DATA PROTECTION
This Data Processing Agreement is entered into between Safeli Limited (company registered in England and Wales, company no. 16932254, ICO registration no. CSN8470526) and the Client named in the accompanying services agreement. It supplements and forms part of that agreement.
In this Agreement, the following terms have the meanings set out below:
This Data Processing Agreement ("DPA") forms part of the agreement between Safeli Limited ("Safeli") and the Client for the provision of the Services. It sets out the terms on which Safeli processes personal data on behalf of the Client.
Safeli processes personal data only on documented instructions from the Client, unless required to do so by applicable law. The subject matter, duration, nature and purpose of processing, the types of personal data and categories of data subjects are set out in Schedule 1.
Safeli shall, in relation to any personal data processed in connection with the Services:
The Client warrants and represents that:
Safeli is built on infrastructure provided by Base44 Ltd. Personal data may be processed outside the UK and EEA. All such transfers are made using one or more of the following lawful transfer mechanisms:
Base44 Ltd. maintains a public sub-processor list and commits to notifying customers of any planned additions or replacements, allowing reasonable time to object. Details are available at base44.com.
The Client provides general authorisation for Safeli to engage sub-processors. Safeli will give reasonable prior notice of any intended changes to sub-processors and the Client may object within 14 days on reasonable grounds.
Safeli requires all sub-processors to comply with data protection obligations materially equivalent to those set out in this DPA. A current list of sub-processors is available on request.
Safeli implements and maintains appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures are set out in Schedule 2.
Safeli will notify the Client without undue delay (and within 72 hours where feasible) on becoming aware of a personal data breach affecting the Client's data.
Safeli shall promptly notify the Client of any data subject request received directly from a data subject in relation to the Client's data. Safeli will assist the Client to fulfil its obligations in respect of such requests, taking into account the nature of the processing and information available.
On termination of the Services, Safeli will, at the Client's choice, either securely delete or return all personal data processed on the Client's behalf. The Client may export all of its data - sites, documents, actions and assessments - directly from the portal at any time during the term of the Services, and may request a final export in spreadsheet or PDF format on termination.
Safeli may retain personal data where required by applicable law, for the minimum period required.
This DPA and any dispute or claim arising out of it shall be governed by and construed in accordance with the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales.
| Subject matter | Provision of compliance management services, including risk assessments, document management, action tracking and reporting. |
| Duration | For the term of the Services agreement between Safeli and the Client. |
| Nature of processing | Collection, storage, organisation, use, disclosure, erasure and destruction. |
| Purpose | Enabling the Client to manage fire, water hygiene and health & safety compliance obligations across its sites. |
| Types of personal data | Names, job titles, email addresses, phone numbers, digital signatures, and photographs of people and premises. |
| Categories of data subjects | The Client's employees, contractors, site visitors and key contacts recorded in the platform. |
| Encryption | All data encrypted in transit (TLS 1.2+) and at rest (AES-256). Key management maintained by the cloud provider. |
| Access control | Role-based permissions (admin, consultant, client) with per-site scoping. Users only access data they are explicitly assigned. |
| Infrastructure certification | Hosted on ISO/IEC 27001:2022 certified infrastructure (cert. no. 1127009, valid until June 2028). |
| Penetration testing | The platform undergoes periodic penetration testing and security audits by external auditors. |
| Audit logging | Complete, timestamped audit trail of all data access and modifications. |
| Incident response | Documented incident response procedures with 72-hour breach notification commitment. |
| Sub-processor oversight | Written agreements with all sub-processors incorporating equivalent data protection obligations. |
| Data minimisation | Collection limited to data necessary for the provision of the Services. |
This DPA takes effect when you enter into a services agreement with Safeli and is incorporated into it by reference. No separate signature is required - it applies automatically to all clients using the Safeli platform.
A countersigned copy, or a version on company letterhead, is available on request at any time.