1. Who we are
PassiveAlert is a trading name of Xpressms Ltd, company number 07202089. Xpressms Ltd is the controller of personal information described in this policy unless we agree otherwise in writing with a business or care organisation. References to “we”, “us” and “our” mean Xpressms Ltd trading as PassiveAlert. Our contact email is hello@passivealert.co.uk.
2. Whose information we handle
We may handle information about the customer who buys the service, authorised portal users and alert recipients, people who contact us, and the person whose home activity is monitored (the “monitored person”). The customer must explain the service to the monitored person and respect their wishes. PassiveAlert must not be installed or used to monitor someone secretly or against their wishes.
3. Information we collect
- Account and contact details: names, email addresses, telephone numbers, postal or installation addresses, login and account records.
- Order and payment records: products, subscription, invoices and payment status. Payment-card details should be handled by our payment provider rather than stored by us.
- Sensor and service data: sensor identifiers, placement or room labels, motion or state-change events, device status, battery and connectivity information, derived routine summaries and configured alerts.
- Communications: enquiries, support messages, installation notes, complaint records and alert-delivery details.
- Technical and security data: IP address, browser or device information, access logs, timestamps and security events.
PassiveAlert does not use cameras or microphones and is not intended to collect recordings. Please do not enter medical details or other unnecessary sensitive information into free-text fields.
4. Why we use information
If information reveals or allows inferences about health, we will only process it where an additional condition under data-protection law applies. Routine sensor events are not used to diagnose a health condition.
5. Monitoring, consent and authorised access
The customer is responsible for making sure the monitored person understands what sensors are used, what information they produce, who can view it and who receives alerts. If the monitored person objects or withdraws permission, the customer must stop monitoring and tell us promptly. We may suspend the service where we reasonably believe monitoring is unlawful, covert or contrary to the monitored person’s wishes.
Customers must invite only appropriate people to the portal, keep recipient details current and remove access when it is no longer needed.
6. Who receives information
We share information only where needed with service providers that help us host and secure the portal, deliver email and SMS messages, process payments, supply or install equipment, provide customer support, and obtain professional advice. We may also disclose information where required by law, to protect rights or safety, or as part of a sale or reorganisation of the business.
Our current technology may include email delivery through Brevo and SMS delivery through ClickSend.
7. International transfers
Some suppliers may process information outside the United Kingdom. Where they do, we use an approved safeguard, such as UK adequacy regulations or the UK International Data Transfer Agreement/addendum, and assess the protection available.
8. How long we keep information
We keep information only for as long as it is needed for the purposes above, including providing the service, resolving disputes and meeting tax, accounting and legal obligations. Account and service information is deleted or anonymised after the account closes in accordance with our retention schedule; financial records may need to be kept for longer. Backup copies expire through their normal cycle.
9. Security
We use proportionate technical and organisational measures designed to protect information, including access controls, password protection, secure transmission, monitoring and restricted administrative access. No internet service can guarantee absolute security. Portal users must use a strong, unique password and tell us promptly about suspected unauthorised access.
10. Your rights
Depending on the circumstances, you may ask us for access to your information, correction, deletion, restriction, portability, or to object to processing. Where processing relies on consent, you may withdraw it at any time. These rights can be subject to legal limits.
Email hello@passivealert.co.uk to exercise a right. We may need to verify your identity. You may also complain to the UK Information Commissioner’s Office at ico.org.uk, although we would appreciate the chance to address your concern first.
11. Cookies and website data
We use cookies or similar storage where necessary to operate secure sessions and remember essential choices. If we introduce non-essential analytics or advertising cookies, we will provide clear information and request consent where required.
12. Children
PassiveAlert is not directed to children, and customer accounts must be created by adults. If the monitored home includes children, the customer is responsible for considering their privacy and complying with applicable law.
13. Changes to this policy
We may update this policy when our service, suppliers or legal obligations change. We will publish the revised version here and, where a change materially affects customers, provide an appropriate notice.