Data Processing Agreement
Last reviewed: 2 August 2026
This Data Processing Agreement ("DPA") forms part of the agreement governing the customer's use of the SafeSite AI Technology platform wherever SafeSite AI Technology Ltd processes personal data on behalf of a customer organisation. A signed copy is available on request by contacting the address in Section 19.
1. Parties
This DPA is between the customer organisation, acting as the data controller ("Controller"), and SafeSite AI Technology Ltd, Company No. 17111651, ICO Registration No. ZC160399, acting as the data processor ("Processor").
This DPA applies only to processing carried out by the Processor on the Controller's behalf. SafeSite AI Technology Ltd may separately act as a controller for account administration, billing, security, service analytics, support and its own legal obligations, as described in its Privacy Policy.
2. Definitions
In this DPA:
- Applicable Data Protection Law means the UK GDPR, the Data Protection Act 2018 and other applicable UK data-protection legislation.
- Controller, Processor, Personal Data, Personal Data Breach, Processing, Data Subject and Supervisory Authority have the meanings given under Applicable Data Protection Law.
- Customer Data means Personal Data processed by the Processor on behalf of the Controller through the platform.
- Subprocessor means another processor engaged by the Processor to process Customer Data.
3. Subject matter and duration
The Processor will process Customer Data as necessary to provide, secure, maintain and support the SafeSite AI Technology platform.
Processing will continue for the duration of the customer's subscription and any limited period afterwards required to return, export or securely delete Customer Data, or to comply with applicable law.
4. Nature and purpose of processing
The Processor may process Customer Data to:
- generate, upload, store, review and improve compliance documents;
- provide RAMS, risk-assessment, method-statement, COSHH and permit workflows;
- record incidents, near misses, audits, corrective actions and management reviews;
- maintain document-control records, approvals, version histories and audit trails;
- provide authentication, access control, platform security, support and service functionality;
- perform other processing documented in the Controller's use of the platform and subscription agreement.
5. Categories of data subjects
Customer Data may relate to:
- the Controller's employees, workers, agency staff, contractors and consultants;
- competent persons, approvers, reviewers and authorised platform users;
- individuals named in incident, near-miss, investigation, audit or corrective-action records;
- other individuals whose information the Controller chooses to include in documents or records.
6. Categories of personal data
Customer Data may include:
- names and contact details;
- job titles, roles and employment-related identifiers;
- training, competency and qualification information;
- signatures, approvals and audit-trail information;
- incident, near-miss and investigation information;
- information contained in RAMS, risk assessments, COSHH assessments, permits, audits and corrective actions;
- health-related information where the Controller chooses to record it;
- uploaded files and related metadata;
- platform usage and activity records associated with authorised users.
The Controller is responsible for determining and documenting the lawful basis for processing Customer Data and, where special-category data is involved, the applicable condition under Article 9 of the UK GDPR and any associated requirements under the Data Protection Act 2018.
7. Controller instructions and responsibilities
The Controller instructs the Processor to process Customer Data:
- to provide the services described in the applicable subscription agreement;
- in accordance with this DPA;
- through the Controller's and its authorised users' configuration and use of the platform; and
- through any other written instructions agreed between the parties.
The Controller is responsible for:
- ensuring its instructions comply with Applicable Data Protection Law;
- ensuring it has a lawful basis for processing and disclosing Customer Data to the Processor;
- giving required privacy information to affected Data Subjects;
- determining whether a data protection impact assessment is required;
- ensuring authorised users only upload information that is necessary and lawful to process.
The Processor will notify the Controller if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law, unless the Processor is legally prohibited from doing so.
8. Processor obligations
The Processor will:
- process Customer Data only on the Controller's documented instructions, unless required otherwise by applicable law;
- notify the Controller of any legal requirement to process Customer Data outside those instructions, unless prohibited by law;
- ensure persons authorised to process Customer Data are subject to confidentiality obligations;
- implement appropriate technical and organisational measures;
- assist the Controller, taking account of the nature of processing and information available to the Processor, with Data Subject requests;
- assist the Controller with security, breach notification, impact assessments and prior consultation obligations where reasonably required;
- make available information reasonably necessary to demonstrate compliance with this DPA;
- maintain records required of processors under Applicable Data Protection Law;
- not sell Customer Data or use it for unrelated advertising purposes.
