This Privacy Policy explains how DVR Digital LLC, doing business as SafetyClinic.app ("SafetyClinic", "we", "us", "our"), collects, uses, shares, and protects information in connection with the SafetyClinic.app website, applications, and related services (the "Service"). SafetyClinic.app is a registered assumed business name of DVR Digital LLC.
If you have questions or want to exercise a privacy right, contact us at support@safetyclinic.app. Registered address: 180 NW Saddlehorn Ct, Prineville, OR 97754.
1. Our role: controller and processor
SafetyClinic is a business-to-business workplace-safety, inspection, and compliance platform. Organizations (our "Customers") subscribe to the Service and invite their workers ("Authorized Users") to use it.
- For the workplace-safety content that an organization and its Authorized Users create — locations, inspections, corrective actions, drills, schedules, safety data sheets, contacts, and related notes and media ("Customer Data") — we act as a data processor (or "service provider") on behalf of the Customer, who is the controller. The Customer's own privacy policy governs how it handles that data.
- For account registration information, website visitor information, billing information, and our own operation and security of the Service, we act as a data controller. This Policy describes that processing.
Our processing of Customer Data on a Customer's behalf is also governed by our Data Processing Addendum.
2. Information we collect
Information you provide
- Account data: your name, work email address, organization name, and role, provided when you sign up, are invited to an organization, or set a password.
- Authentication data: your password (stored only as a secure hash by our authentication provider) or, if you use single sign-on, the basic profile and email your identity provider returns.
- Customer Data: the safety and compliance content you enter, including locations and sites, inspection templates and responses, corrective actions, emergency drills and run times, schedules and assignments, safety data sheets and uploaded documents, site maps and floor plans, contacts and contractors, and any notes, photographs, or files you attach.
- Communications: information you provide when you contact support, respond to a survey, or send us feedback.
Information we collect automatically
- Technical and usage data: app version, device and operating-system type, language, general location inferred from IP address, screens viewed, and actions taken, used to operate, secure, and improve the Service.
- Diagnostic data: if crash reporting is enabled for a build, we receive crash and error reports to fix problems. Crash reporting is off unless explicitly enabled.
- Cookies and local storage: strictly necessary tokens that keep you signed in and keep the Service secure. See our Cookie Policy.
We do not collect information for advertising, and we do not track you across other apps or websites.
Notice at collection
This table is our notice at collection for California residents. It lists the categories of personal information we collect, why we collect them, and how long we keep them. We do not sell personal information and we do not share it for cross-context behavioral advertising.
| Category (CCPA) | Examples | Purpose | Retention |
|---|---|---|---|
| Identifiers | Name, work email, organization, user ID | Create and secure your account, authenticate you, send service email | While the account is active, then a limited period (Section 7) |
| Professional or employment information | Your role and employer, team membership | Apply the permissions your administrators set | While the account is active |
| Internet or network activity | App version, device and OS type, screens viewed, actions taken | Operate, secure, and improve the Service | Limited operational period |
| Geolocation (coarse) | General location inferred from IP address | Security and abuse prevention | Limited operational period |
| Audio, electronic, visual, or similar information | Photographs and files attached to inspections, incidents, and documents | Provide the Service to your organization | Controlled by your organization (Section 7) |
| Sensitive personal information | Health information in the optional employee health and credential module, where your organization enables it | Track occupational-health and credential requirements for your organization's own workforce | Controlled by your organization (Section 7) |
| Inferences | None | We do not create profiles or infer characteristics | Not applicable |
3. Sensitive and health information
The Service is designed for facility and workplace-safety operations. It is not designed or authorized to store patient records, clinical records, or protected health information (PHI) as defined under HIPAA. DVR Digital LLC is not a HIPAA covered entity or business associate, and the Service is not offered as a HIPAA-compliant product. Do not upload PHI or other clinical patient data to the Service. You are responsible for the content you submit.
Employee occupational-health records
If your organization turns on the health & credential module, the Service stores limited records about your own workforce — for example whether an employee's hepatitis B vaccination, N95 respirator fit test, or professional licence is current, and the date it expires. Under HIPAA these are employment records held by an employer, which the definition of protected health information at 45 CFR 160.103 expressly excludes; they are therefore outside HIPAA, and this module does not make DVR Digital LLC a covered entity or business associate.
