SafeContractor Limited (“SafeContractor”) is committed to protecting your privacy. This privacy policy (“Privacy Policy”) explains how SafeContractor collects, stores, and uses your personal information when you interact with us. Crucially, it also explains how we keep that data safe.
We know that there is a lot of information here, but we want you to be fully informed about your rights and how we use your data.
Should we ask you to provide certain information by which you can be identified when using any of SafeContractor’s products, websites, software, applications, or platforms (the “Services”), then you can be assured that it will only be used in accordance with this Privacy Policy. We may change this Privacy Policy by updating this page and/or the Services.
You may give us your personal data by filling in online forms or by corresponding with us by post, phone, email or otherwise. We collect your information:
We will collect and process the following information about you:
SafeContractor’s Services are not intended for children and SafeContractor does not knowingly collect data relating to children unless instructed. If you believe we may have collected information from a child, please contact DPO@safecontractor.com so that we can delete it.
We use information held about you in the following ways:
Information you give to us. We will use this information:
Information we collect about you. We will use this information:
Information we receive from other sources. We will combine this information with information you give to us and information we collect about you. We will use this information and the combined information for the purposes set out above.
Service-Specific Usage. If you wish to see how your personal information is used with your use of SafeContractor Services, please refer to the Services section at the bottom of this Privacy Policy.
Artificial Intelligence. SafeContractor and its Affiliates are in constant pursuit of new and innovative ways to provide you with better, more efficient Services. As such, we are rapidly adopting artificial intelligence (the technologies that empower computers, applications, and systems to learn, reason, and perform a variety of advanced tasks in a human-like manner (“AI”)) throughout our group of companies. SafeContractor:
AI will not make automated decisions about individuals without having a human-in-the-loop component. AI’s purpose is to automate manual and time consuming processes for the benefit of you and us.
We sometimes share your personal data with trusted third parties, including:
We may disclose your personal information to third parties for their own purposes in very specific circumstances, including:
Whenever we collect or process your personal data, we will only keep it for as long as is necessary for the purpose for which it was collected. At the end of that retention period, your data will either be deleted completely or anonymised (e.g., by aggregating it with other data so that it can be used in a non-identifiable way for business planning).
In certain cases, the law requires us to keep personal data for a specific period which SafeContractor must comply with. In this regard, data is retained in accordance with our data retention policy.
We may record calls for training and quality purposes. We will not use the information that we collect from you for any purposes other than: a) for training and monitoring the quality of the information that we provide to you during the call; b) compliance with any regulation or law; or c) evidence in the event of a dispute.
Call recordings are stored securely and access to such recordings is limited to certain personnel only. Recorded calls will be saved in accordance with our data retention policy.
We use ResponseIQ to manage overflow calls which appears as a widget on some SafeContractor websites. You consent to the processing of your personal data when you submit contact information to ResponseIQ who will be the data controller of that information. Should you wish to withdraw your consent to this processing, please contact ResponseIQ as detailed here: https://responseiq.com/gdpr.
You have the right to request:
If you reside in the UK or EEA you also have the right to request:
To ask for your information to be amended, please update your online account, or contact your account manager or our Data Protection Officer at DPO@safecontractor.com .
If we choose not to action your request, we will explain to you the reasons for our refusal.
Your right to withdraw consent
Whenever you have given us your consent to use your personal data, you have the right to change your mind at any time and withdraw that consent.
Your objection to our use of your personal information (or withdrawal of any previously given consent) could mean that we are unable to perform the actions necessary to achieve the purposes set out above (see ‘Use of your information’) or that you may not be able to make use of the Services offered by us. Please note that even after you have chosen to withdraw your consent, we may be able to continue to process your personal information to the extent required or otherwise permitted by law, in particular in connection with exercising and defending our legal rights or meeting our legal and regulatory obligations.
Where we rely on our legitimate interest
Where we are processing your personal data on the basis of our legitimate interest, you can ask us to stop for reasons connected to your individual situation. We must comply unless we believe we have a legitimate overriding reason to continue processing your personal data.
