Privacy Policy

MyHeroID
Effective date: 29 September 2026

1. Introduction

MyHeroID ("we", "our" or "us") is committed to protecting and respecting your privacy.

This Privacy Policy explains how we collect, use, store, share and protect your personal information when you use the MyHeroID platform, website, emergency profile services, QR-linked identification products and related Hero Network services.

We process personal data in accordance with:

  • the UK General Data Protection Regulation ("UK GDPR");
  • the Data Protection Act 2018; and
  • the Privacy and Electronic Communications (EC Directive) Regulations 2003 ("PECR"), where applicable.

Please read this Privacy Policy carefully to understand how your personal information is handled.

2. Data Controller

The data controller responsible for your personal information is:

MyHeroID
MyHeroID
United Kingdom

Email: privacy@myheroid.co.uk

Where MyHeroID processes personal information on behalf of a partner organisation, separate data protection responsibilities may apply. These responsibilities will be communicated where relevant.

3. Information We Collect

Account information

When you create or manage an account, we may collect:

  • your name;
  • your email address;
  • your username;
  • secure password credentials;
  • your account and subscription status; and
  • communication preferences.

Passwords are protected using secure password-management methods and are not intended to be stored or displayed in readable plain-text form.

Emergency profile information

You may voluntarily choose to provide information such as:

  • medical conditions;
  • allergies;
  • medications;
  • blood group;
  • emergency information;
  • care instructions;
  • ICE contact details;
  • Guardian details; and
  • other information you choose to add to an emergency profile.

Some emergency profile information may constitute special category personal data under the UK GDPR because it reveals information about an individual's health.

You control the information entered into the profile and, subject to the functionality provided by the service, which information is made visible through emergency access.

Information about ICE contacts and Guardians

If you provide information about another person, such as an ICE contact or Guardian, you should ensure that you have a lawful reason to provide their information and that they understand how their information will be used.

Product and identifier information

We may collect and process:

  • unique identifier numbers;
  • QR code registrations;
  • identifier activation records;
  • product ownership or assignment records;
  • membership and plan information; and
  • digital or physical asset information.

Usage, technical and security information

We may collect information including:

  • login and authentication records;
  • IP addresses;
  • browser and device information;
  • security events;
  • QR scan events;
  • emergency access events;
  • account activity;
  • notification activity; and
  • administrative and audit records.

Transaction information

Where you purchase a product, membership or subscription, we may process order information, billing details, transaction references, payment status and delivery information.

Payment card information may be collected directly by our payment service provider. MyHeroID does not need to receive or retain full payment card details where payment is handled by that provider.

Communications and support information

If you contact us, we may retain your message, contact details, support history and any information you provide in connection with your enquiry.

4. How We Collect Information

We may collect personal information:

  • directly from you when you register or update an account;
  • when you create or update an emergency profile;
  • when you activate or assign a MyHeroID identifier;
  • when an identifier is scanned;
  • when you purchase a product or subscription;
  • when you contact us or request support;
  • through website forms and account controls;
  • through cookies and similar technologies; and
  • through operational, security and audit logs.

5. Lawful Bases for Processing

Under the UK GDPR, we must have a lawful basis for processing personal information. The lawful basis will depend on the information concerned and the reason it is being processed.

Performance of a contract

We may process personal information where it is necessary to enter into or perform a contract with you, including:

  • creating and managing your account;
  • activating and maintaining identifiers;
  • providing purchased products and services;
  • administering subscriptions or memberships; and
  • providing account and customer support.

Consent

We may rely on your consent where you:

  • provide optional emergency profile information;
  • provide health-related information;
  • enable an optional location or notification feature;
  • agree to receive electronic marketing communications; or
  • enable another optional service that requires consent.

Where consent is the lawful basis, you may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn.

Legitimate interests

We may process personal information where necessary for our legitimate interests, or those of another person, provided those interests are not overridden by your rights and freedoms.

