a. Website visitors
Pages viewed, approximate location, device and browser type, and the site you arrived from. Privacy-friendly analytics (Plausible) runs without cookies and without collecting personal data.
Google Analytics 4 runs only if you accept analytics cookies as described under the
Cookies page.
Our legitimate interest in running and improving the site; consent for non-essential cookies.
b. Enquiries and live chat
Your name, email, company, and whatever you type into a form or the chat widget.
Our legitimate interest in responding, and taking steps toward a possible engagement at your request.
c. Prospective clients (our outbound contact)
The organisation's name, a named contact's role and business email address, and publicly available company information. We source this from public business directories and websites (including via the service Outscraper) and organise it in Baserow.
Our legitimate interest in business-to-business marketing. Every message identifies allSafely clearly and gives you a one-click way to opt out. We keep prospect records for up to 12 months from the date a contact is added, unless you engage us or ask us to stop sooner. When you opt out we remove the record and keep only a minimal suppression entry so we don't contact you again.
d. Clients and suppliers
Contact details for your team, engagement records, timesheets, correspondence, and billing details. Card payments are handled by Stripe and banking by Wise; we do not store full card numbers. Keeping this data is a legal obligation for accounting and tax records.
e. Security and audit logs
On the systems we manage for a client we switch on audit logging (sign-ins, administrative changes). Those logs stay inside the client's own systems and are not exported to allSafely. Where we host a service for a client, its logs are kept for the period agreed in the engagement (section 2). In both cases we act as a processor for the client.