Legal
Privacy notice
Written with UK GDPR in mind. It will be expanded with a full data processing agreement for subscribing organisations.
Who controls the data
For staff accounts and organisation settings, MonitorLog.uk is the controller. For monitoring records created inside an organisation — including descriptions of individuals, vehicle registrations and evidence — the subscribing security company is the controller and MonitorLog acts as processor on its instructions.
What we hold
Account details (name, email, telephone, job title, employee number), organisation and site records, monitoring sessions, log entries, actions taken, uploaded evidence, and technical records such as sign-in times and device information used for audit purposes.
Why we hold it
To provide the monitoring log service, to maintain the audit trail that makes security records credible, to support billing, and to keep the platform secure.
Tenant isolation
Organisation data is separated at database level. A user can only read records belonging to their own organisation. Platform administrators do not browse customer monitoring logs as a matter of course, and support access is logged.
Retention
Retention is configurable per organisation and bounded by the subscription plan. Log entries are never silently deleted — entries recorded in error are marked as such and the original record is preserved for audit.
Evidence files
Photos, video and documents are stored privately and served through short-lived signed links. They are never exposed on publicly guessable URLs and original files are not altered.
Your rights
Individuals may request access, correction, deletion or restriction of their personal data. Where the data sits inside a customer's monitoring log, requests are directed to that security company as controller.
Contact
Privacy questions can be sent to hello@monitorlog.uk and will be answered within one month.
