This Privacy Notice for SafetyDocs Ltd ("we", "us", or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at info@safetydocs.org.
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.
Do we process any sensitive personal information? We do not process sensitive personal information.
Do we collect any information from third parties? We do not collect any information from third parties.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.
In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties.
How do we keep your information safe? We have adequate organisational and technical processes and procedures in place to protect your personal information; however, no method of transmission or storage can be guaranteed 100% secure.
What are your rights? Depending on where you are located geographically, applicable privacy law may give you certain rights regarding your personal information.
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. It may include:
Sensitive Information. We do not process sensitive information.
Payment Data. We may collect data necessary to process your payment if you choose to make purchases, such as your payment instrument number and the security code associated with it. All payment data is handled and stored by Stripe — see their privacy notice.
Social Media Login Data. We may provide you with the option to register using your existing social media account details, like Facebook, X, or other accounts. If you register this way, we collect certain profile information from the social media provider (see "How Do We Handle Your Social Logins?" below).
Application Data. If you use our application(s) and grant access or permission, we may collect:
This information is primarily needed to maintain the security and operation of our application(s), for troubleshooting, and for internal analytics and reporting.
All personal information you provide to us must be true, complete, and accurate, and you must notify us of any changes.
In Short: Some information — such as your IP address and/or browser and device characteristics — is collected automatically when you visit our Services.
We automatically collect certain information when you visit, use, or navigate the Services, including device and usage information such as IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, usage information, and other technical information. This is primarily needed to maintain the security and operation of our Services and for internal analytics and reporting.
We also collect information through cookies and similar technologies.
Google API. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process it for other purposes only with your prior explicit consent.
Security Identification. Your device location is recorded at scan time alongside existing identification, photograph, and shift records. Captured under UK GDPR legitimate interests for safety, audit, and incident response. To request deletion or ask a data-protection question, contact info@safetydocs.org.
Barcode badge generation. If you volunteer or work at our events, you'll be issued a personal QR code. When you scan to check in/out of a shift via SafetyDocs Shifts, we record the time of scan, post and shift assigned, IP address/user-agent of the device used, and — where your browser permits and you grant permission — the device's geolocation coordinates and accuracy. Held under UK GDPR Article 6(1)(f) for event safety, access control, and audit, retained alongside your shift records, and referenced if an incident is investigated in line with the Terrorism (Protection of Premises) Act 2025 (Martyn's Law) and duties to the venue and insurers. You may decline location permission at scan time and check-in still proceeds. To request deletion/correction, contact info@safetydocs.org.
Event check in/out. We process your name, contact details, role, shift records, and photograph for identification, badge production, access control, and event administration. SafetyDocs Shifts also records the time of each scan and, where permitted, device location at check-in/check-out, to evidence safety arrangements to the venue and insurers, support post-event incident review, and meet duties under Martyn's Law. Your browser will request location permission at first scan; you may decline and check-in still proceeds. To request deletion after the event, contact info@safetydocs.org. Records may be retained where required for legal or regulatory obligations (e.g. health and safety or incident reporting).
In Short: We only process your personal information when we believe it is necessary and have a valid legal basis, such as consent, legal compliance, contractual necessity, protecting your rights, or legitimate business interests.
Under the GDPR / UK GDPR, we may rely on:
We are generally the "data controller" under European data protection laws for the personal information described here. This notice does not apply to information we process as a "data processor" on behalf of our customers — in those cases the customer is the data controller.
We may process your information with express or implied consent, which can be withdrawn at any time. In certain exceptional cases permitted by law we may process information without consent — for example for fraud investigation/prevention, business transactions, insurance claims, identifying injured/deceased persons, suspected financial abuse, investigating breach of an agreement or contravention of law, complying with a subpoena/warrant/court order, information produced in the course of employment/business/profession, journalistic/artistic/literary purposes, or publicly available information. De-identified information may be disclosed for approved research or statistics projects subject to ethics oversight.
In Short: We may share information in specific situations and with specific third parties.
In Short: We may use cookies and similar tracking technologies to collect and store your information.
We use cookies and similar technologies (web beacons, pixels) to maintain security, prevent crashes, fix bugs, save preferences, and support basic site functions. We also permit third parties and service providers to use tracking technologies for analytics and advertising, including tailoring ads to your interests and sending abandoned-cart reminders.
Where these technologies are deemed a "sale"/"sharing" under applicable US state laws, you can opt out as described under "Do United States Residents Have Specific Privacy Rights?" below. See our Cookie Notice for more detail.
In Short: We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.
We provide AI Products through third-party AI Service Providers, including OpenAI. Your input, output, and personal information will be shared with and processed by these providers to enable use of our AI Products. You must not use the AI Products in any way that violates the terms or policies of any AI Service Provider.
Our AI Products are designed for: AI document generation and AI research. All personal information processed using our AI Products is handled in line with this Privacy Notice and our agreements with third parties.
In Short: If you register or log in using a social media account, we may access certain information about you.
Where you register using a third-party social account (e.g. Facebook or X), we receive certain profile information from that provider — typically name, email address, friends list, and profile picture, plus other information you've made public. We use this only for purposes described in this notice. We do not control, and are not responsible for, other uses of your information by the social media provider — review their privacy notice for details.
In Short: We keep your information for as long as necessary to fulfil the purposes outlined in this Privacy Notice, unless a longer period is required by law.
When there is no ongoing legitimate business need to process your information, we delete or anonymise it, or, if that isn't possible (e.g. backup archives), we securely store and isolate it from further processing until deletion is possible.
