Back to Home

Privacy Policy

Last updated: 9 September 2026

1. Introduction

This policy describes how LifeSafety.ai Limited collects, uses, shares and stores your personal information - what we collect, why we have it, who we share it with, and what rights you have in relation to it. It applies to our website, our iOS and Android applications and the health and safety platform our customers access (the "Platform").

We are registered in England and Wales and we are located in Milton Keynes. Our processing is subject to the UK General Data Protection Regulation, the Data Protection Act 2018 and, where relevant, the Privacy and Electronic Communications Regulations 2003 (cookies and electronic marketing).

One distinction matters throughout. For data about you as a visitor, enquirer or account holder, we are the controller — we decide why it is processed. For the safety records your employer uploads to the Platform (risk assessments, incident reports, training records and so on), your employer is the controller and we are the processor acting on their instructions. If your query concerns records held by your employer, they are usually the right first point of contact.

2. Who we are

Controller: LifeSafety.ai Limited, Milton Keynes, United Kingdom

Data Protection Officer: dpo@lifesafety.ai

Privacy enquiries: privacy@lifesafety.ai

Telephone: +44 (0)208 720 6528

3. What we collect

What we track depends on how you treat us. Surfing the site leaves far less behind than leading a site team on the Platform.

3.1 Information you give us

  • Account information: Name, email address, telephone number, job title, company name, and business address
  • Billing information: Payment card details, billing address, VAT number
  • Communications: Information you provide when contacting our support team
  • Platform content: Data you upload including risk assessments, incident reports, training records

3.2 Information collected automatically

  • Device information: IP address, browser type, operating system, device type
  • Usage data: Pages visited, features accessed, actions taken
  • Log data: Server logs including access times and system activity

3.3 Mobile app data

The apps request some permissions that the website doesn't. This is because reporting an incident from a live site requires a camera and a location. Each permission is only used for the feature it's associated with, and they can all be revoked in your device settings.

  • Contact information: Name, email address, and phone number for account authentication and communication purposes
  • Location data: Allow the app to use your precise location when you report incidents, make site diary entries or check in at a site. You can turn location access on or off in your device settings.
  • Photos and videos: Camera and photo library access to attach evidence to incident reports, safety inspections, and audit documentation
  • User-generated content: Reports, notes, safety observations, or other content that you create in the app, including text, audio recordings, and other information
  • Device identifiers: Unique device ID, advertising identifier (where permitted), and push notification tokens
  • User ID: Internal account identifier linking your app activity to your LifeSafety.ai account

We use this for the features themselves — reporting incidents, tagging locations, uploading photos — and, in the aggregate, to see which features are being used and where the app is crashing. Our collection is in line with Apple App Store and Google Play privacy guidelines.

4. Why we are allowed to process it

UK GDPR requires a lawful basis for each purpose. Ours are:

  • Performance of a contract — operating your account, delivering the Platform, charging you, and helping you when it breaks.
  • Legitimate interests — to keep the service secure, for the prevention of misuse, for the correction of faults and for the determination of which features are justified in the long run. We balance this with your interests and you can object (see section 10).
  • Legal obligation — tax and accounting records, and responding to lawful requests.
  • Consent — marketing communications and non-essential cookies. You can withdraw your consent at any time without affecting what has already happened.

5. How we use your information

In practice this means we use your data to create and manage accounts, deliver the Platform and its modules to you, process payments and issue invoices, respond to support requests, send service messages (such as maintenance and security notices), investigate incidents that affect your service, and compile aggregate statistics to help us decide what to build next.

We do not use your safety information for advertising profiles, and we do not make decisions about you through automated means with legal or similarly significant effects.

6. Who we share it with

We do not sell personal data, and we never have. We do share it with a small number of suppliers to run the service — cloud hosting, payment processing, email delivery, error monitoring and customer support tooling. They act on our written instructions, may only use the data to perform their service, and are contractually bound to protect it.

Except as described in this Privacy Policy, we do not disclose personal data unless we are required to do so by law, in order to establish, exercise or defend our legal rights, to protect the vital interests of an individual, or where you have given us your consent. If the business is sold or reorganised, data held by us may be transferred as part of that process; you would be notified and this policy would remain in place until revoked or replaced.

7. Where your data is held

Where your data resides depends on where you are located. If you are a customer in the UK or Europe your hosting environment will be in UK data centres. If you are a customer in the United States your hosting environment will be in US data centres. Your data will remain in its home region — we do not migrate a European tenant onto US infrastructure, or vice versa. Other regions are available on request.

Some limited transfers still happen — a supplier with support teams in another country, for instance. Where that involves data leaving its home region we put safeguards in place first, including the UK International Data Transfer Agreement or Standard Contractual Clauses, and assess the destination before anything moves.

8. How long we keep it

We keep personal data for as long as your account is active, and afterwards only where we still need it — to meet accounting and tax obligations, to resolve disputes, or to enforce our agreements. Safety records uploaded by a customer are retained according to that customer's own retention policy, since they control them; on request at the end of a contract we return or delete them. Marketing contact details are removed once you unsubscribe. Server logs are held for a short operational period and then discarded.

9. Keeping it secure

Data in Transit is encrypted using TLS 1.2 (or above) and Data at Rest is encrypted using AES-256. Access to data from within the Platform is controlled through role-based permissions. Administrator accounts are required to have multi-factor authentication enabled. Only employees with a job-related need to do so can access the production systems.

Around that, we regularly test and evaluate security and carry out penetration testing, provide data protection training to our staff, have documented incident-response plans in place and take regular, disaster recovery aware backups of data. No system can be 100% secure however, so in the event of a breach which impacts your rights we will report the breach to the ICO within 72 hours where required, and we will notify you where there is a high risk to you.

10. Your rights

Under UK GDPR you can ask us to:

  • Give you a copy of the personal data we hold about you
  • Correct anything inaccurate or incomplete
  • Erase data we no longer have a good reason to keep
  • Restrict how we process it while a question is resolved
  • Port it to you, or another provider, in a machine-readable format
  • Stop processing based on legitimate interests, and stop direct marketing outright
  • Withdraw consent you previously gave

Email privacy@lifesafety.ai and we will respond within one month. There is no charge unless a request is manifestly unfounded or excessive. We may need to confirm your identity first. If we hold the data as a processor for your employer, we will point you to them and help them answer.

You can complain to the Information Commissioner's Office if you're not satisfied with the way we've dealt with you ico.org.uk or on 0303 123 1113. We would rather you came to us first so we can put it right.

10.1 Mobile app controls

  • Device permissions: You can revoke camera, location, or photo library access in your iOS or Android device settings at any time
  • Push notifications: Turn off notification permissions in device settings
  • Data export: Request a copy of your app data in your account settings, or email privacy@lifesafety.ai
  • Account deletion: Email support@lifesafety.ai with the subject "Delete Account"

11. Cookies

Analytics and other non-essential cookies only run once you accept them, and you can change your mind at any time. Our Cookie Policy lists what each one does.

12. Changes to this policy

We revise this policy as our processing or the law changes. The top date always indicates the current version, and we will not rely on you to notice the change if it materially affects you.

13. Contact us

LifeSafety.ai Limited

Milton Keynes, United Kingdom

Privacy: privacy@lifesafety.ai

Data Protection Officer: dpo@lifesafety.ai

Telephone: +44 (0)208 720 6528

We value your privacy

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies.