E-Dob Log in →

Trust Centre

E-Dob is committed to transparency around how we handle data and security. Below you'll find our current policies and practices.

Privacy Policy

Effective date: 15 June 2026 Last updated: 15 June 2026

This Privacy Policy explains how Ffon Solutions Limited, trading as GuardDog Digital ("we", "us", "our"), processes personal data in connection with E-Dob, our SaaS incident reporting and management platform for organisations, available at eu.e-dob.uk.

E-Dob is provided as a database and workflow platform for the recording, management, and processing of an organisation's incident log and daily occurrence records. The customer organisation determines what data is entered into the platform, who may access it, how it is used, and how long it is retained.

We act as a data processor in relation to personal data uploaded to, stored in, or otherwise processed through the platform by our customers. We act as a data controller only in respect of limited personal data that we process for our own purposes, including account administration, billing, website administration, service operation, security, and compliance.

1. Categories of personal data

We may process the following categories of personal data:

  • User account data — name, email address, role, authentication credentials, login timestamps, and two-factor authentication settings.
  • Incident report data — personal data included in incident reports created by customers, which may relate to staff, service users, visitors, members of the public, contractors, or other individuals involved in an incident.
  • Public statement submissions — content submitted by members of the public at a customer's invitation, including any contact details provided.
  • Billing data — subscription, invoicing, payment, and account administration data.
  • Technical and security data — IP addresses, device and browser information, access logs, audit logs, and security event logs.
  • Medical report data — where enabled, special category health data relating to individuals involved in medical incidents, including patient name, date of birth, contact details, incident narrative, injury details, clinical status, treatment information, hospital attendance, and associated media files.

2. Purposes of processing

We process personal data for the following purposes:

  • to provide, maintain, and support the E-Dob platform;
  • to host, store, organise, and make available customer data at the customer's instruction;
  • to administer user accounts and access permissions;
  • to monitor, secure, and improve the platform;
  • to respond to support requests and troubleshoot technical issues;
  • to manage billing, invoicing, and account administration;
  • to comply with legal and regulatory obligations;
  • to process medical reports where a customer enables that feature and instructs us to do so.

3. Controller and processor roles

Where we process personal data on behalf of a customer, that customer acts as the data controller and we act as the data processor.

In that capacity:

  • the customer determines the purposes and means of processing;
  • the customer determines what data is entered into the platform;
  • the customer determines access permissions and retention settings;
  • the customer is responsible for its own privacy notices, lawful basis, and responses to data subject requests in relation to controller-managed data;
  • we process data only on the customer's documented instructions, except where required by applicable law.

Where we process personal data for our own purposes, we act as an independent data controller.

4. Lawful bases for processing

Where we act as a controller, we rely on the following lawful bases under the UK GDPR, as applicable:

  • Contract — for the provision of the E-Dob service and related account administration;
  • Legitimate interests — for platform security, abuse prevention, fraud detection, service improvement, and business administration, provided that those interests are not overridden by the rights and freedoms of data subjects;
  • Legal obligation — where processing is required to comply with applicable law;
  • Consent — where a member of the public voluntarily submits a statement and consent is the appropriate lawful basis for that submission.

Where we act as a processor, our processing is carried out in accordance with our agreement with the relevant customer and on that customer's instructions.

4.1 Special category data

Where your organisation uses the Medical Reports feature, E-Dob may process special category health data under Article 9 UK GDPR. The applicable Article 9 condition depends on the customer's use case and must be confirmed by the customer’s Data Protection Officer or legal adviser.

Possible Article 9 conditions may include:

  • Explicit consent — where valid and appropriate for the processing activity;
  • Health or social care — where processing is necessary for preventive or occupational medicine, the assessment of working capacity, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems and services.

The customer organisation, as controller, is responsible for ensuring an appropriate Article 9 condition applies and for any related notices, records, or consents required by law.

5. Data retention

We retain personal data only for as long as necessary for the purposes for which it is processed, subject to any applicable legal, regulatory, contractual, or operational requirements.

In summary:

  • Account data is retained for the duration of the subscription and for a limited period thereafter for reactivation, administration, and dispute handling.
  • Security and audit logs are retained for a limited period for security, monitoring, troubleshooting, and abuse prevention.
  • Incident data is retained in accordance with the customer's instructions, configuration, and applicable legal or regulatory requirements.
  • Billing and accounting records are retained for as long as required for tax, accounting, and contractual purposes.
  • Medical report data is retained for the period defined in our Data Retention Policy or as required by the customer's regulatory obligations, including where applicable RIDDOR or CQC requirements.

