SaferSite

Privacy Policy

Last updated: 14 April 2026

This Privacy Policy explains how SaferSite ("we", "us", "our"), operated at safersite.app, collects, uses, stores, and protects your personal data. We are committed to protecting your privacy and processing your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For questions about this policy or to exercise your data rights, contact steve@safersite.app.

1. Information We Collect

We collect the following categories of information:

Account and organisation data. When you register, we collect your full name, work email address, job title/role, phone number (if provided), company name, and registered address. This information is used to set up and verify your account.

RAMS documents. You upload Risk Assessments and Method Statements (RAMS) for compliance review. These documents may contain personal data such as names of responsible persons, subcontractor details, and site personnel information.

Site data.For each construction site you add, we collect the site name, address, postcode, GPS coordinates, nearest A&E hospital details, client information, and site-specific configuration such as active RAMS and standards.

Usage data. We automatically collect information about how you use the Platform, including login times, features accessed, pages viewed, actions taken (such as reviews initiated, approvals given), browser type, and IP address.

Payment data. When you subscribe to a paid plan, payment information is collected and processed by our payment providers (Stripe and GoCardless). We do not store your full card details on our servers. We retain billing records including invoice amounts, dates, and payment status.

Communications. If you contact us via email or through the Platform, we retain the content of those communications.

2. How We Use Your Information

We use your information for the following purposes:

  • Providing the service: Processing your RAMS documents for compliance review, generating compliance scores and findings, managing your sites and subcontractors, and providing document management functionality
  • Account management: Verifying your identity and organisation, managing user roles and access, and authenticating your sessions
  • Billing and payments: Processing subscription payments, generating invoices, and managing your billing account
  • Communication: Sending you service-related notifications, security alerts, billing reminders, and responding to your support requests
  • Platform improvement: Analysing aggregated, anonymised usage patterns to improve the Platform. We do not use individual RAMS documents or your specific data for this purpose — only aggregated analytics such as feature usage frequency and performance metrics
  • Security and compliance: Maintaining audit trails, detecting and preventing fraud or misuse, and complying with legal obligations

3. Legal Basis for Processing

Under UK GDPR, we process your personal data on the following legal bases:

Performance of a contract (Article 6(1)(b)). Processing your account data, RAMS documents, and site information is necessary to provide you with the SaferSite service under our Terms of Service.

Legitimate interests (Article 6(1)(f)). We process usage data and aggregated analytics to improve the Platform and maintain security. We have assessed that these interests do not override your rights and freedoms.

Legal obligation (Article 6(1)(c)). We retain certain records (such as audit trails and financial records) where required by law or regulation.

Consent (Article 6(1)(a)). Where we rely on consent for any specific processing activity, we will clearly ask for your consent at the time and you may withdraw it at any time by contacting us.

4. Data Storage and Security

We take the security of your data seriously and implement measures aligned with ISO 27001 information security standards.

UK cloud infrastructure. Your data is stored and processed on Microsoft Azure infrastructure in the UK South (London) region. RAMS documents are stored in private cloud storage that is not publicly accessible — all document access is proxied through our authenticated server.

Encryption. All data is encrypted at rest and in transit using industry-standard encryption (TLS 1.2+ for data in transit, AES-256 for data at rest).

Access controls.The Platform implements organisation-level data isolation, meaning your data is strictly separated from other organisations' data at the database level. All queries are scoped to your organisation and site. Role-based access controls ensure users can only access data appropriate to their role.

Audit logging. Every significant action on the Platform is recorded in a comprehensive audit trail, including who performed the action, when, and what was changed. This supports both security monitoring and regulatory compliance.

Authentication. User sessions are managed via a secure, httpOnly session cookie. Passwords are hashed using industry-standard algorithms. We support email verification for new accounts.

5. Document Processing

SaferSite provides automated compliance review of RAMS documents. This section explains how your documents are processed.

Automated review.When you submit a RAMS document, it is analysed against UK health and safety regulations, your organisation's corporate standards, and your site-specific rules. The resulting compliance findings are stored within your SaferSite account.

Your documents remain yours. This is a firm commitment. Your RAMS documents, site data, corporate standards, and any other content you upload are never shared with other organisations, used for any purpose other than providing the service to you, or made publicly available. Documents are processed solely for the purpose of generating compliance findings for your account.

Data minimisation. Only the document content necessary for compliance review is processed. Account metadata such as billing information is not included in document processing.

Organisational learning.When your reviewers provide feedback on findings, SaferSite learns your organisation's preferences and standards over time. This learning is private to your organisation and is never shared with other users or organisations.

Review findings. Compliance scores, findings, and recommendations are stored in your account and are accessible only to authorised users within your organisation.

