Legal

    Privacy Policy

    Last updated: 13 March 2026 · Data Controller: Safeheld Limited

    This Privacy Policy explains how Safeheld collects, uses, shares, and protects personal data in relation to our website and Platform. Safeheld processes personal data under UK GDPR, EU GDPR, and applicable data protection laws.

    1. Roles & Scope

    Safeheld generally acts as controller for website analytics, marketing contacts, and account administration data; and as processor for Client Data handled through customer environments.

    Contact: hello@safeheld.com

    2. Categories of Personal Data

    CategoryExamplesSourceLegal Basis
    Account dataName, work email, role, companyProvided by you or your employerContract performance
    Usage telemetryFeature events, logs, browser/device metadata, IPAutomatically collectedLegitimate interests
    Support dataTickets, meeting notes, attachmentsProvided during supportContract performance
    Marketing preferencesOpt-in status, campaign interactionProvided by youConsent
    Security dataAuthentication events, audit trailsPlatform activityLegal obligation / legitimate interests

    3. How We Use Personal Data

    PurposeWhat this includesLegal BasisRetention
    Service deliveryProvisioning, authentication, tenant operationsContract performanceContract term + 12 months
    Security operationsThreat detection, abuse prevention, incident responseLegitimate interestsUp to 24 months
    Customer supportTroubleshooting, remediation, service communicationsContract performanceUp to 24 months
    Product improvementAggregated analytics and reliability metricsLegitimate interestsUp to 26 months
    MarketingNewsletters and event communicationsConsentUntil opt-out

    4. Sharing & Sub-processors

    Safeheld shares personal data only with vetted service providers needed to operate the Platform (hosting, monitoring, communications), professional advisers, and authorities where legally required.

    All sub-processors are bound by contractual data protection obligations and confidentiality commitments.

    5. International Transfers

    Safeheld hosts client data in European Union data centres. Where data is transferred between jurisdictions, Safeheld applies lawful transfer mechanisms such as adequacy decisions or EU Standard Contractual Clauses, together with supplementary safeguards where required.

    6. Security Controls

    • Encryption in transit and at rest.
    • Role-based access controls with least-privilege principles.
    • Operational logging, monitoring, and incident response runbooks.
    • Periodic security testing and vendor risk review procedures.
    • Documented business continuity and recovery planning.

    7. Data Subject Rights

    You may have rights to access, correct, delete, restrict, object, and port personal data, subject to legal limitations.

    Requests can be submitted to hello@safeheld.com. We aim to respond within one month.

    8. Complaints

    If you are dissatisfied with our response, you may contact the UK Information Commissioner's Office (ICO) or your local supervisory authority.

    9. Policy Updates

    We may update this Policy to reflect legal, regulatory, or operational changes. Material updates will be posted with an updated effective date.

    Privacy enquiries: hello@safeheld.com

    The system of record for client funds and reserves