This policy covers use of the Menovia platform (the web and mobile applications). For information about how we handle data belonging to visitors of this website, see our Website Privacy Policy.
1. Purpose
This Privacy Policy explains how Menovia Ltd ("Menovia", "we", "us", "our") collects, uses, stores, and protects personal data when you use the Menovia Health & Safety SaaS platform ("the Platform"). This policy is provided in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Scope
This policy applies to all users of the Menovia platform, including:
- Web application (accessed via browser)
- Mobile application (iOS and Android)
- The API services that support them
This policy covers all personal data processed through the Platform, whether you are a platform administrator, consultancy employee, consultant, or client organisation user.
3. Data Controller and Processor
3.1 When Menovia Acts as Processor
For personal data entered into the Platform by or on behalf of a consultancy organisation (the "Customer"), the Customer is the Data Controller and Menovia acts as a Data Processor. The terms of this processing are governed by our Data Processing Agreement (DPA).
3.2 When Menovia Acts as Controller
Menovia is the Data Controller for:
- Account registration and authentication data
- Platform usage data necessary for service delivery
- Data collected for billing, support, and service improvement purposes
4. What Personal Data We Collect
4.1 Data You Provide
- Identity data - full name and email address. Used for account creation, user identification, and communication.
- Profile data (required) - mobile number and date of birth. Used for user identification and contactability. The Platform requires these once, on first sign-in, before it can be used.
- Profile data (optional) - middle name, job title, start date, home address, next of kin (emergency contact) details, profile photo, and CV. Used for employment record-keeping, emergency contact for health and safety purposes, and user recognition within the Platform. These fields may also be entered by your organisation's administrator on your behalf.
- Organisational data - role, consultancy assignment, organisation membership, and organisation contact and director details (which may include a date of birth). Used for access control, tenant isolation, service delivery, and organisation record-keeping.
- Task data - task titles, descriptions, comments, and due dates. Core platform functionality.
- Attachment data - documents, images, and forms uploaded to tasks. Task documentation and record-keeping.
- Acknowledgement and signature data - signature images and acknowledgement timestamps captured when you acknowledge or sign a distributed document. Compliance evidence for your organisation's document distribution records.
- Training records - training and competency records, certificates, and their expiry dates. Compliance record-keeping and expiry reminders. Where the record is a health surveillance or medical-fitness check, it is also special category data - see section 4.3.
- Feedback data - in-app feedback submissions, together with any image you attach (a screenshot, or a photograph taken with your device camera) and your email address, which identifies you as the reporter. Product improvement and bug reporting. See section 7 for where feedback is sent.
4.2 Data Collected Automatically
- Authentication data - Azure Entra Object ID, multi-factor authentication status, and sign-in timestamps. Used for identity verification and security.
- Audit data - user actions, timestamps, and semantic activity descriptions. Used for accountability, compliance, and security monitoring.
- Device and session data - browser type and device type (via Azure Entra sign-in logs). Used for security monitoring and service compatibility.
- Terms acceptance evidence - your IP address, browser details (user agent), the acceptance timestamp, and your name and email at the time of acceptance, recorded by Menovia in its own database when you accept the End-User Terms. Kept as evidence that the terms were accepted by you.
- Mobile push registration - an anonymous device push token issued by Expo and your device's operating system, a device identifier, and the platform (iOS or Android), stored against your account when you grant notification permission. Used to address a notification to your device. See sections 5A and 7.3.
- Mobile update-check data - your device's IP address, platform and app version, disclosed to Expo each time the app is opened, so that application updates can be delivered. See section 7.2.
4.3 Special Category Data
The Platform is health and safety software, and some of its features are designed to record health-related information, which is special category data as defined in Article 9 of the UK GDPR:
- Incident reports. The incident report templates the Platform provides (and templates consultancies build on it) can require structured details about an injured or affected person, including injury classification, injury type, and the affected body part.
