SafeSentry - Loading

Privacy Policy

Last updated: 14 April 2026

Effective date: 14 April 2026

1. Introduction & Data Controller

SafeSentry is a trading name of Apex Civil Engineering Consultants LTD ("we", "our", "us"), a company registered in England and Wales. We are the data controller for the personal data processed through the SafeSentry platform at safesentry.co.uk.

This Privacy Policy explains how we collect, use, store, share, and protect your personal data in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR) 2003.

By using SafeSentry, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.

Data Protection Contact: For all data protection enquiries, subject access requests, or to exercise your rights, email: [email protected]

2. Personal Data We Collect

2.1 Account & Registration Data

  • Full name, email address, phone number
  • Company name, job title, and role within your organisation
  • Password (stored using bcrypt one-way hashing — we cannot read your password)
  • Account preferences and notification settings

2.2 Document & Project Data

  • RAMS documents uploaded for analysis (PDF, DOCX, DOC)
  • AI-generated evaluation results, scores, and improvement suggestions
  • Project details: name, location, coordinates, client information, project numbers
  • Risk assessments (PoWRA): hazard data, checklists, assessor names, digital signatures
  • Daily site reports, toolbox briefings, snagging lists, delivery logs
  • Equipment registers, permit records, project milestones
  • Near-miss reports and safety observations
  • AI-generated RAMS documents created through our RAMS Generator
  • Chat messages sent to our AI Safety Assistant ("Ask Your RAMS" and chatbot features)

2.3 Site Induction Data

  • Operative name, company, trade/role, email, phone number
  • Emergency contact details
  • CSCS card number, type, and photograph
  • Induction question responses and digital signature

2.4 Site Attendance / Register Data

  • Worker name, position/trade, and company
  • Sign-in and sign-out times, duration on site
  • This data is collected via public QR code pages without requiring a login. Workers provide their name voluntarily when scanning the site QR code.

2.5 Photographs & Media

  • Site photographs uploaded to projects (including EXIF metadata such as date, time, location)
  • CSCS card photographs submitted during inductions

2.6 Certification & Training Data

  • Professional certifications (name, issuer, expiry date, certificate numbers)
  • Training module progress and quiz results
  • Training matrix assignments

2.7 Technical & Usage Data

  • IP address, browser type and version, device type
  • Pages visited, features used, time spent on the platform
  • Authentication tokens and session data
  • Error logs and system performance data

3. Lawful Basis for Processing

Under UK GDPR Article 6, we process your personal data on the following legal bases:

Processing ActivityLawful Basis
Account creation & managementContract performance (Art. 6(1)(b))
RAMS analysis & document processingContract performance (Art. 6(1)(b))
Site inductions & attendance recordingLegitimate interests (Art. 6(1)(f)) — health & safety compliance
AI chatbot & document Q&AContract performance (Art. 6(1)(b))
Certification & training managementLegitimate interests (Art. 6(1)(f)) — workforce competence
Email notifications (service-related)Contract performance (Art. 6(1)(b))
Email notifications (marketing)Consent (Art. 6(1)(a))
Analytics & service improvementLegitimate interests (Art. 6(1)(f))
Security & fraud preventionLegitimate interests (Art. 6(1)(f))
Legal compliance (e.g. HSE requirements)Legal obligation (Art. 6(1)(c))

Legitimate Interest Assessments: Where we rely on legitimate interests, we have conducted balancing tests to ensure our interests do not override the rights and freedoms of data subjects. Records of these assessments are available on request.

4. How We Use Your Data

  • Service delivery: Providing RAMS analysis, project management, attendance tracking, inductions, and all platform features
  • AI processing: Sending document content to AI models for analysis, scoring, and generating recommendations (see Section 5)
  • Communications: Sending email verification, password resets, service notifications, and certification expiry alerts
  • Safety compliance: Maintaining induction records, attendance logs, near-miss reports, and risk assessments as required for health and safety record-keeping
  • Service improvement: Analysing usage patterns, debugging errors, and improving platform features
  • Security: Preventing unauthorised access, detecting fraud, and protecting user data

5. AI Processing & Automated Decision-Making

🤖 How We Use Artificial Intelligence

SafeSentry uses AI (large language models) to:

  • Analyse and score RAMS documents
  • Generate improvement suggestions for safety documentation
  • Answer questions about your uploaded documents ("Ask Your RAMS")
  • Provide safety guidance through the AI chatbot
  • Generate RAMS documents from user-provided project details

Important: When you upload a document or use our AI features, the content is sent to our AI service provider for processing. We use the AI provider's API and do not permit your data to be used for training their models.

AI-generated scores and recommendations are advisory only and do not constitute automated decision-making with legal or similarly significant effects under UK GDPR Article 22. You always have the right to have a human review any AI-generated output.

