Glix Privacy Policy
Last Updated: 5 August 2026
1. About this Privacy Policy
Glix is a workforce management platform provided by Gyzer Technologies Ltd.
This Privacy Policy explains how personal data is collected, used, stored, disclosed and protected when individuals use:
- the Glix website at glixapp.com
- the Glix web platform
- the Glix mobile applications
- Glix application programming interfaces and integrations
- Glix customer support services
- Glix workforce management, scheduling, time and attendance, lone-worker, safety, communication, checkpoint, task and reporting features
This Privacy Policy applies to customer administrators, managers, workers, employees, contractors, agency workers, service providers, website visitors, prospective customers and other individuals whose personal data is processed through Glix.
References to “Glix”, “Gyzer”, “we”, “us” and “our” mean Gyzer Technologies Ltd.
References to “Customer Organisation” mean the employer, business, public authority, charity, agency, contractor or other organisation subscribing to or using Glix.
References to “Authorised User” mean an individual permitted by a Customer Organisation to access Glix.
References to “Customer Data” mean personal data submitted to, collected through or generated within Glix on behalf of a Customer Organisation.
This Privacy Policy does not replace a Customer Organisation’s workforce, employee, contractor, client or service-user privacy notice. Customer Organisations must provide their own privacy information describing how and why they process personal data through Glix.
2. Who is responsible for your personal data
The organisation responsible for personal data depends on the purpose for which the data is processed.
2.1 Customer Organisation as controller
The Customer Organisation normally acts as the data controller for Customer Data processed through Glix.
The Customer Organisation decides:
- which individuals use Glix
- which information gets collected
- why the information is required
- which Glix features are enabled
- when location or monitoring features operate
- who receives access to the information
- how long the information is retained
- how the information supports workforce, safety, client or operational decisions
Customer-controlled data includes information relating to scheduling, attendance, working hours, leave, location, checkpoints, tasks, lone-worker protection, incidents, communications, performance records, client visits and employment administration.
Individuals should contact their employer or relevant Customer Organisation first when exercising rights relating to this data.
2.2 Gyzer Technologies Ltd as processor
Gyzer acts as a data processor when Glix processes Customer Data on behalf of a Customer Organisation.
Gyzer processes this information under the Customer Organisation’s documented instructions, the customer contract and the applicable Data Processing Addendum.
Gyzer assists Customer Organisations with security, data-subject requests, data protection impact assessments, breach management, deletion, return and other processor obligations.
2.3 Gyzer Technologies Ltd as controller
Gyzer acts as a separate data controller where Gyzer decides why and how personal data gets processed for its own legitimate business purposes.
This includes processing for:
- customer account and commercial relationship management
- subscription and billing administration
- identity verification and account security
- fraud, misuse and cyberattack prevention
- service diagnostics and platform security
- customer support administration
- website operation and analytics
- sales enquiries and product demonstrations
- direct marketing
- legal and regulatory compliance
- complaint handling
- establishing, exercising or defending legal claims
- business continuity, audit and corporate governance
Gyzer does not ordinarily act as a joint controller with Customer Organisations. A separate written arrangement will identify any processing where Gyzer and a Customer Organisation jointly determine the purpose and essential means.
3. Personal data we process
The personal data processed through Glix depends on the features selected by the Customer Organisation and the way each individual uses the platform.
3.1 Identity and profile information
This includes:
- full name
- profile photograph
- username and user identifier
- employee or contractor number
- email address
- telephone number
- home or correspondence address where entered
- date of birth where required by the Customer Organisation
- job title
- department
- employment or engagement status
- manager and reporting line
- organisation, team, branch, site or work location
- role and permissions within Glix
- emergency contact details
3.2 Employment and workforce information
This includes:
- employment, worker or contractor details
- availability and working preferences
- skills, licences and qualifications
- training and certification records
- right-to-work or compliance information
- assigned sites, clients, teams and managers
- work documents uploaded by the Customer Organisation or user
- absence, sickness and leave information
- holiday requests and approvals
- disciplinary, performance or workforce-management information entered by the Customer Organisation
- payroll identifiers, pay-related information or cost information where the relevant feature or integration is enabled
3.3 Scheduling, time and attendance information
This includes:
- shift dates, times and locations
- rota information
- shift assignments and changes
- clock-in and clock-out records
- break records
- overtime records
- lateness and absence information
- timesheets
- availability
- leave requests
- shift acceptance, rejection or exchange information
- scheduled and completed tasks
- visit or appointment records
3.4 Location and movement information
Depending on the Customer Organisation’s configuration and the relevant device permissions, Glix processes:
- GPS location
- location coordinates
- location timestamps
- geofence entry and exit information
- clock-in and clock-out location
- checkpoint location
- checkpoint arrival and completion information
- patrol, round, route or visit progress
- last known location during an active lone-worker session
- location associated with an SOS or duress event
- location accuracy and device-location status
Location collection operates only for functions requiring location information, according to the Customer Organisation’s settings and the user’s device configuration.
