SafeProG · Ireland
Privacy Policy
What personal data SafeProG processes, why, for how long, who else touches it, and the rights you hold under the GDPR.
Last updated 5 August 2026
1.Controller and processor — which one we are
This distinction decides who is responsible for what, so it is worth being precise about it.
- For your employees' and contractors' data inside the platform — incidents, assessments, training records, observations — your organisation is the controller and SafePro Global Consultancy is the processor. You decide what goes in and why; we process it on your instructions.
- For your account, billing and our own marketing — the administrator who signs up, invoices, support correspondence — SafePro Global Consultancy is the controller.
SafePro Global Consultancy is registered in Ireland. Contact us about privacy at info@safeproglobal.com.
2.What we process
| Category | Examples | Why |
|---|---|---|
| Account | Name, work email, job title, organisation, seat tier | To create and secure accounts, and apply permissions |
| Authentication | Password hash, session tokens, one-time codes, last-login time | To sign you in and keep others out |
| EHS records | Incidents, risk assessments, permits, audits, observations, training and competency records | To provide the service your organisation subscribed to |
| Uploads | Photos, documents, signatures and attachments you add | Because they are part of the records above |
| Audit trail | Who did what, when, from which network address (hashed) | To make records defensible, and to investigate misuse |
| Billing | Organisation billing contact, plan, seat counts, invoices | To charge for the service and meet tax obligations |
| Technical | Browser type, pages viewed, error diagnostics | To keep the platform working and secure |
Special-category data — including health information in an injury record — may be processed where your organisation puts it into the platform. You are the controller for that, and you are responsible for having a lawful basis and an Article 9 condition for it.
3.Our lawful bases
- Contract — to provide the platform to the organisation that subscribed.
- Legitimate interests — to secure the service, prevent abuse, and communicate with customers about their subscription. We have weighed these against your rights.
- Legal obligation — to keep accounting records and respond to lawful requests.
- Consent — for marketing email to prospects, which you can withdraw at any time.
4.The gAnI assistant and your data
When you use gAnI, the content you submit — the activity description, the uploaded method statement, the question — is sent to Anthropic for processing and the response is returned to you.
- Only what you submit to gAnI is sent. It does not have standing access to your whole database.
- Your data is not used to train AI models, by us or by our AI sub-processor.
- Transfers to the United States are covered by Standard Contractual Clauses.
- gAnI output is a draft for a competent person to review, not an automated decision about any individual. We do not carry out automated decision-making with legal or similarly significant effects.
5.Who else processes your data
We use a small number of sub-processors. Each is bound by a data processing agreement, and each is listed here because the platform actually uses it — not as a generic disclosure.
| Sub-processor | What it does | Where |
|---|---|---|
| Supabase (PostgreSQL) | Primary application database — all customer records | EU (AWS eu-west-1, Ireland) |
| Vercel | Hosting and delivery of the web application | Global edge network; origin in the EU |
| Railway | Hosting of the API service | EU region |
| Resend | Transactional email — invitations, notifications, alerts | EU / US, under Standard Contractual Clauses |
| Paddle | Merchant of record — subscription billing and tax | EU / UK, under Standard Contractual Clauses |
| Anthropic | The gAnI assistant — processes only the content submitted to it | US, under Standard Contractual Clauses |
Your primary database is hosted in the European Union. We will give notice before adding a sub-processor that materially changes how your data is handled.
6.International transfers
Customer records are stored in the EU. Where a sub-processor operates outside the EEA — our email, billing and AI providers — transfers rely on the European Commission's Standard Contractual Clauses together with supplementary technical measures, principally encryption in transit and at rest.
7.How long we keep it
- Live customer records: for as long as your subscription is active.
- After termination: exportable for 30 days, then deleted from live systems, and from backups within a further 90 days.
- Audit trails: 2, 4 or 7 years depending on your plan — this is a deliberate feature, since an audit trail that expires early is worthless as evidence.
- Executed agreements and signature evidence: for the retention period stated in the agreement, because either party may need to prove what was signed.
- Billing and accounting records: as required by Irish tax law.
8.Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy
- have inaccurate data corrected
- have data erased, where no overriding obligation requires us to keep it
- restrict or object to certain processing
- receive your data in a portable, machine-readable format
- withdraw consent at any time, where processing relies on consent
If your data is in the platform because your employer put it there, they are the controller — please contact them first. If you approach us directly we will pass the request on and support them in answering it.
Otherwise, write to info@safeproglobal.com. We respond within one month.
9.Security
Passwords are hashed with bcrypt and never stored in readable form. Sessions expire after 20 minutes of inactivity. Access is gated by role and by seat tier, and every organisation's data is isolated from every other. Signed documents carry a SHA-256 hash so tampering is detectable. The Security page sets out the controls in full.
If a personal data breach occurs, we notify affected controllers without undue delay and support their own notification duties under Article 33.
10.Complaints
If you are unhappy with how we have handled your data, tell us first and we will try to put it right. You also have the right to complain to the Irish Data Protection Commission (DPC) — www.dataprotection.ie.