- Occupational health surveillance and medical-fitness records. The Platform's training catalogue includes a dedicated group of health check and test types, and a record of one of these against a named individual is a record about that person's health. The group covers hand-arm vibration (HAVS) health surveillance, skin health surveillance, audiometry (hearing) testing, lung function testing, vision screening, drugs and alcohol testing, face-fit testing, and safety-critical, working-at-height and confined-space medicals. Each record binds the named individual to the check, the date it was completed, the date it expires, a compliance status, any notes, and the uploaded certificate - which for these types is a screening or fitness-to-work document. These are statutory occupational health surveillance records under, among others, the Control of Vibration at Work Regulations 2005, the Control of Noise at Work Regulations 2005 and regulation 11 of COSHH.
- Free text and attachments. Task descriptions, comments, and uploaded attachments may also contain health-related information.
For this data, the Customer (the consultancy or client organisation entering the record) is the Data Controller and is responsible for its lawful basis. For workplace health and safety records this is typically Article 9(2)(b) of the UK GDPR (obligations and rights under employment, social security and social protection law, read with Schedule 1 Part 1 of the Data Protection Act 2018) or, where relevant, Article 9(2)(f) (establishment, exercise or defence of legal claims). Menovia processes this data solely as a Data Processor under the Data Processing Agreement, protects it with the security measures described in Section 6, and does not use it for any purpose of its own.
4.4 Notification and Device Data
The Platform notifies people when something happens that they need to act on. To do that it processes:
- Notification records - the notification's category and event type, a short title and context line, a link to the record it concerns, the recipient, and read and seen timestamps. Used to deliver in-app notifications and to let you see what you have and have not read.
- Notification preferences - your per-category, per-channel on and off settings, or the default for your role where you have not changed them. Used to let you control how and when you are notified.
- Push device tokens - the push token issued by your device's operating system and push service, the platform (iOS or Android), and a device identifier that keeps one registration per device. Used to address a push notification to the right device, and removed when you sign out or when the token stops being valid.
Notification titles and context lines describe operational events - for example, "Redo item on Atlas House" - and are drawn from the underlying health and safety record. Where a notification is delivered by email or by push, that content is transmitted through the relevant delivery provider named in section 7.
4.5 Personal Data We Obtain From Other Sources
Not all personal data on the Platform is given to us by the person it concerns. This section covers the one category that is not, so that section 2's statement - that this policy covers all personal data processed through the Platform - holds.
Supplier and contractor register. Menovia maintains a single register of health and safety suppliers and contractors - trades businesses, testing companies, equipment providers - which is shared across all customers of the Platform so that a consultancy can find an accredited contractor without building its own list. Each listing carries the business's trade, address and contact details, and where the business is a sole trader or a one-person contractor those contact details are the personal data of an identified individual, and the address may be a home address.
- What we hold - contact name, contact email address, contact telephone number and address for each listing.
- Where it comes from - commercial and trade listings compiled by Menovia, not from the individuals concerned. This is personal data obtained from a source other than the data subject, and this section is the notice required by Article 14 of the UK GDPR.
- Who is the controller - Menovia. The register is Menovia's own commercial directory rather than customer content, so Menovia is the Data Controller for it.
- Lawful basis - legitimate interest (Article 6(1)(f)): maintaining a directory of health and safety suppliers so that customers can identify and engage competent contractors. Only business contact information is held; no special category data is held in the register.
- Who can see it - every customer organisation using the Platform, other than users holding the Employee role. The register is deliberately shared rather than kept separate per customer.
- How long we keep it - as set out in our Data Retention Policy. A listing is reviewed when it is next verified, and removed when the business no longer trades or when removal is requested.
- Your rights - if you are named on a listing you have the rights set out in section 9, including the right to object to this processing and the right to have the listing removed. Contact us using the details in section 13.
