Legal
Privacy Policy
Last updated: 3 May 2026
1. Who we are
SafePlate is operated by Resocial Marketing Ltd, a company registered in Ireland. We provide a digital food safety and HACCP compliance platform for Irish food businesses.
Data controller contact: support@safeplate.ie
2. What data we collect
We collect the following categories of personal data:
- Account data: name, email address, phone number
- Business data: business name, address, EHO district, VAT number
- Staff data: names, training records, fitness-to-work declarations
- Compliance records: temperature logs, control records, corrective actions
- Usage data: login times, feature usage, AI credit consumption
- Payment data: processed by Stripe — we do not store card numbers
3. Why we collect it (legal basis)
We process your data under the following legal bases (GDPR Article 6):
- Contract performance: to provide the SafePlate service you signed up for
- Legal obligation: food safety records are required under EC Regulation 852/2004 and FSAI guidance
- Legitimate interests: improving the platform, preventing fraud, customer support
- Consent: marketing communications (you can withdraw at any time)
4. Special category data
Fitness-to-work declarations and illness records contain health data (special category under GDPR Article 9). We process this data solely to comply with FSAI food handler requirements. This data is never shared with third parties and is encrypted at rest.
5. Who we share data with
- Supabase: database and authentication (EU data centres)
- Anthropic: AI processing for HACCP assessments (data is not used to train models)
- Stripe: payment processing
- Resend: transactional email delivery
- Sentry: error monitoring (anonymised)
We do not sell your data. We do not share data with EHOs or regulators unless legally required.
6. Data retention
Food safety compliance records are retained for a minimum of 2 years (730 days) in line with FSAI guidance. Fitness-to-work and illness records are retained indefinitely as they are regulatory records.
Account data is deleted within 30 days of a valid deletion request, except where retention is required by law.
7. Your rights
Under GDPR you have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion (subject to legal retention requirements)
- Restrict or object to processing
- Data portability (export your records)
- Withdraw consent at any time
To exercise your rights, email support@safeplate.ie. We will respond within 30 days.
8. Cookies
We use strictly necessary cookies for authentication (session management). We only set analytics cookies with your explicit consent. You can manage your cookie preferences at any time using the banner on our website.
9. Data transfers
Some of our processors (Anthropic, Stripe) are based in the United States. Transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission.
10. Complaints
You have the right to lodge a complaint with the Data Protection Commission (DPC) — the Irish supervisory authority.
Website: dataprotection.ie · Phone: +353 57 868 4800
11. Contact
For any privacy queries: support@safeplate.ie
Resocial Marketing Ltd · Dublin, Ireland