Data controller (account data) / processor (operational & patient data): MKCIT LIMITED
MKCIT LIMITED ("we", "our", "us") operates First Responder ("the Service") — a digital platform for event operations, incident-response coordination, workforce/resource management, and (where used by medical providers) clinical record-keeping. First Responder is a trading style of MKCIT LIMITED; our other trading styles are operated by the same legal entity.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
| Legal entity | MKCIT LIMITED, registered in England and Wales |
| Company number | 16953736 |
| Registered office | 9 Hatfield Court, Reading, RG31 7AL |
| VAT number | GB 512 4344 28 |
| ICO registration | ZC116358 |
| Privacy contact | privacy@eventris.uk |
You can reach our privacy team, including for any data-protection enquiry, at privacy@eventris.uk.
2. Our two roles — controller and processor
The Service handles two distinct categories of data, and our legal role differs for each.
a. Where MKCIT LIMITED is the controller — we decide why and how this data is processed:
- user accounts, names, email addresses, and login credentials;
- organisation memberships and subscription/billing information;
- support requests;
- device registrations and push-notification (FCM) tokens;
- security, audit, and platform-protection logs.
b. Where MKCIT LIMITED is the processor — we process this data only on the documented instructions of the client organisation (for example a medical provider, security company, or event organiser), which is the controller:
- patient and incident records;
- clinical observations and health information;
- operational notes and response actions;
- location records generated by responders during an operation.
The client organisation owns and controls these records. If you are a member of the public who was attended to at an event and wish to access or query your record, please contact the organisation that attended you; we will assist that organisation as its processor. Client organisations may export their records at any time, and the records remain theirs if they stop using the Service.
3. Information we process
- Account & identity data — name, email, phone number, login credentials, professional registration body/number (where provided).
- Subscription & billing data — plan, organisation, billing details.
- Operational data — events, incidents, response actions, notes, and other records created while using the Service.
- Location data — a responder's device location, shared with their control room only while they are signed in to an active operational shift (see §4c).
- Health & special-category data — where a client is a medical provider, patient identity and clinical information (e.g. observations such as whether a person is breathing, conscious, or able to walk; and, on clinical builds, fuller patient records). See §5.
- Photos — images of inventory/stock items (and, on clinical builds, clinical images) captured via the device camera/library.
- In-app messages — operational chat and notes.
- Device & technical data — push-notification token, and technical information needed to deliver the Service.
We do not collect advertising identifiers, contacts, browsing history, or behavioural/analytics telemetry, and we do not use the camera/microphone for anything beyond the documented features.
4. Our lawful bases (UK GDPR Article 6)
a. Providing the Service — Article 6(1)(b) (contract). We process account, identity, subscription, and operational data because it is necessary to provide the Service you (or your organisation) have signed up for.
b. Security, audit & platform protection — Article 6(1)(f) (legitimate interests). We process security logs, audit trails, and technical data to keep the Service secure, prevent abuse, and maintain operational integrity. Our legitimate interest is the security and reliability of a safety-critical system; this is balanced against your rights and does not override them.
c. Responder location — Article 6(1)(f) (legitimate interests). Where enabled by the operating organisation, a responder's location is shared with their control room so resources can be coordinated and responder welfare monitored at large event sites — the digital equivalent of responders reporting their position by radio. We rely on legitimate interests rather than consent because withdrawal mid-incident would create operational and safety risks. Location is collected only while the responder is signed in to an active operational shift, runs with a persistent on-screen notification, and can be controlled through operating-system permissions.
5. Health & special-category data (UK GDPR Article 9)
The Service is also available to non-medical organisations (security, stewarding, traffic management, event organisers), who use it to record operational incidents (e.g. welfare, safeguarding, lost children, crowd-management or security incidents) — not health data.
Where a medical provider uses the Service to support its response to medical incidents at events, the records may include health data about patients. For that processing, in addition to an Article 6 basis we rely on:
- Primary — Article 9(2)(h): processing necessary for the provision of health or social care, by or under the responsibility of a health professional (here, the operating medical provider and its clinicians), together with the corresponding condition in DPA 2018 Schedule 1.
- Fallback — Article 9(2)(c): processing necessary to protect the vital interests of a patient who is physically incapable of giving consent (e.g. an unconscious casualty in an emergency).
6. Who we share data with
We do not sell personal data, use it for advertising, or share it for any third party's own purposes. We share data only with:
- The client organisation and its authorised users (for the records they control).
- Sub-processors acting on our instructions:
- Google (Firebase Cloud Messaging) — to deliver push notifications. The notification payload carries no patient, health, or message content (only a generic notice and identifiers).
- UK-based infrastructure provider — UK-based application and database hosting with UK data residency.
- Authorities or regulators where we are legally required to do so.
7. International transfers
The Service is hosted in the United Kingdom with UK data residency, and our real-time messaging is self-hosted. The only routine processing outside the UK is push-notification delivery via Google (Firebase Cloud Messaging), which may involve Google entities outside the UK, subject to Google's applicable transfer mechanisms and safeguards.
8. How long we keep data
- Account & user data (where we are controller): for the life of the account, and for a reasonable period afterwards to meet our legal, tax, and security obligations.
- Patient & clinical records (where we are processor): retention is the client organisation's responsibility as controller. The Service applies, by default, a minimum retention period aligned with NHS guidance — the later of (a) 8 years from the record's creation or (b) the patient's 25th birthday — and allows the controlling provider to configure a longer period where required by its own legal or regulatory obligations. We act on the controller's instructions and do not delete clinical records before the applicable period has elapsed.
9. How we keep data secure
We apply security measures appropriate to the sensitivity of the data, including:
- encryption in transit (TLS) for all connections;
- encryption at rest on the device for cached personal and health data (SQLCipher / AES-256), with the encryption key held in the device's hardware-backed secure storage (iOS Keychain / Android Keystore) and never embedded in the app;
- encryption of patient identifiers at the server level, and encrypted storage of any uploaded documents at rest;
- role-based access controls and account/operation-scoped permissions;
- audit logging of access to records.
10. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and to data portability, and to lodge a complaint with the Information Commissioner's Office (ICO) — ico.org.uk.
Where MKCIT is the controller (account data), contact us at privacy@eventris.uk. Where MKCIT is the processor (patient/operational records), please direct requests to the client organisation that controls those records; we will support that organisation in responding.
You can delete your account — and the personal data we hold as controller — at any time from within the app, or by contacting privacy@eventris.uk.
11. Children
The Service is for use by professional/vetted users and is not directed at children. Records created by client organisations may relate to children (e.g. a child attended to at an event); that data is processed by, and is the responsibility of, the controlling organisation.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified through the Service, and the current version and effective date are always shown at the top of this page.
13. Contact
MKCIT LIMITED, 9 Hatfield Court, Reading, RG31 7AL — privacy@eventris.uk (ICO registration ZC116358).