Privacy Policy
Last updated: 26 September 2026
1. Who we are
Notifyed (“we”, “us”, “our”) provides a public safety alerting platform: a mobile app that delivers safety-related notifications (such as power outages, flooding, and severe weather) to members of the public, and a web portal that lets councils, utilities, emergency services, and other organisations (“Publishers”) create and manage those alerts.
This policy explains what personal data we collect, why, and what rights you have, whether you use the Notifyed mobile app as a member of the public (“Consumer user”) or hold a Publisher account on our web portal.
Notifyed is operated by Notifyed Limited, a company incorporated in England and Wales (company number 14310484), whose registered address is Union House, 111 New Union Street, Coventry, West Midlands, CV1 2NT, United Kingdom.
If you have any questions about this policy or how we handle your data, contact us at [email protected].
2. Scope
This policy covers two separate groups of users, because we collect different data from each:
- Consumer users of the Notifyed mobile app. By default, the app works anonymously: you do not need to create an account, give us your name, or give us your email address to receive alerts.
- Publisher users of the Notifyed web portal (app.notifyed.com), who hold an account on behalf of an organisation to publish or configure alerts.
3. What personal data we collect
3.1 Consumer users (mobile app)
We designed the mobile app to collect as little personal data as possible. We do not require you to register, and we do not ask for your name, email address, or phone number to use the core alerting service.
What we collect and store on our servers:
| Data | What it is | Why |
|---|---|---|
| Installation identifier | A random identifier generated by the app when you first install it. It does not contain or reveal your name or any other identifying detail. | Lets us send alerts to your device and manage your alert preferences without an account. |
| Push notification token | A token issued by your device’s push notification service (see section 8) that lets us deliver a notification to your specific device. | Required to deliver alerts to your device. |
| Approximate area | A coarse indicator of the general area you are in, derived on your device from your location. This is deliberately very imprecise: it identifies only that your device is somewhere within an area of approximately 36 square kilometres (roughly the size of a small town), not a street, building, or precise point. | Lets us match relevant local alerts (for example, a specific power cut or flood warning) to your general area. |
| Device manufacturer, model, and operating system version | Basic technical information about your device. | Used only for error and crash reporting, so we can diagnose and fix problems. This is not used to identify you and is not combined with your location or installation identifier for any other purpose. |
What we deliberately do not collect or transmit from the app:
- Your precise GPS location. Your device works out your precise location locally, on the device itself, purely to calculate the approximate area described above. The precise location reading never leaves your device and is never sent to our servers.
- Your location history. We store only your current approximate area, not where you have been. When your approximate area changes, the previous one is permanently deleted and replaced; we do not retain any record of past locations.
- Your name, email address, or phone number (unless you separately choose to link an account, which is optional and clearly signposted in the app where available).
- Your alert history or app usage in any way that identifies you personally.
Your approximate area is used solely to determine which alerts are relevant to you. It is never shared with Publishers (the organisations who create alerts), and Publishers cannot see who has received their alerts or where any individual user is located.
We do not include any advertising software, behavioural analytics, or third-party tracking code in the mobile app. We do not use advertising identifiers (such as Apple’s IDFA or Google’s Advertising ID), and the app does not report your activity to advertisers or data brokers. The only external services the app communicates with are our own servers and the push notification delivery service described in section 8.
3.2 Publisher users (web portal)
If you sign up for a Publisher account to create alerts on behalf of an organisation, we collect:
- Your name and email address.
- Your organisation’s name and details.
- Any API keys you generate to integrate with our service.
- Records of the alerts and content you or your organisation publish.
- IP address and browser/device information (user agent) recorded in audit logs when you take actions on the platform, for security and accountability purposes.
4. How we use your data and our lawful basis
UK GDPR requires us to have a lawful basis for each way we use personal data.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Delivering safety alerts to your approximate area | Installation identifier, push token, approximate area | Legitimate interests (public safety). Where an alert concerns an immediate risk to life, our processing may also be supported by the vital interests basis, but we rely primarily on legitimate interests as our normal basis. |
| Diagnosing app crashes and errors | Device manufacturer/model/OS version, technical error data | Legitimate interests (keeping the service reliable and secure) |
| Providing and administering Publisher accounts | Name, email, organisation details | Performance of a contract (our terms of service with the Publisher organisation) |
| Security, audit, and accountability | IP address, user agent, action logs | Legitimate interests (protecting the platform and our users from misuse, and meeting our own accountability obligations under UK GDPR Article 5(2)) |
We do not use your data for advertising, and we do not sell personal data to third parties. We will not repurpose data collected for alert delivery for any unrelated purpose, including profiling, contact tracing, behavioural analysis, or marketing. If we ever need to use your data for a materially different purpose, we will tell you first and, where required by law, seek your consent before doing so.
5. Legitimate interests balancing
Where we rely on legitimate interests, UK GDPR requires us to have carried out (and be able to show, if asked) a balancing exercise weighing our interest against your rights. In summary: alert delivery depends on knowing only a coarse area, not who you are or exactly where you are, so the impact on your privacy is deliberately kept low relative to the public safety purpose. A full legitimate interests assessment should be completed and held on file as part of our data protection documentation; it is referenced but not reproduced in full here.
6. How long we keep your data
We do not keep data for longer than we need it for the purposes described above.
- Your approximate area: we store only your current approximate area, not any history of past locations. When your approximate area changes, the previous one is permanently deleted and replaced. There is no retention period because no historical data is kept.