Where we act as processor, deletion or return of customer data is carried out in accordance with the relevant customer agreement and documented instructions, subject to any legal obligation requiring retention.

6. Recipients and sub-processors

We disclose personal data only where necessary for the operation of the service, the provision of support, or compliance with law, including to approved sub-processors and service providers such as:

  • hosting and infrastructure providers;
  • storage and backup providers;
  • email delivery providers;
  • payment processors;
  • customer support and security tooling providers.

A current list of sub-processors is maintained in our Sub-processor List.

We do not sell personal data.

We may disclose personal data to law enforcement authorities, regulators, courts, or other public bodies where required or permitted by law.

7. International transfers

Our primary infrastructure is hosted in the UK/EU region (Laravel Cloud on AWS, eu-west-1 / London).

Where a customer enables optional AI-assisted features, limited incident text may be processed by Google (Gemini API), which is located in the United States. Any such transfer is made only where the customer has enabled the feature and only subject to appropriate safeguards, including Standard Contractual Clauses or equivalent transfer mechanisms where required by applicable law.

8. Data subject rights

Subject to the conditions and exemptions under the UK GDPR, individuals may have the following rights:

  • right of access;
  • right to rectification;
  • right to erasure;
  • right to restriction of processing;
  • right to data portability;
  • right to object to certain processing.

Where we act as processor in relation to customer-controlled data, we will ordinarily refer the request to the relevant customer and provide reasonable assistance to the extent required by our agreement and applicable law.

9. How to exercise your rights

To exercise your rights, or to raise a data protection query, please contact our Data Protection Officer at dpo@e-dob.uk.

General privacy queries may be sent to privacy@e-dob.uk.

If you are uncertain whether your request should be directed to us or to one of our customers, please contact us and we will assist in directing the request appropriately.

10. Personal data breaches

Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with applicable law.

Where we act as processor, we will notify the relevant customer without undue delay in accordance with our contractual obligations.

11. Customer responsibility

If you use the platform on behalf of your organisation, you are responsible for ensuring that your use of the platform complies with your organisation's privacy policy, records management requirements, and internal data governance arrangements.

In particular, the customer organisation is responsible for:

  • determining the lawful basis for its own processing;
  • deciding what incident data is entered into the platform;
  • deciding who may access that data;
  • setting and applying appropriate retention periods;
  • responding to data subject requests in relation to controller-managed data;
  • ensuring that individuals are informed where required by law;
  • ensuring an appropriate Article 9 condition applies where special category data is processed.

12. Data access and use

Ffon Solutions Limited is not responsible for how customers choose to access, review, disclose, or otherwise use data they upload to the platform, except to the extent required by applicable law, our contractual obligations, or our obligations as a data processor.

Access controls within the platform are administered by the customer and its authorised users. The customer remains responsible for ensuring that access is appropriate and properly authorised.

13. Governing law and jurisdiction

This service is governed by the laws of England and Wales, and the courts of England and Wales shall have jurisdiction, subject to any mandatory legal requirements to the contrary.

14. Contact details

Ffon Solutions Limited trading as GuardDog Digital Privacy queries: privacy@e-dob.uk Data Protection Officer: dpo@e-dob.uk


Medical Report Data (Special Category)

Where your organisation uses the Medical Reports feature, E-Dob processes special category data under UK GDPR Article 9, specifically health data relating to individuals involved in medical incidents.

  • Lawful basis (Article 9(2)): Processing is necessary for the purposes of preventive or occupational medicine, the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems and services (Article 9(2)(h) UK GDPR), or with the explicit consent of the data subject (Article 9(2)(a) UK GDPR) — the applicable basis depends on your organisation's specific use case and should be confirmed with your Data Protection Officer.
  • Data processed: Patient name, date of birth, phone number, incident narrative, injury details, clinical status, treatment information, hospital attendance, and associated media files.
  • Retention: Medical reports are retained for the period defined in our Data Retention Policy, or as required by your organisation's regulatory obligations (for example, Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 and Care Quality Commission requirements where applicable).
  • Your responsibilities: As the data controller, your organisation is responsible for ensuring an appropriate Article 9 lawful basis exists for processing medical data through E-Dob, and for obtaining any necessary consent or maintaining appropriate records.