They are still confidential employee information. You remain responsible for handling them in line with 29 CFR 1910.1020, the ADA confidentiality rule at 29 CFR 1630.14(b), and any state law that applies to you. The module records outcomes and dates only — do not enter laboratory results, clinical notes, or respirator medical questionnaires.
4. How we use information
We use information to provide, operate, maintain, and secure the Service; authenticate you and manage your organization's workspace and permissions; send transactional messages such as invitations, confirmations, password resets, and service notices; respond to support requests; monitor, debug, and improve reliability and features; detect, prevent, and investigate fraud, abuse, and security incidents; and comply with legal obligations and enforce our Terms of Service.
Where the EU or UK GDPR applies, our legal bases are performance of a contract, our legitimate interests (securing, improving, and marketing the Service proportionately), compliance with a legal obligation, and consent where required (which you may withdraw at any time).
5. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only:
- With subprocessors and service providers that host and support the Service under contract and only on our instructions. See our Subprocessors list.
- Within your organization: Customer Data is visible to other Authorized Users of the same organization according to the permissions your administrators set.
- For legal reasons: to comply with applicable law, regulation, or legal process, or to protect the rights, property, or safety of SafetyClinic, our users, or the public.
- In a business transfer: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor policy.
6. International data transfers
We are based in the United States and use service providers that may process information in the United States and other countries. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Contact us for more information about these safeguards.
7. Data retention and deletion
We retain personal data for as long as your account or your organization's account is active, and for a limited period afterward as needed to comply with legal obligations, resolve disputes, and enforce our agreements.
You can delete your account in the app (Account → Delete account). Deleting your account removes your personal data and, if you are the sole member of an organization, that organization's Customer Data. Customers may also request export or deletion of their organization's Customer Data by contacting us. Residual copies may persist in encrypted backups for a limited time before being overwritten on our standard backup cycle.
8. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of your personal data; to object to or restrict certain processing; and to withdraw consent. You also have the right not to receive discriminatory treatment for exercising these rights.
To exercise a right, email support@safetyclinic.app. We will verify your request and respond within the time required by applicable law. If your data is Customer Data controlled by your organization, we will refer your request to that organization or act on its instructions.
For residents of California and other US states
We collect the categories of personal information listed in the notice at collection in Section 2, for the business purposes in Section 4. In the preceding 12 months we have not sold personal information and have not shared it for cross-context behavioral advertising, and we do not do so. Because we do not sell or share personal information, we do not offer a "Do Not Sell or Share My Personal Information" link. California residents may exercise rights to know, delete, and correct, and may use an authorized agent. We will not discriminate against you for exercising a right.
Sensitive personal information. Where your organization enables the optional employee health and credential module, we process health information about that organization's own workforce on its behalf. Under HIPAA these are employment records rather than protected health information (45 CFR 160.103), but they are sensitive personal information under the CCPA as amended. We use and disclose that information only to perform the Service for your organization, and never to infer characteristics about you, so the right to limit the use of sensitive personal information under Section 1798.121 does not apply. You may still ask us to access, correct, or delete it, and within the app the record is visible only to you and to your organization's owners and administrators.
Employees, applicants, and business contacts. California privacy rights extend to personal information collected in an employment or business-to-business context. If you use the Service as an employee or contact of one of our customers, the rights above apply to you, and we will refer requests about Customer Data to the organization that controls it.
For residents of the EEA, UK, and Switzerland
You may lodge a complaint with your local data protection authority. If you need an EU or UK representative, contact us and we will provide current details.
9. Security
We protect information using encryption in transit (TLS) and at rest, row-level access controls that scope each organization's data to that organization, least-privilege administrative access, and logging and monitoring. No method is completely secure, but we work to protect your data and will notify affected users and Customers of a personal data breach as required by law.
10. Children
The Service is intended for workplace use by adults and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
11. Third-party links and services
The Service and our communications may link to third-party websites and services we do not control. This Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. Review the privacy policy of any third-party site before providing information.
12. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you in the app or by email before they take effect. The "Last updated" date above shows when the Policy last changed. Your continued use of the Service after an update means you accept the revised Policy.
13. Contact us
DVR Digital LLC (dba SafetyClinic.app)
Address: 180 NW Saddlehorn Ct, Prineville, OR 97754
Email: support@safetyclinic.app