CPAS (Common Position Awareness System) is operated by VIDEAR Ltd, a company registered in England and Wales. We build safety technology for leisure users — kayakers, sailors, paramotor pilots, wild swimmers, hill walkers, and others — making them visible to rescue services in real time.
VIDEAR Ltd is the Data Controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We collect only what is necessary to operate the CPAS safety tracking service.
| Data Type | What It Is | Why We Need It |
|---|---|---|
| Identity | Full name, date of birth, nationality, mobile number, email address | SAR identity — rescue services need to know who they are searching for |
| Location | GPS coordinates, heading, speed, altitude — collected every 30–60 seconds during an active session | Core safety function — broadcast your position to Token Holders and rescue services |
| Activity | Activity type (kayak, sailing, etc.), equipment, club affiliation, planned route | Contextualises your session for SAR coordinators |
| Session Data | Session ID, start time, planned return time, departure location | Enables overdue detection and watchdog alerting |
| Token Holders | Name, mobile number, email, relationship of up to 3 nominees | Alert contacts when you activate, extend, or are overdue |
| Device Data | Battery level, network type (4G/WiFi), device OS version | Assesses reliability of your safety connection |
| Profile Photo | A photo you upload voluntarily | Visual identification for SAR coordinators on the Super User Interface |
CPAS collects your precise location and physical activity data in the background — including when the app is closed or not in use — during an active session only.
Background location is used exclusively to:
Background location data is never used for advertising, analytics, or any commercial purpose.
| Purpose | Legal Basis (UK GDPR) |
|---|---|
| Broadcast your position to Token Holders during a session | Legitimate interests — user safety; Consent |
| Display your position to authorised SAR coordinators (RNLI, Coastguard) | Legitimate interests — public safety |
| Send overdue alerts to Token Holders when you don't return | Legitimate interests — user safety; Consent |
| Provide session history and activity statistics to you | Contract performance |
| Improve the CPAS service | Legitimate interests — aggregated, anonymised data only |
| Comply with legal obligations | Legal obligation |
We do not sell your data. We share it only as follows:
| Recipient | What They See | Why |
|---|---|---|
| Your Token Holders | Your name, position, session status, tracking URL | Core safety function — they monitor your session |
| RNLI / HM Coastguard / SAR coordinators | Your C-ID card, position, session data | Search and rescue operations only |
| Club Commodores (if affiliated) | Your position within club corridor only | Club safety monitoring — role-scoped view |
| AWS (Amazon Web Services) | Encrypted session and position data | Cloud infrastructure — UK region only (eu-west-2 London) |
| BulkSMS | Mobile number and alert message text only | UK SMS delivery for overdue alerts |
| Firebase (Google) | Email, name, authentication data | User authentication and profile storage |
| Data | Retention Period |
|---|---|
| Live session position pings | Retained for 90 days after session close, then deleted |
| Session records (metadata) | 12 months, then anonymised for aggregate statistics |
| Profile and identity data | For the duration of your account, deleted on account closure |
| Token Holder contact details | For the duration of your account, deleted on account closure |
| SAR incident data | 7 years — legal obligation for safety records |
You have the following rights regarding your personal data:
To exercise any right, email privacy@videar.tech. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
All data in transit is encrypted using TLS 1.3. Position pings are transmitted via MQTT over SSL/TLS (port 8883) to AWS IoT Core. Data at rest is encrypted in AWS DynamoDB and Firebase using AES-256.
Access to the Super User Interface (SAR coordinator dashboard) is role-scoped and requires authenticated login. Club commodores see only their own members within their geographic corridor. No user can see another club's data.
We conduct regular security reviews and promptly address any identified vulnerabilities. If you discover a security issue, please report it to security@videar.tech.
CPAS is not intended for users under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has registered without parental consent, please contact us at privacy@videar.tech and we will delete the account immediately.
Users aged 16–17 may use CPAS with parental or guardian consent.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via the app and update the effective date at the top of this page. Continued use of CPAS after notification constitutes acceptance of the updated policy.
Previous versions of this policy are available on request by emailing privacy@videar.tech.
For any privacy-related questions, data subject requests, or concerns: