HIVE IN-STORE
Mobile Application — Published by ADM (Group) Limited
Contents
- 1 Introduction
- 2 Data Controller
- 3 Who This Policy Applies To
- 4 Information We Collect
- 5 How We Use Your Information
- 6 Legal Basis for Processing
- 7 Data Sharing and Disclosure
- 8 Data Storage and Security
- 9 Data Retention
- 10 Your Rights Under UK GDPR
- 11 International Data Transfers
- 12 Children's Privacy
- 13 Changes to This Policy
- 14 Contact Us
1 Introduction
This Privacy Policy explains how ADM (Group) Limited ("ADM Indicia", "we", "us", or "our") collects, uses, stores, and shares personal data in connection with the HIVE IN-STORE mobile application ("the App").
ADM (Group) Limited is incorporated in England and Wales and is committed to protecting the personal data of all individuals who use the App in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy applies exclusively to users of the HIVE IN-STORE App. It does not apply to end customers of ADM Indicia's clients, who have no access to the App and are subject to separate data handling arrangements.
2 Data Controller
ADM (Group) Limited is the Data Controller for all personal data processed through the HIVE IN-STORE App.
ADM (Group) Limited
26-28 Bedford Row, 4th & 5th Floor, London, England, WC1R 4HE
ICO Registration Number: Z2348775
Privacy Contact: Global.Legal@adm-indicia.com
3 Who This Policy Applies To
HIVE IN-STORE is a closed, business-to-business platform. Access is restricted to two categories of authorised users:
- ADM Indicia employees — directly employed staff who use the App to manage, coordinate, and carry out field operations.
- Subcontracted field operatives — individuals engaged by ADM Indicia's Partner Organisations under contract to perform installation, verification, and related field services on behalf of ADM Indicia.
End customers (the clients of ADM Indicia who commission field services) do not have access to the App. Customers may receive operational completion reports — containing photographic evidence, signatures, and work records generated within the App — delivered via a separate web-based management platform. This sharing is described in Section 7.
4 Information We Collect
4.1 Personal Information
- Full name
- Email address
- User account credentials (managed via identity provider)
- Job role and organisational affiliation
4.2 Location Data
- Approximate location (network-based)
- Precise GPS location — collected when field operatives are actively using the App to record attendance, verify site visits, or complete location-dependent tasks
- Location metadata associated with photographs taken within the App (where embedded in image data)
4.3 Camera, Photography, and Device Storage
- Photographs taken via the device camera during field operations — used as evidence of task completion, asset condition, and installation verification
- The App requires access to device storage to read, write, and manage files associated with field operations — including photographs, documents, and completion evidence — both for offline caching and for upload to the platform
- Images and media files may be read from or written to device storage as part of normal operational workflows
4.4 Audio Recordings
- Voice and sound recordings made within the App's internal chat and communication features
4.5 Operational and Work Records
- Work order data, task completion records, asset inspection records
- Electronic signatures captured via the signature functionality
- Documents uploaded or generated during field activities
4.6 Device and Technical Data
- Device identifiers (Android device ID)
- Application performance data, crash logs, and diagnostic information
- App interaction data and usage patterns
4.7 In-App Communications
- Messages and content exchanged via the in-app chat feature between authorised users
4.8 Notifications
- The App may send push notifications to the user's device to alert them to new work order assignments, messages, or operational updates
- Notification content may include user names, task references, and operational status information
5 How We Use Your Information
We use personal data collected through the App for the following purposes:
- To authenticate and manage user access to the App
- To assign, manage, and track field service work orders
- To verify attendance and location at service sites
- To capture photographic, documentary, and signature evidence of completed services
- To facilitate communication between field operatives and management
- To generate operational completion reports for delivery to end customers via the web management platform
- To maintain audit trails and records of field activities
- To synchronise operational data in the background when network connectivity is available, ensuring work records captured offline are uploaded to the platform without requiring the App to be in the foreground
- To send push notifications to alert users to work order assignments, messages, and operational updates
- To monitor App performance, diagnose technical issues, and improve reliability
- To comply with our legal and contractual obligations
6 Legal Basis for Processing
We rely on the following legal bases under UK GDPR Article 6:
- Article 6(1)(b) — Performance of a contract: processing is necessary to fulfil our contractual obligations to employees and to carry out services under contracts with Partner Organisations.
- Article 6(1)(c) — Legal obligation: processing is required to comply with applicable legal requirements.
- Article 6(1)(f) — Legitimate interests: processing is necessary for our legitimate interests in operating a safe, reliable, and accountable field service management platform, where those interests are not overridden by the rights of the individuals concerned.
For subcontracted field operatives, the legal basis for processing is Article 6(1)(b) (performance of the subcontract) and Article 6(1)(f) (legitimate interests in managing and evidencing the delivery of contracted services).
7 Data Sharing and Disclosure
7.1 Partner Organisations
Partner Organisations are engaged by ADM Indicia as subcontractors to deliver field services using the App. They act as Data Processors under UK GDPR, processing personal data only on ADM Indicia's instructions and subject to formal Data Processing Agreements (DPAs). Partner Organisations do not control the data they access via the App.
7.2 End Customers
ADM Indicia's end customers do not access the App. However, they may receive operational completion reports — which may include photographs, signatures, location records, and task completion evidence generated via the App — delivered through the separate HIVE IN-STORE web management platform. This disclosure is made on the basis of our legitimate interests and contractual obligations to evidence the delivery of commissioned services.