Glix does not use workforce location data for advertising.
3.5 Lone-worker, welfare and safety information
Where a Customer Organisation enables safety features, Glix processes:
- check-call schedules
- welfare check responses
- missed check-ins
- escalation records
- SOS or duress activations
- incident time and location
- emergency contact and nominated responder information
- communications connected with an emergency
- actions taken by managers, monitoring centres or responders
- audio, photographs, video or other evidence generated during an incident where the relevant feature is enabled
- device and connection information associated with an emergency event
3.6 Checkpoint, patrol and visit information
This includes:
- assigned checkpoints
- checkpoint order
- planned and completed routes
- arrival and departure timestamps
- QR code, NFC, Bluetooth or other checkpoint interactions where enabled
- missed, skipped or incomplete checkpoints
- visit notes
- proof of attendance
- photographs, forms, signatures or documents submitted at a checkpoint or visit
3.7 Task, form and operational information
This includes:
- assigned tasks
- task status and completion records
- inspection and audit responses
- custom form responses
- notes and comments
- incident and hazard reports
- risk assessments
- photographs and attachments
- signatures
- equipment or asset information
- site instructions
- operational records submitted through Glix
3.8 Communications information
This includes:
- in-app messages
- announcements
- chat content
- message attachments
- notification content
- delivery and read status
- support messages
- feedback
- call, email or meeting records involving Gyzer support or commercial teams
3.9 Client, service-user and third-party information
Customer Organisations sometimes enter information about clients, residents, patients, service users, visitors, subcontractors, site contacts or other third parties.
This includes:
- names and contact details
- addresses and visit locations
- appointment or service information
- site access instructions
- service notes
- signatures
- incident information
- information required to complete a visit, service or task
The Customer Organisation remains responsible for ensuring lawful collection and use of this information.
3.10 Device, technical and usage information
This includes:
- IP address
- device type and model
- operating system
- browser type
- mobile application version
- device language and time zone
- device identifiers
- push-notification token
- authentication and login information
- session information
- feature usage
- application logs
- security events
- error and crash reports
- performance and diagnostic information
- integration activity
- audit records
3.11 Customer and billing information
This includes:
- customer administrator names and contact details
- company details
- subscription plan
- billing address
- invoices
- payment status
- transaction references
- purchase and renewal records
- communications relating to subscriptions, payments and contracts
Payment providers process payment credentials under their own privacy terms.
3.12 Website and marketing information
This includes:
- website visits and interactions
- cookie and similar technology information
- marketing preferences
- sales enquiries
- demonstration requests
- event registrations
- campaign engagement
- business contact information obtained directly from an individual or from legitimate business sources
Further details about cookies appear in the Glix Cookie Policy.
3.13 Enterprise enquiry information
Where you submit the enquiry form on the Glix Enterprise page, we process the answers you give:
- your full name
- your work email address
- your organisation’s name
- the approximate number of people who could use Glix
- the subjects you would like to discuss, and the short note you may add where you select “Other”
- the approximate number of sites or operating locations involved
We record the date and time of the submission, the page it came from and a reference for the enquiry. We do not collect any other information through that form. There are no hidden fields, and every value sent is one shown to you on the page.
We use this information to review your requirements, respond to your enquiry and arrange the most appropriate next conversation. The lawful basis is taking steps at your request before entering a contract, and our legitimate interests in responding to a business enquiry.
The enquiry is delivered to the Glix team by email through Brevo, a transactional email provider acting as a processor on our instructions. It is read by the members of the Glix team responsible for Enterprise enquiries. It is not added to a marketing list.
