Built to be checked
Procurement teams, data protection officers and IT reviewers all ask the same question in different words: can we trust this supplier with our workforce data? This page is the straight answer, with the evidence you need for a security questionnaire or a tender.
Gyzer Technologies Ltd
- Certificate number
- 260792
- Certification body
- British Assessment Bureau
- Accreditation
- UKAS Management Systems
- Initial certification
- 7 February 2025
- Valid to
- 6 February 2028
Subject to annual assessment. Scope covers software development and IT consultancy, cyber security, digital transformation and software management solutions including mobile and web application development.
A certified management system, not a list of good intentions
Glix is provided by Gyzer Technologies Ltd, registered in England and Wales, company number 15058377. The information security management system is certified to ISO/IEC 27001:2022 by a UKAS-accredited certification body.
Access control
Role-based permissions with least-privilege access, authentication controls, and location-scoped managers who see only their own contracts. Bespoke roles and per-organisation permissions on Enterprise agreements.
Encryption and monitoring
Encryption in transit and at rest where appropriate, with logging and security monitoring across the platform.
Secure development
Secure software development practices, environment separation, controlled release processes, and vulnerability and patch management.
Resilience
Backup and recovery arrangements and business continuity planning, tested rather than assumed.
Incident management
Documented incident response procedures. Where Glix acts as processor, qualifying personal data breaches are reported to the customer organisation in line with the Data Processing Addendum and applicable law.
Supplier assurance
Subprocessors are assessed before use and bound by contractual confidentiality, security and data protection obligations. A current list is available on request.
We publish what a buyer needs to assess risk. We do not publish detailed implementation specifics that would help someone attack the platform.
UK data residency and a GDPR toolset in the product
Where data lives
Primary production customer data is hosted in the United Kingdom. Where an approved subprocessor processes limited data outside the UK, recognised transfer safeguards apply, including the UK International Data Transfer Agreement or the UK Addendum to standard contractual clauses.
Controller and processor
Your organisation is the controller for workforce data. Gyzer acts as processor under your documented instructions and the Data Processing Addendum, which forms part of the agreement and is available on request.
Subject access requests
A subject access request export is built into the product, so you can answer a worker or a DPO without raising a support ticket.
Retention you control
Evidence retention is configured per organisation with per-location override. Notes carry retention categories. You set retention to match your own legal obligations.
Honest expiry
When photo evidence reaches the end of its retention period the file is deleted and the record keeps a removed-state marker and the date, so storage limitation does not put a hole in your audit trail.
Payments
Checkout, plan changes and invoices run through Stripe. Glix never holds your card details.
Why lone worker protection survives a failed payment
Ungated by design
SOS, duress, check-ins, escalation, SMS alerts and last-known location ship on every tier. Safety is not an upgrade you can forget to buy.
The failed-payment test
Entitlements are driven live by billing state. When a payment fails, the account moves to a read-only grace lock that preserves safety, so a billing problem never becomes a safety problem.
What Glix is not
Glix is not an emergency service, an alarm receiving centre or a response provider. It escalates to responders you nominate, and it depends on networks, devices and people. In an emergency, always call 999.
What we can send your procurement team

Available on request
- ISO/IEC 27001:2022 certificate of registration
- Data Processing Addendum
- Current subprocessor list
- Completed security questionnaires
- Information on transfer safeguards
- Custom data retention terms on Enterprise agreements
Who to contact
- Security and vulnerability reports
- support@glixapp.com with the subject “Security vulnerability”. Please report privately and give us a reasonable opportunity to investigate before any public disclosure.
- Privacy and data protection
- support@glixapp.com. Full detail is in the privacy policy.
- Procurement and contracts
- support@glixapp.com, or see the terms of service.
- Accessibility
- See the accessibility statement.
- Registered office
- Gyzer Technologies Ltd, 20-22 Wenlock Road, London, N1 7GU, United Kingdom. Registered in England and Wales, company number 15058377.
- ICO registration
- Gyzer Technologies Ltd is registered with the Information Commissioner’s Office under reference ZB712909, verifiable on the ICO data protection register.
This site sets analytics cookies only with your consent, and never for advertising. See the cookie policy for every cookie and storage key we use.

Trust is easier to verify than to promise
Book 20 minutes with us and bring your security questionnaire. We would rather answer it live than send a PDF.
14-day trial, no card, full Pro features