How POPS Notebook collects, uses, and protects your data
POPS Notebook, Inc. ("POPS Notebook", "we", "us") acts as a Data Processor in respect of any personal data processed through the Application. Your police force is the Data Controller for operational data created and used by its officers.
POPS Notebook processes limited account data as a Data Controller for the purposes of authentication, billing, and service delivery. This statement explains what we collect, why, and how we protect it.
We collect and process the minimum data necessary to provide the Application. We operate a Zero-Knowledge architecture: the server cannot decrypt your operational data, officer profiles, or force broadcasts.
The Application employs a layered encryption model designed so that a server breach exposes no decryptable operational data:
We collect data only for the following lawful purposes:
Operational data (rosters, plans, sketches, NDM logs, use-of-force logs, broadcast messages) is retained in ephemeral local cache for a maximum of 24 hours and is never persisted to the cloud.
Account data (username, email hash, force hash, role, qualifications) is retained for the lifetime of your account. You may request deletion of your account at any time, which will permanently remove all associated data from the database.
Audit logs are retained for 12 months to support Information Assurance compliance reviews, as is standard for UK policing audit requirements.
Force license records are retained for the duration of the force's enterprise subscription and for 6 years thereafter for financial audit compliance.
We use the following third-party processors, each acting under their own GDPR-compliant terms:
Sub-processor changes: We commit to providing a minimum of 7 days' written notice to your Force Data Protection Officer prior to engaging any new sub-processor or materially changing the terms of an existing sub-processor arrangement. Forces may raise objections during this notification period. A register of current sub-processors is available on request from info@popsnotebook.co.uk.
As a data subject, you have the following rights:
To exercise any of these rights, contact your Force Data Protection Officer or submit a request through the Application's Settings page. We will respond within 30 days, as required by UK GDPR.
Data portability and off-boarding: Forces retain the right to bulk-export their ForceAdminAudit logs as a CSV report at any time via the Force Admin dashboard. Upon contract termination, forces are provided with a full export of all administrative audit trails and license records. All operational data is ephemeral and device-local — no operational data is held on the server to extract, and all local caches expire automatically within the configured TTL.
The Application does not use tracking cookies or advertising cookies. It uses browser localStorage and sessionStorage for the following purposes:
The Application's hosting platform, database, and serverless compute infrastructure are hosted in United Kingdom data centres. Account data (email hash, force hash, encrypted profile ciphertext) is stored exclusively within the UK and is not transferred to or processed in any third country.
Operational data does not leave the officer's device and is therefore not subject to any transfer. Only account data (hashed identifiers and encrypted ciphertext) is stored on the UK-hosted platform.
Our Zero-Knowledge architecture provides an additional layer of data sovereignty assurance: the server stores zero plain-text PII or operational data. All operational payloads and officer profiles are AES-GCM encrypted on-device before transmission. The server functions as a zero-knowledge relay — it stores only opaque ciphertext blobs and irreversibly hashed identifiers. A database breach, regardless of the geographic location of the servers, exposes no decryptable personal data or operational intelligence.
Our sub-processors (Stripe and SendGrid) operate their own infrastructure which may be located outside the UK. Where any sub-processor transfers personal data internationally, we rely on Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum to ensure a level of data protection equivalent to UK GDPR. Sub-processor data processing is limited to payment processing (Stripe) and transactional email delivery (SendGrid); no operational data or officer profiles are shared with sub-processors.
If you have any questions about this Privacy Statement or how your data is handled, please contact your Force Data Protection Officer or reach out to POPS Notebook support through the Application's Settings page.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data in accordance with UK GDPR.