Privacy Policy & Data Security
Our commitment to safeguarding your contractor safety documentation, digital signatures, and business operational credentials in strict compliance with the UK GDPR and Data Protection Act 2018.
01. Introduction
RAMSMate ("we", "us", or "our") operates the web application platform designed to generate compliant Risk Assessments and Method Statements (RAMS) for contractors, sole traders, and construction enterprises.
This Privacy Policy outlines our procedures regarding the collection, storage, processing, and erasure of contractor information, workforce rosters, site location data, and touch signatures.
02. Information We Collect
To render legally binding, site-ready PDF documents, we collect minimal operational information:
User & Account Data
- Name, email address, password hashes
- Registered company name & VAT details
- Custom branding logo assets
Document Inputs
- Site location coordinates & client names
- Mitigation checklist selections & custom hazards
- Touch signature coordinate matrix data
03. How We Use Collected Data
RAMSMate adheres strictly to data minimisation guidelines. Collected data is utilised solely for:
- PDF Compilation: Overlaying company details, signatures, and custom safety logs into high-contrast PDF documents for your commercial distribution.
- Multi-Tenant Isolation: Ensuring that no other company registered on the system can query or intercept your specific document catalogues.
- Account Operations: Handling subscription invoices, Stripe PAYG tokens, and billing tier overrides securely.
04. Security, Vaulting & Encryption
State-of-the-Art Protection
We protect your credentials and data assets through advanced encryption algorithms both in transit and at rest.
Cryptographic Parameters:
- Credential Hash: Password databases utilise highly secure `bcryptjs` encryption hashing standard, precluding direct reverse-engineering.
- Database Layer: PostgreSQL tables are protected with strict tenant isolation indexes (`companyId` mappings), preventing lateral data breaches.
- Transport Security: All client-to-server exchanges are strictly processed over encrypted TLS 1.3 tunnels.
Data Security Limitation of Liability
While we employ industrial-grade administrative and cryptographic safeguards, no electronic storage system or transmission protocol is entirely impenetrable. To the maximum extent permitted by the UK Data Protection Act 2018 and applicable B2B regulations, RAMSMate, its owners, operators, and developers exclude all liability for security breaches, hacking, malware, unauthorised data modifications, or unauthorised access to your account/documents unless caused by our gross negligence. You accept all residual risks associated with the transmission and cloud storage of your data assets.
05. GDPR & UK DPA Compliance
For the purposes of the EU General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018 (DPA), RAMSMate acts as a **Data Processor** concerning safety logs and signatures generated, and a **Data Controller** for direct user registration accounts.
Your GDPR Rights:
06. Data Retention & Custody
RAMSMate maintains active custody of generated safety documents for as long as your organisational profile remains active in our system.
Under typical Health and Safety Executive (HSE) directives, risk records must be retained for at least **3 to 5 years** from their compilation date to serve as active audit trails. If you request full company termination, all documents, signatures, and cached metadata will be permanently expunged within 30 business days.