Legal

Privacy Policy

Last updated: August 27, 2026

This page is a working draft prepared for pilot customers. Final wording is pending review by SafeSignal's legal counsel before general availability.

1. Who we are

SafeSignal ("we", "us") provides a psychological-safety platform that lets employees raise workplace concerns confidentially and helps organisations respond. The customer organisation is the data controller for reports and staff records; SafeSignal is the data processor.

2. What we collect

  • From HR administrators: name, work email, organisation, role, authentication credentials, session metadata.
  • From employees raising concerns: the free-text content of the report, chosen category, target department/team labels, optional disclosed identity fields, and the private anonymous session token.
  • Automatically: minimal request/log metadata needed to keep the service reliable and secure. We do not use third-party analytics that track report content.

3. Anonymity — what it means and where it ends

Reports are anonymous by default: no account, name, email, or IP is stored alongside the report. However, absolute anonymity cannot be promised in every case. Anonymity may be limited when:

  • You choose to disclose your identity in the form or in a follow-up message.
  • The content of your report itself identifies you (e.g. specific event details).
  • Attachments contain metadata that could reveal identity.
  • A regulator, court, or serious safety concern legally compels disclosure.

Where we can protect you, we do — but we will always describe these limits honestly.

4. How we use information

We use the data only to operate SafeSignal for your organisation: routing concerns to authorised HR staff, providing AI policy-aware guidance, detecting risk patterns, and delivering aggregated culture insights.

5. AI processing

The SafeGuide AI Advice Bot uses the Lovable AI Gateway (Google Gemini) to generate guidance. Report content is transmitted for the duration of the request only. We do not permit AI providers to train on customer content.

6. Sharing

Reports are visible only to authorised administrators of your own organisation. We never share your data with other customers, and never sell it.

7. Retention

Your organisation controls retention. Default retention is the life of the contract plus 90 days, unless required otherwise by law or by your organisation's configuration.

8. Your rights

Where applicable law grants rights of access, correction, deletion, or objection, contact your organisation's HR administrator first. Requests for anonymous reports are handled through your private SafeSignal session link.

9. Security

Encryption in transit, hardened database with organisation-scoped row-level security, single-sign-on where enabled, and periodic security review. See Security.

10. Contact

Privacy questions: contact us. This page will be replaced with the finalised legal text prior to general availability.