Sub-processor List

Effective date: 15 June 2026

E-Dob relies on a small number of carefully selected sub-processors to deliver the service. The table below lists each sub-processor, the purpose for which they are engaged, their processing location, and where to find more information about their compliance posture.

Sub-processor Purpose Location More Info
Laravel Cloud (AWS) Application hosting and managed database AWS eu-west-1 (Ireland) SOC 2 Type 2 certified — cloud.laravel.com/docs/compliance
Cloudflare CDN, object storage (R2), DDoS protection and WAF Global edge network; R2 storage region per bucket configuration cloudflare.com/trust-hub
Stripe Payment processing for subscriptions Global / Ireland (Stripe Payments Europe) PCI-DSS Level 1 certified — stripe.com/legal/ssa
SMTP2GO Transactional email delivery Global delivery network (sender region configurable) smtp2go.com/legal
Google (Gemini API) AI-assisted incident description features (optional, company-controlled toggle) Global — only used if a company enables AI features ai.google.dev/terms
Google AI AI-assisted incident description features (optional, company-controlled toggle) US-based — only used if a company enables AI features transparency.google/
Groq AI AI-assisted incident description features (optional, company-controlled toggle) US-based — only used if a company enables AI features https://trust.groq.com/
20i Website Hosting and CDN provider for our public website - eventcontrol.org and weareguarddog.com UK based 20i.com
Microsoft Azure Entra ID SSO login - enabled on a per account basis US based - Data stored within the EU microsoft.com
Zoom Telephone Services Contact Telephone and meeting systems Zoom.us
Virus Total Malware and Virus protection US Based, Google cloud product - Globally distributed on Google Cloud Platform virus Total
Shock Hosting Development Environment US Based, Development server located in the EU Shock Hosting

Note: We review our sub-processors periodically. Customers will be notified of material changes to this list with reasonable notice where required by applicable data protection agreements.

For questions about our sub-processors, contact dpo@e-dob.uk.

Terms of Service

Effective date: 15 June 2026
Last updated: 15 June 2026

These Terms of Service ("Terms") govern your access to and use of E-Dob, an incident reporting platform provided by Ffon Solutions Limited, trading as GuardDog Digital ("we", "us", "our"). By creating an account, starting a trial, or otherwise using the service, you agree to these Terms.

If you are using E-Dob on behalf of an organisation, you represent that you have authority to bind that organisation to these Terms.

1. Definitions

In these Terms:

  • "Customer" means the organisation or other legal entity that subscribes to E-Dob.
  • "Authorised User" means an individual authorised by the Customer to access the service.
  • "Content" means incident records, statements, reports, attachments, notes, and other data uploaded, entered, or generated through the service by or on behalf of the Customer.
  • "Subscription" means the paid plan selected by the Customer.
  • "Trial Period" means the initial free trial period, if offered.
  • "Acceptable Use Policy" means any acceptable use rules we publish from time to time and make available as part of the service or on our website.

2. The service

E-Dob is a software-as-a-service platform that enables organisations to record, manage, review, and report on incidents, including the collection of statements and the generation of reports.

We may update, modify, suspend, or improve the service from time to time, provided that any material change does not materially reduce the core functionality of the service during an active subscription period without reasonable notice, except where required for security, legal compliance, or to prevent or mitigate harm.

3. Eligibility and account registration

To use the service, you must ensure that:

  • all registration information provided is accurate, current, and complete;
  • you maintain the confidentiality and security of your login credentials;
  • you promptly notify us of any actual or suspected unauthorised access to your account;
  • each Authorised User uses their own account credentials and does not share access unless the platform expressly permits it;
  • you implement appropriate internal controls over user access, permissions, and account administration.

You are responsible for all activity occurring under your account, except to the extent caused by our breach of these Terms or by our failure to implement reasonable security measures required by applicable law.

4. Trial periods

We may offer a 14-day free trial to new customers.

Unless otherwise stated:

  • no credit card is required to begin the Trial Period;
  • the Trial Period begins when the account is activated;
  • we may set reasonable limits on trial use, functionality, storage, or support;
  • at the end of the Trial Period, continued use of the service requires conversion to a paid Subscription.

We reserve the right to determine eligibility for trial access and to suspend or end trial access where we reasonably believe the service is being misused or accessed in breach of these Terms.

