Organise your people
Reduce risk
Run a stronger business
Organise your people
Reduce risk
Run a stronger business
Organise your people
Reduce risk
Run a stronger business
Organise your people
Reduce risk
Run a stronger business
Organise your people
Reduce risk
Run a stronger business
Organise your people
Reduce risk
Run a stronger business
Organise your people
Reduce risk
Run a stronger business
Organise your people
Reduce risk
Run a stronger business

Legal for Platform Subscribers

Service Privacy Policy

Effective date: June 2026  ·  Applies to app.yoursafedocs.com

This policy is for SafeDocs platform subscribers. For general website privacy, see our Privacy Policy.

This Service Privacy Policy sets out in detail how SafeDocs processes personal data on behalf of platform subscribers, specifically the personal data of your employees that you manage through the platform. It covers data categories, sub-processors, security measures, your obligations as data controller, and how data subject rights are handled. It supplements the general Privacy Policy and forms part of the Terms & Conditions.

1. Who This Policy Is For

This policy applies to businesses and individuals who hold an active SafeDocs subscription at app.yoursafedocs.com. It is specifically concerned with the personal data you enter into the platform on behalf of your employees, not your own account data, which is covered in the general Privacy Policy.

If you are an employee whose employer uses SafeDocs to manage your employment records, and you have questions about how your personal data is held, you should direct those questions to your employer in the first instance. Your employer is the data controller for your information. SafeDocs processes it only on their instruction.

2. The Data Controller and Data Processor Relationship

When you use SafeDocs to manage employee data, the following applies:

You

Data Controller

You determine what employee data is collected, for what purpose, and for how long. You are responsible for the lawfulness of that collection and processing, and for informing your employees that their data is held in SafeDocs.

Safe
Docs

Data Processor

SafeDocs processes employee data only as directed by you through the platform. We do not use your employees' data for any purpose other than providing the SafeDocs service to you. We do not sell it, share it with advertisers, or use it to build profiles outside of your workspace.

This relationship is standard in SaaS workforce platforms. It means your employees' rights under applicable data protection law are exercised against you as their employer, with SafeDocs supporting that process where needed.

3. Categories of Personal Data Processed

The following categories of employee personal data may be processed in SafeDocs, depending on the modules you use and the information you enter.

CategoryData fields
IdentityFull name, National ID details, NIC number, tax account number
ContactPersonal email address, phone number
EmploymentJob title, department, employment type, start date, contract type, contract end date, employment status, site assignment
FinancialSalary or hourly rate, overtime rates, allowances, bank account details (encrypted), payroll history, NIC contributions, PAYE deductions, net pay records, payslips
LeaveAnnual leave entitlement, leave balances, vacation taken, sick leave records, leave requests, accrual status, absence log
DisciplinaryDisciplinary case records, warnings, hearing records, outcomes, appeal records
DocumentsEmployment contracts, offer letters, warning letters, job letters, annual review documents, employment status documents, payslips, any other documents filed to the employee record
SchedulingShift assignments, hours worked, schedule history (Advanced tier only)
SystemAudit log entries recording actions taken on the employee record, with timestamps and user IDs
Compliance flagsDo Not Rehire status, record completeness indicators, compliance health score contributions

Not all categories apply to every subscriber. Payroll data, including pay run calculations, NIC contributions, PAYE deductions, payslips, and payroll history, is only processed for Advanced tier subscribers (or subscribers with the Payroll standalone module). Scheduling data is only processed for Advanced tier subscribers (or subscribers with the Scheduling standalone module). You control what data is entered. SafeDocs processes only what you provide.

Special category data

SafeDocs does not request or prompt for special category data (health data, biometric data, racial or ethnic origin, religious beliefs, etc.) as defined under data protection law. If you choose to record health-related information, for example a note about a medical certificate submitted for sick leave, you do so at your own discretion and bear responsibility for the lawfulness of holding that data.

