Privacy

What data the product processes and where the boundaries sit

This factual draft reflects the current implementation. It does not state a legal basis or jurisdiction-specific compliance conclusion.

Pre-launch review status. This page describes current product behavior and is prepared for professional legal review. It is not final, legally approved wording.

Processing roles

HSEVIA controls account and security information, service operations, support and security communications, and limited first-party product analytics needed to operate and understand the service.

Customers control the company and site HSE records, worker or employee information, evidence files and occupational-health information they place in HSEVIA. HSEVIA processes that content to provide the service and according to customer use and instructions. Customers are responsible for appropriate authority, notices, permissions and lawful basis for workforce and personal information they provide. This allocation does not remove HSEVIA's own responsibilities for operating the service.

Data categories

  • Account details such as name, email, verification state and job title.
  • Company, membership, site, project, client and standards configuration.
  • HSE operational information: inspections, risks, permits, audits, training, actions, legal obligations and environmental records.
  • Occupational-health information entered in the Health register, which may be sensitive.
  • Uploaded documents, photographs, evidence, filenames and technical file metadata.
  • Session metadata, including dates, IP address, user agent, verification state and MFA status.
  • Security, administrative and AI audit events.
  • Coarse first-party product-usage milestones, with optional account and company identifiers used for unique funnel counts.
  • Billing status and provider references; Stripe, rather than this app, handles card details.

Storage and access

Account and application records are stored in PostgreSQL. Uploaded source documents are stored in private Supabase object storage and retrieved through authenticated routes after server-side authorization checks. Cloudflare R2 is configured as an independent backup target for stored objects. The Supabase Data API is not used for normal application access.

Cookies, sessions and monitoring

The product uses signed, HTTP-only authentication cookies and a short-lived cookie during two-factor authentication. Theme preference may be stored in the browser. The current implementation has no advertising cookies or separate product-analytics provider. The first-party milestone ledger does not require a separate analytics cookie.

Product analytics is stored in the existing PostgreSQL application infrastructure and records only approved milestone names, optional account/company identifiers and time. It does not intentionally store HSE record text, uploaded file contents, document names, AI prompts or answers, or occupational-health content.

Sentry receives operational error information, with performance tracing configured off. Explicit Sentry events for audit and email incidents use structured tags and omit HSE record content, prompts, filenames, email bodies, actor identity, secrets and raw database errors.

AI processing

AI processing occurs when an enabled AI feature is invoked. Depending on the feature, a request can include a prompt, selected site records, approved knowledge content, extracted document text or a submitted image. The deployment selects the AI provider through configuration. AI audit records keep provider, model, confidence, review and source-reference facts without copying raw prompts or answers into audit metadata.

AI may draft, classify, summarize, recommend and assist retrieval. It cannot silently approve, close, publish, make employment or medical-fitness decisions, or override high-impact HSE decisions. It must not be relied on for medical diagnosis or treatment. Occupational-health records are excluded from Assistant and Copilot context by default, and Document-to-Work blocks health-register extraction. Provider retention and training treatment requires confirmation against current provider terms and configuration.

Providers that may process data

The verified architecture uses Vercel for hosting, Supabase for PostgreSQL and private object storage, Cloudflare R2 for object backups, Resend for transactional email, Stripe for hosted billing and Sentry for monitoring. Each provider receives information according to the feature being used. The production AI provider must be confirmed from deployment configuration before it is named in this public draft.

Export and deletion

Signed-in users can download an allowlisted personal-data export; authentication secrets are excluded. Organization HSE information uses report and Proof Pack exports. Account deletion requires password confirmation and cannot proceed while the account owns a company.

Deletion removes person-owned data and access relationships. Organization evidence can remain with attribution anonymized or detached, and archived files use a retryable deletion process. Backups age out only through configured rotation.

Retention review

The software has no default backup-retention duration, and the exact retention period for organization records is not formally approved. Those periods, legal holds and final privacy wording require professional legal and operational review before launch. No duration is promised by this draft.

Occupational-health boundaries

Customers may store genuine workplace occupational-health information when they have appropriate authority and a lawful basis. Access remains company, site and role scoped. HSEVIA is not an electronic health record, hospital or clinical record system, diagnosis or treatment system, or emergency medical service. It does not replace healthcare advice, competent-person review or professional judgment.