Pilot Launch Offer
Pilot Launch Offer
Join now and enjoy a full year of service for only £5.95

Privacy Policy

Effective date: 24 June 2026

My Home Call Ltd (“we,” “us,” or “our”) is committed to safeguarding your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our mobile application, a My Home Call kiosk, and any associated services (collectively, the “Services”). It should be read together with our Terms of Use, End User Licence Agreement, and Data Retention Policy.

My Home Call Ltd is the sole data controller for the personal data processed through the Services. We do not share personal data with any third party for that party’s own purposes.

  1. How the Service works

Understanding how the Service operates is helpful in understanding what data we collect and how it is used.

  • You register for the Service through our mobile application and create a profile, including your emergency contact details.
  • In a school setting, a parent or legal guardian creates and manages the profile on behalf of their child.
  • When you (or your child) need to contact a saved emergency contact, you can do so from the app on your own device or from a My Home Call kiosk installed at a participating venue (e.g. a school).
  • A My Home Call kiosk is a shared interaction terminal. It does not store personal data. You identify yourself at the kiosk by entering your name and submitting a facial scan, which is transmitted to our servers for matching.
  • All matching of biometric data and management of contact actions takes place on My Home Call’s servers. The result is a call or pre-set message sent to your saved emergency contact. At a My Home Call kiosk in a school, voice calling is disabled: the kiosk sends an SMS to a verified emergency contact, which includes your What3Words location.
  • My Home Call does not interact with emergency services (999, 911, or equivalents). The Service contacts the saved emergency contact you have chosen.
  1. What data we collect

We believe in data minimisation and only collect the personal data necessary to deliver our Services. The categories we collect are:

2.1 Biometric data (special category data)

For secure authentication, we collect biometric data in the form of facial recognition scans. This data is processed on My Home Call’s servers and is used solely to verify your identity. A biometric template is securely stored against your registered profile; the transient scan submitted at the point of authentication is not retained after the match is performed. Biometric data is special category data under Article 9 UK GDPR and is processed on the basis of your explicit consent given at registration.

2.2 Emergency contact details

To enable contact during a moment of need, you provide the names and phone numbers of your designated emergency contacts. This information is used to deliver a call or pre-set message to those contacts when you trigger the Service.

2.3 Location data (What3Words)

When your account is activated by you, the Service will share your precise location using What3Words with your saved emergency contact. We only access your location when the Service is activated. We do not store a continuous historical log of your location.

2.4 Account and usage data

We collect basic account data (e.g. email address, username, unique user ID, subscription status) and basic usage and device data (e.g. how you interact with the app’s features, crash logs, performance data, device model, operating system). This is used to operate the Service, fix bugs, improve performance, and provide support. It is generally analysed in an aggregated and anonymised form.

2.5 Kiosk interaction records

When you use a My Home Call kiosk, we hold a minimal server-side record of the interaction: a timestamp, your profile ID, the emergency contact reached, and the outcome (e.g. successful call, successful message). This record does not contain your facial scan, the content of any message, audio of any call, or location data. The record is held on My Home Call servers only and is not shared with the school, the emergency contact, or any other third party. It is retained for less than 30 days. Further detail is set out in the Data Retention Policy (MHC-LEG-DRP-001).

  1. How we use your data

We use your personal data strictly for the following purposes:

  • Secure user identification: Your biometric data is used exclusively to authenticate your identity, ensuring that only you can access your profile.
  • Delivering contact actions: The names and phone numbers of your emergency contacts are used solely for the purpose of delivering calls or pre-set messages when the Service is activated.
  • Location sharing: Your What3Words location is shared with your saved emergency contact when the Service is activated.
  • Service operation and improvement: Account and usage data are used to operate the Service, identify and fix bugs, improve performance, and provide technical support. This data is generally analysed in an aggregated and anonymised form.

We do not sell, rent, lease, or share your personal data with any third party for marketing or any other purposes, except as required by law, regulation, legal process, or governmental request.

  1. Where we store your data

At the date of this Policy, the My Home Call Service is offered to users in the United Kingdom only and is distributed exclusively via the UK App Store. All personal data is stored on servers located within the United Kingdom and is subject to UK data protection law throughout its lifecycle.

We operate on the principle of regional data localisation. If and when we expand the Service into additional regions, personal data relating to users in that region will be stored on servers located within that region. We do not pool personal data across regions, and we do not transfer personal data out of the region of the user to whom it relates, except where required by law or to deliver the Service as set out in this Policy. We will update this Policy to disclose the specific regions and the safeguards that apply at the point of any such expansion.

Your personal data is encrypted in transit and at rest. Our infrastructure is operated through carefully selected sub-processors that act on documented instructions from My Home Call. See section 7.

Access to your personal data within the app is controlled by biometric verification on your own device. When you access the Service from a shared or unfamiliar device, no personal data is permanently stored on that device. For security, when accessed from a device other than your primary registered device (or where we detect higher risk access), your information may be visible only for a limited period (for example, up to 15 minutes), after which it automatically becomes inaccessible from that device until re-authenticated.