7.3 Technology Sub-Processors
Microsoft Azure is engaged as a Data Processor under a formal Data Processing Addendum (DPA). The North Europe region (Ireland) is covered by the UK Government's adequacy decision for EEA countries, meaning no International Data Transfer Agreement (IDTA) is required for UK-to-Ireland data transfers.
| Sub-Processor | Service / Role | Location | Safeguard |
|---|---|---|---|
| Microsoft Azure (Microsoft Ireland Operations Limited) | Cloud infrastructure provider — hosting, database, file storage, identity management, messaging, and email delivery services used to operate the HIVE IN-STORE platform | North Europe region (Ireland) | Microsoft Products and Services Data Processing Addendum (DPA). North Europe (Ireland) is covered by the UK adequacy decision for EEA countries — no IDTA required. |
A full breakdown of Azure services used within the platform, together with the categories of personal data processed by each, is maintained in ADM Indicia's internal Records of Processing Activities (Article 30 UK GDPR). This record is available to the ICO on request.
7.4 Legal Disclosure
We may disclose personal data to law enforcement, regulatory authorities, or courts where required to do so by law or in response to a valid legal request.
8 Data Storage and Security
All personal data is stored and processed within Microsoft Azure infrastructure hosted in the North Europe region (Ireland).
We implement appropriate technical and organisational security measures to protect personal data against unauthorised access, loss, or disclosure. These measures include:
- Encryption of data in transit (TLS) and at rest
- Role-based access controls limiting data access to authorised personnel
- Centralised secrets and credential management
- Application logging and monitoring retained within ADM Indicia's Azure infrastructure
- Regular security reviews and vulnerability assessments
9 Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy, or as required by law or contract. The table below sets out our retention periods by data category.
| Data Category | Description | Retention Period | Basis for Retention |
|---|---|---|---|
| User account and identity data | Name, email address, login credentials, role and organisational affiliation | Duration of employment / subcontract + 7 years as part of operational work records | Contractual obligation; legitimate interests |
| Operational work records | Work orders, task completion records, asset inspection records, attendance records | 7 years from date of record | Legal obligation; contractual obligation to end customers |
| Photographic and documentary evidence | Photographs, PDFs, and completion evidence captured during field operations | 7 years from date of capture as part of operational work records | Contractual obligation to evidence delivery of commissioned services |
| Electronic signatures | Signatures captured via the App to confirm task completion or acceptance | 7 years from date of capture as part of operational work records | Contractual obligation; legal obligation |
| Audio recordings | Voice and sound recordings made via the in-app chat feature | 7 years from date of capture as part of operational work records | Legitimate interests — internal communications |
| In-app chat messages | Text messages exchanged between authorised users within the App | 7 years from date of capture as part of operational work records | Legitimate interests — internal communications |
| Location data | GPS and network location records associated with field activity | 7 years from date of capture as part of operational work records | Contractual obligation; legitimate interests |
| Application logs and diagnostics | Crash logs, error reports, performance metrics, and structured event logs stored locally on Azure infrastructure via Seq | 90 days for system maintenance and operational troubleshooting | Legitimate interests — system reliability and security monitoring |
| Device-cached data | Data stored locally on the user's device via WatermelonDB for offline use | Cleared on account deactivation or App uninstall | N/A — device-local storage only |
| Authentication tokens and session data | JWT tokens and Redis-cached session data used for App authentication | Session duration; tokens expire per identity provider configuration | Legitimate interests — security and access control |
Locally cached data on user devices is cleared upon account deactivation or when the App is uninstalled.
10 Your Rights Under UK GDPR
As a data subject under UK GDPR, you have the following rights:
- Right of access (Article 15) — to request a copy of the personal data we hold about you
- Right to rectification (Article 16) — to request correction of inaccurate or incomplete data
- Right to erasure (Article 17) — to request deletion of your personal data, subject to legal or contractual retention obligations
- Right to restriction of processing (Article 18) — to request that we limit how we use your data
- Right to data portability (Article 20) — to receive your data in a structured, machine-readable format
- Right to object (Article 21) — to object to processing based on legitimate interests
To exercise any of these rights, please contact us at Global.Legal@adm-indicia.com.
10.1 Data Protection Officer
ADM Indicia has assessed its obligations under UK GDPR and has determined that appointment of a Data Protection Officer is not currently required. Privacy matters are managed by the Global Legal team.
11 International Data Transfers
The HIVE IN-STORE platform is deployed to support operations in the Asia-Pacific (APAC) region. This may involve the transfer of personal data to countries outside the United Kingdom.
Where personal data is transferred outside the UK, we ensure that appropriate safeguards are in place in accordance with UK GDPR Chapter V, including:
- International Data Transfer Agreements (IDTAs) — the UK-specific mechanism replacing EU Standard Contractual Clauses
- Adequacy regulations made by the UK Secretary of State, where applicable
The primary Azure infrastructure is hosted in the North Europe region (Ireland), which is covered by the UK's adequacy decision for EEA countries and does not require an IDTA for UK-to-Ireland transfers.
12 Children's Privacy
The HIVE IN-STORE App is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. Access to the App requires a valid employment or subcontract relationship with ADM Indicia or a Partner Organisation.
13 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. Where changes are material, we will notify authorised users through appropriate channels.
14 Contact Us
If you have any questions, concerns, or complaints about how we handle your personal data, please contact us:
ADM (Group) Limited
26-28 Bedford Row, 4th & 5th Floor, London, England, WC1R 4HE
Email: Global.Legal@adm-indicia.com
You also have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Website: www.ico.org.uk
Telephone: 0303 123 1113
Post: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF