Privacy Policy
Effective Date: October 1, 2025
1. Introduction
WorkSafely SMB, Inc. ("WorkSafely," "we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our OSHA compliance platform and related services (collectively, the "Services").
By accessing or using our Services, you agree to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access our Services.
2. Information We Collect
Personal Information You Provide
- Account Information: Name, email address, phone number, job title, and password
- Company Information: Business name, EIN, address, industry classification (NAICS code), number of employees
- Billing Information: Credit card details, billing address, and payment history
- Communications: Information you provide when you contact us for support or feedback
Safety and Compliance Data
- Employee safety records and training certifications
- Workplace incidents, injuries, and near-miss reports
- Hazard assessments and safety inspection results
- Equipment inventories and maintenance records
- Chemical inventories and safety data sheets
- Job roles and associated safety requirements
- Safety program documents and policies
Automatically Collected Information
- Device Information: IP address, browser type and version, operating system, device identifiers
- Usage Data: Pages visited, features used, time spent on pages, click patterns, search queries
- Location Data: General geographic location based on IP address
- Cookies and Tracking: Session cookies, persistent cookies, web beacons, and similar technologies
- Performance Data: System performance metrics, error reports, and debugging information
3. How We Use Your Information
Service Delivery
- Create and manage your account
- Generate customized OSHA-compliant safety programs
- Track and manage workplace safety incidents
- Maintain training records and certification tracking
- Provide compliance alerts and deadline reminders
- Generate required OSHA reports and documentation
Communication
- Send service-related notifications and updates
- Respond to your inquiries and support requests
- Send compliance reminders and important safety alerts
- Provide product updates and new feature announcements (with your consent)
- Send marketing communications (with your consent)
Improvement and Analytics
- Analyze usage patterns to improve our Services
- Develop new features and functionality
- Conduct research and analysis on safety trends
- Monitor and prevent fraudulent activity
- Ensure platform security and stability
Legal and Compliance
- Comply with applicable laws and regulations
- Respond to legal requests and court orders
- Enforce our Terms of Service and other agreements
- Protect our rights, property, and safety
4. Information Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We may share your information in the following circumstances:
Service Providers
We share information with trusted third-party service providers who assist us in operating our Services, including:
- Cloud hosting and infrastructure providers (AWS)
- Payment processing services (Stripe)
- Email delivery services
- Analytics providers
- Customer support tools
These providers are contractually bound to protect your information and use it only for the services they provide to us.
Business Transfers
If WorkSafely is involved in a merger, acquisition, asset sale, or bankruptcy, your information may be transferred as part of that transaction. We will notify you of any change in ownership or control of your personal information.
Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities, including:
- Court orders and subpoenas
- Government agency requests
- OSHA investigations or audits
- To protect the rights, property, or safety of WorkSafely, our users, or others
Aggregated or Anonymized Data
We may share aggregated or anonymized information that cannot reasonably be used to identify you. This may include industry benchmarks, safety statistics, and trend analyses.
With Your Consent
We may share your information with third parties when you explicitly consent to or request such sharing.
5. Data Security
We implement comprehensive security measures to protect your information from unauthorized access, use, alteration, and disclosure. Our security practices include:
- Industry-standard encryption for data in transit (TLS/SSL) and at rest (AES-256)
- Secure data centers with SOC 2 Type II certification
- Regular security audits and vulnerability assessments
- Multi-factor authentication options for user accounts
- Role-based access controls and principle of least privilege
- Employee background checks and security training
- Incident response and breach notification procedures
- Regular backups and disaster recovery planning
- PCI DSS compliance for payment processing
Despite our security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your information.
6. Data Retention
We retain your information for as long as necessary to provide our Services and comply with legal obligations:
- Account Information: Retained for the duration of your account and up to 7 years after closure
- OSHA Records: Maintained according to OSHA requirements (typically 5 years for most records)
- Incident Records: Retained for 5 years plus the current year per OSHA regulations
- Training Records: Maintained for the duration of employment plus 5 years
- Financial Records: Retained for 7 years for tax and accounting purposes
- Communications: Retained for 3 years or as required by law
After the retention period, we securely delete or anonymize your information using industry-standard methods.
7. Your Rights and Choices
Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information (subject to legal requirements)
- Portability: Receive your information in a structured, commonly used format
- Restriction: Request that we limit the processing of your information
- Objection: Object to certain processing of your information
- Withdraw Consent: Withdraw previously given consent for data processing
How to Exercise Your Rights
To exercise any of these rights, please contact us at contact@worksafely.com. We will respond to your request within 30 days.
Communication Preferences
You can manage your communication preferences through:
- Account settings in the platform
- Unsubscribe links in our emails
- Contacting us directly at contact@worksafely.com
Cookie Management
You can manage cookies through your browser settings. Note that disabling certain cookies may limit the functionality of our Services.
8. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information we collect, use, disclose, and sell
- Right to delete personal information (with certain exceptions)
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your privacy rights
- Right to request specific pieces of personal information collected
To exercise these rights, California residents can contact us at contact@worksafely.com.
California "Shine the Light" Law
California residents may request information about disclosure of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.
9. International Data Transfers
Our Services are operated in the United States. If you are located outside the United States, please be aware that information we collect will be transferred to and processed in the United States.
We ensure appropriate safeguards are in place for international transfers, including:
- Standard contractual clauses approved by regulatory authorities
- Data processing agreements with service providers
- Compliance with applicable data protection laws
10. Children's Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information.
If you believe we have collected information from a child under 18, please contact us immediately at contact@worksafely.com.
11. Third-Party Services and Links
Our Services may contain links to third-party websites, services, or applications. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
Our Services may also integrate with third-party services you choose to connect, such as:
- Single sign-on providers
- Calendar applications for training schedules
- HR management systems
Your use of these integrations is governed by the third party's privacy policy.
12. Do Not Track Signals
Our Services do not currently respond to "Do Not Track" signals from web browsers. However, you can manage your tracking preferences through cookie settings and by contacting us directly.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will:
- Update the "Effective Date" at the top of this policy
- Notify you by email (for registered users)
- Display a prominent notice on our website
- Obtain your consent where required by law
Your continued use of our Services after changes indicates acceptance of the updated Privacy Policy.
14. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
WorkSafely SMB, Inc.
Email: contact@worksafely.com
For privacy-specific inquiries, you may also email: privacy@worksafely.com
15. Accessibility
We are committed to ensuring this Privacy Policy is accessible to individuals with disabilities. If you need this policy in an alternative format, please contact us at contact@worksafely.com.