6. Data Retention

We retain your data according to the following schedule:

Active accounts. While your subscription is active, we retain all account data, RAMS documents, review findings, site data, and usage data necessary to provide the service.

Cancelled accounts. When your account is cancelled or terminated, you have 30 days to request an export of your data. After the 30-day period, we will delete your account data, RAMS documents, and site data.

Audit trail records. Audit trail data (who did what, when) is retained for 7 years from the date of the action, in line with regulatory requirements for construction health and safety records. This applies even after account cancellation.

Financial records. Billing and payment records are retained for 7 years in accordance with HMRC requirements.

Anonymised data. Aggregated, anonymised usage statistics that cannot identify you or your organisation may be retained indefinitely.

7. Your Rights Under UK GDPR

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access: You can request a copy of the personal data we hold about you
  • Right to rectification: You can ask us to correct inaccurate or incomplete personal data
  • Right to erasure: You can ask us to delete your personal data, subject to our legal obligations to retain certain records
  • Right to data portability: You can request your personal data in a structured, commonly used, machine-readable format
  • Right to restrict processing: You can ask us to limit how we process your personal data in certain circumstances
  • Right to object: You can object to processing of your personal data where we rely on legitimate interests as the legal basis

How to exercise your rights. You can exercise any of these rights by emailing steve@safersite.app. Organisation administrators can also submit data requests through the Platform Admin area. We will respond to your request within one month, as required by UK GDPR. In complex cases, we may extend this by a further two months, and we will inform you if this is necessary.

Right to complain.If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Cookies

SaferSite uses a minimal, privacy-respecting approach to cookies.

Session cookie (essential). We use a single httpOnly session cookie called ss-session to authenticate your sessions securely. This cookie is strictly essential for the Platform to function and cannot be disabled. It is set when you log in and removed when you log out or when your session expires.

Analytics. We use privacy-first, cookieless analytics hosted on our own UK infrastructure to understand how the Platform is used. It collects only aggregated, anonymised usage data (such as page views and referring sites), sets no analytics cookies, does not track you across other websites, and does not share data with third-party advertisers.

No advertising cookies. We do not use any advertising, retargeting, or social media tracking cookies. We do not use Facebook Pixel or any similar advertising technology.

9. Third-Party Services

We use the following third-party services to operate the Platform. Each provider has been assessed for data protection compliance:

ServiceProviderPurpose
Cloud InfrastructureMicrosoft Azure (UK South, London)Application hosting, PostgreSQL database, document storage, secrets management, and edge delivery
Automated Review EngineDeepInfraAutomated analysis of submitted RAMS documents by the review engine
Card PaymentsStripeProcessing credit and debit card payments
Direct DebitGoCardlessProcessing Direct Debit payments
EmailResendTransactional email delivery (notifications, invitations)
AnalyticsSelf-hosted (first-party, cookieless)Aggregated usage analytics on our own Azure infrastructure — no third-party analytics processor

We only share the minimum data necessary with each provider. We do not sell your personal data to any third party.

10. International Data Transfers

Your data is primarily stored and processed in the United Kingdom (Microsoft Azure, UK South / London region). However, some of our third-party service providers are based outside the UK, which means limited data transfers outside the UK may occur:

  • Microsoft Azure:Your data is stored and processed in Azure's UK South (London) region, within the United Kingdom.
  • Automated review engine (DeepInfra): The text of submitted RAMS documents is processed by our inference provider to generate the automated review. This provider is based in the United States, and this processing may occur outside the UK. Where personal data is transferred outside the UK, we put in place appropriate safeguards as required by UK GDPR.
  • Stripe and GoCardless: Payment processing. Both maintain appropriate safeguards and comply with PCI DSS for payment data security.

Where data is transferred outside the UK, we ensure that appropriate safeguards are in place as required by UK GDPR, including Standard Contractual Clauses approved by the Information Commissioner's Office.

11. Children

SaferSite is a business-to-business service designed for use by construction industry professionals. The Platform is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a person under 18, we will take steps to delete that information promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, technology, legal requirements, or other factors. We will provide at least 30 days advance notice of any material changes by:

  • Sending an email notification to the address associated with your account
  • Posting the updated policy on the Platform with a revised "Last updated" date

We encourage you to review this policy periodically. Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated policy.

13. Data Protection Contact

For any questions about this Privacy Policy, to exercise your data rights, or to raise a data protection concern, please contact:

Data Protection Contact: Steve Trueman

Email: steve@safersite.app

Website: safersite.app

We aim to respond to all data protection enquiries within 5 business days and to complete formal data subject requests within one month as required by UK GDPR.