4. Purpose and Legal Basis for Processing

SafeDocs processes employee personal data on your behalf for the following purposes:

  • Employment records management: maintaining accurate and complete personnel files for each employee
  • Payroll calculation: computing gross pay, statutory deductions, and net pay for each pay period
  • Statutory compliance: supporting NIC contribution tracking, PAYE calculation, and leave entitlement accrual in accordance with Saint Lucia law
  • HR document generation: producing employment contracts, letters, appraisals, and other documents using employee record data
  • Leave administration: recording and tracking leave requests, approvals, balances, and absences
  • Disciplinary process management: maintaining records of formal HR processes in compliance with the Saint Lucia Labour Act
  • Shift scheduling: assigning and tracking shifts, hours, and site coverage (Advanced tier)
  • Compliance monitoring: identifying gaps in employee records that create regulatory or legal risk
  • Audit trail: maintaining a permanent log of all actions taken in the workspace for accountability and legal purposes
  • Notifications: sending automated emails to employees where you have configured this (payslip delivery, schedule publication)

SafeDocs does not process employee data for any purpose outside those listed above without your explicit instruction.

5. Sub-Processors

SafeDocs uses the following sub-processors to deliver the platform service. Each has been selected based on their security standards and data handling commitments. By subscribing to SafeDocs, you authorise the use of these sub-processors.

Database, authentication & storage

All platform data, such as employee records, payroll runs, documents, and audit logs, is stored in a managed cloud database. Authentication sessions and file storage (payslips, HR documents) are handled by the same provider. Data is held in Ireland and/or the United States.

Email delivery

Transactional email notifications. Employee names and email addresses are passed to this service when sending automated notifications such as payslip delivery, schedule publication, and compliance alerts. Data is processed in the United States.

We will notify you of any changes to the sub-processor list that materially affect how your data is processed, with reasonable advance notice.

6. Technical and Organisational Security Measures

SafeDocs implements the following measures to protect employee personal data processed through the platform:

Access control

  • Tenant isolation: every database query is enforced at row level through database-level security policies. No user can access another business's data. This is enforced at the database level, not the application level alone.
  • Role-based access: within your workspace, access is controlled by user role. Admin and Manager roles have full access to all modules permitted by your plan. Viewer roles have read-only access. Employee roles are restricted strictly to the individual employee's own record.
  • Authentication: all platform access requires authenticated login. Session tokens are handled securely.

Encryption

  • In transit: all data is transmitted over HTTPS using TLS encryption. Unencrypted connections are not accepted.
  • At rest: bank account details are encrypted at rest in the database. All other data benefits from infrastructure-level encryption at rest.

Audit and integrity

  • Audit logging: every create, update, and delete action is permanently recorded in the audit log with the user ID, timestamp, affected record, and the nature of the change. Audit logs cannot be edited or deleted.
  • Payroll lock: confirmed payroll runs are permanently locked after confirmation. They cannot be modified or deleted.
  • Do Not Rehire flag: once set on an employee record, this flag cannot be removed by any platform user, preserving the integrity of the compliance record.

Operational security

  • No employee personal data is stored in browser localStorage
  • Environment variables are used for all API keys and credentials; none are hardcoded or committed to version control
  • Error messages displayed to users do not expose database structure, tenant IDs, or system internals
  • File downloads (payslips, toolkit files) use time-limited signed URLs that expire and cannot be reused

7. Data Retention and Deletion

During your subscription

Employee data is retained in full while your subscription is active. Terminated or inactive employees remain in your records permanently for compliance purposes: their records are retained but clearly marked as Inactive. You may request an employee record to be deleted, subject to any legal retention obligations.

After subscription termination

Following termination of your SafeDocs subscription, your workspace data, including all employee records, payroll history, and documents, is retained for 12 months before permanent deletion. This window allows you to request a data export if needed. After 12 months, all data is permanently deleted with no possibility of recovery.

Specific retention rules

  • Payroll records: retained in line with Saint Lucia Inland Revenue Department record-keeping requirements for tax purposes
  • Audit logs: retained permanently as they form part of the legal and compliance record
  • Disciplinary records: retained for the duration of the subscription and post-termination period; these have legal standing under the Saint Lucia Labour Act and should not be deleted prematurely
  • Payslips: retained for the duration of the subscription and the post-termination window; employees should be given copies before subscription ends

Requesting deletion

To request early deletion of specific records or your entire workspace, contact businessautopilot@yoursafedocs.com. We will action deletion requests within 30 days, subject to any records that must be retained under applicable law.