5. Subscriptions, fees, and payment

Paid subscriptions are billed through Stripe or another payment provider we may appoint from time to time.

By subscribing, you authorise us and our payment provider to charge the applicable fees on a recurring basis in accordance with your selected plan and billing cycle.

Unless stated otherwise:

  • fees are payable in advance;
  • fees are non-refundable, except where required by law;
  • failure to pay may result in suspension or restriction of access;
  • you are responsible for applicable taxes, duties, or levies, other than taxes on our income.

We may change our pricing on reasonable notice, but any price change will not apply to the then-current billing period unless you agree otherwise.

6. Cancellation and termination

You may cancel your Subscription at any time through the account settings or by contacting us.

Unless otherwise stated:

  • cancellation takes effect at the end of the current billing period;
  • no pro-rata refunds are provided, except where required by law;
  • your access remains available until the end of the paid term or Trial Period, as applicable.

We may suspend or terminate your access immediately if:

  • you materially or repeatedly breach these Terms;
  • you breach the Acceptable Use Policy;
  • your use of the service creates a security, legal, regulatory, or operational risk;
  • payment is overdue and remains unpaid after notice;
  • we are required to do so by law.

7. Acceptable use

Your use of E-Dob must comply with our Acceptable Use Policy, which forms part of these Terms.

You must not, and must not permit others to:

  • use the service unlawfully;
  • upload or transmit malicious code;
  • interfere with the integrity, security, or availability of the service;
  • attempt unauthorised access to systems, accounts, data, functions, APIs, source code, or infrastructure;
  • access or attempt to access any part of the service that you are not authorised to access;
  • share, disclose, transfer, or permit the use of login credentials or access tokens except where the service expressly permits authorised multi-user access through account controls;
  • reverse engineer, decompile, disassemble, scrape, probe, scan, or otherwise attempt to derive source code, internal architecture, security features, or technical information, except to the extent permitted by law;
  • bypass, disable, tamper with, or interfere with security controls, authentication measures, logging, monitoring, rate limiting, or access restrictions;
  • use the service in a way that infringes the rights of any person;
  • use the service in breach of any applicable law, regulation, or regulatory guidance.

Any breach of this clause is a material breach of these Terms.

8. Customer data and content

As between you and us, the Customer retains all rights in and to the Content uploaded to or created in the service, subject to the rights granted to us in these Terms.

You grant us a limited, non-exclusive, worldwide, royalty-free licence to host, copy, process, transmit, display, and otherwise use Content solely to:

  • provide and maintain the service;
  • support Customer and Authorised User access;
  • perform security, backup, and restoration functions;
  • comply with law and enforce these Terms.

You are responsible for ensuring that:

  • you have all necessary rights, consents, and lawful bases to upload or submit Content;
  • the Content is accurate and lawful;
  • your use of the service complies with applicable data protection law.

We process personal data in accordance with our Privacy Policy and, where applicable, our data processing terms.

9. Security and compliance

We implement reasonable technical and organisational measures designed to protect the service and the data processed through it.

However, no system is completely secure, and we do not guarantee absolute security or uninterrupted availability.

You are responsible for maintaining appropriate internal controls, including access management, password hygiene, user permissions, device security, and lawful retention practices within your organisation.

Without limiting your responsibilities, you acknowledge and agree that the Customer is responsible for any unauthorised access, disclosure, loss, or misuse of Content or account access caused by:

  • sharing or disclosing login credentials or access details;
  • weak or reused passwords;
  • failure to use available security features;
  • failure to remove access promptly when a user leaves or changes role;
  • compromised devices within your control;
  • internal admin misconfiguration or misuse by your personnel.

This clause does not limit our liability where the relevant issue is caused by our breach of these Terms, our fraud, our wilful misconduct, or any liability that cannot lawfully be excluded.

10. Service availability and support

We use reasonable efforts to keep E-Dob available and operational. At this stage, we do not provide a formal uptime service level agreement unless expressly agreed in writing.

The service is provided on an "as is" and "as available" basis, subject to any non-excludable rights you may have under law.

We may suspend the service temporarily for:

  • planned maintenance;
  • emergency maintenance;
  • security remediation;
  • updates, upgrades, or bug fixes;
  • events outside our reasonable control;
  • mitigation of suspected misuse, compromise, or unlawful access.

