Privacy Policy
How Safe For The Office™ handles information from facilitators, participants, and visitors — and what we deliberately do not collect.
- Participant answers are never stored — not in a database, not in logs
- Participant identities are never persisted after a session ends
- No participant account, email address, or password is required
- All persistent data is hosted in Canada (AWS ca-central-1)
- No advertising networks, no behavioural tracking, no third-party analytics
- Designed to support organizations operating under PIPEDA requirements
1. Privacy Overview
Safe For The Office™ is a workshop facilitation platform for professional environments. This Privacy Policy explains what information is collected when you use the platform as a facilitator, as a participant, or when you contact us — and what we deliberately do not collect.
For detailed procurement and compliance documentation, visit our Trust Center.
2. Privacy-First Participant Model
Participants join a workshop session by entering a display name. No email address, password, phone number, or account is required. Participants are anonymous to the platform.
During a live session, participant names and responses are held in the server's active memory only. This is a deliberate architectural decision — not a configuration option. The database tables that previously stored participant data were permanently removed from the platform schema. Participant data is never written to any database, log file, or persistent storage.
Participant answers are never stored. When a session ends — whether the facilitator closes it, it expires, or the server restarts — all participant data is immediately and permanently gone. There is no recovery path because there is nothing to recover from.
What participants and facilitators see during a live session depends on the activity type. For example, some activities show responses attributed to display names during the session; others show only aggregate results. In all cases, this display is driven by runtime memory only — nothing is written to a database.
3. Information We Collect
Safe For The Office™ collects and stores the following categories of information:
Facilitator account information — When a facilitator account is created, we store the email address, display name, and a cryptographic hash of the password. The original password is never stored. Account status, role, and last sign-in timestamp are also stored. This information is used to authenticate facilitator sessions and operate the platform.
Workshop room records — When a facilitator creates a room, we store the room code, activity type, content pack selection, room state, and timestamps. This operational record allows facilitators to see their session history. Room records do not contain any participant information.
Administrative audit records — All administrative actions on the platform — logins, logouts, room management operations, and account changes — are recorded in an append-only audit log. This log records only the actions of platform administrators, not participant activity.
Operational events — The platform records anonymized room lifecycle events (when rooms are created, opened, started, and completed) for operational monitoring. These events contain no participant names, answers, or identifiers.
Password reset tokens — When a password reset is requested, only a cryptographic hash of the single-use token is stored. The original token value is never persisted. Tokens expire after one hour.
Contact form submissions — When you submit the contact form, your name, email address, and message are used only to respond to your enquiry. This information is not used for marketing and is not shared with third parties.
4. Information We Do Not Collect
Safe For The Office™ does not collect or store:
- - Participant names (in-memory only during a live session — never written to a database)
- - Participant responses or answers (in-memory only — never written to a database)
- - Participant email addresses (never requested)
- - Participant phone numbers or home addresses
- - Participant IP addresses (not logged)
- - Device identifiers or browser fingerprints
- - Behavioural tracking data or advertising identifiers
- - Social media profile information
- - Biometric data of any kind
5. How Information Is Used
Information collected by Safe For The Office™ is used only to operate the platform:
- - Facilitator account information is used to authenticate sessions and manage platform access
- - Room records are used to support facilitator session history and platform operations
- - Audit records are used for administrative accountability and security
- - Operational events are used for platform health monitoring
- - Contact form submissions are used to respond to enquiries
No information is sold to third parties. No information is used for advertising or behavioural profiling.
6. Cookies and Browser Storage
Safe For The Office™ uses one cookie: __sfto_session. This is an authentication session cookie used to keep facilitators and administrators signed in. It is set with HttpOnly, Secure, and SameSite=Strict flags. It expires after 8 hours and is cleared when you sign out.
No advertising cookies, tracking pixels, analytics cookies, or cross-site tracking cookies are used.
Browser local storage may be used to remember your theme preference (light or dark mode) and preserve active workshop plan state between page loads. Local storage data is never transmitted to our servers.
Participants who join a workshop session do not receive a persistent session cookie. Participant state is held in server memory only.
For full cookie details, see the Cookie Policy.
7. Data Retention
Safe For The Office™ applies a data minimization approach:
- - Participant data — zero retention. Cleared when the session ends.
- - Facilitator accounts — retained while the account is active.
- - Room records — currently retained indefinitely. An automated cleanup policy is planned.
- - Admin audit log — 1-year retention policy. Cleanup is currently performed manually.
- - Operational events — 90-day retention policy. Cleanup is currently performed manually.
- - Password reset tokens — expire after 1 hour. Cleaned up periodically.
For the full retention schedule, see the Data Retention policy.
8. Data Residency and Service Providers
All persistent production data — facilitator accounts, room records, audit logs, and operational events — is stored in Canada using Amazon Web Services infrastructure in the AWS ca-central-1 region (Montréal, Québec).
The deployment pipeline uses GitHub Actions, which processes application code only — not user data. No user data is transmitted outside Canada as part of the deployment process.
Safe For The Office™ does not currently use third-party email delivery, payment processing, or analytics services that process user data. If any such service is added in the future, it will be disclosed here before it is activated.
For full infrastructure details, see the Data Residency policy.
9. Security Safeguards
Safe For The Office™ uses the following safeguards to protect stored information:
- - All connections are encrypted in transit using TLS
- - Passwords are hashed using scrypt, a memory-hard algorithm — original passwords are never stored
- - Session cookies are set with HttpOnly, Secure, and SameSite=Strict flags
- - All credentials and secrets are stored in AWS Secrets Manager — not in application code
- - Database connections use TLS with certificate verification
- - Administrative access is role-based and database-authoritative
- - All administrative actions are recorded in an append-only audit log
We do not claim SOC 2, ISO 27001, or FedRAMP certification. For the full security control list, see the Data Security policy.
10. Privacy Requests
You may contact us to request:
- - Access to your facilitator account information
- - Correction of your facilitator account information
- - Closure or deletion of your facilitator account
- - Privacy clarification or documentation for procurement purposes
- - Responsible disclosure of a security concern
Participants do not have account records to access or delete — participant data is never stored.
To submit a request, use the contact form. We respond to every message personally. We do not currently offer automated self-service account deletion.
11. AI and Participant Responses
Safe For The Office™ does not use AI to process, analyze, or interpret participant responses. Participant answers are not sent to any language model, machine learning system, or AI service. The platform does not score participants, evaluate behaviour, or make automated decisions about individuals.
AI tools were used to assist with platform development and documentation. This is disclosed in the interest of transparency. AI tools did not have access to production systems or user data during development.
For full details, see the AI Policy.
12. PIPEDA Alignment
Safe For The Office™ is designed to support organizations operating under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). The platform applies privacy-first design, data minimization, purpose-based processing, and appropriate safeguards.
This Privacy Policy is not a legal certification and does not replace your organization's own privacy or legal review. For detailed PIPEDA alignment documentation, see the PIPEDA Alignment page.
13. Policy Updates
This Privacy Policy will be updated when the platform's data practices change in a material way. The effective date at the bottom of this page reflects the most recent review. If AI features that involve participant data are introduced in the future, this policy will be updated before those features are released.
14. Trust Center
For detailed procurement and compliance documentation — including data handling, retention schedules, security controls, data residency, PIPEDA alignment, cookie details, and AI policy — visit the Trust Center.
15. Contact
For privacy questions, requests, or procurement documentation, contact us using the contact form. We respond to every message personally.
Effective date: October 2026