Trust

Data protection & security

How our platforms and this website protect personal data, in line with GDPR Articles 28, 32, 33 and 35.

Last updated 8 October 2026

Our commitment

Built for sensitive data. HSE records can include personal and health information about employees, contractors and visitors. AccelSafety is designed and operated to protect that data and to help our customers meet their own GDPR duties.

This page describes how our platforms protect customer data and how this website protects visitors. It complements our Privacy policy.

Controller and processor

Our customers are the controllers of the data they put into AccelSafety, AccelKnit or AccelRealEstate. Accel Safety is their processor and acts only on documented instructions.

Every customer receives a Data Processing Agreement that covers everything GDPR Article 28 requires: the subject matter, duration, nature and purpose of processing, the types of data and data subjects, confidentiality, security, sub-processors, assistance with data subject rights and breaches, deletion or return at the end, and audits.

Health and other special category data

Incident and injury records may contain health data, a special category under GDPR Article 9. The platform supports this with:

  • access limited to the part of the organization a person is responsible for, enforced on the server
  • approvals, reviews and configuration restricted to authorized roles
  • data minimization: only the fields needed for each record
  • a complete audit trail of who viewed or changed a record
  • support for customers' data protection impact assessments (Article 35)

Technical and organizational measures

In line with GDPR Article 32, we apply measures proportionate to the risk:

AreaMeasures
Access controlMulti-factor sign-in, idle time-outs, role-based permissions, scope enforced on the server, least privilege for our staff
EncryptionTLS for all data in transit; encryption at rest for databases and backups
IntegrityFull audit logs; records corrected or removed only with a reason and administrator approval
AvailabilityManaged cloud hosting, regular backups and tested restores
SeparationEach customer's data is logically separated; demo and training data never mix with live data
DevelopmentSecure configuration, dependency updates, code review and testing before release
PeopleConfidentiality commitments and data protection training for everyone with access
TestingRegular review of security controls and providers

Sub-processors

We use a small number of sub-processors for hosting, email delivery and backups. Each is bound by written terms equivalent to our Data Processing Agreement. Customers receive the current list and are notified in advance of changes, with the right to object.

Helping customers with data subject rights

The platform helps customers answer access, correction, erasure, restriction and portability requests: records can be searched, exported, corrected with an audit trail, and deleted or anonymized in line with the customer's retention rules.

Personal data breaches

We maintain an incident response procedure. If a breach affects customer data, we notify the customer without undue delay, giving them what they need to notify the supervisory authority within 72 hours (Article 33) and, where required, the people affected (Article 34).

Data location and transfers

Hosting regions are agreed with each customer. Where EU, EEA or UK personal data is transferred outside those regions, we use Standard Contractual Clauses and supplementary measures such as encryption.

Retention and deletion

Customers set retention periods per record type. At the end of a contract, customer data is returned in a standard format or deleted, and backups expire on a fixed schedule.

How this website protects you

  • No third-party requests. Fonts, scripts and images are served from our own site. Nothing is loaded from Google, social networks or advertising networks.
  • No tracking by default. Only strictly necessary storage is used until you choose otherwise in Cookie settings.
  • Forms that send, not store. Our contact and referral forms send your message over HTTPS straight to info@accelsafety.com. Nothing is saved in a database on the web server, and the only temporary trace is a one-hour hashed IP used to block spam.
  • Plain social links. LinkedIn and Facebook are simple links, not embedded plugins, so they cannot track you on our pages.
  • Our own chat. The website chat is built by us and loads nothing from third parties. Messages go straight to our mailbox and are not stored on the web server.
  • Encrypted connection. The site is served only over HTTPS.

Contact

Data protection questions, DPA requests and security reports: privacy@accelsafety.com.