11. Beta or optional features

From time to time, we may offer optional, preview, beta, or experimental features.

Such features are provided for evaluation purposes and may be changed, discontinued, or limited at any time without notice. They may not be supported, fully tested, or suitable for production use.

12. Intellectual property

We and our licensors retain all intellectual property rights in and to the service, including software, interfaces, design, trademarks, logos, and documentation.

Except as expressly permitted in these Terms, you acquire no rights in our intellectual property.

You may not copy, reproduce, distribute, modify, or create derivative works from the service or our materials without our prior written consent, except to the extent permitted by law.

13. Confidentiality

Each party may receive confidential information from the other in connection with the service.

Each party agrees to:

  • keep the other party's confidential information confidential;
  • use it only for the purposes of performing or receiving the service;
  • disclose it only to employees, contractors, advisers, or sub-processors who need to know it and are bound by appropriate confidentiality obligations.

This clause does not apply to information that is public, already lawfully known, independently developed, or required to be disclosed by law.

14. Data protection

Where we process personal data on your behalf, we do so as a processor and in accordance with our Privacy Policy and any applicable data processing agreement.

Where we act as controller, we process personal data in accordance with applicable data protection law and our Privacy Policy.

Nothing in these Terms limits or excludes any obligation imposed on us by applicable data protection law.

15. Warranties and disclaimers

You warrant that:

  • you have authority to enter into these Terms;
  • your use of the service will comply with applicable law;
  • all information you provide is accurate to the best of your knowledge.

To the maximum extent permitted by law, we disclaim all warranties not expressly set out in these Terms, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement, except to the extent such disclaimers are not permitted by law.

16. Limitation of liability

Nothing in these Terms limits or excludes liability that cannot lawfully be limited or excluded, including liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be excluded under applicable law.

Subject to the preceding sentence, to the maximum extent permitted by law:

  • we shall not be liable for any indirect, incidental, special, consequential, or punitive loss or damage;
  • we shall not be liable for loss of profit, loss of revenue, loss of business, loss of goodwill, or loss of anticipated savings;
  • we shall not be liable for loss or corruption of data to the extent resulting from your failure to maintain appropriate backups, your failure to manage access controls, your sharing of credentials, your failure to follow our published instructions, or your misuse of the service, except where caused by our breach;
  • we shall not be liable for unauthorised access, disclosure, alteration, loss, or destruction of data arising from misuse of the service by you or any Authorised User, except where caused by our breach, negligence, or other liability that cannot lawfully be excluded;
  • we shall not be liable for reverse engineering, unauthorised access attempts, malware, phishing, credential theft, or similar malicious acts by third parties, except to the extent directly caused by our breach of these Terms or our failure to implement reasonable security measures required by law.

Our total aggregate liability arising out of or in connection with these Terms or the service shall be limited to the total fees paid or payable by you in the 12 months preceding the event giving rise to the claim.

This clause does not apply to any liability which cannot be limited under law.

17. Indemnity

You agree to indemnify, defend, and hold harmless us, our developers, directors, officers, employees, contractors, agents, affiliates, and licensors from and against claims, losses, liabilities, damages, costs, and expenses, including reasonable legal fees, arising out of or in connection with:

  • your breach of these Terms;
  • your breach of applicable law;
  • Content submitted by you or on your behalf;
  • your misuse of the service;
  • your or your users' sharing, disclosure, compromise, or misuse of login credentials or access details;
  • unauthorised access resulting from the acts or omissions of you or your users;
  • any attempt by you or any person using your credentials or devices to reverse engineer, decompile, disassemble, probe, scan, hack, or otherwise access parts of the service you are not authorised to access;
  • any claim that your Content infringes the rights of a third party;
  • any third-party claim arising from use of the service in breach of these Terms.

This indemnity does not apply to the extent the relevant claim or loss is caused by our breach, negligence, wilful misconduct, fraud, or any liability that cannot be excluded or limited under applicable law.

18. Term and variation

These Terms apply from the date you first access or use the service and remain in force until terminated in accordance with these Terms.

We may update these Terms from time to time. Where a change is material, we will provide reasonable notice before it takes effect. Your continued use of the service after the effective date of an update constitutes acceptance of the updated Terms.

19. Export and deletion of data

On termination or expiry of a Subscription, you may request an export of your Content within a reasonable period, subject to technical limitations and lawful retention obligations.

