iWork Privacy Policy - Bracknell BID

Bracknell BID iWork Privacy Policy

**Effective date:** 6 July 2026
**Last updated:** 6 July 2026

## 1. About this policy

This Privacy Policy explains how personal data is collected, used, stored and shared when you use the Bracknell BID iWork mobile application (the **App**) and the associated iWork loyalty card service (the **Service**).

The App enables eligible employees in the Bracknell Business Improvement District area to discover and redeem offers. It also enables participating businesses and authorised administrators to manage business profiles, employee access, offers and redemption reporting.

## 2. Who is responsible for your personal data

The data controller for the App and Service is:

**Bracknell Investment Group Limited**, trading as **Bracknell BID**
Company number: 12415065
Suite 321, Venture House
2 Arlington Square
Bracknell, Berkshire
RG12 1WA
United Kingdom

Privacy and support enquiries:

- Email: [developer@bracknellbid.co.uk](mailto:developer@bracknellbid.co.uk)
- General enquiries: [enquiries@bracknellbid.co.uk](mailto:enquiries@bracknellbid.co.uk)
- Telephone: 01344 949080

In this policy, “we”, “us” and “our” refer to Bracknell Investment Group Limited trading as Bracknell BID.

## 3. Personal data we collect

The data we collect depends on whether you use an employee, business or administrator account and which App features you use.

### 3.1 Account and identity data

We may collect:

- your user ID, first name and last name;
- your email address, username and telephone number;
- your password and authentication information;
- email-verification and password-reset information;
- your account type, account status and verification status;
- the business or workplace linked to your account;
- your age bracket, gender selection and residential postcode;
- the dates on which your account was created or updated; and
- your email and push-notification preferences.

Passwords are transmitted to our authentication service to create or access your account. The App also uses operating-system-protected credential storage for authentication credentials and session tokens on your device. You should protect access to your device and must not share your password.

### 3.2 Business account data

If you register or manage a business account, we may collect:

- business name, website and email domain;
- contact name, contact email address, job title and telephone number;
- business address and postcode;
- opening hours;
- business logo images;
- business QR codes;
- offers created or managed by the business; and
- information about employees linked to the business and their account status.

Business profile and offer information may be visible to App users where this is necessary to provide the Service.

### 3.3 Offer, redemption and service activity

We may collect:

- offers displayed, selected, claimed or redeemed;
- user, offer and business identifiers associated with a redemption;
- redemption dates, codes, frequency and status;
- offer-management and account-administration activity;
- broadcast or service messages delivered to an account; and
- aggregated or account-level redemption information used for business reporting, service support, fraud prevention and troubleshooting.

### 3.4 Device, notification and technical data

Where push notifications are enabled, we may collect:

- a Firebase or Apple push-notification token;
- a device or installation identifier, including the Android device ID where applicable;
- device platform;
- App version;
- notification permission and preference status; and
- identifiers included in notification messages, such as an offer or broadcast identifier.

Our servers and hosting providers may also process ordinary technical records such as request dates and times, IP addresses, response status, and security or diagnostic logs. These records are used to deliver, secure and troubleshoot the Service.

The App does not use third-party advertising SDKs and we do not use your personal data for behavioural advertising.

### 3.5 Camera, QR codes and images

The App requests camera access only when you choose to scan a participating business’s iWork QR code. The camera image is used to recognise the QR code. The App does not intentionally retain or upload a photograph or video of the camera view. The identifier encoded in the QR code is used to retrieve the relevant business and in-store offers.

Business users may choose an image from their device to upload as a business logo. The selected image is transmitted to and stored by the Service so that it can be displayed with the business and its offers.

The App does not request access to your device’s precise or approximate location.

### 3.6 Information you provide to support

If you contact us, we may collect your contact details, the contents of your message, screenshots or other information you choose to provide, and records of our response. Please do not send unnecessary sensitive information.

