Application/service: TouchGuard — Android app (package cz.ttc.tg), available on Google Play, and the TouchGuard web application (customer account and administration interface)
Developer / Provider: TTC Apki, s.r.o., Třebohostická 987/5, 100 00 Prague 10 – Strašnice, Czech Republic
Effective Date: July 8, 2026
1. Introduction
TouchGuard is a workforce management application for security guards, patrol officers, and lone workers. It is used by employees and contractors of organizations (typically security companies) that operate a TouchGuard account and provide mobile devices and/or web access to their staff. This policy covers both the Android application and the web application used to administer TouchGuard.
The application is not intended for general consumers.
This policy describes what data is collected, why, where it is sent, and how you can exercise your rights.
Roles under the GDPR. The organization that provides you with the application (your employer or client, “the Organization”) acts as the data controller for the operational data described below (location, patrol/checkpoint events, attachments, forms, alarms, device status). That data is transmitted to and stored on the TouchGuard server used by the Organization. TTC Apki acts as a processor of this operational data on the Organization’s instructions.
Separately, TTC Apki also acts as an independent data controller for certain data it processes on its own behalf—specifically, customer account registration and administration, invoicing and accounting, security and fraud-prevention logging for the platform itself, handling of support requests, and (where applicable) marketing communications and newsletters. That processing is described in full in TTC Apki’s general Personal Data Processing Policy (“Zásady zpracování osobních údajů”), available on our website.
If you have questions about how your organization uses your operational data, contact your organization first. For questions about TTC Apki's own processing as a controller, contact the data protection officer listed in Section 10.
2. Data Collected by the Application
2.1 Data Provided by You or Your Organization
- User identity. Your name and a personal identification number (PIN) assigned by your organization, used to identify which employee is logged in on a shared device.
- Attachments you create. Photos, video recordings, audio recordings, scanned barcodes or QR codes, recognized text, and handwritten signatures that you attach to patrol reports, forms, tasks, or incident records. These are created only when you actively use the corresponding feature and are uploaded to your organization's TouchGuard server.
- Form and report content. Answers you enter into checklists, forms, task logs, and incident reports.
- Visitor data (if the visitor management module is enabled by your organization). Visitor's name, visitor's phone number, vehicle license plate number, and the name of the visiting company.
- Scanned identity document data (if document scanning is enabled in conjunction with the visitor management module). Document type, issuing country, document number, nationality, date of birth, and document expiration date. This data is collected only if your organization has specifically enabled this optional feature.
2.2 Data Collected Automatically
- Location data (precise, including background). The application collects GPS location data during active work shifts, patrols, and while lone worker protection is enabled, so that the organization can verify patrol routes, dispatch help in an emergency, and locate a worker who has triggered an alarm or stopped responding. Location data may be collected in the background while the protection service is running. Location data is sent to your organization's TouchGuard server.
- Device and status information. Device manufacturer and model, Android version, application version, battery level and charging status, mobile signal strength, network connectivity status, and synchronization timestamps. Where available, the device’s IMEI or a device identifier entered during device registration is used so that the Organization can link the physical device to its records.
- Safety incidents. Alarm activations (panic button, man-down detection, missed check-in), checkpoint scans (NFC tags, Bluetooth beacons, QR codes) with timestamps.
- Push notification token. A Firebase Cloud Messaging registration token used to deliver instructions and alerts from the server to the device.
- Crash and diagnostic data. Crash reports and non-fatal error reports are collected through Google Firebase Crashlytics (device model, OS version, application version, stack traces).
- Usage analytics. Basic usage events (such as which screens are visited) are collected through Google Firebase Analytics to help improve the application. Firebase may use device identifiers, including the advertising ID, for this purpose. The application does not display advertisements and does not use this data for advertising purposes.
- Wearable data (only if your organization has a license for TouchGuard WATCH). If you are issued a TouchGuard WATCH device, the application processes a status/alert indicator based on heart rate monitoring and active eSIM connectivity status. The underlying precise heart rate value is not transmitted to the server—only the result of the on-device evaluation (e.g., an alert flag) is sent.
2.3 Data collected through the web application (customer account)
- Account and administrative data. When an organization administrator ("Responsible Person") manages the account via the web application, it processes the identification, contact, and role data needed to administer the account and its users, as described in section 2.1 above and in TTC Apki's general Personal Data Processing Policy.
- Cookies and similar technologies. The web application uses cookies that are strictly necessary for login, session management, and security. If analytics or preference cookies are used, this is disclosed in a separate cookie banner or notice, along with the option to accept or decline non-essential cookies.
2.4 Data That the Application Does NOT Collect
- No contacts, call logs, emails, browsing history, or files unrelated to the app.
- No data is sold to third parties.
- No advertising or marketing profiling is conducted.
3. Permissions and How They Are Used
The following applies to the Android app. The web app does not request device-level permissions; see section 2.3 for information on the cookies used by the web app instead.