We keep an enquiry for as long as we need it to respond and to manage the resulting discussion. Where it leads to a customer relationship it becomes part of that relationship record and follows the retention described in section 14.2. Where it does not, we delete it or place it beyond normal operational use once the enquiry is closed.
Submitting the form does not subscribe you to marketing communications and does not create marketing consent. The form sets no cookie. To limit abusive submissions, our server briefly holds a one-way hashed form of the network address a submission arrived from; it is held only in memory, is never written to storage or included in the enquiry, and is never used for marketing or analytics.
4. Special-category and criminal-offence data
Certain Glix features process information receiving additional protection under data protection law.
This includes information relating to:
- physical or mental health
- sickness absence
- disability or workplace adjustments
- injuries and incidents
- care or support needs
- racial or ethnic origin where entered for a lawful workforce purpose
- religious requirements affecting scheduling or work
- trade-union membership where entered by a Customer Organisation
- biometric information where a separately approved feature processes biometric data for identification
- criminal allegations, convictions, DBS information or safeguarding records
The Customer Organisation must identify an appropriate lawful basis, an applicable special-category or criminal-offence condition and any required safeguards before entering or collecting this information through Glix.
Gyzer does not determine the Customer Organisation’s lawful basis for Customer Data.
Customer Organisations should avoid entering special-category or criminal-offence data unless the information is necessary, proportionate and supported by law.
5. How we receive personal data
We receive personal data from:
- you
- your employer or Customer Organisation
- customer administrators and managers
- other Authorised Users
- your device while you use Glix
- integrations authorised by you or the Customer Organisation
- payroll, identity, scheduling, human resources or business systems connected to Glix
- nominated responders, monitoring centres or emergency contacts
- support and communications providers
- payment providers
- publicly available business sources used for business-to-business communications
6. How Customer Organisations use personal data through Glix
Customer Organisations use Glix to support activities including:
- creating and managing user accounts
- planning and publishing rotas
- assigning workers to shifts, sites, clients and tasks
- recording working time, attendance and breaks
- managing availability, leave and absence
- confirming attendance at workplaces, checkpoints or client locations
- supporting lone-worker safety and welfare checks
- responding to SOS, duress or emergency events
- managing incidents, risks, hazards and evidence
- communicating with workers and managers
- managing training, licences and workforce documents
- producing operational, attendance, payroll and compliance reports
- managing visits, services and field-work activity
- protecting workers, clients, property and business operations
- meeting contractual, regulatory, employment, health and safety or safeguarding obligations
The Customer Organisation must explain its lawful bases in its own privacy notice.
Granting location, camera, microphone, notification or Bluetooth permission through a mobile device provides technical access to the relevant device function. A device permission does not, by itself, establish the Customer Organisation’s lawful basis under data protection law.
7. How Gyzer uses personal data as controller
Where Gyzer acts as controller, we use personal data for the following purposes.
7.1 Providing and administering Glix
We use account, contact, subscription and support information to:
- set up customer accounts
- manage customer administrators
- provide requested services
- process subscriptions
- respond to enquiries
- deliver support
- manage renewals
- communicate service information
The lawful basis is performance of a contract, steps requested before entering a contract, or our legitimate interests in managing customer relationships.
7.2 Security, fraud prevention and service integrity
We use identity, device, usage, authentication and audit information to:
- authenticate users
- protect accounts
- detect unauthorised access
- prevent fraud and misuse
- investigate suspicious activity
- maintain platform availability
- test and improve security
- enforce customer agreements and acceptable-use requirements
The lawful basis is our legitimate interests in protecting Glix, our customers, users and business, together with legal obligations applying to security and data protection.
7.3 Support and service improvement
We use support records, diagnostics, error reports and feedback to:
- resolve technical issues
- investigate service failures
- improve performance
- improve accessibility and usability
- develop and test features
- maintain service quality
Where possible, Gyzer uses aggregated or de-identified information for product analysis and improvement.
The lawful basis is performance of a contract and our legitimate interests in operating and improving Glix.