Direct marketing and Opt Out
In most cases, we do not undertake marketing, promotions or competitions via the software applications or platforms. This is undertaken via other means. You can ask us to stop sending you marketing messages at any time by contacting us. Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us because of a service purchase, service experience or other transactions.
You have the right to stop the use of your personal data for direct marketing activity through all channels, or selected channels. We must always comply with your request.
If you opt out of receiving marketing communications, you will still receive Service-related communications that are essential for administrative or customer service purposes for example relating to order confirmations for purchases, updates to our terms and conditions, and checking that your contact details are correct.
Checking your identity
To protect your information, we will ask you to verify your identity before proceeding with any request you make under this Privacy Policy. If you have authorised a third party to submit a request on your behalf, we will ask them to prove they have your permission to act.
Partner websites
Our website may contain links to and from the websites of our partner networks, affinity scheme partners, advertisers, and affiliates. Please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. You should check these policies before you submit any personal data to these websites.
If you fail to provide personal data
If you fail to provide personal data when requested, we may not be able to perform the actions that are necessary to achieve the purposes set out above (see ‘Use of your information’) or that you may not be able to make use of the Services offered by us. In this case, we may have to cancel the Services you have with us but we will notify you if this is the case.
Our website uses cookies to distinguish you from other website users. This helps us to provide you with a good browsing experience. For detailed information on the cookies we use and the purposes for which we use them, see our cookie policy.
All information you provide to us is stored on our secure servers. Any payment transactions will be encrypted using SSL technology. Where you have chosen a password which enables you to access certain parts of our website, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our website; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
EEA/UK
In order to provide our Services, we may need to transfer your personal information to locations outside the country in which you provide it or where you are viewing this website for the purposes set out in this Privacy Policy. This may entail a transfer of your information from a location within the European Economic Area (the “EEA”) or the UK to outside the EEA/UK, or from outside the EEA to a location within the EEA/UK. As such, your personal data may be accessible to law enforcement and national security authorities of these jurisdictions pursuant to applicable laws. Please see ‘Sharing your information’ for more detail on how the information may be shared within our group of companies and with third party service providers.
The level of information protection in countries outside the EEA/UK may be less than that offered within the EEA/UK. Where this is the case, we will implement appropriate measures to ensure that your personal information remains protected and secure in accordance with applicable data protection laws. EU and UK standard contractual clauses are in place between SafeContractor and all of its Affiliates that share and process personal data. Please contact us using the details in the ‘How to contact us’ section below to request a copy of these clauses. Where our third-party service providers process personal data outside the EEA/UK in the course of providing Services to us, our written agreement with them will include appropriate measures, usually standard contractual clauses.
UK & EEA
We hope this Privacy Policy has been helpful in terms of how we use your personal data and your rights in relation to such personal data. If you have any questions or wish to make a complaint, please contact our Data Protection Officer:
Email us at DPO@safecontractor.com
Write to us at Data Protection Officer, Axys House, Heol Crochendy, Parc Nantgarw, Cardiff CF15 7TW.
If you are not satisfied with our response or believe we are processing your personal data not in accordance with the law you can complain to the Information Commissioner’s Office (ICO).Service-Specific Usage
Data Types
Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity such as statistical or demographic data. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this Privacy Policy.
Communications Data includes your communication preferences in receiving service communications from us.
Contact Data includes billing and operational address(es), email address and telephone numbers.
Financial Data includes bank account and payment card details.
Identity Data includes first name, last name, username or similar identifier, title, and in certain circumstances, your date of birth (this is used solely to determine whether an individual meets the legal age requirement to undertake specific types of work on behalf of a client), account or reference number.
Marketing and Communications Data includes your marketing and communication preferences in receiving marketing from us and our third parties.
Profile Data includes your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.
Sensitive Information includes information relating to any health and safety incident occurring at your workplace, which may include information about your health or medical conditions (which requires a higher level of protection under applicable data protection law).
Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our Services.
Transaction Data includes details about payments to and from you and other details of Services you have purchased from us.
Services Data includes data provided by you necessary for the provision of the Services.
Usage Data includes information about how you use our Services.
Purposes for which we will use your personal data – all Services
| Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest |
| To deliver our Services. | (a) Identity Data
(b) Contact Data (c) Services Data |
Performance of a contract with you or our client |
| To manage our relationship with you which will include:
(a) Notifying you about changes to our terms or this Privacy Policy (b) Asking you to leave a review or take a survey (c) Manage payments, fees, and charges (d) Collect and recover money owed to us |
(a) Identity Data
(b) Contact Data (c) Marketing and Communications Data (d) Financial Data (e) Transaction Data |
(a) Performance of a contract with you or our client
(b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our Services, to collect debts due to us) |
| To enable you to partake in a prize draw, competition or complete a survey | (a) Identity Data
(b) Contact Data (c) Usage Data (d) Marketing and Communications Data |
(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to study how customers use our Services, to develop them and grow our business) |
| To administer and protect our business and a relevant platform (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) and monitoring usage of a relevant platform and compliance with the contract we have in place with our client | (a) Identity Data
(b) Contact Data (c) Technical Data |
(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)
(b) Necessary to comply with a legal obligation |
| To deliver relevant platform content to you | (a) Identity Data
(b) Contact Data (c) Usage Data (d) Marketing and Communications Data (e) Technical Data |
Necessary for our legitimate interests or soft opt-in, where relevant (to study how customers use our Services, to develop them, to grow our business and to inform our marketing strategy) |
| To use data analytics to improve a platform, services, marketing, customer relationships and experiences | (a) Technical Data
(b) Usage Data |
Necessary for our legitimate interests (to define types of customers for our Services, to keep our Platform updated and relevant, to develop our business and to inform our marketing strategy) |
| To make suggestions and recommendations to you about goods or services that may be of interest to you | (a) Identity Data
(b) Contact Data (c) Technical Data (d) Usage Data |
Necessary for our legitimate interests or soft opt-in, where relevant (to develop our Services and grow our business) |
SafeContractor Platform
When you use the SafeContractor and SafeSupplier platform (the SafeContractor Platform), your personal data will be processed in accordance with the information below.
Disclosures of your personal data
In addition to the disclosure of personal data in accordance with this Privacy Policy, with your use of the SafeContractor Platform we may have to share your personal data as follows:
SafePlanet
SafePlanet allows organisations to measure their and/or their supply chain’s carbon emissions. Whenever you use SafePlanet Services, your data may be processed and stored in Planet Mark’s and its Affiliates’ platforms and systems. All documents and information submitted or uploaded to Planet Mark, its Affiliates, or their platforms and systems including any personal data contained therein shall be processed in accordance with this Privacy Policy.
Appointed Subprocessors
| Purpose of Processing | Sub-Processors |
| Electronic Signature Service | DocuSign Inc. |
| Call Recordings and Tracking | Ring Central |
| Software Analytics | Airbrake Technologies, Inc, Walkme Ltd., Pendo |
| Data processing and integration | Dataddo, Zapier |
| Customer Relationship Management | Microsoft Dynamics 365 |
| Online Chat | LiveChat Inc |
| Cloud Hosting | Amazon Web Services, Microsoft Azure |
| Payment Processors | Bambora Inc., Stripe, Inc., PayPal Holdings, Inc., WorldPay, Stripe, GoCardless, Global Payment Inc. |
| Platform Engagement | Twilio Inc. (SendGrid), Pendo, StreamYard |
| Email Services | Sinch Mailgun, Microsoft Office 365 |
| Monitoring and security | Datadog |
| Sales Engagement Platforms | HubSpot, Inc., LinkedIn, Meta |
| Web Analytics | Google LLC, Pendo, Hotjar |
| Marketing and Email Automation | WeDoCRM |
| Project management and issue tracking | Atlassian Jira |
| Testing platform | Browserstack |