Effective: July 23, 2026
This Privacy Notice explains how BYDUTY LLC (“ByDuty,” “we,” “us,” or “our”) handles personal data when you use the ByDuty websites, mobile applications, hosted platform, and related support services (collectively, the “Services”).
1. Our role and your organization’s role
ByDuty is a business-to-business workforce operations service. When an employer, security company, client, or other organization gives you access to ByDuty, that organization generally decides why and how workforce and operational data is used. In that setting, the organization is usually the data controller and BYDUTY LLC acts as its processor or service provider under the applicable customer agreement.
BYDUTY LLC acts as a controller for data used to manage our direct business relationship, operate and secure the Services, administer accounts and billing, communicate with customers, and provide support. These roles can vary based on the relationship and applicable law. If your account is managed by an organization, contact that organization first about its workplace monitoring practices or a request concerning data it controls.
2. Personal data we handle
The data handled depends on your role, the modules your organization enables, and how you use the Services.
Information provided by you or your organization
- Identity, contact, and account data: name, email address, phone number, username, user or employee identifiers, organization, role, profile details, authentication and session data, and account preferences.
- Employment and compliance data: job and assignment information, licenses, permits, certifications, training records, availability, qualifications, background-check status, policy acknowledgments, waivers, and consent records.
- Biometric data where enabled: biometric identifiers used for an organization’s configured shift-verification workflow and the related consent records. Face ID, Touch ID, or similar device-unlock templates used only for local device authentication are handled by the device operating system and are not provided to ByDuty.
- Work, scheduling, and financial records: shifts, sites, patrol and checkpoint activity, clock-in and clock-out events, breaks, timesheets, pay rates, payroll and deduction metadata, expenses, invoices, and payment-transaction metadata.
- Safety, incident, and media data: incident and daily activity reports, dispatch tasks, welfare checks, SOS or duress events, notes, witness or visitor details, and information about injuries or health when included in a report. Reports and enabled workflows, including body-camera workflows, may include photos, video, audio, recordings, transcriptions, signatures, or other uploaded files.
- Communications and submitted content: in-app messages, comments, email or SMS content processed through enabled modules, support requests, feedback, survey responses, and content submitted to AI-assisted reporting, search, transcription, or other enabled AI features, together with the resulting output.
Information collected from devices and use of the Services
- Location and field activity: precise or approximate location, location timestamps, movement and geofence events, route or patrol activity, and the location associated with timekeeping, checkpoint, dispatch, welfare, SOS, or duress events.
- Device and push data: device and app identifiers, operating system, app version, language, push-notification token, notification preferences, and network information.
- Usage, security, and diagnostics: feature activity, access and audit logs, IP address, timestamps, synchronization status, notification delivery and engagement, crash reports, performance data, and error or security-event details.
Information from other sources
We may receive data from your organization, its authorized users and clients, customer-selected identity or business integrations, communications providers, payment processors, and other services that your organization connects to ByDuty.
3. Location and background access
Depending on organization settings, your role, an active workflow, and device permissions, the mobile app may collect precise location while it is in the foreground or background. Background access can continue while the screen is locked for enabled workflows such as shifts, timekeeping, patrol verification, dispatch, geofences, welfare checks, or emergency response.
The app presents the device permission request, but your organization determines its workplace monitoring policy and when a configured workflow should operate. You can review device permissions and available in-app consent controls. Limiting a permission may prevent a location-dependent feature from working. Contact your organization for details about its collection practices and lawful basis.
4. How we use personal data
- Provide, maintain, synchronize, and support the Services, including offline field workflows.
- Authenticate users, apply role-based permissions, and manage organizations and accounts.
- Run scheduling, dispatch, attendance, patrol, reporting, safety, compliance, payroll, invoicing, and client-facing workflows selected by a customer.
- Send operational, safety, account, support, email, SMS, and push communications.
- Process content through an AI or transcription feature when a user or organization requests that feature.
- Monitor reliability, diagnose errors, prevent misuse, protect the Services, investigate incidents, and maintain audit records.
- Administer subscriptions, payments, customer relationships, and support requests.
- Comply with law, enforce agreements, and establish, exercise, or defend legal claims.
5. How personal data is disclosed
We disclose personal data only as reasonably needed for the purposes described above, including to:
- Your organization and its authorized users: administrators, supervisors, dispatchers, assigned coworkers, and authorized clients, based on role, assignment, organization settings, and the workflow involved.
- Service providers: vendors that support hosting, data storage, backups, authentication, communications, payment processing, security, support, diagnostics, AI, or transcription. Depending on enabled features, these may include Expo and OneSignal for push notifications, Sentry for diagnostics, Resend for email, Twilio or Telnyx for SMS, and Stripe for payment processing.
- Customer-selected integrations and recipients: services or people that an authorized customer user directs ByDuty to connect with or notify.
- Legal, safety, and corporate recipients: authorities or other parties when reasonably necessary to comply with law, protect rights or safety, investigate abuse, respond to an emergency, or support a merger, financing, acquisition, reorganization, or sale of all or part of the business.
We do not sell or rent personal data. We do not share personal data for cross-context behavioral advertising, and the ByDuty mobile app does not serve third-party ads or track users across other companies’ apps or websites for advertising.
6. Retention
We retain personal data for as long as reasonably needed to provide the Services, follow customer instructions and configured retention settings, maintain security and audit records, meet legal, accounting, safety, or contractual requirements, resolve disputes, and enforce agreements. The period therefore varies by data type, customer relationship, and applicable law.
When data is no longer needed, we delete, de-identify, or pseudonymize it as appropriate. Deleted data may remain in protected backups until those backups are replaced through normal cycles. We may retain limited information where required for legal, fraud-prevention, security, or recordkeeping purposes.
7. Security
We use administrative, technical, and organizational measures designed to protect personal data. These include encrypted network transport, authentication and role-based access controls, organization-level data separation, audit logging, and safeguards for stored data and backups. No system or transmission method is completely secure, so we cannot guarantee absolute security.
8. Your choices and privacy rights
Depending on your location and relationship with ByDuty, you may have rights to access or receive a copy of personal data, correct it, request deletion, restrict or object to processing, request portability, or withdraw consent. You may also be able to manage location, camera, microphone, biometric authentication, and notification permissions through the app or device settings.
If your organization manages your account, submit the request to its administrator or privacy contact because it controls most workforce data. You may use an available in-app account-deletion control or contact us for help. We may need to verify your identity and refer a request to the responsible customer. Rights can be limited by applicable law, customer instructions, and permitted legal, security, or recordkeeping needs.
9. International processing
ByDuty, its customers, and service providers may process personal data in countries other than the country where you live. Where required, the responsible party uses appropriate safeguards for international transfers under applicable law.
10. Changes to this notice
We may update this Privacy Notice as the Services or legal requirements change. We will post the revised notice here with a new effective date and provide additional notice when required.
11. Contact us
Questions or requests concerning BYDUTY LLC’s handling of personal data can be sent to [email protected]. If your organization controls the data, we may direct your request to that organization.