7.4 Billing, accounting and legal compliance
We use customer, billing and transaction information to:
- issue invoices
- administer payments
- maintain accounting records
- complete audits
- meet tax, corporate and regulatory obligations
- respond to lawful requests
The lawful basis is performance of a contract and compliance with legal obligations.
7.5 Marketing and business development
We use business contact and marketing information to:
- respond to sales enquiries
- arrange demonstrations
- send requested information
- communicate relevant Glix services and updates
- manage marketing preferences
We rely on consent where law requires consent. In other business-to-business contexts, we rely on legitimate interests, subject to the individual’s right to object and applicable electronic marketing rules.
Every eligible marketing communication includes an unsubscribe method.
7.6 Legal claims and business protection
We process relevant information to:
- enforce agreements
- resolve disputes
- investigate complaints
- protect legal rights
- respond to legal proceedings
- obtain professional advice
- establish, exercise or defend legal claims
The lawful basis is our legitimate interests, compliance with legal obligations and the legal-claims conditions applying to protected information.
8. Location, monitoring and workforce transparency
Location, attendance, checkpoint and lone-worker features involve workforce monitoring.
The Customer Organisation decides whether to enable these features and remains responsible for:
- identifying a lawful basis
- assessing necessity and proportionality
- completing a data protection impact assessment where required
- providing workers with clear privacy information
- explaining when monitoring starts and stops
- limiting access to authorised personnel
- setting appropriate retention periods
- avoiding excessive or unrelated monitoring
- using information fairly in employment or contractual decisions
Glix displays or requests relevant device permissions when a feature needs location or another device function.
Turning off a required permission stops or limits the related Glix feature. The Customer Organisation remains responsible for explaining any workplace or contractual consequences associated with disabling a required function.
During an active SOS, duress, lone-worker or emergency event, Glix processes the information required to support the configured emergency workflow until the event closes or the relevant collection ends.
9. Automated processing and decision-making
Depending on the Customer Organisation’s configuration, Glix generates operational outputs such as:
- attendance alerts
- missed check-in alerts
- late-arrival notifications
- checkpoint status
- timesheet calculations
- shift conflict warnings
- task status
- risk or exception indicators
- route and visit information
- management reports
Gyzer does not use personal data under this Privacy Policy to make solely automated decisions producing legal or similarly significant effects on individuals.
Customer Organisations remain responsible for all employment, disciplinary, scheduling, performance, safeguarding and operational decisions.
Customer Organisations should review Glix-generated alerts, scores, reports and recommendations before taking action affecting an individual.
10. When we share personal data
We disclose personal data only where necessary for the purposes described in this Privacy Policy.
10.1 Customer Organisations and Authorised Users
Customer Data is visible to the Customer Organisation and its Authorised Users according to assigned roles, permissions, teams, sites, clients and responsibilities.
Customer Organisations control internal access.
10.2 Service providers and subprocessors
Gyzer works with service providers supporting:
- cloud hosting and data storage
- identity and authentication
- email, SMS and push notifications
- transactional email delivery for enquiries submitted on the Glix website
- application monitoring and diagnostics
- customer support
- payment processing
- backup and recovery
- security testing
- analytics
- communications
- professional services
Each service provider receives access limited to its assigned function and remains subject to contractual confidentiality, security and data-protection obligations.
Customer Organisations receive information about relevant subprocessors through the customer contracting process or by contacting support@glixapp.com.
10.3 Customer-selected integrations
Where a Customer Organisation connects Glix to another platform, relevant information passes between Glix and the selected provider.
The Customer Organisation remains responsible for authorising the integration and reviewing the third party’s privacy and security terms.
10.4 Safety and emergency recipients
During a lone-worker, welfare, SOS, duress or emergency event, Glix shares relevant information with recipients configured by the Customer Organisation.
Recipients include:
- customer managers
- nominated responders
- emergency contacts
- monitoring or alarm receiving centres
- security providers
- health and safety personnel
- emergency services
Disclosure is limited to information relevant to the event and the configured response process.
10.5 Professional advisers
We disclose information to lawyers, accountants, auditors, insurers, consultants and other professional advisers where needed for advice, audit, insurance, compliance or legal claims.
10.6 Public authorities and legal requirements
We disclose information where law, court order, regulatory requirement or lawful authority requires disclosure.
We also disclose information where necessary to protect life, personal safety, legal rights, systems or property.
