Before public production launch, the operator should have this notice reviewed against the final hosting location, customer agreements, Australian privacy obligations and actual data-retention settings.
1. Information LoneWatch may process
- Microsoft work identity information such as display name, tenant ID, object ID and work username.
- Worker contact information, including a mobile number when the worker or organisation provides one.
- Lone-work session details such as task description, start/end times and check-in state.
- Location evidence, including last-known coordinates, accuracy, timestamps, sites and zones.
- Motion and safety evidence used for inactivity or possible-fall evaluation.
- Device protection information such as notification permission, battery state and background capability.
- Incident, responder, acknowledgement, routing and notification delivery records.
- Enterprise onboarding information such as Entra tenant connections, manager suggestions and Teams integration state.
2. Why the information is used
LoneWatch uses this information to provide lone-worker monitoring, identify safety events, route incidents, notify authorised responders, support enterprise administration, troubleshoot service health and maintain an auditable safety record.
3. Location and motion
Location and motion data can be sensitive. LoneWatch is designed to collect these signals for active safety functions rather than general employee surveillance. Customer policies should define when monitoring is active, who may access history and how long high-volume telemetry is retained.
4. Microsoft and Teams
LoneWatch can authenticate users through Microsoft Entra ID and can use Microsoft Teams workflows for safety alerts. Microsoft processes information under its own terms and privacy documentation. Directory manager data is used to generate administrator-review suggestions rather than automatically becoming the sole safety authority.
5. Access and disclosure
Access should be role-based. Worker mobile numbers are designed to be exposed to the worker and an actively assigned responder for an incident, rather than broadly included in Teams or push notification payloads. Customer administrators may have access to organisation-level safety configuration and records.
6. Retention
Final production retention periods should be documented in the applicable customer agreement and service configuration. LoneWatch intends to keep high-volume telemetry for shorter periods than incident and audit evidence, where operational and legal requirements allow.
7. Security
Production deployment is designed to use encrypted HTTPS connections, managed cloud database services, encrypted secret storage, tenant isolation and operational monitoring. No internet-connected system can be guaranteed completely secure.
8. Your organisation
Where LoneWatch is provided through an employer or contracting organisation, that organisation may be responsible for decisions about workforce monitoring, lawful basis, notices, retention and access. Workers should also refer to their organisation's privacy and safety policies.
9. Contact
Privacy questions can be sent to privacy@lonewatch.app.