  1. Consent and your control over your data

We believe you should have complete control over your personal data. You can:

  • Access, review, and manage all of the personal information we hold about you directly within the My Home Call app.
  • Update or delete your personal information, including emergency contacts, at any time through the app’s settings.
  • Withdraw your consent to the collection and processing of your personal data and close your account at any time. Upon account closure, we will delete your personal data in accordance with our Data Retention Policy.

For users under 13, a parent or legal guardian must provide verifiable consent to create and manage the account. The parent or guardian has the ability to review, modify, and delete the child’s personal information. We adhere to the ICO Age Appropriate Design Code (Children’s Code) in our handling of children’s data.

  1. Sharing your data

In the normal operation of the Service:

  • When you trigger the Service, your designated emergency contact will receive a call or pre-set message from you. If location sharing is enabled, your What3Words location will be included.

My Home Call does not directly contact emergency services (999, 911, or equivalents) and does not share your data with them automatically. You should always dial your local emergency number directly in any life-threatening situation.

Where the Service is used at a school, the school does not receive, hold, or have access to any personal data processed through the Service. The school hosts the physical kiosk hardware only.

  1. Sub-processors

To deliver the Service, we use a limited number of sub-processors that operate under contract on documented instructions from My Home Call. These are not third parties acting for their own purposes; they are infrastructure providers acting on our behalf. The categories of sub-processor we currently use include:

  • A cloud hosting provider for our UK servers.
  • What3Words, which generates and shares precise location information when the Service is activated.
  • Tech5, which supports secure biometric verification.
  • Loqate, which supports address verification and data entry during onboarding.
  • Additional biometric authentication API providers, used to support secure identity verification.
  • Telephony and messaging providers, used to deliver calls and messages to your saved emergency contact.

We conduct due diligence on each sub-processor to ensure they meet our data protection requirements and comply with UK GDPR and other applicable laws. We share only the minimum data necessary for the specific function they provide. A current list of named sub-processors will be maintained in a separate Sub-Processor Register and will be made available on request.

  1. Your rights

Under UK GDPR and the Data Protection Act 2018, you have the following rights regarding your personal data:

  • Right of access: to receive confirmation of whether we process your personal data and a copy of that data.
  • Right to rectification: to have inaccurate or incomplete data corrected.
  • Right to erasure (right to be forgotten): to request deletion in certain circumstances.
  • Right to restrict processing: to limit how we use your data in certain circumstances.
  • Right to data portability: to receive your data in a structured, commonly used format.
  • Right to object: to object to certain types of processing, including any processing for direct marketing.
  • Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time.

You can exercise these rights through the app where applicable (for example, accessing, updating, or deleting your information) or by contacting us at hello@myhomecall.com. We will respond to your request in accordance with applicable data protection laws.

If you have a concern about how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection. Details are available at ico.org.uk.

  1. Children’s privacy

My Home Call is designed to be safe for use by children with parental consent, particularly in school settings where the Service is delivered via a kiosk. We adhere to the ICO Age Appropriate Design Code (Children’s Code).

For users under 13, a parent or legal guardian must provide verifiable consent to create and manage the account. The parent or guardian is the account holder and is responsible for the child’s use of the Service. The parent or guardian can review, modify, and delete the child’s personal information at any time.

If we become aware that we have collected personal data from a child under 13 without verifiable parental consent, we will take steps to delete that information as quickly as possible.

  1. Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected, in line with our Data Retention Policy (MHC-LEG-DRP-001). Key points:

  • Biometric template and emergency contact details: retained for the duration of your active account; deleted on account closure (subject to a 30 day grace period for accidental reactivation).
  • Kiosk interaction records: retained for less than 30 days, then permanently deleted.
  • Location data: not retained as a continuous log; transmitted at the moment of Service activation and not stored after transmission.
  • Account information: may be retained for up to 7 years after termination to comply with legal obligations (e.g. tax and accounting).
  • Payment and billing records: retained for up to 7 years from the date of the transaction.

Please see the Data Retention Policy for the full schedule of retention periods.

  1. Security measures

We implement industry standard technical and organisational measures to protect your personal data, including:

  • Encryption of sensitive data in transit and at rest, with particular attention to biometric information.
  • Strict access controls within My Home Call, limiting who can access personal data to those with a need to know.
  • Time limited visibility of personal data on shared or unfamiliar devices, with automatic clearance after the visibility period.
  • Regular security audits and vulnerability assessments of our systems.
  • Data minimisation by design: we only collect what is necessary for the Service.

While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the internet or method of electronic storage is 100% secure. We continuously work to enhance our security measures.

  1. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our Service, our practices, or the law. We will notify you of significant changes via the app or by email to your registered address, and we encourage you to review this Policy periodically.

  1. Contact us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: hello@myhomecall.com

 

By using My Home Call, you acknowledge that you have read, understood, and agree to this Privacy Policy and our Terms of Use.

Want to know more?

Please fill in the form below and we’ll contact you ASAP.