Following termination, we will delete or return Content in accordance with our data retention practices, our Privacy Policy, and any applicable agreement between the parties.

20. Force majeure

We shall not be liable for any delay or failure to perform our obligations to the extent caused by an event beyond our reasonable control, including failures of internet service providers, cloud hosting outages, cyber incidents affecting third-party infrastructure, labour disputes, governmental action, acts of war, civil unrest, or natural disasters.

Force majeure does not apply to the extent the delay or failure is caused by our breach, negligence, fraud, wilful misconduct, or any other liability that cannot lawfully be excluded.

21. Notices

Any notice under these Terms may be given by email to the contact details associated with the account or to the contact details published in our trust centre.

22. Governing law and jurisdiction

These Terms and any dispute or claim arising out of or in connection with them, whether contractual or non-contractual, are governed by the laws of England and Wales.

The courts of England and Wales shall have exclusive jurisdiction to settle any dispute arising out of or in connection with these Terms, subject to any mandatory legal rights that apply.

23. Contact

Questions about these Terms can be sent to:

GuardDog Digital
Ffon Solutions Limited
Email: privacy@e-dob.uk

Acceptable Use Policy

Effective date: 15 June 2026
Last updated: 15 June 2026

This Acceptable Use Policy ("AUP") sets out what is and is not permitted when using E-Dob. It supplements and forms part of our Terms of Service. Capitalised terms have the meaning given in the Terms of Service unless otherwise stated.

This AUP applies to all users of the service, including the Customer, Authorised Users, administrators, and anyone else accessing the service through a customer account.

1. General principle

E-Dob is designed for lawful incident reporting, management, and record-keeping. You must use the service responsibly, lawfully, and only for legitimate business or organisational purposes.

You are responsible for ensuring that your use of the service, and the Content you submit to it, complies with:

  • applicable law;
  • your organisation’s internal policies and procedures;
  • applicable data protection, confidentiality, and records management obligations;
  • the Terms of Service;
  • this AUP.

2. Prohibited uses

You must not use E-Dob to, or permit it to be used to:

2.1 Unlawful, harmful, or abusive content

  • store, transmit, publish, distribute, or otherwise make available any Content that is unlawful, defamatory, obscene, threatening, abusive, discriminatory, hateful, or otherwise harmful;
  • use the service to harass, intimidate, stalk, threaten, abuse, or exploit any person;
  • upload or disseminate Content that incites violence, hatred, self-harm, or criminal activity;
  • use the service in a way that infringes the rights of any person, including privacy, confidence, intellectual property, or data protection rights.

2.2 Security abuse and unauthorised access

  • upload, introduce, transmit, or distribute malware, ransomware, viruses, worms, trojans, spyware, logic bombs, or any other malicious or harmful code;
  • attempt to bypass, defeat, disable, impair, probe, or test the vulnerability of any security, authentication, authorisation, logging, monitoring, encryption, or access-control mechanism, except where we have expressly authorised you in writing to do so;
  • access, or attempt to access, any account, data, environment, tenant, workspace, dataset, system, API, or function that you are not authorised to access;
  • use stolen, shared, compromised, misappropriated, or third-party credentials;
  • share login credentials, authentication codes, API keys, tokens, or account access details except where the service expressly permits such sharing through approved administrative controls;
  • impersonate another person or misrepresent your identity or authority;
  • interfere with or disrupt the integrity, security, availability, or performance of the service or any related network or system.

2.3 Reverse engineering and technical misuse

  • reverse engineer, decompile, disassemble, decode, derive source code from, or otherwise attempt to discover the source code, algorithms, architecture, or underlying ideas of the platform or any related software, except to the extent expressly permitted by law;
  • copy, reproduce, scrape, crawl, extract, harvest, or collect data from the service by automated or manual means in a way that is not authorised by us;
  • use bots, scripts, or automation tools to create excessive requests, overload the service, evade rate limits, or otherwise place an unreasonable burden on our systems;
  • benchmark, probe, scan, or test the service for security weaknesses without our prior written consent;
  • use the service for cryptomining, credential stuffing, phishing, spam, or any other fraudulent or malicious activity.

