Application/service: TouchGuard — Android application (package cz.ttc.tg), available on Google Play, and the TouchGuard web application (customer account and administration interface)
Developer / Provider: TTC Apki, s.r.o., Třebohostická 987/5, 100 00 Praha 10 – Strašnice, Czech Republic
Effective date: July 8, 2026
1. Introduction
TouchGuard is a workforce management application for security guards, patrol officers and lone workers. It is used by employees and contractors of organizations (typically security companies) that operate a TouchGuard account and provision mobile devices and/or web access for their staff. This policy covers both the Android application and the web application used to administer TouchGuard.
The application is not intended for general consumers.
This policy describes what data is collected, why, where it is sent and how you can exercise your rights.
Roles under GDPR. The organization that provides you with the application (your employer or client, "the Organization") acts as the data controller of the operational data described below (location, patrol/checkpoint events, attachments, forms, alarms, device status). That data is transmitted to and stored on the TouchGuard server used by that Organization. TTC Apki acts as a processor of this operational data on the Organization's instructions.
Separately, TTC Apki also acts as an independent data controller for certain data it processes in its own right — in particular customer account registration and administration, invoicing and accounting, security and fraud-prevention logging of the platform itself, handling of support requests, and (where applicable) marketing communications and newsletters. That processing is described in full in TTC Apki's general Personal Data Processing Policy ("Zásady zpracování osobních údajů"), available on our website.
If you have questions about how your Organization uses your operational data, contact your Organization first. For questions about TTC Apki's own processing as a controller, use the data-protection contact in section 10.
2. Data the application collects
2.1 Data you or your Organization provide
- User identity. Your name and a personal identification number (PIN) assigned by your Organization, used to distinguish which worker is logged in on a shared device.
- Attachments you create. Photos, video recordings, audio recordings, scanned barcodes or QR codes, recognized text and handwritten signatures that you attach to patrol reports, forms, tasks or incident records. These are created only when you actively use the corresponding function and are uploaded to your Organization's TouchGuard server.
- Form and report content. Answers you fill into checklists, forms, task records and incident reports.
- Visitor data (if the visitor-management module is enabled by your Organization). Visitor name, visitor phone number, vehicle registration plate, and the name of the visiting company.
- Scanned identity document data (if document scanning is enabled together with the visitor-management module). Document type, issuing country, document number, nationality, date of birth and document validity date. This data is only collected when your Organization has specifically activated this optional functionality.
2.2 Data collected automatically
- Location data (precise, including background). The application collects GPS position during active work shifts, patrols and while lone worker protection is enabled, so that the Organization can verify patrol routes, dispatch help in an emergency and locate a worker who raised an alarm or stopped responding. Location may be collected in the background while the protection service is running. Location data is sent to your Organization's TouchGuard server.
- Device and status information. Device manufacturer and model, Android version, application version, battery level and charging state, mobile signal strength, network connectivity state and synchronization timestamps. Where available, the device IMEI or a device identifier entered during device registration is used so the Organization can pair the physical device with its records.
- Safety events. Alarm activations (panic button, man-down detection, missed check-in), checkpoint scans (NFC tags, Bluetooth beacons, QR codes) with timestamps.
- Push notification token. A Firebase Cloud Messaging registration token used to deliver instructions and alerts from the server to the device.
- Crash and diagnostics data. Crash reports and non-fatal error reports are collected through Google Firebase Crashlytics (device model, OS version, application version, stack traces).
- Usage analytics. Basic usage events (for example which screens are visited) are collected through Google Firebase Analytics to help improve the application. Firebase may use device identifiers, including the advertising ID, for this purpose. The application does not display advertising and does not use this data for advertising purposes.
- Wearable data (only if your Organization licenses TouchGuard WATCH). If you are issued a TouchGuard WATCH device, the application processes a status/alert indicator derived from heart-rate monitoring and active-eSIM connectivity status. The underlying precise heart-rate value is not transmitted to the server — only the result of the on-device evaluation (e.g., an alert flag) is sent.
2.3 Data collected through the web application (customer account)
- Account and administration data. When an Organization administrator ("Responsible Person") manages the account via the web application, it processes the identification, contact and role data needed to administer the account and its users, as described in section 2.1 above and in TTC Apki's general Personal Data Processing Policy.
- Cookies and similar technologies. The web application uses cookies that are strictly necessary for login, session management and security. If analytics or preference cookies are used, this is disclosed in a separate cookie banner or notice, together with the option to accept or decline non-essential cookies.
2.4 Data the application does NOT collect
- No contacts, call logs, e-mails, browsing history or files unrelated to the application.
- No data is sold to third parties.
- No advertising or marketing profiling is performed.
3. Permissions and how they are used
The following applies to the Android application. The web application does not request device-level permissions; see section 2.3 for cookies used by the web application instead.
The application requests the following sensitive permissions. Each permission is used only for the purpose described and only when the corresponding function is enabled by your Organization:
- Location (fine, coarse, background) — patrol route tracking, alarm localization and lone worker protection during work shifts.
- Camera — taking photo and video attachments, scanning barcodes and QR codes at checkpoints, on-device text recognition, and (where the visitor-management module with document scanning is enabled) scanning identity documents. Images used for barcode, text and document recognition are processed on the device.
- Microphone — recording audio attachments to reports and, where configured, acoustic check-in detection.
- Phone (read phone state, make calls) — reading mobile signal strength and call status for safety monitoring, and placing calls to predefined numbers (for example a dispatch center) directly from an alarm screen.
- SMS (send) — sending alarm and status text messages to predefined numbers when configured by the Organization, for example as a fallback when there is no data connectivity.
- Bluetooth — detecting Bluetooth beacons that mark checkpoints, and pairing with TouchGuard WATCH devices where licensed.
- NFC — reading NFC checkpoint tags.
- Notifications, foreground service, boot, exact alarms — keeping the protection and synchronization service running reliably and alerting you to assigned tasks and alarms.
- Storage (older Android versions) — saving attachments and downloaded files.
- Display over other apps, modify system settings — showing alarm and status overlays and adjusting volume or screen state during an alarm, on devices where the Organization enables kiosk-style operation.
Runtime permissions are requested in the application, and you can deny or revoke them in the system settings. Denying a permission disables the corresponding function; depending on your Organization's configuration, some functions may be required for your work duties.
4. Where the data goes
- Your Organization's TouchGuard server. All operational data (location, patrol events, alarms, attachments, forms, device status, visitor and document-scan data where applicable) is transmitted over an encrypted HTTPS connection to the server used by your Organization. Depending on the deployment model your Organization has chosen, this server is either (a) operated on infrastructure provided by TTC Apki's hosting sub-processor, currently SH.cz s.r.o. (Czech Republic), or (b) operated on-premise, directly on infrastructure owned and controlled by your Organization. The retention of this data is governed by your Organization's policies, subject to the platform defaults described in section 6.
- Google LLC (Firebase). Crash reports, analytics events and push notification routing are processed by Google Firebase services (Crashlytics, Analytics, Cloud Messaging) as our service providers. Where this involves processing outside the European Economic Area, such transfers are safeguarded by Standard Contractual Clauses and, where applicable, other legally recognized transfer mechanisms, consistent with Google's published data processing terms. See Google's privacy policy at policies.google.com/privacy and Firebase privacy information at firebase.google.com/support/privacy.
No other third parties receive your data. Data is not sold and is not used for advertising.
5. Data storage and security
Data waiting for synchronization is stored in the application's private storage on the device. Transfers to the server use encrypted HTTPS connections. Access to the data on the server is managed by your Organization.
As an optional configuration, TouchGuard offers a "Deleted user anonymization" feature that your Organization can enable. Once active, removing a user from the system immediately replaces that user's name with a generic system value, so that deleted user records can no longer be linked back to other personal data or records they created.
6. Data retention
- Data stored locally on the device is kept only until it is synchronized to the server or until the application is unregistered or uninstalled.
- The standard retention period for reports, logs and records generated through use of the system is 12 months; data older than 12 months is automatically deleted. Your Organization's administrator can shorten this period (in increments of one calendar month) in the system settings.
- After your Organization's contract with TTC Apki ends (or its last active licence expires), personal data and user data are, as a rule, deleted or anonymized within 10 business days, except where TTC Apki is required by law to retain certain data for longer, where a limited data set must be kept to settle outstanding obligations, or where data is temporarily retained in routine backup copies as part of the standard backup cycle — in which case it is kept only to the extent and for as long as strictly necessary.
- Crash and analytics data is retained by Google Firebase according to its standard retention periods.
7. Your rights
Depending on your jurisdiction (for example under the EU GDPR), you may have the right to access, rectify, delete or restrict the processing of your personal data, and the right to data portability and to object to processing.
Because your Organization is the controller of the operational data described in this policy, please direct requests about that data to your Organization first. For questions about TTC Apki's own processing as a controller (see section 1), or if you need help identifying the right contact, write to the data-protection e-mail in section 10; for general app support, use the support e-mail. We will assist or forward your request where we can.
8. Children
The application is a professional tool intended for adult workers. It is not directed at children under 16, and we do not knowingly collect data from children.
9. Changes to this policy
We may update this policy from time to time. The current version is always available at this page. Material changes will be announced in the application or through your Organization.
10. Contact
TTC Apki, s.r.o.
Třebohostická 987/5, 100 00 Praha 10 – Strašnice, Czech Republic
E-mail (app / support): podpora@apki.cz
E-mail (data protection): gdpr@ttc.cz