Privacy notice
Last updated: 12 June 2026
Who we are
Safegen (“Safegen”, “we”) provides health & safety management software to organisations in the UK. For the personal data your organisation puts into Safegen — safety checks, incident reports, risk assessments and the people named in them — your organisation is the data controller and we are a processor, acting on its instructions. For the account data we need to run the service (your name, email and sign-in records), we are the controller.
What we collect
- Account data — name, email address, hashed password, and the organisation(s) you belong to.
- Content your organisation creates — checks, incident reports, risk assessments, documents, photos and signatures captured during safety workflows. People named in these records (e.g. an injured person or witness) are included.
- Technical data — IP address and user-agent attached to sessions and security rate-limiting, plus server logs needed to operate and secure the service.
Why we process it
To provide the service your organisation signed up for (contract); to secure it against abuse — session management, rate limiting, audit logging (legitimate interests); and to send the transactional emails the product generates, such as assignment notifications and overdue digests (contract). We do not sell personal data, use it for advertising, or train machine-learning models on it.
Who else touches it (subprocessors)
- Vercel — application hosting.
- Railway — PostgreSQL database hosting.
- Resend — transactional email delivery.
Each is bound by its own data-processing terms. Regions and details are enumerated in the data-processing agreement available to customers on request.
How long we keep it
Your organisation controls its records and can delete them in-product; health & safety law often requires employers to retain incident records for several years, so retention inside the product is your organisation's policy decision. Account data is kept while your account is active. When an organisation leaves Safegen, its data is deleted on request or after a wind-down period.
Your rights
Under UK GDPR you can request access to, correction of, or deletion of your personal data, and you can object to or ask us to restrict processing. For records inside your employer's Safegen workspace, contact your employer (the controller) — we'll support them in responding. For account data, contact us directly. You can also complain to the ICO (ico.org.uk).
Contact
Email hello@safegen.co.uk for anything privacy-related, including data-processing agreements, export and deletion requests.