Privacy & Data Protection
Protecting people should never mean losing control of their data
SIBGuard uses information about movement, location, safety events and environmental conditions to help organisations protect people and understand what is happening across their operations.
We recognise that this information can be sensitive. Privacy is therefore not an additional feature. It is an essential part of how SIBGuard should be configured, deployed and used.
Our goal is clear: to provide the information needed to protect life and health, without turning workplace safety into disproportionate employee monitoring.
Discuss your privacy requirements
Website Privacy Policy
Privacy and GDPR are related, but they are not the same
Our approach to privacy
Privacy is about how the system is designed and used in practice.
It means having a clear purpose for collecting information, limiting the data to what is genuinely necessary, controlling who can access it and preventing its use for purposes unrelated to health protection, safety or the agreed operational use.
Our approach to GDPR
GDPR is the European legal framework governing the processing of personal data.
SIBGuard is designed to help customers implement appropriate privacy and data-protection measures. However, no technology alone can make an organisation GDPR compliant.
Compliance also depends on the purpose of the deployment, its configuration, the legal basis for processing, the customer’s internal procedures and the way the organisation uses the system.
Our Privacy Principles
Safety, not employee performance monitoring
The primary purpose of SIBGuard is to protect people, identify dangerous situations and enable a faster response when an incident occurs.
The system is not designed to evaluate employee productivity or create general employee performance profiles.
Clear and limited purpose
Every deployment should begin with a clearly defined purpose.
Organisations should determine which safety or operational risks need to be addressed and configure the system accordingly. Data collected for workplace safety should not automatically be used for unrelated purposes.
Data minimisation
SIBGuard deployments can be configured around the information required for the intended safety and operational use cases.
The objective is to avoid collecting information simply because it is technically possible to do so.
Controlled access
Access to information should be limited to authorised people with a legitimate operational need.
Different roles may require different levels of access. For example, a safety responder may need information about an active incident, while an administrator may only need access to system configuration.
Appropriate retention
Information should only be retained for as long as it is needed for its defined purpose or required by applicable law.
Retention requirements should be agreed as part of the deployment and aligned with the customer’s internal policies.
Transparency
People should be able to understand:
- what information is collected;
- why it is collected;
- how it is used;
- who can access it;
- and how long it is retained.
SIBGuard encourages customers to communicate these points clearly before the system is introduced.
What SIBGuard Evaluates
SIBGuard processes technical signals from connected devices, positioning infrastructure and environmental sensors to identify safety-relevant situations.
Depending on the enabled features, this information may include:
- device or user location;
- movement and inactivity;
- detected falls and emergency events;
- entry into or presence within defined safety zones;
- environmental conditions;
- device status;
- and records related to alerts and incident response.
The exact scope depends on the individual deployment.
SIBGuard does not determine a person’s health status or provide a medical diagnosis. It technically evaluates signals from movement, devices and the surrounding environment to identify predefined safety events.
Security, Data Separation & Auditability
SIBGuard protects customer information through encryption, controlled data separation, access management and continuous security monitoring.
Our security approach is designed not only to protect data, but also to provide an auditable record of how the platform and its data are accessed and changed.
Encryption
Customer data is encrypted both in transit and at rest.
Encryption protects information while it is transferred between devices, platform services and authorised users, as well as while it is stored within the SIBGuard platform.
Separation of Customer Data
Customer data is logically separated at both the application and database layers.
Customer information, user identity records and operational data are maintained in separate data structures. Controlled identifiers are used to connect information only when this is required for an authorised system function.
Access controls and customer-specific data boundaries are used to prevent information belonging to one customer from being exposed to another customer.
This is logical data separation. It does not necessarily mean that every customer is hosted in a physically separate database or infrastructure environment.
Separation of Telemetry and User Identity
SIBGuard collects technical telemetry to monitor the security, reliability, performance and operation of the platform.
Telemetry and analytical information are stored separately from directly identifying user information. Our analytical datasets do not combine technical telemetry with tables containing identifiable user profiles.
Product analytics may be used to understand how platform features are used and where the user experience can be improved. It is not used to evaluate the performance or behaviour of individual workers.
Customer operational data is not combined with website analytics or marketing data.
Role-Based Access
Access to customer information is restricted according to defined roles and operational responsibilities.
Users and administrators are only given access to the information and functions required for their role. Sensitive administrative actions are recorded so that they can be reviewed when necessary.
Audit and Security Monitoring
SIBGuard uses several purpose-specific categories of logs and monitoring data.
Audit Logs
Audit logs record relevant changes to customer data and provide information about who performed a change, what was changed and when the action occurred.
Security Logs
Security logs record sign-ins, permission changes and sensitive administrative actions. They help identify suspicious activity and support security investigations.
Application Logs
Application logs help identify service errors and failed requests. Their purpose is to maintain the reliable and correct operation of the platform.
