Last updated: July 2026
MySafeOps ("we", "us", "our") is committed to protecting the privacy and personal data of our users. This policy explains how we collect, use, store, and protect your information in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
MySafeOps is a construction safety management platform operated from the United Kingdom by an individual sole trader trading as MySafeOps. For the purposes of data protection law relating to account holders and website visitors, we are the data controller.
Your organisation is usually the data controller for worker, site, and project information you enter into the product. We act as a data processor for that operational data when you use optional cloud features — see our Data processing overview.
Contact: privacy@mysafeops.com
Trading identity and business address are available on request at privacy@mysafeops.com for contracts, invoices, and regulatory correspondence. We are registered with the Information Commissioner's Office (ICO) where required by law; our registration reference is available on request.
When you register, we collect: name, email address, phone number, company name, and role (admin/supervisor/worker).
Organisations may store worker information including: name, role, company, phone, CSCS card details, certificate numbers and expiry dates, emergency contacts, and medical information (if provided voluntarily).
Documents created in the platform including: RAMS, permits to work, site reports, incident reports, risk assessments, method statements, checklists, and inspection records.
Site photographs (which may include GPS location data), uploaded documents, certificate scans, site plan drawings, and company logos.
Vehicle registrations, MOT/insurance/tax dates, equipment serial numbers, inspection records, and calibration certificates.
IP address, browser type, device information, and usage analytics. We do not use third-party tracking cookies.
Depending on how you use MySafeOps, personal data may be processed by the following infrastructure (see also section 5):
Data may also remain in your browser (local storage / IndexedDB) when you use offline-first features without cloud sync.
Security measures include:
We use vetted subprocessors to deliver the service. A summary list is in our Data processing overview and on the Security & trust page. Where personal data is processed outside the UK, we rely on appropriate safeguards (for example the UK International Data Transfer Agreement / Addendum) as reflected in the DPA we agree with your organisation.
We never sell your data for third-party marketing.
We retain your data for as long as your account is active. UK health and safety law requires certain records to be kept for specific periods:
When you delete your account, we will delete all personal data within 30 days, except where we are legally required to retain it.
You have the right to:
To exercise any of these rights, email: privacy@mysafeops.com
When workers take photos using MySafeOps, the app may record GPS coordinates. This is used solely for documenting site conditions and is stored with the photo. Location tracking is only active during photo capture — we do not continuously track worker locations.
We use essential cookies and browser storage required for sign-in, security, and preferences. We do not use advertising or cross-site tracking cookies on the product. Optional analytics or error reporting may be enabled in some deployments — see our Cookie policy.
MySafeOps is not intended for anyone under 16. We do not knowingly collect data from children.
We may update this policy from time to time. We will notify you of significant changes via email or in-app notification.
If you have concerns about how we handle your data, please contact us first at privacy@mysafeops.com. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
Related: Terms of service · Data processing · Cookies · Accessibility · Security & trust