What personal data we hold, why, and for how long. The credential inside a handover is encrypted in the sender's browser and is never readable by us.
SafeHanded is provided by Harman AJ Ltd, a company registered in England and Wales under company number 17412886, registered office Office 1575, 60 Tottenham Court Road, Fitzrovia, London W1T 2EW. We are registered with the Information Commissioner's Office under registration number ZC232588.
Contact us about privacy at privacy@safehanded.com.
We are the controller for the personal data described in section 3: data about visitors to our website, people who contact us, the people who hold SafeHanded accounts (for running and securing those accounts) and our customers' billing contacts.
We are a processor for the data our customers put into SafeHanded, such as the people they send handover requests to, the contents of their audit logs and their client contacts. The customer organisation decides how that data is used, and our Data Processing Agreement governs our handling of it. If you received a SafeHanded link, see our handover privacy notice.
| Who | What we collect | Why | Legal basis |
|---|---|---|---|
| Website visitors | IP address, requested page, browser user agent, in the logs of our web servers and of Cloudflare, which delivers the website. The website sets no cookies and uses no analytics. | To serve the site, keep it secure and diagnose faults. | Legitimate interests (running a secure website). |
| People who contact us | Name, email, organisation, reason and message from the contact form or your email. | To reply and, for sales enquiries, to follow up on them. | Legitimate interests (responding to enquiries). |
| Account holders | Name, work email, profile photo and phone extension if added, sign-in identity from your identity provider, passkey public keys, devices and sessions (with IP address and browser), sign-in links sent to you. | To create and secure your account, authenticate you, detect misuse and send service messages such as sign-in links, invitations and security notices. | Contract with your organisation, and our legitimate interests in securing the service. |
| Billing contacts | Organisation name, billing contact and email, billing address, tax ID, subscription and invoice history. Card details are collected and held by Stripe; we see only the card type and last four digits. | To take payment, issue invoices and keep accounting records. | Contract; legal obligation (tax and company records). |
| Security researchers | Your name or handle, email and report. | To investigate and fix what you report, and credit you if you wish. | Legitimate interests (securing the service). |
| Link-checker users | The address and token of the link you paste. Your browser strips the part after the # before sending. We record an approximate country and a keyed hash of your IP address, and delete both within minutes once the check has been counted. | To tell you whether a link is genuine and to limit abuse. | Legitimate interests (fraud prevention). |
We do not sell personal data, use it for advertising, or make decisions about anyone by automated means that have legal or similarly significant effects. We send service messages to account holders but no marketing email unless you ask for it.
A credential handed over through SafeHanded is encrypted in the sender's browser to the keys of the named recipients before it reaches us. We store only the encrypted form, hold no key that can decrypt it, and have no way to decrypt it on our servers. The security page explains the design.
We can see that a handover took place and its metadata, such as who requested it, when, and the ticket reference. We cannot see the credential itself.
We share personal data only with the service providers that help us run SafeHanded, listed with their locations on our sub-processors page: hosting, website delivery, payments, email, SMS and anti-abuse checks. Each acts under a contract that limits its use of the data.
When a customer connects SafeHanded to its own helpdesk, identity provider, mailbox, chat tool or other service, we send data to that service on the customer's instructions.
We may disclose data where the law requires it, to protect people's safety, or to a buyer of the SafeHanded business under equivalent confidentiality. Because of the design in section 4, we have no readable credentials to disclose.
SafeHanded's service data is hosted in the European Union, with Hetzner in Germany and Finland. The UK recognises the EU as providing adequate protection for personal data.
Some of our providers are based in, or may access data from, the United States or other countries. Where personal data is transferred outside the UK or EEA, we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with additional safeguards where needed. Contact us for a copy of the relevant safeguards.
| Data | How long |
|---|---|
| Encrypted credentials and attachments | Until the handover is completed, expires or its ticket closes, under the customer's settings (at most 30 days), then deleted. Backup copies, still encrypted, are removed within a further 30 days. |
| Handover records and audit logs | For the retention period the customer sets, within the limit of its plan (30 days on Free, up to 2 years on MSP, or longer where a contract sets it), then deleted. |
| Account, session and device data | While the account is active. Sessions and revoked devices are deleted 90 days after they end; sign-in links after 24 hours. |
| Customer data after an organisation closes | Deleted 30 days after closure, and removed from backups within a further 30 days. |
| Billing and invoice records | Six years after the end of the financial year they relate to, as UK tax law requires. |
| Enquiries and security reports | Up to 24 months after our last exchange. |
| Web server logs | 14 days. |
If we ever restore a backup, we re-apply the deletions in this section before the service resumes.
Besides browser-side encryption, SafeHanded uses passkey sign-in, per-organisation isolation enforced in the database, encryption of integration credentials, a tamper-evident audit log, and tests that fail our build if secret material could reach our servers or logs. Our staff can view an organisation's account only for support, security or legal reasons. Such access is read-only, time-limited and recorded in that organisation's audit log.
Under the UK GDPR, and the EU GDPR where it applies, you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or transfer it to you or someone else. Where we rely on legitimate interests, you can object at any time. Email privacy@safehanded.com. We will reply within one month, and may ask you to confirm your identity.
If your request concerns data a customer organisation put into SafeHanded, such as a handover request sent to you, that organisation is the controller. We will pass your request to it and help it respond.
If you are unhappy with how we have handled your data, please tell us first at privacy@safehanded.com. We will acknowledge your complaint within 30 days and tell you the outcome.
You also have the right to complain to the Information Commissioner's Office, or, in the EU, to the supervisory authority where you live or work.
We will post any update to this policy on this page with a new effective date, and tell account owners by email about significant changes.