Privacy Policy
Last updated: 22 September 2026
1. Who we are
Safety Campaign Hub (“we”, “us”, “our”) provides a software-as-a-service platform for generating QHSSE campaigns, learning from incidents, and planning QHSSE weeks. This policy explains how we handle personal data in connection with our website and services.
2. Data we collect
- Account data: name, work email address, organisation name, and role, provided when you sign up or are invited by a colleague.
- Content you create: organisation profile, campaigns, incidents, and other content you generate or store in the product.
- Observation reports: the description you write or dictate, location and site details, hazard classification, immediate actions taken, and — unless you report confidentially or anonymously — your name. Confidential reports hide the reporter from other users but remain visible to designated reviewers; anonymous reports store no reporter identity at all.
- Voice recordings: when you use voice capture, audio is sent for transcription, converted to text, and is not retained after transcription. Only the resulting text is stored on the observation.
- Photos and evidence files: images attached to observations or to action evidence. Please avoid photographing faces, ID badges, or personal documents; the product reminds you of this at the point of capture.
- Corrective action data: action owners, due dates, completion notes, verification decisions, and the audit trail of who changed what and when.
- Contractor details: contractor or supplier company names and, where an action is assigned externally, the contact name and email of the assigned action owner.
- Usage data: pages visited, features used, and basic device/browser metadata, collected via privacy-preserving analytics.
- Support communications: messages you send to us via email or contact forms.
- Marketing opt-ins: if you subscribe via one of our free tools, we store the email address you provide together with the tool name and timestamp.
3. How we use data
- To provide, secure, and improve the service.
- To authenticate you and enforce role-based access within your organisation.
- To communicate service, billing, and security notices.
- With consent, to send occasional product updates and safety campaign ideas. You can unsubscribe at any time.
- To comply with legal obligations and protect our legitimate interests.
4. AI processing
We use AI models to transcribe voice notes, translate observation text, suggest hazard classification and risk ratings, propose corrective actions, summarise trends, and generate campaign material. AI suggestions are always labelled as suggestions and require human confirmation before they are recorded as a decision. Content sent to our AI provider is processed to return a result for you; it is not used to train third-party models. Where a campaign is generated from observation trends, only anonymised, aggregated context is used — never reporter names or identifiable photos.
5. Legal bases (UK GDPR / EU GDPR)
We rely on the following legal bases: performance of a contract with you or your organisation, our legitimate interests in operating a secure product and in workplace health and safety management, consent for marketing communications, and compliance with legal obligations. Where observation data touches on health and safety at work, processing is carried out to meet your organisation’s obligations as an employer.
6. Sharing and processors
We share data with vetted subprocessors that help us run the service, including cloud hosting, database and authentication, AI inference and transcription, payment processing, email delivery, and analytics. Where your organisation assigns an action to an external contractor, that recipient can see only the single action assigned to them and nothing else in your workspace. We do not sell personal data. A current subprocessor list is available on request.
7. International transfers
Personal data may be processed in the United Kingdom, the European Economic Area, and other jurisdictions where our subprocessors operate, using recognised safeguards such as Standard Contractual Clauses.
8. Retention
We keep account and content data for as long as your organisation has an active account, and for a limited period afterwards to meet legal, tax, and audit obligations. Observation records, actions, evidence, and audit trails are retained for the period your organisation configures for safety record keeping. Voice audio is discarded immediately after transcription. Marketing contact data is kept until you unsubscribe.
9. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. To exercise these rights, contact info@safetycampaignhub.com. Anonymous observations contain no reporter identity, so we cannot link them back to an individual for access or deletion requests.
10. Security
We use industry-standard security controls including encryption in transit, row-level-security-scoped multi-tenant data isolation, role-based access controls, and monitored infrastructure. No online service can be 100% secure; please use a strong, unique password and enable available account protections.
11. Cookies
We use strictly necessary cookies to keep you signed in and optional analytics cookies to understand aggregate product usage. You can control cookies through your browser.
12. Children
The service is intended for business users and is not directed at children under 16.
13. Changes to this policy
We may update this policy from time to time. Material changes will be communicated in the product or by email to account owners.
14. Contact
Questions or requests: info@safetycampaignhub.com.