5. How We Use Your Data
We process personal data for the following purposes, with the lawful basis under the UK GDPR shown for each:
- Providing and maintaining the Platform - performance of contract (Article 6(1)(b))
- User authentication and access control - performance of contract (Article 6(1)(b))
- Tenant isolation and data security - legitimate interest (Article 6(1)(f))
- Audit logging of user actions - legitimate interest (Article 6(1)(f))
- Responding to support requests and feedback - performance of contract (Article 6(1)(b))
- Sending transactional emails, such as user invitations - performance of contract (Article 6(1)(b))
- Delivering operational notifications about health and safety events across the in-app, email and push channels - performance of contract (Article 6(1)(b))
- Maintaining the supplier and contractor register (section 4.5) - legitimate interest (Article 6(1)(f))
- Complying with legal obligations - legal obligation (Article 6(1)(c))
We do not use personal data for marketing, profiling, or automated decision-making. Notifications are operational and compliance communications, never marketing.
5A. Notifications and Communications
The Platform keeps the relevant people informed when something happens that they should know about - a task is assigned, an action item is completed, approved or rejected, a document needs acknowledging, a permit needs approval, or a certificate is expiring.
Channels. There are three:
- In-app - a notification list within the web and mobile apps, available to signed-in users.
- Email - notification emails sent through our email provider (section 7). Urgent events are sent promptly; routine events may be grouped into a periodic digest. A notification email carries the title and description of the record it concerns, which is health and safety content authored by platform users.
- Push - notifications delivered to a registered mobile or tablet device through the operating system's push service (section 7). Push requires the device-level permission that you grant or decline on your device.
Availability. The email and push channels are enabled for an organisation by configuration, so whether you receive notifications on a given channel depends on your organisation's settings and on your own preferences. This policy describes the processing that occurs when a channel is in use; it does not state which channels are switched on at any given moment, because that changes. Our Subprocessor List records the current position for each delivery provider and is available on request.
Who is notified. Notifications are routed using the Platform's existing access and visibility rules, so you are only notified about matters within your role and scope. You are never notified of your own action. The amount of detail shown scales with your involvement and your role.
Your control. Each user has a notification preference matrix in their profile settings, letting them turn each channel on or off per category, other than any notification that is essential to the service. Push additionally requires the operating-system permission, which can be withdrawn at any time in device settings. Signing out removes the push registration for that device.
6. How We Store and Protect Your Data
6.1 Data Location
All primary data is stored within Microsoft Azure UK South and UK West regions. Personal data does not leave the United Kingdom for primary storage or processing.
- Database: Azure PostgreSQL Flexible Server (UK South/UK West)
- File storage: Azure Blob Storage (UK South/UK West)
- Authentication: Azure Entra External ID
6.2 Security Measures
- Encryption at rest: AES-256 encryption on all database and file storage (Azure-managed keys)
- Encryption in transit: TLS 1.2+ enforced on all connections
- Authentication: Azure Entra External ID, using the OAuth 2.0 authorization code flow with PKCE. Your email address is verified by a one-time passcode when your account is first created. Multi-factor authentication is enforced on Menovia platform administrator accounts; it is not currently enforced on customer end-user accounts. No passwords are stored by Menovia.
- Tenant isolation: every database record is scoped to its owning tenant, and all queries are automatically restricted to the authenticated user's tenant.
- File isolation: uploaded files are stored under tenant-scoped paths, so one customer's files are never addressable from another's.
- Access control: role-based access control across six roles (Platform Admin, Consultancy Admin, Consultant, Client Admin, Client Manager, Employee) enforced at the API layer
Further detail on our security practices is available to customers on request.
7. Data Sharing and Subprocessors
We share personal data only with the following third-party subprocessors, as necessary to deliver the Platform:
- Microsoft Azure - cloud infrastructure, database, file storage, and authentication (Entra External ID). Processes all platform data, in the UK South and UK West regions.
- Postmark (ActiveCampaign, LLC) - transactional email delivery: user invitations, record emails and health and safety notification emails. Processes email addresses and user names, and - for notification and record emails - the title, description and due date of the underlying task, permit, training or announcement record, which is health and safety content rather than contact details. One template, the site induction certificate, attaches the certificate itself as a PDF; no other email carries an attachment, and no uploaded document or task attachment is sent. In the United States.
- Azure DevOps (Microsoft) - engineering tooling and user feedback tracking. Processes the text you write in a feedback submission, any images you attach (screenshots, and photographs taken with your device camera), your email address recorded as a searchable tag identifying you as the reporter, and the name of your consultancy and organisation together with the page you were on. Also processes production error diagnostics, which are not authored by Menovia and can incidentally contain identifiers. In the European Union and United States.
- Azure Application Insights (Microsoft) - application monitoring and diagnostics. Processes request telemetry and error diagnostics, which may incidentally include user or organisation identifiers and IP addresses, in the Azure UK region.
- Expo (650 Industries, Inc.) - mobile app update delivery and push notification tokens. Processes a device push token and device identifier linked to your account, and - on each app launch - your device's IP address, platform and app version, in the United States.
- Apple (APNs) / Google (FCM) - operating-system delivery of mobile push notifications, reached via Expo. Process a device push token, and the notification title and summary if and when push notifications are enabled, in the United States and other regions operated by those providers.
We do not sell, rent, or trade personal data to any third party.
7.1 International Data Transfers
Where subprocessors process data outside the UK, the position is as follows:
- Postmark: UK International Data Transfer Agreement (IDTA) / Standard Contractual Clauses (SCCs) as maintained by ActiveCampaign
- Azure DevOps: Microsoft's Data Protection Addendum, incorporating UK IDTA / SCCs
- Expo, Apple and Google: a transfer safeguard for these providers has not yet been put in place. This is being addressed; until it is, the position is stated here rather than implied.
7.2 Mobile Application Update Checks
The Menovia mobile app checks for application updates each time it is opened. This check is made to Expo, our mobile build and update provider, and necessarily discloses your device's IP address, operating system platform and the version of the app you are running. It contains no health and safety records, documents or attachments.
This check is part of how the app is kept up to date and happens whether or not you have enabled push notifications. It cannot currently be turned off from within the app.
7.3 Push Notifications and Device Tokens
If you grant the mobile app permission to send notifications, your device is issued an anonymous push token by Expo and the operating system provider (Apple or Google). We store that token against your user account so that a notification can be addressed to your device. The token identifies a device installation, not you personally, and cannot be used to access your Menovia account.
Where the push channel is in use for your organisation, the notification's title and summary are transmitted to Expo and on to Apple's or Google's push service for delivery to your device. What that content can contain is described in section 5A. Whether the channel is in use is a configuration matter that changes over time; the current position for each delivery provider is recorded in our Subprocessor List, which we maintain continuously and make available on request. If you withdraw notification permission in your device settings, or sign out, no further notifications can be delivered to that device.
8. Data Retention
8.1 Active Accounts
Personal data is retained for the duration of the service agreement between Menovia and the Customer. Users and Customers can delete individual records (tasks, comments, attachments) through the Platform interface at any time. Individual users may also delete their own account at any time; see Section 8.4 for how account deletion is handled. An administrator at your consultancy or organisation can also delete a user account; that route has a different effect and is described in Section 8.5.
8.2 Account Termination
Upon termination of a Customer's service agreement:
- Customer data is available for export for 30 days following termination
- Customer personal data is deleted within 90 days of termination, unless retention is required by law or the category is one of those listed below. This includes database records and stored files.
- Written confirmation of deletion is available upon request
Categories retained beyond 90 days. Each of the following is retained for a stated reason, and each is listed with its period in our Data Retention Policy, which is the authoritative schedule and is available on request:
- Audit log records - kept for 12 months from termination, after which they are deleted. The audit trail is the Customer's tamper-evident record of who did what for health and safety compliance, and it is kept beyond the 90-day window so that it remains available for post-termination compliance enquiries and for the establishment, exercise or defence of legal claims.