8. Data Subject Rights

Your employees, as the individuals whose personal data is held in SafeDocs, are data subjects with rights under applicable data protection law. These rights include access, correction, deletion, portability, and objection.

Because you are the data controller, data subject requests from your employees should be directed to you in the first instance. SafeDocs will support you in responding to these requests as follows:

Right of access

An employee's full record is visible within your SafeDocs workspace. You can view, print, or export any employee's data to respond to an access request.

Right to correction

All employee record fields can be edited by an Admin or Manager. Corrections take effect immediately and are logged in the audit trail.

Right to deletion

Individual records or fields can be removed through the platform. Where retention law prevents immediate deletion, we will advise. Contact us for workspace-wide deletion requests.

Right to portability

Employee data can be exported as CSV from the Employee Register. Document files can be downloaded from the employee's Docs tab. Contact us if you need a full structured export of all workspace data.

Right to object

If an employee objects to a specific processing activity, contact us to discuss what is technically possible within the platform constraints.

We will respond to data subject support requests directed to SafeDocs within 30 days.

9. Personal Data Breaches

In the event of a personal data breach affecting employee data processed through SafeDocs, the following process applies:

  • Detection: SafeDocs monitors platform activity and infrastructure for security anomalies and potential breaches
  • Notification to you: we will notify you by email within 72 hours of becoming aware of a breach that is likely to affect your employees' personal data. The notification will include the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed to address it
  • Notification to data subjects: you are responsible for notifying your affected employees in accordance with applicable law. SafeDocs will provide all information we hold about the breach to support you in doing this
  • Remediation: we will take all reasonable steps to contain the breach, restore security, and prevent recurrence

To report a suspected breach or security concern, contact businessautopilot@yoursafedocs.com immediately with the subject line [SECURITY].

10. Cross-Border Data Transfers

SafeDocs is based in Saint Lucia. Our infrastructure and service providers operate primarily in the United States and Ireland. Employee data entered into the platform is therefore processed in these jurisdictions as part of normal platform operation.

By subscribing to SafeDocs and entering employee data into the platform, you acknowledge and authorise this cross-border processing. Each sub-processor operates under data processing agreements and privacy frameworks appropriate to their jurisdiction.

If your organisation has specific requirements about data residency or cross-border transfers, for example due to sector-specific regulation, please contact us to discuss whether SafeDocs can meet those requirements before subscribing.

11. Your Obligations as Data Controller

As the data controller for your employees' personal data, you are responsible for:

  • Lawful basis: having a lawful basis to collect and process each category of employee data you enter into SafeDocs. For most employment data, this will be the performance of an employment contract and compliance with legal obligations.
  • Transparency: informing your employees that their personal data is held and managed in a digital workforce management platform (SafeDocs), what data is held, and their rights in relation to it
  • Accuracy: ensuring that the employee data you enter is accurate, complete, and kept up to date
  • Access management: assigning appropriate user roles to team members in your workspace and removing access promptly when a team member leaves
  • Special category data: taking additional care if you choose to record any special category data (health information, etc.); this requires a higher lawful basis and appropriate safeguards
  • Data export before termination: exporting any employee data you wish to retain before your subscription ends, as data will be deleted 12 months after termination

12. Changes to This Policy

We may update this Service Privacy Policy as the platform evolves, sub-processors change, or applicable law requires. The current version is always available at yoursafedocs.com/service-privacy.

Material changes, particularly any change to the sub-processor list, security measures, or data retention terms, will be communicated to active subscribers by email at least 14 days before taking effect.

13. Contact

For any questions about this policy, data subject rights requests, security concerns, or deletion requests:

SafeDocs

businessautopilot@yoursafedocs.com

www.yoursafedocs.com

Saint Lucia

Related documents: Privacy Policy  ·  Terms & Conditions