Privacy Policy
Last updated: 28 September 2026
This Privacy Policy explains how ARC Safety Platform (Pty) Ltd (“we”, “us”) collects, uses and protects personal information when you use the ARC Safety Platform (the “Service”). We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).
1. Who is responsible for your information
ARC Safety Platform (Pty) Ltd is the responsible party for the personal information we collect about our account holders. Where you enter personal information about other people into the Service (for example site contacts or appointees), you are the responsible party for that information and we process it on your behalf as an operator.
2. Information we collect
- Account information — name, email address, phone number, organisation details and login credentials.
- Content you enter — sites, clients, contractors, contacts, appointees, inspection and audit findings, non-conformances, and photographs you upload as evidence.
- Usage information — logs, device and browser information, and records of actions taken in the Service, used to operate, secure and improve it.
- Payment information — billing details processed by our payment provider. We do not store full card numbers on our systems.
3. How we use your information
- To provide, maintain and secure the Service and your account.
- To generate the reports, audits and records you create.
- To process payments and manage subscriptions.
- To communicate with you about your account, support and service updates.
- To comply with our legal obligations and to detect and prevent misuse.
4. Service providers we share information with
We use trusted third parties to run the Service. They process information only as needed to provide their function to us:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication and file storage |
| Vercel | Website and application hosting |
| Paystack | Payment processing |
| Anthropic | AI assistance for drafting findings (from the text you submit) |
| Brevo | Sending account, report and notification emails |
We do not sell your personal information. Some of these providers may process information outside South Africa; where they do, we rely on their contractual and technical safeguards for cross-border processing as contemplated by POPIA.
5. Security
We apply appropriate technical and organisational measures to protect personal information, including access controls, organisation-level data isolation, encryption in transit, and restricted administrative access. No system is completely secure, and we cannot guarantee absolute security.
6. Retention
We retain personal information for as long as your account is active and as needed to provide the Service. If your account is cancelled or closed, we retain your organisation’s data — including account information, inspection, audit and non-conformance records, and photographs — for 5 years from the date of closure, so that historical safety records remain available if you, your clients, or a regulator need them, and it is then automatically and permanently deleted. We may keep information for longer than 5 years where a longer period is required by law (for example certain occupational health and safety recordkeeping obligations) or to resolve an active dispute or unpaid invoice. You may request earlier deletion as described below, subject to any record we are legally required to keep.
7. Your rights under POPIA
- Request access to the personal information we hold about you.
- Request correction or deletion of your personal information.
- Object to processing in certain circumstances.
- Lodge a complaint with the Information Regulator of South Africa.
To exercise these rights, contact us using the details below. Note that where we act as an operator for content you entered about others, requests from those individuals should be directed to you as the responsible party.
8. Cookies and sessions
The Service uses necessary browser storage and session cookies to keep you signed in and to operate core features. We do not use third-party advertising cookies.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified through the Service or by email. The “last updated” date above shows when it was last revised.
10. Contact us
For privacy questions or to exercise your rights, contact our information officer at ai@riskconsultants.biz.