Privacy Policy
How SafeWorks collects, uses, stores, and protects personal information when providing the service.
Effective date: July 22, 2026
Last updated: July 22, 2026
Scope and roles
This policy applies to SafeWorks websites, applications, and support services. The subscribing organization controls the safety records entered by its users. SafeWorks processes that information to provide the service and acts as the service provider for customer-controlled records.
Information processed
SafeWorks processes information needed to operate customer workspaces and provide safety workflows.
- Account, workspace, role, location, and authentication information.
- Hazard, inspection, investigation, corrective-action, evidence, and audit records submitted by authorized users.
- Billing identifiers and subscription state supplied by Stripe.
- Technical, security, support, and delivery information needed to operate and protect the service.
Collection, authority, and consent
Information may be provided directly by account users, workspace administrators, authorized reporters, integrated service providers, and through normal service usage.
Subscribing organizations are responsible for having authority to submit worker, witness, injury, investigation, and related safety information.
SafeWorks processes information necessary to provide the contracted service and uses consent or another lawful basis where required by applicable law.
Purposes and lawful use
Information is used to deliver requested features, enforce workspace separation and role-based access controls, support customers, process billing, send service communications, investigate security events, meet legal obligations, and improve reliability. SafeWorks does not sell customer data.
Service providers and transfers
SafeWorks uses infrastructure and service providers for hosting, database, authentication, storage, billing, and email delivery. SafeWorks relies on trusted service providers that support hosting, data storage, payments, and email delivery. Processing may occur outside the customer jurisdiction subject to provider safeguards and contractual controls.
Retention, access, and requests
Customer records are retained according to the Data Retention and Deletion Policy and customer instructions. Access, correction, export, deletion, or other privacy concerns should first be directed to the workspace administrator or SafeWorks' Privacy Officer at rob@safeworks.online. SafeWorks may need to verify identity and authority and may refer requests concerning customer-controlled records to the subscribing organization.
Privacy incidents
SafeWorks maintains an incident-response process. Affected customers will be notified when required by applicable law. SafeWorks preserves required incident and breach records.
Privacy accountability and contact
SafeWorks' Privacy Officer is the contact for privacy accountability and can be reached at rob@safeworks.online. Material policy changes will be dated and communicated through an appropriate service channel.