In Short: We aim to protect your personal information through organisational and technical security measures.
Despite our safeguards, no electronic transmission or storage technology can be guaranteed 100% secure. Transmission of information to and from our Services is at your own risk — access the Services only within a secure environment.
In Short: We do not knowingly collect data from or market to children under 18 (or the equivalent age in your jurisdiction).
By using the Services you represent that you are at least 18 (or the applicable age), or a parent/guardian consenting to a minor dependent's use. If we learn that data from a minor has been collected, we will deactivate the account and delete such data. Contact info@safetydocs.org if you become aware of any such data.
In Short: Depending on your state or region of residence (e.g. EEA, UK, Switzerland, Canada, or certain US states), you have rights over your personal information, and may review, change, or terminate your account at any time.
In regions such as the EEA, UK, Switzerland, and Canada, rights may include access, rectification, erasure, restriction of processing, data portability, and objection to automated decision-making. Where an automated decision produces legal or similarly significant effects, we will explain the main factors and offer a way to request human review. Contact us using the details in "How Can You Contact Us About This Notice?" to exercise these rights.
EEA/UK residents who believe we are unlawfully processing their data may complain to their Member State or UK data protection authority. Switzerland residents may contact the Federal Data Protection and Information Commissioner.
Withdrawing consent: where we rely on consent, you may withdraw it at any time by contacting us — this won't affect the lawfulness of prior processing.
Opting out of marketing: unsubscribe via the link in our emails, reply "STOP"/"UNSUBSCRIBE" to SMS, or contact us. We may still send necessary service-related messages.
No mobile information is shared with third parties/affiliates for marketing purposes. Sharing with subcontractors for support services is permitted. Text messaging originator opt-in data and consent is never shared with third parties.
To review or change your account information, or terminate your account, log in to your account settings and update it, or click Delete Account. We will deactivate/delete your account, though we may retain some information to prevent fraud, troubleshoot, assist investigations, or comply with legal requirements.
You can also manage cookies via your browser settings, though this may affect certain features.
Since no uniform standard for Do-Not-Track (DNT) signals has been finalised, we do not currently respond to DNT browser signals. If a standard is adopted that we must follow, we will update this notice accordingly.
In Short: Residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia may have rights to access, correct, obtain a copy of, or delete their personal information, and to withdraw consent, subject to limitations under applicable law.
The table below shows categories of personal information collected in the past 12 months (illustrative examples only — see "What Information Do We Collect?" for the full inventory):
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Real name, alias, postal address, phone/mobile number, unique personal identifier, online identifier, IP address, email address, account name | NO |
| B. Personal info under California Customer Records statute | Name, contact information, education, employment, employment history, financial information | NO |
| C. Protected classification characteristics | Gender, age, date of birth, race and ethnicity, national origin, marital status, other demographic data | NO |
| D. Commercial information | Transaction information, purchase history, financial details, payment information | NO |
| E. Biometric information | Fingerprints and voiceprints | NO |
| F. Internet or similar network activity | Browsing history, search history, online behaviour, interest data, interactions with websites/apps/ads | NO |
| G. Geolocation data | Device location | NO |
| H. Audio, electronic, sensory, or similar information | Images, audio, video, or call recordings | NO |
| I. Professional or employment-related information | Business contact details, job title, work history, professional qualifications | NO |
| J. Education Information | Student records and directory information | NO |
| K. Inferences | Inferences drawn to create a profile of preferences/characteristics | NO |
| L. Sensitive personal information | — | NO |
We may also collect other personal information when you interact with us in person, online, by phone, or mail — e.g. customer support, surveys/contests, and Service delivery/inquiries.
Will your information be shared with anyone else? We may disclose information to service providers under written contract (see "When And With Whom Do We Share Your Personal Information?"). We may use your information for internal business purposes such as technological research and demonstration — this is not considered "selling." We have not disclosed, sold, or shared personal information to third parties for a business or commercial purpose in the preceding 12 months, and will not do so in the future.
Depending on your state, you may also have rights to: access categories of data processed (e.g. Minnesota); obtain a list of categories of third parties data was disclosed to (e.g. California, Delaware, Maryland); obtain a list of specific third parties (e.g. Minnesota, Oregon); obtain a list of third parties data was sold to (e.g. Connecticut); review/correct profiling (e.g. Connecticut, Minnesota); limit use/disclosure of sensitive data (e.g. California); and opt out of voice/facial recognition data collection (e.g. Florida).
Contact us by submitting a data subject access request or by emailing info@safetydocs.org. You may designate an authorised agent under certain state laws; we may require proof of valid authorisation.
We will verify your identity using only the information provided in your request. If we cannot verify identity from information we already hold, we may request additional information for verification, security, or fraud-prevention purposes. Agent-submitted requests require written, signed permission from you.
If we decline to act on your request, you may appeal by emailing info@safetydocs.org. We will inform you in writing of the outcome and reasoning. If denied, you may complain to your state attorney general.
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
Updates are indicated by a revised "Last updated" date at the top. Material changes may be notified via a prominent notice or direct notification. Please review this notice frequently.
Email us at info@safetydocs.org or write to us at:
UK residents: we are the "data controller" of your personal information. Our UK representative is David Franklin — contact by email at david@safetydocs.org, via www.safetydocs.org, by phone at +447859775480, or by post to:
Based on applicable laws in your country or US state of residence, you may have the right to request access to, details about, correction of, or deletion of your personal information, and to withdraw consent, subject to legal limitations. To request this, please fill out and submit a data subject access request.
© 2026 SafetyDocs Ltd. All rights reserved.