2.4 Misuse of content and records

  • enter inaccurate, fabricated, misleading, or deliberately incomplete incident information where this could affect safety, safeguarding, compliance, investigations, or legal records;
  • alter, delete, conceal, destroy, or improperly withhold incident records except where authorised by applicable law, policy, or internal process;
  • use the service to retaliate against, unfairly target, or maliciously report another person;
  • create duplicate, false, or abusive reports for harassment, disruption, or nuisance.

2.5 Circumventing controls

  • circumvent user permissions, workflow controls, approval processes, retention settings, audit trails, or any other governance control built into the service;
  • disable, remove, or interfere with required notices, warnings, or record-retention functionality;
  • use the service in a way that undermines the integrity of logs, audit trails, or evidence records.

3. Responsible use of incident data

Incident reports should contain only the information necessary for the incident being reported and handled appropriately.

You should not upload personal data unless it is relevant and necessary for the incident or subsequent management process.

3.1 Special category data

You must not upload special category personal data, including health data, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetic data, biometric data, sex life, or sexual orientation, unless:

  • it is directly relevant to the incident or matter being recorded;
  • you have a lawful basis and, where applicable, a valid Article 9 condition under UK GDPR;
  • the data is processed in accordance with applicable law and your organisation’s own policies.

3.2 Criminal offence data

You must not upload criminal offence data unless it is necessary, lawful, and authorised by your organisation’s policies and applicable law.

3.3 Minimisation

You should:

  • keep entries fact-based and objective;
  • avoid speculation, personal opinion, or unnecessary commentary;
  • redact or omit unnecessary personal data where possible;
  • use the minimum data necessary to record the incident accurately.

4. Email, attachments, and file uploads

If the service permits file uploads, you must ensure that any files, images, recordings, or attachments uploaded:

  • are relevant to the incident or purpose for which they are provided;
  • do not contain malware or other harmful code;
  • do not infringe the rights of any third party;
  • do not contain unnecessary sensitive personal data.

You must not upload material that you know, or ought reasonably to know, is false, unlawful, or malicious.

5. Account security and admin responsibilities

Customers and Authorised Users must:

  • keep credentials confidential;
  • use strong passwords and, where available, multi-factor authentication;
  • ensure accounts are allocated only to authorised personnel;
  • remove access promptly when a user leaves, changes role, or no longer requires access;
  • review account activity and permissions regularly;
  • notify us promptly of suspected compromise, misuse, or unauthorised access.

You are responsible for activity performed through your accounts and for any access arising from your failure to secure credentials, devices, or permissions, except to the extent caused by our breach or by any liability that cannot lawfully be excluded.

6. API and integration use

Where we make APIs or integrations available, you must:

  • use them only in accordance with our documentation and any usage limits we specify;
  • not exceed published rate limits or quotas;
  • not use integrations to harvest, exfiltrate, or repurpose data beyond the authorised purpose;
  • not use APIs in a way that degrades service performance, security, or stability.

We may suspend API access where we reasonably believe it is causing harm, misuse, or material service disruption.

7. Third-party systems and credentials

If you connect E-Dob to third-party systems, you are responsible for:

  • ensuring you have the right to make that connection;
  • complying with the third party’s terms and policies;
  • maintaining the security of third-party credentials and tokens;
  • understanding any data sharing, transfer, or access implications.

We are not responsible for the security or conduct of third-party platforms, except to the extent required by law or our own breach.

8. Prohibited evasion and circumvention

You must not:

  • create multiple accounts to evade suspension, enforcement, or usage limits;
  • attempt to conceal identity or activity for the purpose of abuse or unauthorised access;
  • use the service to test, circumvent, or exploit vulnerabilities;
  • interfere with or bypass any content moderation, security, compliance, or reporting process.

9. Monitoring and investigation

We may monitor use of the service to the extent reasonably necessary to:

  • protect the security and integrity of the service;
  • investigate suspected breaches;
  • prevent abuse, fraud, or unauthorised access;
  • comply with law;
  • enforce the Terms of Service and this AUP.

Any monitoring will be carried out in accordance with applicable law and our Privacy Policy.

10. Enforcement

If we reasonably believe that this AUP or the Terms of Service have been breached, we may take any action we consider appropriate, including:

  • issuing a warning;
  • requiring you to remove or correct Content;
  • restricting, suspending, or terminating access, including immediately where necessary;
  • disabling specific functionality, integrations, or API access;
  • reporting the matter to the Customer’s administrator or designated contact;
  • preserving evidence and audit logs;
  • referring the matter to law enforcement, regulators, or other relevant authorities where appropriate.