- Published alert records: alerts published by organisations through the platform are retained for a period that depends on the Publisher’s service plan (7 days for the free tier, 30 days for the professional tier, 365 days for the enterprise tier). After this period, the alert and its associated geographic coverage data are automatically deleted. These records describe the alert itself (its content and the area it covered), not individual users or their locations.
- Installation identifier and push token: if the push notification service reports that your token is no longer valid (for example, because the app has been uninstalled), we delete the associated record immediately. As a safety net, we also automatically delete any record where the device has not contacted us for 90 days.
- Publisher account and audit records: kept for the duration of the account, plus a further period afterwards where we are required to retain security and accountability records. Audit records are subject to a tiered retention schedule consistent with UK GDPR Article 5(1)(e) (data should not be kept for longer than necessary).
7. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate data.
- Erasure (“the right to be forgotten”) of your data, subject to any legal reason we may need to keep it.
- Restriction of how we use your data in certain circumstances.
- Object to processing based on legitimate interests.
- Data portability, where applicable.
- Lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk, or with the supervisory authority in your country of residence, if you believe we have not handled your data properly.
Because most consumer use of Notifyed is anonymous, we hold very little information that identifies you individually. If you have linked an account to your device, or you are a Publisher user, you can request access to, correction of, or deletion of your account data by contacting us at [email protected]. If you delete the app from your device, your installation identifier and push token become inactive and are removed automatically after the period described in section 6. No residual profile, location history, or usage record remains after this deletion. For most Consumer users, uninstalling the app is the simplest and most complete way to remove all data associated with your device.
We aim to respond to any request within one calendar month, as required by UK GDPR, and will let you know if a complex request needs longer (up to a further two months).
8. Who we share your data with
We only share personal data with third parties where necessary to run the service, and we choose providers who can meet UK GDPR standards.
- Push notification delivery. To deliver alerts to your device, we use Google’s push notification infrastructure (Firebase Cloud Messaging). This means your push token, and the fact that a notification should be sent to it, is processed by Google. Google is based in the United States; this transfer is protected by Standard Contractual Clauses, a mechanism recognised under UK GDPR for transfers outside the UK and EU.
- Error and crash monitoring. We use a specialist error-monitoring service to help us find and fix technical problems. This service is configured so that it does not receive your name, email address, IP address, or location; only technical error information (such as device model and operating system version) is sent, with personal details actively filtered out before anything is transmitted.
- Cloud infrastructure. Our core databases are hosted in regional data centres selected to meet the data residency requirements of the jurisdictions we serve. Data belonging to users in the United Kingdom and the European Economic Area is held in EU-jurisdiction data centres. Data belonging to users in the United States is held in FedRAMP-authorised infrastructure within the United States. Data belonging to users in other regions (such as Asia-Pacific and Oceania) is held in data centres appropriate to those regions. In each case, data residency is enforced at the infrastructure level, meaning your data cannot be moved outside its designated region. UK adequacy regulations treat the EU as providing an adequate level of data protection, so the arrangement for UK users is consistent with UK GDPR’s rules on international transfers.
We use push notification tokens solely to deliver alerts to your device, not for tracking, identifying your device, or building a profile of your app usage.
We do not sell your personal data, and we do not share it for third-party advertising or marketing purposes.
Law enforcement and official requests. We will only disclose personal data to law enforcement or government authorities if we are legally required to do so by a valid court order, warrant, or other binding legal process. We do not voluntarily share user data with any law enforcement or government body. If we receive a valid legal request, we will disclose only the minimum data necessary, and we will notify the affected user where we are legally permitted to do so. Because most Consumer users are anonymous, we hold very little data that would be meaningful in response to such a request.
9. International data transfers
Your core account and alert data is stored in a regional data centre appropriate to your location (see section 8), and we enforce data residency so it stays there. Where personal data is transferred outside the UK or the European Economic Area as part of delivering the service (for example, for push notification delivery as described in section 8), we rely on Standard Contractual Clauses or another lawful transfer mechanism recognised under UK GDPR, and we take steps to ensure an equivalent standard of protection is maintained.
10. Children
Notifyed is not directed at, and is not intended for use by, children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us so that we can take appropriate action.
11. Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse, including minimising the personal data we collect in the first place, restricting precise location to your device only, and filtering personal details out of our technical error reporting.
If a personal data breach poses a risk to your rights, we will notify the Information Commissioner’s Office within 72 hours as required by UK GDPR. If the breach is likely to result in a high risk to you, we will also inform you directly as soon as possible.
12. Cookies (web portal)
Our web portal (app.notifyed.com) uses a strictly necessary cookie to keep you signed in. This cookie is essential to the operation of the service and does not require your consent under the Privacy and Electronic Communications Regulations (PECR). We do not use advertising or tracking cookies on the web portal.
Our public marketing website uses a cookieless analytics service that does not set cookies and does not process personal data, so no cookie consent is required for it.
13. Changes to this policy
We may update this policy from time to time, for example if we introduce new features or change how we handle data. We will update the “last updated” date at the top of this page, and where a change is significant, we will take reasonable steps to notify you (such as an in-app notice).
14. Contact us
If you have any questions about this policy, or want to exercise any of the rights described in section 7, please contact us at [email protected].
If you are not satisfied with our response, you have the right to complain to the Information Commissioner’s Office: ico.org.uk, telephone 0303 123 1113.