Privacy policy
Last updated: 17 August 2026 · Provisional: this policy is awaiting formal legal review, and the operating company's registered details will be added here once its registration completes.
Who we are
TechSafe Etc is an independent UK service for managing IT asset disposal, operated by its founding team while the operating company is being established. For anything in this policy, contact us through the account form on our homepage. We will reply to the email address you give.
On the platform, organisations raise disposal requests, approved destructors carry out the work, and the compliance paperwork that proves it is stored permanently against each job.
What we collect and why
Sign-ups. If you create an account on our website we collect your name, company name and email address. We use these details to confirm your address, review the request and, if it is approved, set up your organisation's account.
Accounts. An account goes live only after we have reviewed and approved it; access begins from an emailed invitation. For each account we hold a name, work email address, a securely hashed password and, where enabled, encrypted two-factor authentication settings. We never store passwords in a readable form.
Activity records. Because the platform's purpose is to provide a reliable compliance record, actions taken in the platform (sign-ins, uploads, downloads, assignments, approvals and sign-offs) are recorded in an audit trail together with the account that performed them. This record is the product: it is what demonstrates the chain of custody for your disposals.
Documents. Asset lists, destruction certificates and supporting files uploaded to a disposal request are stored privately and are accessible only to the organisations involved in that request.
Legal bases
We process account and activity data to perform our contract with your organisation, and enquiry data on the basis of our legitimate interest in responding to people who contact us. Audit records are kept in our own and our clients' legitimate interest in an accurate compliance record.
How long we keep things
Account requests that do not lead to an account are deleted no later than 90 days after they are received.
Invitations that are never accepted are deleted 30 days after they expire.
Account and audit records are retained for as long as your organisation uses the platform. When an account is deleted, the personal identifiers are scrubbed, including the address on emails previously sent to it, but an anonymised record of its past actions is kept, because removing it would falsify the compliance history of jobs it took part in.
Disposal records and certificates are retained permanently as compliance documents, under the control of the client organisation they belong to.
Where data lives and who processes it
Our database and file storage are hosted by Supabase in London, United Kingdom, and the application's server functions run on Vercel in London (pinned by configuration). Static content is delivered through Vercel's global network. Transactional email (invitations, password resets, job updates) is delivered by Resend. Each of these services is a sub-processor, handling data only on our instructions.
We do not sell personal data, and we do not use it for advertising.
Security
Access to data is strictly separated by organisation and enforced on every request: one client can never see another's records, and a destructor sees only the jobs assigned to it. Files are stored privately and served only through short-lived signed links. Passwords are hashed with a modern memory-hard algorithm, two-factor secrets are encrypted, and every significant action is logged.
Your rights
Under UK GDPR you have rights of access, rectification, erasure, restriction, portability and objection. To exercise any of them, contact us through the account form on our homepage. Where a request for erasure conflicts with a compliance record we are required to keep intact, we will anonymise rather than delete, and explain what we have done.
You also have the right to complain to the Information Commissioner's Office (ico.org.uk).