These interests may include:

  • protecting accounts and platform security;
  • preventing and investigating fraud or misuse;
  • maintaining audit and security records;
  • operating and improving the service;
  • responding to support enquiries; and
  • establishing, exercising or defending legal claims.

Legal obligation

We may process information where necessary to comply with a legal or regulatory obligation.

Vital interests

In limited circumstances, personal information may be processed where this is necessary to protect someone's life and the person is physically or legally incapable of giving consent.

6. Special Category Data

Emergency profile information may include health information and may therefore constitute special category personal data under the UK GDPR.

Where we process health information, we will identify both a lawful basis under Article 6 of the UK GDPR and an additional condition under Article 9.

For optional health information intentionally added to a MyHeroID profile, we will generally rely on the user's explicit consent. Where applicable, processing may also be necessary to protect vital interests in circumstances where the individual is physically or legally incapable of providing consent.

You may remove or update optional health information through the available profile controls, subject to any information we must retain for legal, security or evidential purposes.

7. How We Use Your Information

We may use personal information to:

  • create, authenticate and maintain your account;
  • provide emergency profile functionality;
  • display information authorised for emergency access;
  • activate and manage QR-linked identifiers;
  • send scan, access, security or service notifications;
  • process purchases, subscriptions and renewals;
  • administer your membership or plan entitlements;
  • provide customer and technical support;
  • detect, investigate and prevent fraud or misuse;
  • maintain security and audit records;
  • improve the reliability and functionality of the platform;
  • comply with legal obligations; and
  • establish, exercise or defend legal claims.
We do not sell your personal information. We do not permit service providers to use your information for their own unrelated marketing purposes.

8. Emergency Access

MyHeroID is designed to allow selected emergency information to be accessed when a registered identifier is scanned.

When an identifier is scanned:

  • the identifier may be validated;
  • applicable access and visibility controls are applied;
  • information configured for emergency display may be presented;
  • the access or scan event may be recorded; and
  • notifications may be issued in accordance with the account settings and available plan features.

Information configured for emergency display should be treated as information that may be viewed by any person who scans or otherwise obtains access to the relevant identifier.

You should not make information visible through emergency access unless you are comfortable with it being viewed for the intended emergency purpose.

9. How We Share Information

We may share personal information only where reasonably necessary and where a lawful basis applies.

Service providers

We may use trusted service providers that supply services such as:

  • website and database hosting;
  • cloud infrastructure;
  • email delivery;
  • SMS delivery;
  • payment processing;
  • website analytics;
  • security monitoring; and
  • technical support systems.

Where a provider acts as our processor, it may process personal information only on our documented instructions and must apply appropriate data protection and security safeguards.

Emergency profile viewers

Information you configure for emergency visibility may be displayed to a person who scans or accesses the relevant identifier.

Professional advisers

We may disclose information to professional advisers such as solicitors, accountants, insurers or security specialists where reasonably necessary.

Legal and regulatory authorities

We may disclose information where required by law, court order, regulatory requirement or another lawful request.

Business changes

If MyHeroID or relevant business assets are sold, transferred or reorganised, personal information may be disclosed to appropriate parties as part of that process, subject to applicable data protection requirements.

10. International Transfers

Some service providers may process personal information outside the United Kingdom.

Where a restricted transfer takes place, we will use an appropriate safeguard recognised under UK data protection law. This may include:

  • an adequacy regulation;
  • the UK International Data Transfer Agreement or an approved UK Addendum;
  • another lawful transfer mechanism; and
  • additional technical, contractual or organisational safeguards where required.

11. Data Security

We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, disclosure or access.

Security measures may include:

  • encryption of sensitive stored information where appropriate;
  • secure password handling;
  • role-based permissions and capability controls;
  • restricted administrative access;
  • input validation and output escaping;
  • secure handling of credentials and API keys;
  • activity and audit logging;
  • security monitoring;
  • software maintenance and vulnerability management;
  • backup and recovery controls; and
  • incident investigation procedures.