6. Data Sharing & Third-Party Processors

6.1 We Do Not Sell Your Data

We will never sell, rent, or trade your personal data or documents to third parties for marketing or any other purpose.

6.2 Sub-Processors

We share data with the following categories of processors, all bound by data processing agreements:

  • Cloud hosting & infrastructure: Servers, databases, and file storage (data encrypted at rest and in transit)
  • AI service provider: For document analysis, scoring, and AI-powered features
  • Email service: For transactional emails (verification, password resets, notifications)
  • Content delivery network: For serving static assets efficiently

6.3 Legal Disclosures

We may disclose your data if required to:

  • Comply with a legal obligation, court order, or regulatory request (e.g. HSE investigation)
  • Protect the rights, property, or safety of our users, employees, or the public
  • Enforce our Terms and Conditions
  • In connection with a merger, acquisition, or sale of assets (users will be notified in advance)

7. International Data Transfers

Some of our sub-processors may process data outside the United Kingdom. Where this occurs, we ensure adequate safeguards are in place through:

  • UK adequacy regulations (for countries deemed adequate by the UK Government)
  • International Data Transfer Agreements (IDTAs) or the UK Addendum to Standard Contractual Clauses
  • Supplementary measures where necessary (encryption, pseudonymisation)

Details of the specific safeguards applied to international transfers are available on request by contacting [email protected].

8. Data Retention

Data TypeRetention Period
Account dataDuration of account + 12 months after deletion request
RAMS documents & evaluationsDuration of account (user may delete at any time)
Site induction recordsDuration of project + 6 years (health & safety record-keeping)
Attendance / site register recordsDuration of project + 6 years (health & safety record-keeping)
Near-miss reportsDuration of project + 6 years
Certifications & training recordsDuration of account + 3 years
AI chat conversationsDuration of session (not permanently stored)
Security & error logs90 days
Email communications12 months

Health and safety records are retained for 6 years after project completion in line with the Limitation Act 1980 and CDM Regulations 2015 guidance. This ensures records are available in the event of a regulatory investigation, claim, or prosecution.

9. Data Security

🔒 Security Measures

  • All data encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Passwords hashed with bcrypt (one-way — cannot be reversed)
  • Session-based authentication with secure, HTTP-only cookies
  • Role-based access controls within company accounts
  • Regular security monitoring and vulnerability assessment
  • Cloud-hosted infrastructure with enterprise-grade security
  • Automatic session expiry after periods of inactivity
  • Email verification required for all new accounts

While we implement industry-standard security measures, no system is 100% secure. We encourage users to choose strong passwords, keep credentials confidential, and report any suspected security issues promptly.

10. Your Rights Under UK GDPR

Under the UK GDPR and Data Protection Act 2018, you have the following rights:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you (Subject Access Request)
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data
  • Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements
  • Right to Restrict Processing (Art. 18): Request that we limit how we use your data while a complaint is resolved
  • Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format
  • Right to Object (Art. 21): Object to processing based on legitimate interests, including profiling
  • Rights Related to Automated Decision-Making (Art. 22): Right not to be subject to decisions based solely on automated processing with legal or significant effects
  • Right to Withdraw Consent: Where we process based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing

To exercise any of these rights, email [email protected]. We will respond within one calendar month as required by law. We may need to verify your identity before fulfilling your request.

Note on Erasure Requests: Certain health and safety records (inductions, attendance, near-miss reports) may need to be retained for legal compliance even after an erasure request. We will explain any such limitations clearly when responding to your request.

11. Cookies & Tracking Technologies

We use strictly necessary cookies to operate the platform. For full details, please see our Cookie Policy.

In summary:

  • Essential cookies: Authentication session, CSRF protection, user preferences — required for the Service to function
  • No third-party advertising or tracking cookies
  • No social media tracking pixels

12. Children's Privacy

SafeSentry is designed for use by construction industry professionals and is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that a child under 18 has provided personal data, we will take steps to delete it promptly.

13. Data Breach Procedures

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, as required by UK GDPR Article 33
  • Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Article 34)
  • Document all breaches in our internal breach register, including facts, effects, and remedial actions taken

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will:

  • Update the "Last updated" date at the top of this page
  • Notify registered users of material changes via email or in-platform notification
  • Where required, seek fresh consent before applying significant changes to how we process your data

15. Complaints & Supervisory Authority

If you are unhappy with how we handle your personal data, please contact us first at [email protected] so we can try to resolve the issue.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office

Website: ico.org.uk

Helpline: 0303 123 1113

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

16. Contact Us

Apex Civil Engineering Consultants LTD

Trading as SafeSentry

Data Protection Email: [email protected]

General Enquiries: [email protected]