Touch4SafetyHome

Privacy, GDPR & cookies

Version 2.0, last updated 15 August 2026. This notice is written by the Touch4Safety team and explains how we handle personal data and storage in this app. It is information, not legal advice, and it does not claim any certification or third-party audit. It sits inside the legal & compliance pack together with the terms and the data processing addendum.

Important: Touch4Safety is extra help only

Touch4Safety is a supportive tool. It is not an emergency service, alarm centre, medical device or guarantee of rescue. It does not contact police, ambulance or fire services. In an emergency, always call your local emergency number (112 in the EU/EEA, 911 in the US). Touch4Safety accepts no responsibility or liability for any incident, injury, loss or damage of any kind. See the terms and disclaimer.

Who is responsible for your data

For consumers using Touch4Safety for themselves and their own family, Touch4Safety — operated by Strandadata, Norway (EU/EEA data protection regime) — is the data controller, reachable at lars@strandadata.no. Where an organisation, employer, school or care provider deploys Touch4Safety to protect other people, that organisation is the controller and we act as its processor under the data processing addendum.

Cookies and local storage

Under the EU/EEA ePrivacy rules and the GDPR — and comparable regimes such as the UK GDPR and PECR, Switzerland's nFADP, Norway's implementation of the GDPR, Canada's PIPEDA and Quebec Law 25, Brazil's LGPD and the California CCPA/CPRA — non-essential storage requires your consent, and refusing must be as easy as accepting. Nothing optional is written before you choose, and you can change your mind at any time.

  • Strictly necessary — keeping you signed in (session token in your browser's local storage), your language choice, offline safety data queued while you have no coverage, and your consent record. Always active; no consent needed.
  • Functional — comfort settings and map tiles cached on your device so maps keep working offline. Optional.
  • Anonymous statistics — aggregated usage and presence counts that help us find problems. Optional, and never used for advertising or profiling.
  • No advertising or tracking cookies — we do not sell or share personal data for advertising or cross-site profiling, and there are no third-party ad or social pixels in this app.

If your browser sends a Global Privacy Control or Do Not Track signal, we treat it as an opt-out from everything optional automatically, without showing you the banner. Your choice is stored with a version number and timestamp; if this notice changes materially we ask again.

What we process, and why

  • Account data (name, email, language, time zone) — to give you an account.
  • Safety People you add (name, phone, email) — so we can alert them on your behalf, on your instruction.
  • Location — only when you start a session that shares it, and only for the duration and recipients you choose.
  • Emergency information you enter — shown to your Safety People only during an SOS or escalation, and only if you keep sharing switched on.
  • Safety sessions, notification records and audit logs — to run escalations and show your own history.
  • Subscription and payment status — to operate the Family plan.

Legal bases (GDPR Art. 6): performance of the contract for running the service, your consent for location sharing and optional storage, and our legitimate interest in security and abuse prevention. Health-related notes you choose to add are special category data (Art. 9) and are processed only on your explicit consent — you can delete them at any time.

Your rights

You can request access, correction, deletion, restriction, objection, portability, and withdrawal of consent at any time. The app includes export and delete-my-account tools, and administrators only ever see aggregated numbers — never your location, messages or emergency information. You also have the right to complain to your national data protection authority (in Norway, Datatilsynet).

Where your data is stored (data residency)

Touch4Safety is operated for users worldwide, and personal data is stored on managed infrastructure hosted in the European Union (EU/EEA). Static app files are delivered through a global content network so the app loads quickly wherever you are; those edge nodes serve code and images only — not your account data.

When a processor we rely on (for example email, SMS or voice delivery, or payments) processes data outside the EU/EEA, that transfer is covered by the European Commission's Standard Contractual Clauses together with additional technical safeguards such as encryption in transit and at rest. Map tiles and address lookups are requested without account identifiers, and cached on your own device so the map keeps working offline.

If your organisation requires a specific storage region, contact us before signing up and we will confirm what we can support.