- Terms acceptance records - retained. The record that a named person accepted the End-User Terms (their name, email address, the IP address and browser details captured at the time, and the timestamp) is held in an append-only store that permits no amendment and no deletion, precisely so that it cannot be altered after the fact. Deleting it would destroy the evidence it exists to provide. Retained under Article 17(3)(e) UK GDPR (establishment, exercise or defence of legal claims).
- In-app feedback records - retained. Feedback submitted through the Platform is tracked as a product issue and identifies the person who reported it. Retained under Article 6(1)(f) for product improvement and defect tracking. A Customer or an individual may ask for their feedback records to be deleted; see section 9.
This list is exhaustive as at the date of this policy. Where a further category needs to be retained beyond 90 days, it is added to the Data Retention Policy schedule and to this list at the next revision of this policy.
8.3 Backups
Database backups are retained for up to 35 days. Backups are encrypted with AES-256 and stored within Azure UK regions. Personal data in backups is naturally purged as backup retention windows expire.
8.4 Individual Account Deletion
When an individual user deletes their own account (via the in-app "Delete My Account" function), Menovia does not erase every record the user has created. Instead, Menovia anonymises the user's personal data in place:
- Identifying personal data on your account and profile (name, email address, and the identifier that links the account to a real person) is scrubbed or removed. The same identifiers are also scrubbed from account invitation records: invitations addressed to you have the email address blanked, and invitations you sent or redeemed have the email address and sign-in identifier references removed, leaving only the sender's display name and the invitation's lifecycle timestamps as provenance.
- The account is marked as deleted and access is revoked immediately.
- Personal files uploaded to your profile (profile photo, CV) are removed on a best-effort basis. Signature images drawn when acknowledging a document are not removed - they form part of the acknowledgement evidence described below.
- Health and safety records, tasks, and activity entries the user contributed are retained in anonymised form, because these records form part of the Customer's (Data Controller's) compliance history and may be subject to statutory retention obligations. Where such a record carries no identity snapshot of the kind listed below, once the account fields are scrubbed it no longer constitutes personal data relating to the departed user.
The following record types deliberately retain limited personal data after account deletion, because they exist as evidence and rewriting them would destroy their evidential value:
- Audit trail entries keep the name you acted under at the time of each recorded action. The audit trail is your organisation's tamper-evident record of who did what for health and safety compliance. This data is retained under Article 17(3)(b) UK GDPR (compliance with a legal obligation) and Article 17(3)(e) (establishment, exercise or defence of legal claims).
- Terms acceptance records keep the name and email address you accepted the End-User Terms under, together with the IP address and browser details captured at the time of acceptance, as evidence that the terms were accepted by you. This data is retained under Article 17(3)(e).
- Document acknowledgement records keep the name you acknowledged the document under, together with any typed initials and any drawn signature image captured as part of the acknowledgement, as evidence that the document was acknowledged by you. Retained under Article 17(3)(b) and Article 17(3)(e).
- Attendance records (for example, a toolbox talk or training session sheet) keep your name as captured on the sheet, and the name of the person who captured the attendance. Retained under Article 17(3)(b) and Article 17(3)(e).
- Meeting attendee records keep the name you were recorded under, as part of your organisation's record of who attended a health and safety meeting. Retained under Article 17(3)(b) and Article 17(3)(e).
- Document authorship and invitation records keep the display name of the user who created a document or issued an account invitation, together with the invitation's lifecycle timestamps, as provenance for those records. The email address and sign-in identifier references on invitation records are scrubbed as described above. Retained under Article 17(3)(e).
Depending on the records involved, the scrubbing described above may amount to pseudonymisation rather than full anonymisation; either way, the residual records are protected by the same safeguards described in Section 6.
