Log in

โ† Safeticity

Privacy Policy

Effective date: 8 September 2026

Safeticity ("we", "us", or "our") is committed to protecting the personal information you share with us. This Privacy Policy is in two parts. Part A covers this website and early-access applications. Part B covers the Safeticity platform: the web dashboard and the Safeticity mobile app used by organisations that have signed up.

Safeticity is in early access. The platform is under active development, and we will update this policy as features change. The effective date at the top tells you which version you are reading.

Part A โ€” The website and early access

1. Information We Collect

When you submit an early-access application we collect:

2. How We Use Your Information

We use the information you submit to:

We do not sell, rent, or share your personal information with third parties for their own marketing purposes.

3. Legal Basis for Processing

We process your data on the basis of your consent (submitting the form) and our legitimate interest in communicating with prospective customers of Safeticity.

4. Data Retention

We retain your application data for as long as is reasonably necessary to fulfil the purpose for which it was collected, or until you ask us to delete it. If you become a customer, your application record is retained as part of your account history.

5. Cookies and Tracking

This site does not use advertising or analytics cookies. A session cookie is used to maintain form state and, once you have an account, to keep you signed in across the Safeticity website and dashboard. UTM parameters in the URL are stored alongside your application to help us understand where applicants come from.

Part B โ€” The Safeticity platform (dashboard and mobile app)

6. Who Is Responsible for Your Data

Safeticity is a health, safety and environment (HSE) record-keeping system used by organisations. When you use the dashboard or the mobile app, you do so as a member of an organisation that has signed up for Safeticity. That organisation, usually your employer or the contractor you work for, decides what safety information is recorded and why. In data protection terms, your organisation is the controller of the safety records you and your colleagues create, and Safeticity processes that data on its behalf and on its instructions.

Safeticity is the controller for the data we need to run the service itself: your account and sign-in details, and the security and audit records described below.

7. Account Data

To give you an account we store your name, email address, the role(s) your organisation has assigned you, your language preference, and whether your account is active. If you sign in with Google, we also store the identifier Google assigns to your account. We do not store a phone number, photo, or job title on your account.

If you were invited to Safeticity, we hold your email address and the role you were invited to from the moment the invitation is sent until it is accepted or expires.

When you sign in on the web we record the session's IP address and browser identifier for the life of the session. When you sign in on the mobile app we issue a sign-in token that is labelled with the app name and expires after 180 days of inactivity.

8. Safety Records You Create

The purpose of the platform is to record workplace safety information. Depending on which features your organisation uses, the records you create may contain:

These records are your organisation's safety evidence. They are visible to the members of your organisation who are authorised to see them, which normally includes your organisation's administrators and the administrators of the projects and sites you belong to.

9. Device Permissions Used by the Mobile App

The Safeticity app asks for the following permissions, each for a single purpose:

The app does not use advertising identifiers, contacts, push notification services, analytics, or crash-reporting services.

10. Processing and Storage on Your Device

Meeting recordings are transcribed to text on your device using a speech recognition model bundled with the app. No audio is sent anywhere for transcription. The recording and the transcript are then uploaded together as part of the meeting record.

So that you can work offline, the app keeps reports, photos, and recordings on your device until they have been uploaded, and keeps your sign-in token in the phone's secure storage. Signing out removes the token and any pending uploads. Documents you have opened in the app stay in the app's cache after you sign out, so that safety documents remain available offline, for example at sea, until you clear the app's data.

11. AI Photo Classification

When you attach a photo to an observation, the app can suggest a classification for it. If your organisation has this feature enabled and you use it, the photo is sent to Anthropic, an AI provider, with fixed instructions to classify it as a safety observation. Only the image is sent: no name, email address, location, site name, or report text accompanies it. Anthropic processes it under its commercial API terms.

The suggested classification is stored with your report and you can change it before submitting. We keep a log of each classification request (who made it, when, and the processing cost) so your organisation can monitor its usage. The raw AI response is deleted from our logs after 48 hours.

12. Sign in with Google

If you choose to sign in with Google, we receive your name, email address, and Google account identifier from Google, and nothing else. We use this only to create and sign you into your Safeticity account. If your organisation has verified its email domain, a Google account on that domain is automatically added to that organisation. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

13. Other Service Providers

We use a hosting provider to run the platform and store its data, and an email delivery provider to send account and notification emails. When you click a link in an email from us, we record the click and the IP address it came from so that we can confirm delivery and detect misuse. We do not use analytics, advertising, or error-tracking services on the platform. We do not sell personal information.

14. Retention

Safeticity is designed as an immutable safety ledger. Safety records are not edited in place or overwritten: a correction creates a new version and the earlier version is kept. This is deliberate. Incident and safety records may be needed months or years later for investigations, audits, and regulatory or legal obligations, and their value depends on being complete and unaltered. The same applies to photos uploaded through the dashboard, which keep their embedded metadata (such as capture time and location) because it can be evidence.

Accordingly, safety records, attachments, and the audit trail are retained for as long as your organisation's account is active, and thereafter for as long as your organisation instructs us to keep them or the law requires. When an organisation leaves Safeticity, it may request an export of its data. Because your name appears on records you created, your account details are retained alongside those records even after your account is deactivated.

Shorter periods apply to operational data: web sessions expire after two hours of inactivity, mobile sign-in tokens after 180 days of inactivity, uploads that were never attached to a record are deleted after 48 hours, and raw AI responses after 48 hours.

15. Audit Trail

To protect the integrity of safety records we keep an audit log of who created, changed, approved, or acknowledged what, and when, together with the IP address of the request. The log records which fields changed, never their contents. Your organisation's authorised administrators can view the audit log for their organisation.

16. Who Can See Your Data

We do not share personal information with anyone else unless required by law.

17. Your Rights

Depending on your jurisdiction you may have the right to access, correct, or delete your personal information, to receive a copy of it, or to restrict or object to its processing. Because your organisation is the controller of safety records, requests about those records should go to your organisation in the first instance; we will assist it in responding. You can also contact us directly at privacy@safeti.city and we will coordinate with your organisation. Note that deletion may be limited where a record must be kept as safety or legal evidence.

You can sign out of the mobile app on one device or on all devices at any time from the profile screen.

18. Security

All traffic between the app, the dashboard, and our servers is encrypted in transit. Passwords are stored only as salted hashes, sign-in tokens are hashed on the server and held in your phone's secure storage on the device, and access to every record is controlled by the roles your organisation assigns. We take reasonable technical and organisational measures to protect your personal information against unauthorised access, loss, or disclosure.

19. Mobile App Data Summary

For the Safeticity Android app, in the categories used by Google Play:

Data is encrypted in transit. You can request deletion of your data as described in Section 17.

General

20. International Transfers

Your information may be processed on servers outside your country of residence. Where this involves transfer outside the European Economic Area, we ensure appropriate safeguards are in place.

21. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. Material changes will be communicated via the email address you provided, where practicable.

22. Contact

If you have questions about this Privacy Policy, please contact us at privacy@safeti.city.