Access to personal information is restricted to people and service providers that have a legitimate need to access it.

No internet-based service can guarantee absolute security. You are responsible for keeping your account password confidential and for contacting us if you suspect unauthorised account access.

12. Data Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including the provision of services and compliance with legal, accounting, security and reporting obligations.

Retention periods may depend on factors including:

  • the type and sensitivity of the information;
  • whether your account or membership remains active;
  • the duration of our contractual relationship;
  • security and fraud-prevention requirements;
  • applicable statutory limitation periods; and
  • legal or regulatory obligations.

When personal information is no longer required, it will be deleted, anonymised or securely isolated, as appropriate.

Backup copies may continue to exist for a limited period until they are overwritten or securely removed through the normal backup cycle.

13. Your Data Protection Rights

Depending on the circumstances, you may have the right to:

  • be informed about how your information is used;
  • request access to your personal information;
  • request correction of inaccurate or incomplete information;
  • request erasure of your personal information;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive certain information in a portable format;
  • withdraw consent where processing is based on consent; and
  • object to decisions based solely on automated processing where applicable.

These rights are not absolute. A request may be limited or refused where an exemption or another lawful reason applies.

To exercise a right, contact us at privacy@myheroid.co.uk privacy@myheroid.co.uk .

We may request information necessary to verify your identity before responding. We will normally respond within one month, although the law permits an extension for complex or numerous requests.

14. Complaints

If you have concerns about how we use your information, please contact us first so that we can investigate.

You also have the right to complain to the Information Commissioner's Office ("ICO"), the UK's data protection regulator.

Information about raising a concern is available on the https://ico.org.uk/make-a-complaint/ ICO complaints website .

15. Marketing Communications

Where permitted by law, and where any required consent has been obtained, we may send information about:

  • MyHeroID product updates;
  • new or updated Hero Network services;
  • special offers; and
  • relevant news or promotional information.

You may unsubscribe from marketing at any time by using the unsubscribe link in the message or by contacting us.

You may still receive essential service communications, including account, security, transaction, subscription and operational notices.

16. Cookies and Similar Technologies

MyHeroID may use cookies and similar technologies to:

  • provide essential website functionality;
  • maintain secure login sessions;
  • remember preferences;
  • protect accounts and prevent misuse;
  • measure website performance; and
  • understand how the website and services are used.

Non-essential cookies will be used only where permitted by law and, where required, after consent has been obtained.

Further information should be provided in the MyHeroID Cookie Policy and cookie consent controls.

17. Children's Information

A parent, legal guardian or properly authorised representative may create and manage a MyHeroID profile for a child where the service permits this.

The person creating or managing the profile must have the authority to provide the child's information and must consider the child's best interests when deciding what information should be stored or made visible during emergency access.

Additional consent and age-verification arrangements may apply where an online service is offered directly to a child.

18. Information About Other People

If you provide personal information about an ICE contact, Guardian, family member or another person, you are responsible for ensuring that:

  • the information is accurate;
  • you have a lawful reason to provide it;
  • its use is appropriate for the intended purpose; and
  • the person has been given relevant information about how their data may be used, where required.

19. Automated Decision-Making

MyHeroID does not intend to make decisions that produce legal or similarly significant effects about users solely through automated processing.

If this changes, we will provide appropriate information about the logic involved, the significance of the processing and the rights available to affected individuals.

20. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes to our services, legal requirements or data protection practices.

The latest version will be published on the MyHeroID website. Where appropriate, we may also notify registered users of significant changes through their account or by email.

The effective date displayed at the beginning of this policy shows when the current version took effect.

21. Contact Us

For privacy, data protection or UK GDPR enquiries, please contact:

Privacy Officer
MyHeroID
[Insert legal business or proprietor name]
[Insert registered or correspondence address]
United Kingdom

Email: privacy@myheroid.co.uk privacy@myheroid.co.uk
Built in Breakdance

Share with