Identity information: Microsoft Entra identity and group information used to verify that you belong to the correct organisation and role.
- Safety information: protected-session times and type, check-in responses, alarms, cancellation attempts, incident outcomes, responder actions and resolution notes.
- Location information: coordinates together with capture time, source and reported accuracy while location collection is permitted.
- Communications: information in messages, support requests and the contact form, including your name, work email, organisation, role, team size, enquiry type and message.
Personal information we receive from your use of Ordin
- Log information: IP address, browser type and settings, date and time of a request, requested page and basic interaction information.
- Device information: device and installation identifiers, operating system, push-notification token, last-seen time, permission state, battery, connectivity and safety-capability reports.
- Service information: policy version, check-in schedule, escalation steps, notification delivery attempts and append-only safety and administrative audit records.
- Anti-abuse information: Turnstile verification results and limited request data used to prevent automated or abusive contact submissions.
Information we receive from other sources
We receive information from your employer or customer organisation, its identity and staff-management systems, authorised responders and administrators, your device and operating system, and suppliers that help us provide notifications, telecommunications, hosting, authentication, email and security services.
Safety information can reveal sensitive facts indirectly. For example, an alarm note or location may indicate a person’s health, disability, trade-union activity or another special category of information even though Ordin does not ask workers to create a health profile.
How we use personal information
We use personal information for the following purposes:
- to provide, analyse, maintain and secure the Ordin website and service;
- to authenticate users and enforce organisation, staff-group and role boundaries;
- to run protected sessions, check-ins, alarms and configured escalation workflows;
- to give authorised responders the context needed to assess and manage a live incident;
- to send safety notifications and configured SMS or voice escalations;
- to show workers their session, alarm and location history;
- to maintain device readiness, diagnose faults and investigate misuse or security events;
- to provide audit evidence, incident reporting and configuration-based privacy and DPIA documents;
- to respond to enquiries, manage customer relationships and communicate important service information; and
- to comply with legal obligations and protect the rights, privacy, safety and property of users, customers, Aether Partners Limited and others.
We do not sell personal information, use customer safety information for behavioural advertising or use Ordin as a worker-performance surveillance tool.
Server-held deadlines can mark a check-in as missed, raise an alarm and begin a configured escalation route. These are safety workflow actions, not solely automated decisions about employment, discipline or another matter with legal or similarly significant effects. Authorised people assess and resolve incidents.
Disclosure of personal information
We disclose personal information in the following circumstances:
- Customer organisations and authorised users: information is shown to the organisation that provides your account and its authorised workers, responders and administrators according to configured role and tenant boundaries.
- Responder organisations: an alarm receiving centre or other responder organisation selected by the customer may receive information needed to manage an incident.
- Suppliers and service providers: we use providers for hosting, databases, authentication, email, anti-abuse checks, push notifications and telecommunications. They process information on our instructions for those services.
- Professional advisers and authorities: we may share information with advisers, auditors, insurers, regulators, police, ambulance services or other authorities where reasonably necessary, lawful and proportionate.
- Business transfers: if Aether Partners Limited is involved in a reorganisation, financing, sale or transfer of a business or service, information may be disclosed as part of that transaction subject to appropriate protections.
Suppliers used by an implemented deployment may include Supabase for backend and authentication services, Microsoft for Entra sign-in, Expo and Apple or Google for push delivery, Twilio where SMS or voice escalation is enabled, Cloudflare for website delivery and Turnstile verification, and Resend for contact-form email delivery. The suppliers and regions enabled for a customer deployment are recorded in its service documentation.
Retention
We retain personal information only for as long as needed to provide the service, fulfil the purposes described here, resolve disputes, protect safety and security, and comply with legal or contractual obligations.
Customer organisations approve separate retention periods for location, incident detail and audit evidence. Ordin requires those values before its configuration-based privacy and DPIA pack can be generated. The exact periods for your deployment appear in your organisation’s privacy notice.
- location points are deleted when the configured location period expires;
- older resolved incidents are minimised by removing resolution notes and related sensitive detail at the configured incident threshold;
- safety and administrative audit events are deleted when the approved audit period expires; and
- inactive identities are pseudonymised when they are no longer needed to preserve linked sessions, incidents or other lawful records.
We may retain limited information for longer where required by law, needed to prevent fraud or abuse, protect the service, establish or defend legal claims, or keep an audit record of an erasure request.
Data controls
Ordin provides controls over the information used for safety operations. Depending on your role and organisation, you can view your session and alarm history, see the location record associated with your protection session, and receive confirmation when collection has stopped.
