Security, Privacy & Operational Trust
SafeAspect AI is AI-assisted workplace HSE/EHS field reporting software for industrial teams. A competent HSE/EHS professional must review every output before use, submission, or implementation.
1. Data Processing Addendum (DPA)
Enterprise customers may request a separate Data Processing Addendum (DPA), confidentiality agreement, or Standard Contractual Clauses (SCCs) where required by applicable law or corporate procurement.
- For Customer Data uploaded to the Platform, the customer organization remains the Data Controller; KURGU DIGITAL SOFTWARE acts as Data Processor.
- DPA / SCC packages are provided on request for enterprise evaluation and contracting.
- Related legal baseline: Terms of Service and Privacy Policy.
2. Data location
Production application and database hosting for SafeAspect AI currently run in the European Union (France). Some processing leaves the EU when required to operate the product (notably AI inference and payment processing), consistent with the Privacy Policy international transfer section.
- Primary production hosting: EU — France (Contabo GmbH infrastructure).
- Primary database: Microsoft SQL Server on the same EU production environment.
- Backups / operational copies: Kept with the production hosting environment unless an enterprise arrangement specifies otherwise.
- AI inference: Field content used to draft reports is processed via the OpenAI API. That processing typically occurs on OpenAI infrastructure outside the EU (commonly the United States).
- Payments: Processed by Paddle as merchant of record (region depends on Paddle’s processing).
- Transactional email: Sent through the company’s mail provider for platform notifications.
- Enterprise customers may request transfer documentation (including SCCs) where applicable.
3. Key subprocessors / service providers
- Contabo GmbH — application and database hosting (EU / France).
- OpenAI — AI model inference used to draft HSE/EHS records and related analyses.
- Paddle — payments, invoicing, and tax handling for paid credits and subscriptions.
- Company mail / SMTP provider — transactional and support email delivery.
- Cloudflare Turnstile — bot protection on selected public forms (for example Contact), where enabled.
A fuller subprocessor list can be provided with a DPA package on request.
4. Backup
Production data is protected with commercially reasonable backup practices appropriate to the current hosting setup. Exact schedules and retention windows are confirmed for enterprise evaluations on request — we do not publish a fixed public backup SLA here.
- Database and application data are backed up as part of production operations.
- Platform access uses HTTPS/TLS in transit.
- Customers should export and retain copies of critical HSE records they need independently of the Platform.
5. Disaster recovery
Recovery from major infrastructure failure relies on restoring from available backups and rebuilding the application environment. The following are operational targets, not public service credits:
- Recovery Time Objective (RTO): restore critical services within 24 hours where reasonably practicable.
- Recovery Point Objective (RPO): aim to limit recoverable data loss to under 24 hours, depending on the last successful backup.
- DR validation: restore procedures are reviewed when infrastructure changes materially; formal annual DR test reports can be shared with enterprise buyers under NDA when available.
6. Security architecture overview
KURGU DIGITAL SOFTWARE implements commercially reasonable administrative, technical, and organizational safeguards intended to protect information processed through the Platform.
- Encryption in transit for Platform access over HTTPS/TLS.
- Cookie-based authentication with authorization and ownership checks on customer records and files.
- Tenant / account scoping so users operate within their organization’s workspace.
- Protected admin and report endpoints; unauthorized access is blocked at page and API boundaries.
- AI draft outputs require competent HSE/EHS professional review before use or submission.
- No internet-facing system can be guaranteed completely secure; residual risk remains.
Detailed architecture diagrams and control matrices are available to enterprise evaluators under NDA on request.
7. Penetration testing
- Independent penetration-test reports are not published on this website.
- Enterprise buyers may request the latest available security testing summary under NDA.
- Critical and high findings from any formal assessment are tracked to remediation before claiming a clean status publicly.
8. Uptime
SafeAspect AI is operated with commercially reasonable efforts to keep the Platform available. We do not currently publish a public uptime percentage or status-page SLA for self-serve accounts.
- Planned maintenance is communicated where reasonably practicable.
- Enterprise customers may negotiate availability reporting in their contract.
- Incident notices for material outages are handled through support / email channels.
9. Service Level Agreement (SLA)
A formal SLA with service credits or remedies is available for contracted enterprise plans, not as a default public guarantee for every pay-as-you-go credit account.
- Self-serve / pay-as-you-go: commercially reasonable efforts; no public uptime credit schedule.
- Enterprise: availability, support response, and escalation terms may be negotiated in the order form or MSA.
10. API access
- There is no public developer API for general self-serve use at this time.
- Product capabilities are delivered through the authenticated web application at app.safeaspect.com.
- Enterprise integrations or private API access may be discussed under a separate agreement.
- Acceptable use of the Platform and any connected services is governed by the Acceptable Use Policy.
11. Data export
Customers can export operational records from supported modules inside the application.
- Self-serve formats today: PDF report exports, DOCX where available, and CSV / Excel exports for supported modules (for example training, CAPA, near miss, and similar management views).
- Assisted export: organization owners may request a structured export package via Contact.
- Typical assisted-export turnaround: within 15 business days after identity and ownership verification.
- Personal-data portability requests follow the Privacy Policy process.
12. Account closure and data deletion
Upon termination, access to the Platform and associated data may be limited or removed in accordance with retention policies and legal obligations described in the Terms and Privacy Policy.
- Request: Account owner emails info@safeaspect.com (or uses in-app account settings when available) to request closure.
- Verification: We verify the requester controls the account / organization.
- Export window: Customers should complete needed exports before closure; assisted export may be requested during verification.
- Production deletion: After closure is confirmed, Customer Data is removed from production systems within a target of 30 days.
- Backups: Residual copies may remain in backups until the normal backup rotation completes (typically within the following backup cycle, up to about 30 additional days).
- Legal holds: Data may be retained longer where required by law, dispute, fraud prevention, or accounting obligations.
13. Customer references
Named logos and case studies are published only with customer permission. Homepage testimonials, where shown, are individual feedback and are not a ranked vendor claim.
- Public logo walls and case studies are added only with written approval.
- Private reference calls are available to serious enterprise evaluators on request.
- We do not self-rank SafeAspect AI in analyst reports or invent “#1” market claims.
How this page relates to legal documents
- Privacy Policy — controller/processor roles, retention, transfers, security measures.
- Terms of Service — DPA request path, AI output disclaimer, termination.
- Acceptable Use Policy — prohibited misuse, API and upload responsibilities.
- Cookie Policy — cookies and similar technologies.
Security & privacy contact
KURGU DIGITAL SOFTWARE — operator of SafeAspect AI
Founder: Murat ERALP
Established: 2008
Mahmutbey Cad. Sakarya Çıkmazı Sok. Gül İş Merkezi No: 1 K: 4 Ofis: 43-44Şirinevler, 34188 Bahçelievler/İstanbul
TURKEY
Email: info@safeaspect.com
Website: safeaspect.com
Contracts and legal terms are governed by applicable laws in the United States, Canada, Australia, the Middle East, and other international jurisdictions — not exclusively under the laws of the Republic of Türkiye.
For DPA, security questionnaire, pentest summary (NDA), data residency confirmation, or enterprise SLA discussions, email info@safeaspect.com or use the Contact form.