This approach reconciles an individual's right to erasure with the Customer's legal obligation to retain health and safety records and with both parties' need to evidence past actions and agreements. Where a user is the last remaining administrator of a consultancy, deletion is handled through an administrator-succession process before the account is anonymised.
8.5 Deletion of Your Account by an Administrator
Separately from the self-service route described in Section 8.4, an administrator at your consultancy or organisation can delete a user account from the Platform's user management screens. This is a different operation from deleting your own account. The effect on your personal data is the same; what differs is who initiates it and what is recorded about why.
When an administrator deletes an account:
- Access ends immediately. The account is marked as deleted and can no longer sign in.
- Any open tasks assigned to the user are unassigned so the work is not lost.
- The user's role assignments, consultant-to-organisation assignments and permit-issuer authorisations are revoked, each recorded with the administrator who revoked it and the reason.
- Any unredeemed invitations addressed to the user's email address are revoked.
- The user's memberships and saved preferences are removed, so they no longer appear against any consultancy, organisation or site.
- An audit entry is written recording the deletion, the administrator who performed it, and the reason they gave.
- The personal data on the profile is scrubbed, and the profile files are removed. Administrator deletion applies the same scrub as the self-service route described in section 8.4: the name, email address and authentication identifier on the account, and the personal details held on the profile record, are removed or overwritten, and the profile photo and CV are deleted from storage on a best-effort basis.
The two routes have the same effect on your personal data. Whether you delete your own account or an administrator deletes it, the same personal data is scrubbed, the same files are removed, and the same record types listed in section 8.4 deliberately retain an identity snapshot as evidence, for the same reasons. The difference between the routes is who initiates the deletion and what is recorded about why, not what survives it.
9. Your Rights
Under the UK GDPR, you have the following rights regarding your personal data:
- Access (Article 15) - request a copy of the personal data we hold about you
- Rectification (Article 16) - request correction of inaccurate personal data
- Erasure (Article 17) - request deletion of your personal data, subject to legal retention obligations. Where records must be retained (for example, health and safety records), Menovia anonymises your personal data in place rather than deleting the underlying record - see Section 8.4
- Restriction (Article 18) - request that we restrict processing of your personal data
- Data portability (Article 20) - receive your personal data in a structured, commonly used, machine-readable format
- Object (Article 21) - object to processing of your personal data based on legitimate interests
- Withdraw consent (Article 7) - where processing is based on consent, withdraw that consent at any time
9.1 How to Exercise Your Rights
- If you are an end user: contact your organisation's administrator in the first instance. Your organisation (the Data Controller) is responsible for managing your data subject requests, with Menovia's assistance.
- If you are a Customer (Data Controller): contact Menovia directly. We will respond within 10 working days.
- If you wish to contact Menovia directly: email privacy@menovia.co.uk
9.2 Right to Complain
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated:
- Website: ico.org.uk
- Helpline: 0303 123 1113
10. Cookies and Tracking
The Menovia Platform does not use cookies for tracking, advertising, or analytics purposes. Session authentication is handled entirely through Azure Entra External ID, with sign-in tokens kept in your browser's local storage on the device you sign in from.
No third-party tracking scripts, advertising pixels, or analytics services are embedded in the Platform.
11. Children's Data
The Menovia Platform is a business-to-business service designed for use by health and safety professionals and their organisations. We do not knowingly collect personal data from children under the age of 18. If you believe a child's data has been submitted to the Platform, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated to Customers via email or in-platform notification. The "Last updated" date at the top of this page indicates when the policy was last updated.
13. Contact
For questions or concerns about this Privacy Policy or our data protection practices:
- Email: privacy@menovia.co.uk
- Data protection contact: Nathaniel Waterworth, Technical Director, Menovia Ltd
- Post: Menovia Ltd, Clockwise, Yorkshire House, Greek Street, Leeds, LS1 5SH
