Legal
Privacy Policy
Last updated: 13 March 2026 · Data Controller: Safeheld Limited
1. Roles & Scope
Safeheld generally acts as controller for website analytics, marketing contacts, and account administration data; and as processor for Client Data handled through customer environments.
Contact: hello@safeheld.com
2. Categories of Personal Data
| Category | Examples | Source | Legal Basis |
|---|---|---|---|
| Account data | Name, work email, role, company | Provided by you or your employer | Contract performance |
| Usage telemetry | Feature events, logs, browser/device metadata, IP | Automatically collected | Legitimate interests |
| Support data | Tickets, meeting notes, attachments | Provided during support | Contract performance |
| Marketing preferences | Opt-in status, campaign interaction | Provided by you | Consent |
| Security data | Authentication events, audit trails | Platform activity | Legal obligation / legitimate interests |
3. How We Use Personal Data
| Purpose | What this includes | Legal Basis | Retention |
|---|---|---|---|
| Service delivery | Provisioning, authentication, tenant operations | Contract performance | Contract term + 12 months |
| Security operations | Threat detection, abuse prevention, incident response | Legitimate interests | Up to 24 months |
| Customer support | Troubleshooting, remediation, service communications | Contract performance | Up to 24 months |
| Product improvement | Aggregated analytics and reliability metrics | Legitimate interests | Up to 26 months |
| Marketing | Newsletters and event communications | Consent | Until opt-out |
4. Sharing & Sub-processors
Safeheld shares personal data only with vetted service providers needed to operate the Platform (hosting, monitoring, communications), professional advisers, and authorities where legally required.
All sub-processors are bound by contractual data protection obligations and confidentiality commitments.
5. International Transfers
Safeheld hosts client data in European Union data centres. Where data is transferred between jurisdictions, Safeheld applies lawful transfer mechanisms such as adequacy decisions or EU Standard Contractual Clauses, together with supplementary safeguards where required.
6. Security Controls
- Encryption in transit and at rest.
- Role-based access controls with least-privilege principles.
- Operational logging, monitoring, and incident response runbooks.
- Periodic security testing and vendor risk review procedures.
- Documented business continuity and recovery planning.
7. Data Subject Rights
You may have rights to access, correct, delete, restrict, object, and port personal data, subject to legal limitations.
Requests can be submitted to hello@safeheld.com. We aim to respond within one month.
8. Complaints
If you are dissatisfied with our response, you may contact the UK Information Commissioner's Office (ICO) or your local supervisory authority.
9. Policy Updates
We may update this Policy to reflect legal, regulatory, or operational changes. Material updates will be posted with an updated effective date.
Privacy enquiries: hello@safeheld.com