{# PLACEHOLDER LEGAL TEXT: generic SaaS boilerplate, not reviewed by a solicitor. Must be reviewed and finalised before real launch - this product stores personal data about staff (name, email, role, training/acknowledgment timestamps), which has real UK GDPR implications for both Safegrd (as processor/controller) and the venues using it (as controller of their own staff's data). Get proper advice on lawful basis, data processing agreements with venues, and retention periods before this is used with real staff data. #} Privacy Policy — Safegrd
Placeholder document. This is illustrative text, not reviewed by a solicitor. Safegrd stores personal data about venue staff (names, emails, roles, and training completion records) - this policy must be properly drafted, with GDPR lawful basis and retention periods confirmed, before real staff data is processed.

Privacy Policy

Last updated: placeholder — not yet finalised.

1. What we collect

Account holders (managers): username, email address, and the venues you manage.

Staff members: when a manager adds a staff member, we store their name, email address, role, and timestamped records of which procedures and training items they have acknowledged or completed. Staff access their checklist via a unique link and are not required to create an account or password.

2. Why we process this data

To operate the Service: letting managers track venue compliance readiness, and letting staff view and acknowledge procedures and training. Venues act as the data controller for their own staff's data; Safegrd acts as a data processor on their behalf for that data.

3. Where data is stored

Data is stored in a PostgreSQL database hosted on Render. Uploaded procedure documents are stored on the same hosting platform.

4. Third parties

We use Stripe to process subscription payments (Stripe does not receive staff compliance data) and Render to host the application and database.

5. Retention

Placeholder: data is retained for as long as the account is active. A specific retention and deletion schedule needs to be defined and documented here.

6. Your rights

Under UK GDPR, individuals have rights to access, correct, or request deletion of their personal data. Requests from venue staff should be directed to their venue manager in the first instance, or to us at the contact below.

7. Cookies

We use a single essential session cookie to keep you signed in. We don't use advertising or analytics cookies.

8. Contact

Placeholder contact: privacy@safegrd.example