Customer administrators control staff-group policy, check-in and tracking cadence, responder routing, escalation and retention. They can export assurance reporting and a versioned privacy and DPIA pack from the settings in force.
You can remove device permissions through your operating system, but doing so may stop configured protection methods from working. Follow your organisation’s fallback procedure if a permission, notification or connectivity warning appears.
For account removal, see account deletion. Do not send a cancellation PIN, access token or fallback secret through the public website or ordinary email.
Your rights
Depending on the circumstances and lawful basis, you may have the right to access your personal information, correct it, ask for erasure or restriction, object to processing, receive information you supplied in a portable format, withdraw consent where consent is used, and complain to a supervisory authority.
You have a specific right to object to processing based on legitimate interests or public task. Whether processing must stop depends on the circumstances and any compelling lawful grounds. Direct marketing must stop when you object.
For worker-app or control-room information, contact your organisation’s service lead or data-protection team first because it is normally the controller. We assist it with verified requests. For website enquiries or information controlled by Aether Partners Limited, email info@aetherpartners.co.uk. We may need to confirm your identity and will explain if a right is limited by law.
If you remain dissatisfied, you can complain to the Information Commissioner’s Office using its data-protection complaint guidance.
Children
Ordin is a workplace service and is not directed to children. A person under 18 may use it only where their organisation has lawfully authorised that use, provided appropriate supervision and safeguards, and confirmed that the service is suitable for their role.
If you believe a child has provided personal information to us without appropriate authorisation, contact us at info@aetherpartners.co.uk so we can investigate.
Security
We implement technical, administrative and organisational measures designed to protect personal information from loss, misuse and unauthorised access, disclosure, alteration or destruction. These include role-based access, database row-level security, organisation boundaries, limited service functions, encrypted network connections and audit records for safety and administrative actions.
No internet or email transmission is completely secure. Take care when deciding what information to include in incident notes, support requests or enquiries.
Legal bases for processing
The personal information processed, the purposes for processing and the lawful basis depend on how you use Ordin and who controls the information.
| Purpose | Information involved | Typical basis |
|---|---|---|
| Provide and maintain the service | Account, device, session, check-in, alarm, location and audit information | Customer organisation’s contract, legal obligation, public task, legitimate interests or vital interests, as applicable |
| Respond to enquiries and manage relationships | Contact details, organisation, role, team size and message | Steps requested before a contract, legitimate interests or consent where specifically requested |
| Prevent abuse and protect security | Log, device, account, communication and anti-abuse information | Legal obligation or legitimate interests in protecting the service and people using it |
| Meet legal and safety duties | Relevant account, incident, audit and communication information | Legal obligation, protection of vital interests or legitimate interests, as applicable |
Your organisation is responsible for identifying and documenting the lawful basis and, where relevant, the additional condition for special-category information used in its workforce monitoring. Consent is not normally appropriate for employment monitoring when a worker has no genuine choice.
Data transfers
Hosting regions and suppliers are selected and documented for each customer deployment. Some suppliers or their support operations may process information outside the United Kingdom. A restricted transfer is permitted only where it is covered by an applicable adequacy regulation or safeguards such as the UK International Data Transfer Agreement or UK Addendum, together with proportionate technical and organisational measures.
Your organisation’s privacy notice and data-processing documentation provide the deployment-specific position. You may contact us for information about safeguards that apply to processing for which Aether Partners Limited is the controller.
Changes to this Privacy Policy
We may update this Privacy Policy when the service, suppliers, processing activities or law changes. We will publish the updated version and effective date on this page, and use an additional notice where required by law or appropriate for a material change.
Customer organisations are responsible for updating their own worker notices before changing how they use Ordin.
Data controller
Aether Partners Limited is the controller for this public website, contact enquiries, our own customer administration, service security and legal compliance activities.
Your employer or customer organisation is normally the controller for workforce and safety information processed through your Ordin account. Contact its service lead or data-protection team for that information.
Aether Partners Limited is registered in England and Wales under company number 17199332. Our registered office is Suite 2, 10 Abbey Parade, London, SW19 1DG.
How to contact us
Questions, privacy requests and concerns about processing controlled by Aether Partners Limited can be sent to info@aetherpartners.co.uk or by post to Aether Partners Limited, Suite 2, 10 Abbey Parade, London, SW19 1DG.
Do not use this address, the contact form or ordinary email to report an alarm or an immediate emergency. Call 999 when appropriate and follow your organisation’s emergency procedure.