10.7 Corporate transactions
Where Gyzer undergoes a merger, investment, financing, restructuring, sale, acquisition or transfer of assets, relevant personal data forms part of the due-diligence or transaction process under confidentiality and data-protection safeguards.
Gyzer does not sell personal data to data brokers or use Customer Data for third-party behavioural advertising.
11. International data transfers
Gyzer and its service providers process personal data in the United Kingdom and, where required for service delivery, in other countries.
Where a transfer qualifies as a restricted international transfer, Gyzer applies an approved safeguard, including:
- UK adequacy regulations
- the UK International Data Transfer Agreement
- the UK Addendum to approved standard contractual clauses
- European Commission standard contractual clauses where the EU GDPR applies
- contractual, technical and organisational supplementary measures
Gyzer reviews transfer risks and limits transferred information to what the relevant service requires.
Customer Organisations seeking information about applicable transfer safeguards should contact support@glixapp.com.
12. Data security
Gyzer maintains an information security management system certified to ISO/IEC 27001:2022 by a UKAS-accredited certification body.
Our security programme includes measures appropriate to the nature and risk of the processing, including:
- role-based access controls
- least-privilege access
- authentication controls
- encryption during transmission and storage where appropriate
- logging and security monitoring
- secure software development practices
- environment separation and controlled release processes
- backup and recovery arrangements
- vulnerability and patch management
- incident response procedures
- supplier security assessment
- staff confidentiality and security training
- business continuity arrangements
No online service provides absolute security. Users must protect login credentials, use approved devices and report suspected unauthorised access promptly.
13. Personal data breaches
Where Gyzer acts as processor, Gyzer informs the relevant Customer Organisation of a qualifying Customer Data breach in accordance with the Data Processing Addendum and applicable law.
The Customer Organisation remains responsible for deciding whether to notify affected individuals or a supervisory authority, with Gyzer providing reasonable assistance.
Where Gyzer acts as controller, Gyzer investigates the incident and provides regulatory or individual notifications where law requires notification.
14. Data retention
Gyzer keeps personal data only for as long as necessary for the relevant purpose.
14.1 Customer Data
Customer Data is retained:
- during the customer subscription
- for periods selected or instructed by the Customer Organisation
- for the period required to provide exports, transition support, return or deletion following termination
- during secure backup rotation
- for longer where law, litigation, investigation or a valid preservation requirement requires restricted retention
The customer contract and Data Processing Addendum govern return and deletion after termination.
Customer Organisations control their own workforce and operational retention requirements.
14.2 Gyzer-controlled data
Gyzer retains:
- account and customer relationship information for the duration of the relationship and for a reasonable period afterwards to manage audit, disputes and legal claims
- billing, tax and accounting information for applicable statutory periods
- support records for as long as needed to resolve issues, maintain service history and manage legal claims
- security and audit logs according to security, investigation and risk requirements
- marketing information until an individual unsubscribes, objects or the information no longer supports a legitimate business purpose
- a limited suppression record after an opt-out, so Gyzer continues to honour the request
- complaint and rights-request records for accountability, legal and regulatory purposes
- website enquiries, including Enterprise enquiries, for as long as needed to respond and manage the resulting discussion, as described in section 3.13
When retention ends, Gyzer deletes, anonymises or places the information beyond normal operational use.
15. Your data protection rights
Depending on applicable law and the circumstances, you have the right to:
- receive information about personal data processing
- request access to your personal data
- request correction of inaccurate or incomplete information
- request deletion of personal data
- request restriction of processing
- object to processing based on legitimate interests
- object to direct marketing
- request transfer of eligible personal data
- withdraw consent where processing relies on consent
- challenge qualifying automated decisions
- submit a data protection complaint
These rights are subject to legal conditions and exemptions.
15.1 Requests involving Customer Data
For workforce, employment, scheduling, attendance, location, safety, client or operational information controlled by a Customer Organisation, contact the relevant employer or Customer Organisation.
Where Gyzer receives a request concerning Customer Data, Gyzer forwards the request to the relevant Customer Organisation or assists the Customer Organisation in responding.
Gyzer does not independently delete Customer Data where the Customer Organisation needs the information for lawful employment, contractual, safety, payroll, regulatory or legal purposes.