The application requests the following sensitive permissions. Each permission is used only for the purpose described and only when the corresponding feature is enabled by your organization:
- Location (fine, coarse, background) — patrol route tracking, alarm localization, and lone worker protection during work shifts.
- Camera — taking photos and videos, scanning barcodes and QR codes at checkpoints, on-device text recognition, and (when the visitor management module with document scanning is enabled) scanning identity documents. Images used for barcode, text, and document recognition are processed on the device.
- Microphone — recording audio attachments to reports and, where configured, acoustic check-in detection.
- Phone (read phone status, make calls) — reading mobile signal strength and call status for safety monitoring, and placing calls to predefined numbers (such as a dispatch center) directly from an alarm screen.
- SMS (send) — sending alarm and status text messages to predefined numbers when configured by the organization, for example, as a fallback when there is no data connectivity.
- Bluetooth — detecting Bluetooth beacons that mark checkpoints, and pairing with TouchGuard WATCH devices where licensed.
- NFC — reading NFC checkpoint tags.
- Notifications, foreground service, boot, exact alarms — ensuring that the protection and synchronization service runs reliably and alerts you to assigned tasks and alarms.
- Storage (older Android versions) — saving attachments and downloaded files.
- Display over other apps, modify system settings — such as showing alarm and status overlays and adjusting the volume or screen state during an alarm — on devices where the organization enables kiosk-style operation.
The app requests runtime permissions, and you can deny or revoke them in the system settings. Denying a permission disables the corresponding feature; depending on your organization's configuration, some features may be required for your job duties.
4. Where the data goes
- Your organization's TouchGuard server. All operational data (location, patrol events, alarms, attachments, forms, device status, visitor and document-scan data, where applicable) is transmitted over an encrypted HTTPS connection to the server used by your Organization. Depending on the deployment model your Organization has chosen, this server is either (a) operated on infrastructure provided by TTC Apki’s hosting sub-processor, currently SH.cz s.r.o. (Czech Republic), or (b) operated on-premises, directly on infrastructure owned and controlled by your Organization. The retention of this data is governed by your Organization’s policies, subject to the platform defaults described in section 6.
- Google LLC (Firebase). Crash reports, analytics events, and push notification routing are processed by Google Firebase services (Crashlytics, Analytics, Cloud Messaging) as our service providers. Where this involves processing outside the European Economic Area, such transfers are safeguarded by Standard Contractual Clauses and, where applicable, other legally recognized transfer mechanisms, consistent with Google’s published data processing terms. See Google’s privacy policy at policies.google.com/privacy and Firebase privacy information at firebase.google.com/support/privacy.
No other third parties receive your data. Data is not sold and is not used for advertising.
5. Data Storage and Security
Data awaiting synchronization is stored in the application's private storage on the device. Transfers to the server use encrypted HTTPS connections. Access to the data on the server is managed by your organization.
As an optional configuration, TouchGuard offers a "Deleted user anonymization" feature that your organization can enable. Once enabled, removing a user from the system immediately replaces that user's name with a generic system value, so that deleted user records can no longer be linked back to other personal data or records they created.
6. Data Retention
- Data stored locally on the device is retained only until it is synchronized with the server or until the application is unregistered or uninstalled.
- The standard retention period for reports, logs, and records generated through use of the system is 12 months; data older than 12 months is automatically deleted. Your organization's administrator can shorten this period (in increments of one calendar month) in the system settings.
- After your organization’s contract with TTC Apki ends (or its last active license expires), personal data and user data are, as a rule, deleted or anonymized within 10 business days, except where TTC Apki is required by law to retain certain data for a longer period, where a limited set of data must be retained to settle outstanding obligations, or where data is temporarily retained in routine backup copies as part of the standard backup cycle—in which case it is retained only to the extent and for as long as strictly necessary.
- Crash and analytics data is retained by Google Firebase in accordance with its standard retention periods.
7. Your Rights
Depending on your jurisdiction (for example, under the EU GDPR), you may have the right to access, correct, delete, or restrict the processing of your personal data, as well as the right to data portability and the right to object to processing.
Because your Organization is the controller of the operational data described in this policy, please direct requests regarding that data to your Organization first. For questions about TTC Apki’s own processing as a controller (see section 1), or if you need help identifying the correct contact, please write to the data protection email address listed in section 10; for general app support, please use the support email address. We will assist you or forward your request as appropriate.
8. Children
The application is a professional tool intended for adult workers. It is not intended for children under 16, and we do not knowingly collect data from children.
9. Changes to this policy
We may update this policy from time to time. The current version is always available on this page. Significant changes will be announced in the app or through your organization.
10. Contact
TTC Apki, s.r.o.
Třebohostická 987/5, 100 00 Prague 10 – Strašnice, Czech Republic
Email (app / support): podpora@apki.cz
Email (data protection): gdpr@ttc.cz