9. Confidentiality
The Processor will ensure that personnel authorised to access Customer Data:
- access it only where necessary to perform their duties;
- are subject to contractual, statutory or professional confidentiality obligations;
- receive appropriate privacy and security instructions.
10. Security measures
The Processor will maintain technical and organisational measures appropriate to the risks presented by the processing. Measures may include, where applicable, encryption in transit, authentication and access controls, tenant and organisation-level access restrictions, row-level database security, secure development and deployment controls, rate limiting and abuse prevention, logging and security monitoring, and backup and recovery controls.
Further details may be made available to the Controller on reasonable request, subject to security and confidentiality restrictions.
11. Subprocessors
The Controller gives the Processor general written authorisation to engage Subprocessors. Current Subprocessors may include:
- Supabase - database, storage and authentication infrastructure.
- Vercel - hosting, deployment and platform infrastructure.
- Anthropic - AI-assisted document analysis, review and generation.
- Stripe - billing and payment processing.
- Upstash - rate limiting, caching and supporting infrastructure.
The Processor will:
- impose data-protection obligations on each Subprocessor that provide materially equivalent protection to this DPA;
- remain responsible to the Controller for the Subprocessor's performance of those obligations;
- give reasonable advance notice of any intended addition or replacement;
- allow the Controller to object on reasonable data-protection grounds.
If the parties cannot resolve an objection in good faith, the Controller may terminate the affected service in accordance with the subscription agreement.
12. International transfers
The Processor will not make a restricted transfer of Customer Data outside the United Kingdom unless the transfer is permitted under Applicable Data Protection Law.
Where required, the Processor will rely on an appropriate transfer mechanism, which may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission Standard Contractual Clauses;
- another lawful safeguard or exception.
Where required, the Processor or relevant Subprocessor will complete an appropriate transfer-risk assessment and implement supplementary safeguards.
13. Data-subject requests
Where the Processor receives a request directly from a Data Subject concerning Customer Data processed on behalf of the Controller, the Processor will promptly notify the Controller unless legally prohibited, will not respond substantively except on the Controller's documented instructions or where required by law, and will provide reasonable assistance using appropriate technical and organisational measures. The Controller remains responsible for responding to the request.
14. Personal Data Breaches
The Processor will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Data. The notice will include, where reasonably available, the nature of the breach, the categories and approximate numbers of affected Data Subjects and records, the likely consequences, and measures taken or proposed to contain and remediate it. Information may be provided in phases where it is not available at the same time. The Processor's notification does not constitute an admission of fault or liability.
15. Return and deletion
At the end of the services, the Processor will, at the Controller's choice:
- return or make available an export of Customer Data in a reasonably accessible format; or
- delete the Customer Data.
Following return or deletion, the Processor will delete remaining copies unless applicable law requires continued storage. Customer Data may remain temporarily within secure backups until those backups are overwritten in accordance with the Processor's ordinary retention cycle. During that period, the data remains protected and will not be restored except for legitimate disaster-recovery or legal purposes.
16. Audit and inspection rights
The Processor will make available information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR and this DPA. The Controller may conduct an audit itself or through an independent auditor, subject to reasonable advance written notice, no more than once per year unless a security incident or regulatory requirement justifies additional review, reasonable scope and duration, confidentiality and security requirements, avoidance of unreasonable disruption, and the Controller bearing its own costs and, where an audit creates material additional work, reimbursing the Processor's reasonable costs.
The Processor may satisfy audit requests initially through questionnaires, policies, certifications, reports or other documentation. On-site inspection should be reserved for cases where those materials are reasonably insufficient.
17. Liability and relationship to other terms
This DPA forms part of the agreement between the parties. The liability limits and exclusions in the SafeSite AI Technology Terms & Conditions apply to this DPA, except where Applicable Data Protection Law prohibits such limitation. If this DPA conflicts with the Terms & Conditions on a matter concerning the processing of Customer Data, this DPA prevails to the extent of that conflict.
18. Governing law
This DPA is governed by the same governing law and jurisdiction as the applicable subscription agreement or Terms & Conditions.
19. Contact
Questions, notices and requests concerning this DPA should be sent to: privacy@safesiteaitechnology.com