## 4. How we use personal data

We use personal data to:

- register, verify, authenticate and administer accounts;
- determine eligibility and link employees with participating businesses;
- display active and relevant offers;
- support online and in-store offer redemption;
- prevent duplicate, unauthorised or fraudulent redemptions;
- allow businesses to create offers and administer linked employees;
- provide redemption reporting and Service analytics to authorised businesses;
- send verification codes, password-reset messages and essential Service communications;
- send optional email or push notifications where enabled;
- respond to support, privacy and security enquiries;
- maintain, diagnose, secure and improve the App and Service;
- enforce applicable terms and protect users, businesses and the Service; and
- comply with legal and regulatory obligations.

We do not sell personal data.

## 5. Our lawful bases

Under UK data protection law, we rely on one or more of the following lawful bases:

- **Contract:** processing needed to create and administer your account and provide the Service you request.
- **Legitimate interests:** operating and improving the loyalty scheme, administering participating businesses, supporting users, producing appropriate redemption reporting, and protecting the Service from misuse. We consider the effect of this processing on your rights and interests.
- **Consent:** where consent is appropriate, including optional device permissions and optional marketing or notification choices. You can withdraw consent through the App or device settings, although this does not affect earlier lawful processing.
- **Legal obligation:** processing required to comply with applicable law, regulatory requests or legal proceedings.
- **Legal claims and vital interests:** where reasonably necessary to establish, exercise or defend legal claims, protect a person, or respond to a serious security incident.

## 6. Notifications

Push notifications are optional. If you enable them, the App uses Firebase Cloud Messaging and, on Apple devices, Apple Push Notification service to deliver messages. These providers process device or installation identifiers and message-delivery data.

You can change push permission in your device settings and change available email or push preferences in the App. Disabling optional notifications does not prevent us from sending essential account, verification, password-reset, security or Service messages where another permitted channel is available.

## 7. When we share personal data

We share personal data only where reasonably necessary for the purposes described in this policy.

### 7.1 Your linked workplace or participating business

Authorised representatives of a business may be able to see information needed to administer linked employees, account status and offer redemptions. This may include an employee’s name, contact or workplace details, account status and relevant redemption records.

### 7.2 Service providers

We use service providers that process data on our behalf, including:

- cloud hosting and infrastructure providers, including Microsoft Azure;
- Google Firebase Cloud Messaging for Android and cross-platform notification delivery;
- Apple Push Notification service for notifications on Apple devices;
- email, security, maintenance and technical-support providers; and
- professional advisers where reasonably required.

These providers may process only the data needed to perform their services and are subject to their own legal obligations and contractual terms.

More information about relevant provider practices is available at:

- [Google Firebase privacy and security](https://firebase.google.com/support/privacy)
- [Google Privacy Policy](https://policies.google.com/privacy)
- [Apple Privacy Policy](https://www.apple.com/legal/privacy/)
- [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement)

### 7.3 Legal and organisational disclosures

We may disclose data where required by law, court order or a competent authority; to investigate or prevent fraud, abuse or security incidents; to protect legal rights; or as part of a reorganisation or transfer of the Service, subject to appropriate safeguards.

## 8. International transfers

Some service providers may process data outside the United Kingdom. Where personal data is transferred internationally, we use an applicable lawful transfer mechanism and appropriate safeguards, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another legally recognised safeguard.

## 9. Data retention

We keep personal data only for as long as reasonably necessary for the purposes described in this policy.

- Account and profile data is generally retained while the account remains active.
- Authentication and verification records are retained only for as long as needed to provide account access, protect security and resolve support issues.
- Device and push-notification records are retained while notifications remain enabled or until the token becomes invalid, the device registration is removed, or the account is deleted.
- Business profile, offer and logo information is retained while needed to operate the Service and maintain appropriate business records.
- Redemption and activity records may be retained after an account is closed where reasonably necessary for reporting, fraud prevention, dispute resolution, security, legal claims or legal obligations. Where identifiable data is no longer required, it will be deleted or anonymised.
- Support and security records are retained for the time needed to resolve the matter and maintain appropriate evidence.
- Backups are overwritten on a controlled cycle. Data scheduled for deletion may remain in a protected backup until that backup is overwritten, and will not be restored for ordinary use.