Deleting a Glix mobile application or disabling an account does not automatically delete Customer Data held for the Customer Organisation.
15.2 Requests involving Gyzer-controlled data
For information controlled by Gyzer, contact:
Email: support@glixapp.com
Postal address: Data Protection Contact, Gyzer Technologies Ltd, 20-22 Wenlock Road, London, England, N1 7GU, United Kingdom
Gyzer requests identity verification where necessary to protect personal data.
Gyzer responds within the timeframe required by applicable law.
16. Data protection complaints
For complaints about Customer Data, contact the relevant Customer Organisation first.
For complaints about personal data controlled by Gyzer, send the complaint to support@glixapp.com with the subject “Data Protection Complaint”.
Gyzer will:
- provide a clear route for submitting the complaint
- acknowledge receipt within 30 days
- take appropriate steps to investigate without undue delay
- request further information where needed
- keep the complainant appropriately informed
- communicate the outcome
Individuals also have the right to complain to the Information Commissioner’s Office, the United Kingdom’s data-protection regulator.
Where another supervisory authority has jurisdiction, individuals also have the right to contact the relevant authority.
17. Direct marketing
Submitting an enquiry or booking a demonstration does not subscribe you to marketing communications, and does not create marketing consent. Marketing consent is asked for separately, is never a condition of making an enquiry, and is recorded independently of it.
You have the right to stop direct marketing at any time.
Use the unsubscribe link included in an eligible marketing email or contact support@glixapp.com.
Service messages concerning security, account administration, contractual changes, incidents or essential platform operation do not constitute marketing and continue where needed to provide or protect the service.
18. Cookies and similar technologies
The Glix website and web application use cookies and related technologies for:
- essential operation
- authentication
- security
- preferences
- performance measurement
- analytics
Gyzer requests consent before placing non-essential cookies where applicable law requires consent.
Further information appears in the Glix Cookie Policy and cookie-preference controls.
19. Third-party services and links
Glix includes links or integrations involving third-party services.
Where you choose to book a demonstration, the link takes you to our booking service at scheduapp.com, which collects the details needed to arrange the meeting and asks its own short set of questions. The Glix website sends nothing about you to that page: the link carries no identifier, no tracking parameter and nothing you have entered.
Third parties process personal data under their own privacy terms where they act as independent controllers.
Gyzer does not control an external provider’s independent processing. Users and Customer Organisations should review the relevant provider’s privacy information before enabling an integration or submitting information.
20. Children and young workers
Glix is a business workforce platform and is not directed to children for personal or consumer use.
A Customer Organisation using Glix in connection with a worker under 18 remains responsible for:
- confirming lawful employment or engagement
- providing clear and age-appropriate privacy information
- applying appropriate safeguards
- limiting monitoring
- protecting the young person’s rights and interests
Gyzer applies additional care where processing relates to children or young people.
21. Customer Organisation responsibilities
Customer Organisations using Glix must:
- process personal data lawfully, fairly and transparently
- provide appropriate privacy notices
- identify lawful bases and special-category conditions
- collect only necessary and proportionate information
- keep information accurate
- configure access permissions appropriately
- protect administrator credentials
- respond to rights requests and complaints
- set and enforce retention periods
- assess high-risk processing
- complete data protection impact assessments where required
- avoid excessive workforce monitoring
- train authorised personnel
- ensure instructions given to Gyzer comply with applicable law
- manage connected integrations and external recipients
- notify Gyzer promptly of suspected misuse or security incidents
22. Changes to this Privacy Policy
Gyzer reviews this Privacy Policy regularly.
Where a change materially affects personal data processing, Gyzer provides notice through an appropriate channel, including the Glix website, platform, application, customer administrator communication or email.
The “Last Updated” date identifies the latest published version.
Continued use after an update does not replace any consent required by law.
23. Contact details
Data Protection Contact
Gyzer Technologies Ltd
20-22 Wenlock Road
London
England
N1 7GU
United Kingdom
Registered in England and Wales, company number 15058377.
Registered with the Information Commissioner’s Office, registration reference ZB712909.
Email: support@glixapp.com
Telephone: +44 020 8243 8601
Glix website: www.GlixApp.com
Gyzer Technologies website: GyzerTech.com