Legal
How we collect, use and protect the personal data you share with us.
Last updated: 29 July 2026
Sesto Group B.V. respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, why we collect it, the legal bases we rely on, how long we keep it, who we share it with, and the rights you have under the General Data Protection Regulation (GDPR).
Sesto Group B.V. ("Protrix", "we", "us", "our") is the controller responsible for the personal data described in this policy, except where we act as a processor on behalf of a business client (see "Our role: controller and processor" below).
This policy applies to our website, our platform (web application and back-end services) and our guard mobile app. Access to the platform is invite-only; we provision accounts for our business clients and their authorised personnel, and there is no public sign-up. This policy does not cover third-party websites or services that we link to but do not control.
Depending on how you interact with us, we may collect the following categories of personal data:
We collect personal data:
We process personal data for the purposes below, relying on the legal bases set out for each under Article 6 of the GDPR:
Protrix is a platform. The companies that use it to run escort missions are our customers, and most of the personal data on the platform belongs to them rather than to us. Which of us is responsible for a given piece of data depends on why it is there, so this section sets that out plainly.
We are the controller for our website, for the administration of platform accounts, for billing our customers, and for keeping the platform secure and free from abuse. For those purposes we decide how and why personal data is processed, and the rest of this policy describes what we do.
We are a processor for the operational data a customer runs through the platform and the guard app to carry out its own missions: the missions themselves, routes, evidence, messages and location trails. We handle that data on the customer’s documented instructions, under a written data-processing agreement. For that data the customer is the controller, and it is the customer who decides what is collected and who decides how long it is kept.
A third party is often involved. Guards are usually employed by subcontractor organisations rather than by the customer or by us. Where a piece of processing exists so that an employer can supervise its own staff (most clearly the recording of a guard’s route to and from a job, as opposed to the escort itself), that employer is the controller for it, and the obligations that come with monitoring staff are theirs. The platform will not record those parts of a route until the employer has confirmed it has met them.
What this means if you want to exercise a right. You can always write to us and we will help. But where the data relates to a mission run by one of our customers, that customer is the controller, and we may need to pass your request to them, or ask them to instruct us, before we can act. Where it relates to your employer’s supervision of you as a member of its staff, your employer is the controller and the request belongs with them. We will tell you which applies rather than leaving you to guess.
The guard mobile app collects location in two separate ways. Both of them run in the background, which means the app keeps collecting your position while it is closed or not in use. Neither of them runs outside the windows described here.
The mission trail. From the moment a mission is dispatched, which is when you set off towards the pickup point, until the mission is closed after you are back at base, the app records your position about once every 30 seconds. It records even when you are standing still, because a gap in the trail would otherwise look identical to a broken recorder. This tracking is meant to be visible: an ongoing notification is shown on your device for as long as it runs, and it stops as soon as the mission ends. The trail is used to show the route that was actually driven, to document the mission, and to measure the distance of the escort itself.
Duress alarms. While a duress alarm is open, the app streams your position about once every 15 seconds to the security operations centre so that they can find you and send help. This stops as soon as the operations centre closes the alarm. For a silent alarm, the ongoing notification your device shows is deliberately worded so that it does not reveal to anyone looking at your screen that a location is being shared. That is a safety decision, and it is exactly why this sharing is set out here, and in the app before you first use it, rather than being left to the notification.
Your position is also recorded at specific moments, rather than continuously:
Location permission is asked for in two steps: permission to use your location while the app is open, and permission to keep using it in the background. You can refuse either one, and you can withdraw both later in your device settings.
Refusing does not lock you out of the app, and it never stops you completing a mission step. What it means is that your events are recorded without a position. If you allow location only while the app is open, the mission trail stops being recorded whenever you put the app away. If you refuse location outright, no trail is recorded at all. Your employer may treat either as incomplete mission documentation.
Where the law of your country treats workplace location monitoring as something to be agreed with employee representatives, that is a matter between you and your employer, who provisions your account and decides how the platform is used.
Guard location is deliberately not visible to everyone who uses the platform. The rules below are enforced by the database itself, not only by what an app chooses to display:
Photos taken as mission evidence, which includes the pickup and drop-off checklists, stop photos, check-ins, incident photos and expense receipts, can only be taken with the camera inside the app. You cannot substitute a picture from your photo library for mission evidence.
Chat is different. When you attach something to a chat message or to a technical support request, you can use the camera, choose an image from your device photo library, or attach any other kind of file. Please attach only what the mission needs. Files other than evidence photos are uploaded exactly as they are, so anything inside them, including any information the file itself carries about where or when it was made, is uploaded with it.
Evidence photos are re-encoded when they are taken and stamped with the time, an optional short note, and the coordinates. Chat attachments are not stamped.
Photos and files uploaded as mission evidence are visible to our staff, to your employer, and to the customer organisation for the mission they belong to. Chat attachments are visible to the people in that conversation. All of it is held by a specialist object-storage provider in the Netherlands rather than on our application server.
The platform is used across borders, so messages are translated automatically into the language each recipient reads. To do this, the text of the message is sent to an external artificial-intelligence provider that runs a large language model, which returns the translation. That provider may in turn route the request onward to a further model provider.
This applies to mission conversations, one-to-one messages, incident and duress messages and support messages. It happens whenever a message is sent, and for guards it is always on. It applies to the text of the message, not to its attachments.
We are telling you this plainly because it is a real transfer of message content to a third party, and because that provider may operate outside the European Economic Area. See "International transfers and data residency" below.
We require that provider to route messages only to model providers that do not store the message text and do not use it to train their models. That is a routing restriction we set on every request, not a promise we ask you to take on trust.
Messages are stored in readable form on our servers. That is necessary because they form part of the mission record and because translation requires it, and it means they are not end-to-end encrypted. They are encrypted in transit and are subject to the access controls described in this policy. Please keep messages to what the mission needs, and do not put personal information into a message that the mission does not require.
The guard app shows maps. On Android these are Google Maps, which means the map provider receives your device network address and the coordinates of the area shown on your screen in order to draw the map. On iPhone the app uses Apple Maps instead.
Separately, when someone on the platform views a recorded mission trail matched to the road network, our server sends the recorded coordinates of that trail to Google’s Roads service, which returns the same route aligned to the roads. This is a transfer of recorded guard location to a third party, and we disclose it for that reason.
The web platform also uses Google services to look up addresses, to suggest addresses while an operator types into an address field, and to calculate planned routes. That happens on the web platform and not in the guard app.
The guard app and the platform report unexpected errors so that we can find and fix them. This is switched on in the version of the app we publish. A report contains the technical detail of the failure: the type of error, its message, the internal stack trace, and the app version, component and language in use.
These reports go to our own error-tracking system, running on our own infrastructure. They are not sent to an outside analytics company.
We do not deliberately attach your name, email address or account identifier to an error report. We also do not filter what an error message contains, so if a failure happens while the app is handling a piece of your data, that data can appear inside the technical detail of the report. Error reports are used only to diagnose and fix faults.
You can switch on fingerprint or face unlock as a second lock on top of your password. If you do, the check is performed entirely by your device operating system. The app asks the device to verify you and receives nothing back except a yes or a no.
No fingerprint, face scan, template or any other biometric information is ever read by the app, stored by us, or transmitted anywhere. The only thing kept is a setting on your own device recording that the lock is switched on. Your device passcode stays available as a fallback, so a failed reading cannot lock you out of your work.
This is worth stating plainly. The guard mobile app contains no analytics software, no usage-tracking software and no advertising software of any kind. It does not read your device advertising identifier, it does not build a device fingerprint, and it does not profile you.
We do not sell personal data, we do not share personal data for advertising, and we run no advertising or third-party marketing trackers on our website or platform either.
Our website and platform use only the cookies needed to function, such as keeping you signed in, maintaining your session and remembering your language preference. We do not use advertising or third-party marketing trackers. For full details, see our Cookie Policy.
The guard mobile app does not use cookies, but it does store data on your device so that it can work where there is no signal: your signed-in session, an encrypted queue of actions waiting to be sent, and a short-lived copy of recently viewed mission data. Signing out clears your session and the queued actions. The short-lived copy expires by itself within a day, and removing the app deletes everything the app has stored.
We do not sell your personal data, and we do not share it for advertising. We share it only as far as needed to provide the Services and to meet our obligations, with:
Our platform, its database, and the storage that holds uploaded photos and files are hosted in the European Union.
Some of the third-party services described above are operated from outside the European Economic Area, or may route a request onward to a provider outside it. This applies in particular to the automatic translation of messages, the delivery of push notifications to your device, and the mapping and route-matching services. Where a transfer of personal data outside the European Economic Area takes place, we put in place appropriate safeguards, such as the European Commission’s Standard Contractual Clauses.
We keep personal data for as long as it is needed for the purposes described in this policy, and for as long as the law and our clients’ own record-keeping obligations require. Records that document a transport mission that has already been carried out are kept for the duration of our agreement with the client concerned and for any retention period that applies to them by law.
We would rather describe what actually happens than publish a schedule we do not enforce. So there is one automatic deletion we can point to, and we do not claim any others:
You can ask us to delete your account and the personal data behind it. There is a separate page that explains how to make the request and exactly what happens: see our Account and Data Deletion page. In summary, once we have verified the request:
We apply technical and organisational measures designed to protect personal data, including:
Under the GDPR, and subject to certain conditions, you have the right to:
Write to us at support@protrix.global, or use the options built into the products. In the guard app, open Account and tap Delete account. On the web platform, open Settings, then Account and privacy, where you can request deletion or ask for a copy of your data. Every request is verified before we act on it, because accounts are provisioned by employers and these actions cannot be undone.
Where the data relates to a mission run by one of our customers, that customer is the controller, and we may need to pass your request to them, or ask them to instruct us, before we can act.
Where it relates to your employer’s supervision of you as a member of its staff, your employer is the controller and the request belongs with them.
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Some platform features, such as the automatic translation of mission messages into the recipient’s language, use automated processing to support, not replace, human decisions. Reports about content or behaviour are reviewed by a person, never decided by software alone.
Our website, platform and Services are intended for businesses and their personnel and are not directed at children. We do not knowingly collect personal data from children.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal obligations. We will post the updated policy with a revised "last updated" date and, where changes are material, take reasonable steps to notify you.
To exercise any of your rights, or for any questions about this policy, contact us at support@protrix.global or by post at Sesto Group B.V., Sikkel 40B, 3274 KK Heinenoord, the Netherlands. Where the operational data relates to a mission run by one of our business clients, that client is the controller and we may direct your request to them.
If you are in the Netherlands and believe we have not handled your data properly, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl). You may also contact the supervisory authority in your own country.