SafetyClinic.app
Features Privacy Terms Sign inSign in
Legal

Privacy Policy

Effective July 23, 2026 · Last updated July 23, 2026

This Privacy Policy explains how DVR Digital LLC, doing business as SafetyClinic.app ("SafetyClinic", "we", "us", "our"), collects, uses, shares, and protects information in connection with the SafetyClinic.app website, applications, and related services (the "Service"). SafetyClinic.app is a registered assumed business name of DVR Digital LLC.

If you have questions or want to exercise a privacy right, contact us at support@safetyclinic.app. Registered address: 180 NW Saddlehorn Ct, Prineville, OR 97754.

Contents

  • 1. Our role: controller and processor
  • 2. Information we collect
  • 3. Sensitive and health information
  • 4. How we use information
  • 5. How we share information
  • 6. International data transfers
  • 7. Data retention and deletion
  • 8. Your privacy rights
  • 9. Security
  • 10. Children
  • 11. Third-party links
  • 12. Changes to this Policy
  • 13. Contact us

1. Our role: controller and processor

SafetyClinic is a business-to-business workplace-safety, inspection, and compliance platform. Organizations (our "Customers") subscribe to the Service and invite their workers ("Authorized Users") to use it.

  • For the workplace-safety content that an organization and its Authorized Users create — locations, inspections, corrective actions, drills, schedules, safety data sheets, contacts, and related notes and media ("Customer Data") — we act as a data processor (or "service provider") on behalf of the Customer, who is the controller. The Customer's own privacy policy governs how it handles that data.
  • For account registration information, website visitor information, billing information, and our own operation and security of the Service, we act as a data controller. This Policy describes that processing.

Our processing of Customer Data on a Customer's behalf is also governed by our Data Processing Addendum.

2. Information we collect

Information you provide

  • Account data: your name, work email address, organization name, and role, provided when you sign up, are invited to an organization, or set a password.
  • Authentication data: your password (stored only as a secure hash by our authentication provider) or, if you use single sign-on, the basic profile and email your identity provider returns.
  • Customer Data: the safety and compliance content you enter, including locations and sites, inspection templates and responses, corrective actions, emergency drills and run times, schedules and assignments, safety data sheets and uploaded documents, site maps and floor plans, contacts and contractors, and any notes, photographs, or files you attach.
  • Communications: information you provide when you contact support, respond to a survey, or send us feedback.

Information we collect automatically

  • Technical and usage data: app version, device and operating-system type, language, general location inferred from IP address, screens viewed, and actions taken, used to operate, secure, and improve the Service.
  • Diagnostic data: if crash reporting is enabled for a build, we receive crash and error reports to fix problems. Crash reporting is off unless explicitly enabled.
  • Cookies and local storage: strictly necessary tokens that keep you signed in and keep the Service secure. See our Cookie Policy.

We do not collect information for advertising, and we do not track you across other apps or websites.

Notice at collection

This table is our notice at collection for California residents. It lists the categories of personal information we collect, why we collect them, and how long we keep them. We do not sell personal information and we do not share it for cross-context behavioral advertising.

Category (CCPA)ExamplesPurposeRetention
IdentifiersName, work email, organization, user IDCreate and secure your account, authenticate you, send service emailWhile the account is active, then a limited period (Section 7)
Professional or employment informationYour role and employer, team membershipApply the permissions your administrators setWhile the account is active
Internet or network activityApp version, device and OS type, screens viewed, actions takenOperate, secure, and improve the ServiceLimited operational period
Geolocation (coarse)General location inferred from IP addressSecurity and abuse preventionLimited operational period
Audio, electronic, visual, or similar informationPhotographs and files attached to inspections, incidents, and documentsProvide the Service to your organizationControlled by your organization (Section 7)
Sensitive personal informationHealth information in the optional employee health and credential module, where your organization enables itTrack occupational-health and credential requirements for your organization's own workforceControlled by your organization (Section 7)
InferencesNoneWe do not create profiles or infer characteristicsNot applicable

3. Sensitive and health information

The Service is designed for facility and workplace-safety operations. It is not designed or authorized to store patient records, clinical records, or protected health information (PHI) as defined under HIPAA. DVR Digital LLC is not a HIPAA covered entity or business associate, and the Service is not offered as a HIPAA-compliant product. Do not upload PHI or other clinical patient data to the Service. You are responsible for the content you submit.

Employee occupational-health records

If your organization turns on the health & credential module, the Service stores limited records about your own workforce — for example whether an employee's hepatitis B vaccination, N95 respirator fit test, or professional licence is current, and the date it expires. Under HIPAA these are employment records held by an employer, which the definition of protected health information at 45 CFR 160.103 expressly excludes; they are therefore outside HIPAA, and this module does not make DVR Digital LLC a covered entity or business associate.

