Privacy policy
How Saphion Limited handles personal data in the Saphion platform and on this website.
Who we are
The Saphion platform is operated by Saphion Limited, a company registered in England. For personal data processed through Saphion on behalf of a customer organisation, that organisation is the data controller and Saphion Limited is its processor. For this website, and for our own business contacts, Saphion Limited is the controller.
What we collect
We collect only what we need to run the service:
- Account data. Name, work email, role, and the Organisation you belong to.
- Organisation data. Your sites, projects, templates, hazard library entries, and the documents your team creates.
- Usage data. Pages visited, features used, errors, and approximate location derived from IP address — used to keep the product working and secure.
- Website data. If you accept analytics on this website, aggregated and anonymised usage statistics. See the Cookie policy.
Access to Saphion is arranged with your organisation rather than bought online, so we do not collect card details from individual users.
Why we use it
- To provide the service — drafting, review, finalisation, export and retention.
- To send essential service email, such as sign-in, invitations and security notices.
- To keep the service secure, diagnose faults and improve the product.
- To administer the commercial relationship with your organisation.
We do not sell personal data, and we do not use it for advertising.
Legal basis
Under UK GDPR we rely on: contract (providing the service), legitimate interests (keeping it secure and improving it), consent (where the law requires it, such as non-essential cookies), and legal obligation (such as tax records).
AI and your content
Saphion produces AI-assisted drafts using your project details, templates and hazard library. To do this we send the relevant content to our AI processors for the duration of the request.
Your content is not used to train shared models, and is not retained by our AI processors beyond what is needed to complete the request.
Sharing and processors
We share personal data only with processors who help us run Saphion — hosting, AI inference, error reporting and email. Each is bound by a written agreement to protect the data and use it only for the agreed purpose. A current list is available on request.
Retention
We keep Organisation data for as long as the service is provided to your organisation. After the arrangement ends, data is retained for an agreed wind-down period and then deleted, unless we are required to keep it by law.
Your rights
Under UK GDPR you have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, and receive a copy in a portable format. Email privacy@saphion.co.uk to exercise any of these rights.
Where Saphion processes data on behalf of your organisation, we will usually direct your request to that organisation as the controller, and support them in answering it.
Security
Data is encrypted in transit and at rest. Access is role-based and audited. We run dependency monitoring and have an incident response process. No system is perfectly secure — tell us immediately if you suspect a problem, at security@saphion.co.uk.
Cookies
Saphion uses a small number of essential cookies for sign-in, security and remembering your Organisation. We use no advertising or remarketing trackers anywhere.
On this public website we use Google Analytics only if you accept it, and we honour the Global Privacy Control browser signal as a rejection. Our Cookie policy lists every cookie we set, its purpose, provider and retention, and how to change or withdraw your choice.
Contact and complaints
Questions or complaints? Email privacy@saphion.co.uk. You also have the right to complain to the UK Information Commissioner's Office (ICO).