We periodically review retained data. Different retention periods may apply where the law requires or permits us to keep a record for longer.

## 10. Account and data deletion

You may request deletion of your iWork account and associated personal data at any time.

BID area employees can request deletion of their account and associated personal data by emailing
[developer@bracknellbid.co.uk](mailto:developer@bracknellbid.co.uk).

To submit a request without using the App, email [developer@bracknellbid.co.uk](mailto:developer@bracknellbid.co.uk) with the subject **“iWork account deletion request”** and include:

- the email address registered to the account;
- your name;
- whether the account is an employee or business account; and
- enough information for us to verify that you control the account.

Do not send your password. We may contact you through the registered email address or request other proportionate evidence to prevent unauthorised deletion.

After verification, we will delete or anonymise the account and associated personal data without undue delay, normally within 30 days. We will also instruct relevant processors to delete associated data where required.

Some information may be retained where necessary for legal obligations, security, fraud prevention, dispute resolution or legal claims. We will inform you if an exception materially affects your request. Data already anonymised so that it can no longer identify you may be retained.

Deleting the App from a device does not itself delete your account. You must submit an account deletion request using the process above.

## 11. Your data protection rights

Depending on the circumstances, UK data protection law may give you the right to:

- be informed about the use of your personal data;
- request access to your personal data;
- ask us to correct inaccurate or incomplete data;
- ask us to erase your personal data;
- ask us to restrict processing;
- object to processing based on legitimate interests or direct marketing;
- receive certain data in a portable format;
- withdraw consent at any time where processing relies on consent; and
- complain to a supervisory authority.

These rights are not absolute. We may need to verify your identity and may retain or continue processing some information where permitted or required by law. We normally respond to valid requests within one month.

To exercise a right, contact [developer@bracknellbid.co.uk](mailto:developer@bracknellbid.co.uk).

You may complain to the UK Information Commissioner’s Office:

- Website: [https://ico.org.uk/make-a-complaint/](https://ico.org.uk/make-a-complaint/)
- Telephone: 0303 123 1113

We would appreciate the opportunity to address your concern before you contact the ICO.

## 12. Security

We use administrative, organisational and technical measures designed to protect personal data. These include authenticated access, role-based functionality, encrypted HTTPS connections, platform-protected credential storage, access controls, and security monitoring and maintenance.

No electronic system is completely secure. You are responsible for keeping your password and device secure and for notifying us promptly if you suspect unauthorised access.

## 13. Children

The Service is intended for people working in the Bracknell BID area and is not directed to children under 18. We do not knowingly permit children under 18 to create an account. If you believe a child has provided personal data, contact us so that we can investigate and take appropriate action.

## 14. Automated decision-making

The App may automatically apply account status, offer eligibility, validity dates and redemption-frequency rules. We do not use personal data in the App for solely automated decisions that produce legal or similarly significant effects on an individual.

## 15. External applications and links

The App may open an external email, telephone, maps, browser, sharing or app store service at your request. Information you choose to send to an external service is governed by that provider’s privacy policy. We are not responsible for the privacy practices of independent third-party websites or applications.

## 16. Changes to this policy

We may update this policy when the App, Service, law or our data practices change. We will publish the updated policy and revise the “Last updated” date. Where a change materially affects your rights or how we use personal data, we will provide an appropriate additional notice.

## 17. Contact us

For privacy questions, rights requests or account deletion:

**Bracknell BID iWork Privacy**
Bracknell Investment Group Limited
Suite 321, Venture House
2 Arlington Square
Bracknell, Berkshire
RG12 1WA
United Kingdom
[developer@bracknellbid.co.uk](mailto:developer@bracknellbid.co.uk)
01344 949080

Scroll to Top
Secret Link