This policy explains how the operator of kitcompliance.com (“KitCompliance”, “we”, “us”) handles personal data. KitCompliance is workplace first-aid compliance software: organisations use it to record kits, inspections, equipment, first-aider certificates and accident-book entries.
This page is a factual description of the product as built. It is not a substitute for legal advice. If you need a contract that names a specific legal entity, registered office or DPO, contact us before processing special-category data at scale.
Who this applies to
- Account holders — people who register an organisation and sign in.
- People recorded by a customer — first-aiders, injured persons named in an accident record, and anyone whose details a customer types into the app. The customer is the controller of that workplace data; we process it on their instructions as a processor.
- Website visitors — people reading the marketing site, docs and blog.
What we collect
Account and organisation data
Name, email address, password hash (we do not store the password), organisation name, role, optional Google account identifier if you sign in with Google, plan and billing identifiers from Stripe, and product usage needed to enforce plan limits.
Workplace records the customer enters
Kit locations and contents, inspection results, equipment and servicing history, training certificates, and accident-book fields (including what happened, who was involved, and optional scene photos). Accident records can include health information. Customers must have a lawful basis under UK GDPR before they enter it.
Technical data
Server logs (path, method, time, coarse IP for rate limiting), and optional error reports sent to Sentry when that is configured. We do not run advertising cookies on the public site.
Why we use it
- To provide the service the organisation signed up for.
- To authenticate sessions and prevent abuse (rate limiting).
- To send transactional email: password resets, expiry and inspection reminders, and messages an admin chooses to send.
- To take payment and activate the matching subscription plan.
- To diagnose faults when error reporting is enabled.
- To meet a legal obligation if we are required to retain or disclose information.
For our own account data the legal bases are typically contract (running the account you asked for) and legitimate interests (keeping the service secure). For accident-book content the customer determines the basis; that is often a legal obligation on the employer.
Where it is stored
Application data is stored in a SQLite database on the hosting volume, and uploaded accident photos live on the same persistent volume. Photo URLs are short-lived signed links; they are not meant to be indexed or cached publicly. Hosting is currently on Railway. Email is sent through Resend. Payments go through Stripe. Optional error monitoring uses Sentry. Optional SMS alerts use Twilio.
Those providers act as processors or independent controllers for payment. We do not sell personal data.
How long we keep it
Account and workplace records stay until the organisation deletes them or asks us to delete the account. Customers are responsible for accident-book retention periods under UK health and safety law (often years, not days). Server logs are kept only as long as needed for security and debugging. Signed upload links expire (default 12 hours).
Sharing
We share data with the subprocessors named above, and with someone you authorise (for example another user on the same organisation). We disclose information if required by law. We do not share data with advertisers.
Your rights (UK GDPR)
Depending on your role you can ask for access, correction, deletion, restriction, objection, or portability. Account holders can correct much of this in the app. People named only inside a customer’s accident book should contact that employer first — they are the controller. You can complain to the Information Commissioner’s Office.
Cookies and sign-in
After you log in we set an HttpOnly session cookie
(kc_session) so the browser can call the API. It is
essential to the service. A CSRF token is stored by the app so other
sites cannot reuse that cookie. We do not use it for advertising.
Children
The product is for workplace compliance, not for children to open accounts. Early-years customers may record first-aid provision for a setting; they remain responsible for any data about children they enter.
Contact
Privacy questions: privacy@kitcompliance.com. Security disclosures: security@kitcompliance.com (see also security.txt).