Privacy policy
Last updated 25 September 2026
Draft. This has not yet been checked by a solicitor, and the parts in square brackets still need filling in. It describes how Keelsafe actually works today.
Who we are
Keelsafe is run by [legal name of the company], [registered address], company number [number]. For anything about your data, contact us at [privacy email address].
Two kinds of data, two roles
Your company's records. When a company uses Keelsafe it records information about its staff, subcontractors and sites: names, job titles, training certificates, incidents and injuries, leave, HR details, permits and so on. The company decides what goes in and why. For that data the company is the controller and Keelsafe is its processor: we only handle it to run the service for that company, under a data processing agreement ([to be written]).
Account and billing data. For the people who sign in (name, email address, what they do in the app) and for billing contacts, Keelsafe is the controller.
What we keep, and why
- Logins: name, email address, a one-way scrambled copy of the password (never the password itself), roles, and when you last signed in. Needed to let you in and show you what your role allows.
- An audit trail of who changed what and when, so every company has a record it can rely on.
- Files you upload (certificates, RAMS, photos), stored privately and only opened through the app after it checks who is asking.
- Billing: the plan, the payment status and invoices. Card details go straight to Stripe; Keelsafe never sees or stores a card number.
The legal bases are the contract with the company using the service, and our legitimate interest in running it securely.
Where it's kept
On servers in the European Union: the app, its database and uploaded files are hosted by Railway in its EU West (Amsterdam) region. A nightly encrypted backup is kept on the same hosting for 7 days and, [once switched on], an encrypted copy with Cloudflare R2 in the EU for 30 days.
Who else handles it
- Railway: hosting (EU).
- Stripe: card payments and invoices, for companies that pay by card.
- [Resend or Postmark]: sending emails such as invites and reminders, once email is switched on.
- [Cloudflare]: the off-site copy of the backups, once switched on.
We don't sell data, share it for advertising, or send it to an AI model.
Cookies
One cookie keeps you signed in. There are no tracking, advertising or analytics cookies.
How long we keep it
Each company decides how long its records are kept, and can set retention periods in the app. When a company closes its account, its data is deleted at once. Deleted data stays in backups until they age out: up to 7 days on the hosting and [30] days in the off-site copy.
Your rights
You can ask for a copy of your data, to correct it, to delete it, or to object to or restrict how it's used. If you're recorded by a company that uses Keelsafe, ask that company first: it controls those records and can download everything held about one person from the app. You can also contact us at [privacy email address], and you can complain to the Data Protection Commission (Ireland) or the Information Commissioner's Office (UK).
Security
Each company's data is kept apart and every request is checked against who is signed in and what their role allows. Passwords are stored scrambled, sign-in attempts are limited, backups are encrypted, and the site only works over a secure connection.