Incident and Operational Logs
Incident and operational logs document events that occur during service incidents or outages. They support investigation, service recovery and the prevention of similar events.
Technical Metrics
Technical metrics are used to monitor service health, performance, availability and capacity.
Request Tracing
Technical tracing helps identify the path of individual requests across platform services. It is used for troubleshooting, performance analysis and service reliability.
Product Analytics
Product analytics helps us understand how platform features are used and where the user experience can be improved.
Product analytics is kept separate from directly identifying user information and is not intended for monitoring individual employee performance.
Security and Data-Use Reviews
SIBGuard maintains an audit process focused on platform security and the responsible handling of customer data.
The process includes reviews of:
- access to customer information;
- changes to user permissions;
- sensitive administrative actions;
- relevant changes to customer data;
- security events and suspicious activity;
- service errors and operational incidents;
- and the effectiveness of existing security controls.
Audit information allows us to identify unusual activity, investigate incidents and verify that data is handled according to defined security rules.
GDPR and the Division of Responsibilities
The roles of the parties depend on the specific deployment and contractual arrangement.
In a typical customer deployment:
- the customer determines why and how personal data is processed and will usually act as the data controller;
- RallCont, as the provider of SIBGuard, may process data on the customer’s documented instructions and act as a data processor.
The final allocation of roles and responsibilities must be confirmed for each individual deployment.
How SIBGuard Supports GDPR Responsibilities
SIBGuard can support a responsible implementation through:
- configurable system scope and enabled features;
- role-based access to information;
- defined data-retention requirements;
- controlled user and administrator permissions;
- separation of customer data;
- separation of telemetry from directly identifying user information;
- audit records covering relevant access and changes;
- encryption of data in transit and at rest;
- deployment-specific technical documentation;
- and information required for privacy and risk assessments.
Where required, contractual documentation should define processing instructions, confidentiality, security responsibilities, retention, data deletion, data location and the involvement of relevant service providers.
The Customer Is Responsible For
The customer is responsible for:
- defining a specific and legitimate purpose for using the system;
- identifying the appropriate legal basis for processing;
- informing employees and other affected individuals;
- determining what information is genuinely necessary;
- deciding who may access the information;
- setting appropriate retention periods;
- assessing whether a Data Protection Impact Assessment is required;
- and handling requests from individuals under applicable data-protection law.
SIBGuard Is Responsible For
Within the scope of the specific contractual relationship, SIBGuard is responsible for:
- providing accurate information about how the system works;
- processing data according to the agreed terms and the customer’s documented instructions;
- supporting appropriate system configuration and access control;
- protecting information with suitable technical and organisational measures;
- maintaining relevant audit and security records;
- and providing technical information required for the customer’s privacy assessment.
Privacy by Design Starts Before Deployment
Privacy requirements should be discussed before the system is activated.
For each deployment, we recommend defining:
- the safety and operational purposes of the system;
- the minimum information required for those purposes;
- the features and sensors that will be enabled;
- who may access live and historical information;
- the applicable retention periods;
- the deployment architecture and data location;
- the required employee communication and internal policies;
- and the necessary contractual and data-protection documentation.
This creates a clear and auditable foundation for the responsible use of SIBGuard.
Frequently Asked Questions
Is SIBGuard an employee surveillance system?
No. SIBGuard is designed primarily to protect people and identify safety-relevant situations.
Because some features may involve location or movement data, each deployment must have a clear purpose, appropriate configuration and transparent internal rules. SIBGuard should not be used for disproportionate employee monitoring.
Does SIBGuard assess a person’s health?
No. SIBGuard is not a medical diagnostic system.
It technically evaluates signals such as movement, inactivity, device events and environmental conditions to identify predefined situations and generate alerts.
Who can access SIBGuard data?
Access is intended for authorised users according to their roles and operational responsibilities.
The specific access model must be configured for each customer so that users only see the information they need.
Is SIBGuard GDPR compliant?
SIBGuard is designed to support customers in meeting their GDPR obligations. However, GDPR compliance cannot be guaranteed by a product alone.
It depends on the purpose of the processing, the selected configuration, the legal basis, transparency towards affected individuals, internal procedures and the way the organisation uses the system.
Do we need a Data Protection Impact Assessment?
That depends on the scope and context of the deployment.
Systematic monitoring, location tracking or other processing that may create a high risk to individuals can require a Data Protection Impact Assessment, or DPIA.
Customers should evaluate this requirement with their privacy or legal specialists before deployment. SIBGuard can provide relevant technical information about the proposed system configuration for this assessment.
Where can I find information about data collected through this website?
Information about contact forms, cookies, analytics and other processing related specifically to the SIBGuard website is available in our Website Privacy Policy.
Let’s Design the Right Privacy Model
Every workplace, risk profile and deployment is different.
Before proposing a solution, we will discuss your intended use, system configuration, access requirements and data-protection expectations.