This Privacy Policy explains how SaferSite ("we", "us", "our"), operated at safersite.app, collects, uses, stores, and protects your personal data. We are committed to protecting your privacy and processing your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For questions about this policy or to exercise your data rights, contact steve@safersite.app.
We collect the following categories of information:
Account and organisation data. When you register, we collect your full name, work email address, job title/role, phone number (if provided), company name, and registered address. This information is used to set up and verify your account.
RAMS documents. You upload Risk Assessments and Method Statements (RAMS) for compliance review. These documents may contain personal data such as names of responsible persons, subcontractor details, and site personnel information.
Site data.For each construction site you add, we collect the site name, address, postcode, GPS coordinates, nearest A&E hospital details, client information, and site-specific configuration such as active RAMS and standards.
Usage data. We automatically collect information about how you use the Platform, including login times, features accessed, pages viewed, actions taken (such as reviews initiated, approvals given), browser type, and IP address.
Payment data. When you subscribe to a paid plan, payment information is collected and processed by our payment providers (Stripe and GoCardless). We do not store your full card details on our servers. We retain billing records including invoice amounts, dates, and payment status.
Communications. If you contact us via email or through the Platform, we retain the content of those communications.
We use your information for the following purposes:
Under UK GDPR, we process your personal data on the following legal bases:
Performance of a contract (Article 6(1)(b)). Processing your account data, RAMS documents, and site information is necessary to provide you with the SaferSite service under our Terms of Service.
Legitimate interests (Article 6(1)(f)). We process usage data and aggregated analytics to improve the Platform and maintain security. We have assessed that these interests do not override your rights and freedoms.
Legal obligation (Article 6(1)(c)). We retain certain records (such as audit trails and financial records) where required by law or regulation.
Consent (Article 6(1)(a)). Where we rely on consent for any specific processing activity, we will clearly ask for your consent at the time and you may withdraw it at any time by contacting us.
We take the security of your data seriously and implement measures aligned with ISO 27001 information security standards.
UK cloud infrastructure. Your data is stored and processed on Microsoft Azure infrastructure in the UK South (London) region. RAMS documents are stored in private cloud storage that is not publicly accessible — all document access is proxied through our authenticated server.
Encryption. All data is encrypted at rest and in transit using industry-standard encryption (TLS 1.2+ for data in transit, AES-256 for data at rest).
Access controls.The Platform implements organisation-level data isolation, meaning your data is strictly separated from other organisations' data at the database level. All queries are scoped to your organisation and site. Role-based access controls ensure users can only access data appropriate to their role.
Audit logging. Every significant action on the Platform is recorded in a comprehensive audit trail, including who performed the action, when, and what was changed. This supports both security monitoring and regulatory compliance.
Authentication. User sessions are managed via a secure, httpOnly session cookie. Passwords are hashed using industry-standard algorithms. We support email verification for new accounts.
SaferSite provides automated compliance review of RAMS documents. This section explains how your documents are processed.
Automated review.When you submit a RAMS document, it is analysed against UK health and safety regulations, your organisation's corporate standards, and your site-specific rules. The resulting compliance findings are stored within your SaferSite account.
Your documents remain yours. This is a firm commitment. Your RAMS documents, site data, corporate standards, and any other content you upload are never shared with other organisations, used for any purpose other than providing the service to you, or made publicly available. Documents are processed solely for the purpose of generating compliance findings for your account.
Data minimisation. Only the document content necessary for compliance review is processed. Account metadata such as billing information is not included in document processing.
Organisational learning.When your reviewers provide feedback on findings, SaferSite learns your organisation's preferences and standards over time. This learning is private to your organisation and is never shared with other users or organisations.
Review findings. Compliance scores, findings, and recommendations are stored in your account and are accessible only to authorised users within your organisation.
We retain your data according to the following schedule:
Active accounts. While your subscription is active, we retain all account data, RAMS documents, review findings, site data, and usage data necessary to provide the service.
Cancelled accounts. When your account is cancelled or terminated, you have 30 days to request an export of your data. After the 30-day period, we will delete your account data, RAMS documents, and site data.
Audit trail records. Audit trail data (who did what, when) is retained for 7 years from the date of the action, in line with regulatory requirements for construction health and safety records. This applies even after account cancellation.
Financial records. Billing and payment records are retained for 7 years in accordance with HMRC requirements.
Anonymised data. Aggregated, anonymised usage statistics that cannot identify you or your organisation may be retained indefinitely.
Under UK GDPR, you have the following rights regarding your personal data:
How to exercise your rights. You can exercise any of these rights by emailing steve@safersite.app. Organisation administrators can also submit data requests through the Platform Admin area. We will respond to your request within one month, as required by UK GDPR. In complex cases, we may extend this by a further two months, and we will inform you if this is necessary.
Right to complain.If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
SaferSite uses a minimal, privacy-respecting approach to cookies.
Session cookie (essential). We use a single httpOnly session cookie called ss-session to authenticate your sessions securely. This cookie is strictly essential for the Platform to function and cannot be disabled. It is set when you log in and removed when you log out or when your session expires.
Analytics. We use privacy-first, cookieless analytics hosted on our own UK infrastructure to understand how the Platform is used. It collects only aggregated, anonymised usage data (such as page views and referring sites), sets no analytics cookies, does not track you across other websites, and does not share data with third-party advertisers.
No advertising cookies. We do not use any advertising, retargeting, or social media tracking cookies. We do not use Facebook Pixel or any similar advertising technology.
We use the following third-party services to operate the Platform. Each provider has been assessed for data protection compliance:
| Service | Provider | Purpose |
|---|---|---|
| Cloud Infrastructure | Microsoft Azure (UK South, London) | Application hosting, PostgreSQL database, document storage, secrets management, and edge delivery |
| Automated Review Engine | DeepInfra | Automated analysis of submitted RAMS documents by the review engine |
| Card Payments | Stripe | Processing credit and debit card payments |
| Direct Debit | GoCardless | Processing Direct Debit payments |
| Resend | Transactional email delivery (notifications, invitations) | |
| Analytics | Self-hosted (first-party, cookieless) | Aggregated usage analytics on our own Azure infrastructure — no third-party analytics processor |
We only share the minimum data necessary with each provider. We do not sell your personal data to any third party.
Your data is primarily stored and processed in the United Kingdom (Microsoft Azure, UK South / London region). However, some of our third-party service providers are based outside the UK, which means limited data transfers outside the UK may occur:
Where data is transferred outside the UK, we ensure that appropriate safeguards are in place as required by UK GDPR, including Standard Contractual Clauses approved by the Information Commissioner's Office.
SaferSite is a business-to-business service designed for use by construction industry professionals. The Platform is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a person under 18, we will take steps to delete that information promptly.
We may update this Privacy Policy from time to time to reflect changes to our practices, technology, legal requirements, or other factors. We will provide at least 30 days advance notice of any material changes by:
We encourage you to review this policy periodically. Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated policy.
For any questions about this Privacy Policy, to exercise your data rights, or to raise a data protection concern, please contact:
Data Protection Contact: Steve Trueman
Email: steve@safersite.app
Website: safersite.app
We aim to respond to all data protection enquiries within 5 business days and to complete formal data subject requests within one month as required by UK GDPR.