Privacy Policy
Last updated: placeholder — not yet finalised.
1. What we collect
Account holders (managers): username, email address, and the venues you manage.
Staff members: when a manager adds a staff member, we store their name, email address, role, and timestamped records of which procedures and training items they have acknowledged or completed. Staff access their checklist via a unique link and are not required to create an account or password.
2. Why we process this data
To operate the Service: letting managers track venue compliance readiness, and letting staff view and acknowledge procedures and training. Venues act as the data controller for their own staff's data; Safegrd acts as a data processor on their behalf for that data.
3. Where data is stored
Data is stored in a PostgreSQL database hosted on Render. Uploaded procedure documents are stored on the same hosting platform.
4. Third parties
We use Stripe to process subscription payments (Stripe does not receive staff compliance data) and Render to host the application and database.
5. Retention
Placeholder: data is retained for as long as the account is active. A specific retention and deletion schedule needs to be defined and documented here.
6. Your rights
Under UK GDPR, individuals have rights to access, correct, or request deletion of their personal data. Requests from venue staff should be directed to their venue manager in the first instance, or to us at the contact below.
7. Cookies
We use a single essential session cookie to keep you signed in. We don't use advertising or analytics cookies.
8. Contact
Placeholder contact: privacy@safegrd.example