They are still confidential employee information. You remain responsible for handling them in line with 29 CFR 1910.1020, the ADA confidentiality rule at 29 CFR 1630.14(b), and any state law that applies to you. The module records outcomes and dates only — do not enter laboratory results, clinical notes, or respirator medical questionnaires.

4. How we use information

We use information to provide, operate, maintain, and secure the Service; authenticate you and manage your organization's workspace and permissions; send transactional messages such as invitations, confirmations, password resets, and service notices; respond to support requests; monitor, debug, and improve reliability and features; detect, prevent, and investigate fraud, abuse, and security incidents; and comply with legal obligations and enforce our Terms of Service.

Where the EU or UK GDPR applies, our legal bases are performance of a contract, our legitimate interests (securing, improving, and marketing the Service proportionately), compliance with a legal obligation, and consent where required (which you may withdraw at any time).

5. How we share information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only:

  • With subprocessors and service providers that host and support the Service under contract and only on our instructions. See our Subprocessors list.
  • Within your organization: Customer Data is visible to other Authorized Users of the same organization according to the permissions your administrators set.
  • For legal reasons: to comply with applicable law, regulation, or legal process, or to protect the rights, property, or safety of SafetyClinic, our users, or the public.
  • In a business transfer: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor policy.

6. International data transfers

We are based in the United States and use service providers that may process information in the United States and other countries. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Contact us for more information about these safeguards.

7. Data retention and deletion

We retain personal data for as long as your account or your organization's account is active, and for a limited period afterward as needed to comply with legal obligations, resolve disputes, and enforce our agreements.

You can delete your account in the app (Account → Delete account). Deleting your account removes your personal data and, if you are the sole member of an organization, that organization's Customer Data. Customers may also request export or deletion of their organization's Customer Data by contacting us. Residual copies may persist in encrypted backups for a limited time before being overwritten on our standard backup cycle.

8. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of your personal data; to object to or restrict certain processing; and to withdraw consent. You also have the right not to receive discriminatory treatment for exercising these rights.

To exercise a right, email support@safetyclinic.app. We will verify your request and respond within the time required by applicable law. If your data is Customer Data controlled by your organization, we will refer your request to that organization or act on its instructions.

For residents of California and other US states

We collect the categories of personal information listed in the notice at collection in Section 2, for the business purposes in Section 4. In the preceding 12 months we have not sold personal information and have not shared it for cross-context behavioral advertising, and we do not do so. Because we do not sell or share personal information, we do not offer a "Do Not Sell or Share My Personal Information" link. California residents may exercise rights to know, delete, and correct, and may use an authorized agent. We will not discriminate against you for exercising a right.

Sensitive personal information. Where your organization enables the optional employee health and credential module, we process health information about that organization's own workforce on its behalf. Under HIPAA these are employment records rather than protected health information (45 CFR 160.103), but they are sensitive personal information under the CCPA as amended. We use and disclose that information only to perform the Service for your organization, and never to infer characteristics about you, so the right to limit the use of sensitive personal information under Section 1798.121 does not apply. You may still ask us to access, correct, or delete it, and within the app the record is visible only to you and to your organization's owners and administrators.

Employees, applicants, and business contacts. California privacy rights extend to personal information collected in an employment or business-to-business context. If you use the Service as an employee or contact of one of our customers, the rights above apply to you, and we will refer requests about Customer Data to the organization that controls it.

For residents of the EEA, UK, and Switzerland

You may lodge a complaint with your local data protection authority. If you need an EU or UK representative, contact us and we will provide current details.

9. Security

We protect information using encryption in transit (TLS) and at rest, row-level access controls that scope each organization's data to that organization, least-privilege administrative access, and logging and monitoring. No method is completely secure, but we work to protect your data and will notify affected users and Customers of a personal data breach as required by law.

10. Children

The Service is intended for workplace use by adults and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

11. Third-party links and services

The Service and our communications may link to third-party websites and services we do not control. This Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. Review the privacy policy of any third-party site before providing information.

12. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will notify you in the app or by email before they take effect. The "Last updated" date above shows when the Policy last changed. Your continued use of the Service after an update means you accept the revised Policy.

13. Contact us

DVR Digital LLC (dba SafetyClinic.app)
Address: 180 NW Saddlehorn Ct, Prineville, OR 97754
Email: support@safetyclinic.app

SafetyClinic.app

Workplace safety and compliance for healthcare and aged care teams.

Product

  • Features
  • Pricing
  • Sign in

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Addendum
  • Acceptable Use
  • Subprocessors
  • Cookie Policy

Contact

  • support@safetyclinic.app
© 2026 SafetyClinic.app. All rights reserved. SafetyClinic.app is a registered assumed business name of DVR Digital LLC. Web · iOS · Android
SafetyClinic.app