Sharing and retention

We share data only with the processors needed to run the service (hosting and database, email/SMS/voice delivery, web push, payment processing, the AI assistant you choose to use, and map tiles) and with the Safety People you have chosen. The full list, with purpose and processing region, is in the data processing addendum. Data is kept while your account is active and deleted when you delete your account, apart from minimal records we must keep for accounting or security. Backups roll off within 30 days. Precise location trails from a session are only visible to the recipients of that session, and anonymous visitor locations are coarsened to roughly 11 km.

Children and vulnerable users

You must be 16 or older to hold your own account. Younger family members are added by a responsible adult who is accountable for their consent, and their location is only shared within their own family. We do not knowingly collect data from children outside that structure, and we do not profile children or use their data for any purpose other than keeping them safe. Under the US COPPA and the UK Age Appropriate Design Code we apply the most protective default settings: sharing off, precise location off, no optional storage.

Automated decisions and AI

The escalation engine follows the exact plan you configured — fixed steps and wait times — so it is deterministic, not profiling, and it never decides anything about you beyond sending the alerts you asked for. Touch AI answers only when you write to it; your messages are not used to train models and are not used for advertising. There is no automated decision-making with legal or similarly significant effects (GDPR Art. 22).

Security and breach notification

Personal data is encrypted in transit and at rest, every table is protected by row-level security, safe words and cancel PINs are isolated and hashed, invitation and alert links are single-use, expiring and rate-limited, and administrators see aggregated numbers only. Automated security regression checks and dependency vulnerability scans run on every change. If a breach affecting your personal data occurs, we notify the competent supervisory authority within 72 hours (GDPR Art. 33) and tell affected users where the risk to them is high.

Regional annexes — your rights where you live

The protections above apply to everyone. These annexes add the wording and rights specific to each region.

  • EU/EEA and Norway (GDPR) — access, rectification, erasure, restriction, objection, portability and withdrawal of consent; complaints to your national authority, in Norway Datatilsynet. Legal bases are stated above. Our supervisory authority is Datatilsynet.
  • United Kingdom (UK GDPR, PECR) — the same rights, with complaints to the Information Commissioner's Office. UK transfers use the International Data Transfer Addendum.
  • Switzerland (nFADP) — access and deletion rights, with complaints to the FDPIC; transfers use the Swiss-recognised SCC addendum.
  • United States (CA CPRA, CO, CT, VA, TX, OR, MT and similar) — you may know, access, correct, delete and obtain a portable copy of your personal information, and limit the use of sensitive personal information (precise geolocation and health notes, which we use only to deliver the safety features you switch on). We do not sell personal information and do not share it for cross-context behavioural advertising, so no “Do Not Sell or Share My Personal Information” sale exists to opt out of; we still honour Global Privacy Control automatically. We do not discriminate against anyone who exercises a right, and we answer within 45 days. Authorised agents may act for you with written proof.
  • Canada (PIPEDA, Quebec Law 25) — meaningful consent before optional processing, access and correction rights, a named privacy contact, and notification of confidentiality incidents to the OPC or CAI.
  • Brazil (LGPD) — confirmation of processing, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent; complaints to the ANPD.
  • Australia (Privacy Act, APPs) — access and correction rights and notification under the Notifiable Data Breaches scheme; complaints to the OAIC.
  • Japan (APPI) — disclosure, correction and cessation-of-use rights, with cross-border transfers disclosed above.
  • South Africa (POPIA) — access, correction and objection rights; complaints to the Information Regulator.
  • India (DPDP Act) — access, correction, erasure and grievance redressal; write to the contact below as our grievance channel.
  • Everywhere else — we apply the GDPR standard as our global baseline.

Changes to this notice

When we change this notice materially we update the version and date at the top, show the change in the app, and ask for your cookie choice again where consent is affected. Earlier versions are available on request.

Contact

Questions about privacy, a data request, a DPA or a grievance: contact the account owner at lars@strandadata.no. We answer within one month (GDPR Art. 12), or 45 days for US state requests.

Please tell us if any organisation-specific detail here needs correcting, and we will update it.