We may take enforcement action without prior notice where:

  • the breach creates a security risk;
  • there is suspected unauthorised access;
  • the service is being used for malicious or unlawful activity;
  • immediate action is necessary to protect the service, our customers, or third parties.

11. Reporting misuse

If you become aware of any suspected misuse, breach, compromise, or unauthorised access, you must report it promptly to:

security@e-dob.uk

You should include, where relevant:

  • a description of the incident;
  • the affected account or workspace;
  • the date and time of the issue;
  • any logs, screenshots, or other supporting material.

12. No waiver

Our failure to enforce this AUP in any instance does not mean we waive our right to enforce it later.

13. Changes to this AUP

We may update this AUP from time to time. Where a change is material, we will provide reasonable notice before it takes effect. Continued use of the service after the effective date of any update constitutes acceptance of the revised AUP.

14. Contact

Questions about this AUP should be sent to:

GuardDog Digital
Ffon Solutions Limited
Email: security@e-dob.uk

Security Overview

Effective date: 15 June 2026

We take the security of E-Dob and the data entrusted to us seriously. This overview describes, at a high level, the measures we have in place. It is intentionally a summary and does not disclose sensitive architectural detail.

Infrastructure

E-Dob runs on Laravel Cloud (built on AWS), a SOC 2 Type 2 certified platform, with primary infrastructure in the UK/EU region (eu-west-1, London). Edge protection, CDN and a web application firewall (WAF) are provided by Cloudflare.

Encryption

  • In transit: all traffic is encrypted using TLS.
  • At rest: data is encrypted at rest via the underlying managed platform and object storage.

Access controls

  • Role-based access control restricts what each user can see and do.
  • Company data isolation ensures organisations can only access their own data.
  • Two-factor authentication (2FA) is available to protect accounts.
  • Account lockout is applied after repeated failed login attempts to deter brute-force attacks.

Application security

  • A Content Security Policy (CSP) and other hardening headers are enforced.
  • Input validation is applied throughout the application.
  • We carry out regular dependency audits to identify and address known vulnerabilities.
  • We operate security monitoring to detect and respond to suspicious activity.

Incident response

If you believe you have found a security vulnerability, please report it responsibly to security@e-dob.uk. We will investigate and respond promptly.

Our ongoing commitment

We conduct regular internal security reviews aligned with ISO 27001 principles as part of our ongoing security programme, and continue to invest in improving the security of the platform.

Data Retention Policy

Effective date: 15 June 2026

This policy explains how long different categories of data are retained within E-Dob. Retention periods balance the need to provide the service, meet legal obligations, and avoid keeping data longer than necessary.

Account data

Account data is retained while a subscription is active, and for 30 days after cancellation to allow for reactivation. After that period it is deleted, unless we are required to retain it for longer to comply with a legal obligation.

Incident report data

Incident reports are retained according to the customer's own regulatory requirements. E-Dob does not impose a maximum retention period; instead we recommend that customers configure retention in line with their sector's requirements.

Area for future development: the platform does not currently provide a configurable retention setting for incident data. Until such configuration is available, incident report data is currently retained indefinitely unless deletion is requested. We have flagged automated, customer-configurable incident retention as a planned enhancement.

Audit logs and security events

Audit logs and security event records are retained for 12 months for security monitoring and accountability purposes.

Login attempt records

Records of login attempts (used for brute-force protection and account lockout) are retained for 90 days.

Backups

Database backups are retained in line with Laravel Cloud's managed database backup retention. See the Laravel Cloud documentation for details of their backup schedule and retention.

Requesting deletion

To request deletion of personal data, or to ask a question about retention, contact our Data Protection Officer at dpo@e-dob.uk. Where we process data on behalf of a customer, we will refer or assist with the request in accordance with our agreement with that customer.

Medical Reports

Retention period: Medical reports contain special category health data (UK GDPR Article 9). Retention should be determined by your organisation's regulatory requirements:

  • For workplace incidents: minimum 3 years recommended (RIDDOR)
  • For healthcare settings: follow CQC/NHS records management guidance
  • Default (if no specific requirement): 7 years

Deletion: Medical reports are deleted on account closure per the account data retention period above. If specific medical records need to be retained beyond account closure, export them before cancelling your subscription.

Access: Medical report data is accessible only to authenticated users within your organisation.