Security Report AI

Privacy

Security Report AI is an account-based service. It stores data on a hosted backend — it does not keep your information only in the browser.

What is stored

When you use the service with an account, the following is stored in a hosted database and file storage, not just in your browser:

  • • Account data: the email address you sign up with, the password held by the authentication provider in hashed form, and an optional display name.
  • • Workspace data: the hotel/property name and the optional country and room count you enter, plus which accounts belong to that workspace and with which role.
  • • Incident reports: the narrative you write or dictate, the structured report generated from it, workflow status, review and closure metadata, saved SOP recommendations, and the change history of each report.
  • • Voice input: audio recorded through the in-app recorder is sent to a speech-to-text provider to produce the transcript. The transcript is what gets stored with the report.
  • • SOP documents: files you upload are stored in private file storage, and the extracted text is stored in searchable fragments used to answer questions and to ground procedure suggestions.
  • • Technical logs: standard request and error logs generated by the hosting and backend platforms.

Content you enter may contain personal data

Incident narratives, reports and uploaded procedures are free-form. They can contain personal data about guests, staff or third parties. Decide what you enter accordingly, and keep entries limited to what your own incident-handling process requires.

Who can see it

  • • Data is scoped to a single hotel workspace. Accounts belonging to one workspace cannot read another workspace's incidents, documents or history — this is enforced at the database level, not only in the interface.
  • • Operators of the service can access the underlying infrastructure for maintenance and support.

Processors used

The service relies on third parties to run: a cloud application host, a managed database, authentication and file-storage provider, and AI model providers used for transcription, report structuring, text embeddings and question answering. Text and audio you submit are transmitted to those AI providers to produce the output shown in the app.

The register of sub-processors, with the function each one performs, is on the sub-processors page.

Data processing agreement

A data processing agreement covering the customer as controller and the operating entity as processor is prepared in outline. Its scope is set out on the DPA page. Until it is executed, processing terms are the ones set out in the written pilot agreement.

Retention and deletion

Data is kept for as long as the workspace exists. Incident records are deliberately not deletable from the interface, and the change history of a report is append-only, because the product is intended to keep a reliable audit trail. Deletion of a workspace and its content is handled on request through the pilot contact.

No automatic expiry or deletion job runs today. Intended retention windows are held in a single documented configuration inside the product and will be described here before any automated deletion is switched on.

Your requests

Signed-in users can download a machine-readable export of the records their account is authorised to read from Settings → Privacy & data. Requests to access, correct or delete data, or any other question about how data is handled, are handled manually through the contact below.

Controller and contact

  • • The operating entity, its registered address, VAT number and published contact addresses are not confirmed yet. They are provided in writing to each pilot customer before any data is entered, and will be listed here once registered.

What this page does not claim

This page describes how the product currently behaves. It does not claim certification, audit or regulatory compliance of any kind, and no such claim should be inferred from it.

This page is an informational description of how the product currently works. It is not legal advice and it is not a substitute for the data-processing terms agreed with your organisation. It is updated as the product changes.

Back to home