Privacy Policy
Last updated: September 8, 2026
1. Who we are
This Privacy Policy explains how Devtine (Pvt) Ltd ("Devtine," "we," "us," or "our") collects, uses, discloses, and protects information in connection with Safetify, our AI-assisted EHS (Environment, Health & Safety) platform, made up of a mobile field-worker application, a web-based tenant dashboard, and a super-admin panel used by Devtine to manage client companies (together, the "Service"). Safetify is a business-to-business product: our direct customers are companies ("Customer" or "Tenant") that deploy Safetify to their own employees and contractors ("Field Workers," "Authorized Users").
2. Scope and roles
For data submitted by Field Workers and dashboard users through the Service (checklist responses, hazard/incident reports, photos, voice notes, location data, and safety records), Devtine acts as a data processor / service provider on behalf of the Customer, who is the data controller responsible for its workforce's data. This policy also covers information collected directly by Devtine on this marketing website and in the course of our own commercial relationship with Customers.
3. Information we collect
Depending on how the Service is used, we collect the following categories of information:
- Account and profile information: name, phone number, job title/role (Field Worker, Supervisor, HSE Manager, Tenant Admin), employee/worker ID, and device-binding information used for secure offline access.
- Location data (GPS): site check-in coordinates and GPS tags automatically attached to hazard reports, incident reports, and permit requests, used to associate field activity with the correct site and to power location-based site check-in.
- Photos and voice recordings: images and voice notes captured for hazard reports, incident/near-miss reports, and inspections, including AI-generated transcriptions of voice notes and AI-drafted summaries of report content.
- Worker personal information: certification and training records, permit and JSA sign-off history, corrective-action assignments, and toolbox-talk attendance.
- Usage and device data: app version, device model, offline sync status, IP address, and log data generated as Authorized Users interact with the Service.
- Business contact information: if you contact us through this website (e.g. via email), we receive whatever information you choose to include, such as your name, email address, and company details.
4. How we use information
We use the information described above to:
- Provide the core Service — pre-task checklists, hazard and incident reporting, permit-to-work and JSA workflows, corrective actions, certifications, and reporting/analytics for Customer's HSE managers and supervisors.
- Power AI-assisted features — summarizing field reports, transcribing voice notes, suggesting severity classifications, detecting compliance gaps, and generating risk scores and weekly digests from Customer's own historical safety data. AI output is always presented as a reviewable draft that a human user must confirm.
- Enable offline-first operation — data captured with no signal at a remote site is stored securely on-device and synced to our servers once connectivity is restored.
- Secure accounts and devices — including device-binding for field workers, and revoking access when a worker is offboarded.
- Maintain audit and compliance records — safety data, certification history, and permit/incident records are kept as the Customer's compliance and audit trail.
- Operate, maintain, and improve the Service, including security monitoring, debugging, and customer support.
- Respond to inquiries sent through this website.
5. AI processing
Text, photo, and voice-note content submitted through the Service may be sent to a third-party large language model (LLM) provider to generate draft summaries, classifications, and transcriptions. This processing is used solely to power the AI-assisted features described above and is subject to contractual data-handling commitments with our AI provider(s). AI-generated output is never published or acted upon automatically — it is always surfaced to a human Customer user as an editable draft requiring explicit confirmation.
6. How we share information
We do not sell personal information. We share information only:
- Within the Customer's own tenant — data submitted by a Field Worker is visible to that Customer's authorized Supervisors, HSE Managers, and Tenant Admins as needed to operate the Service. Each Customer's data is logically isolated (schema-per-tenant) from every other Customer.
- With infrastructure and sub-processors that host and operate the Service on our behalf — including our database hosting provider, our cloud object-storage provider (for photos and voice notes), and our AI/LLM provider — each bound by appropriate data-protection terms.
- Where required by law, regulation, legal process, or to protect the rights, property, or safety of Devtine, our Customers, or others.
- In connection with a merger, acquisition, or sale of assets, subject to continued protection of personal information under this policy or a materially equivalent one.
7. Data retention
Safety data — photos, voice notes, AI-generated results, and related metadata — is retained indefinitely for the duration of the Customer's subscription, because this data forms the compliance and audit record required for regulatory purposes and is the input to our risk-intelligence features. We do not apply an automatic deletion policy to this safety-critical evidence. Upon termination of a Customer's subscription, data is made available for export for a reasonable transition period and is thereafter deleted or anonymized in accordance with our data retention practices, except where we are required by law to retain it longer.
8. Data security
We use industry-standard technical and organizational measures to protect information, including encryption of data in transit, schema-per-tenant isolation in our multi-tenant database, role-based access control enforced on the server (not just in the app interface), and short-lived, presigned upload URLs so photo and voice-note files never pass through our application servers unnecessarily. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. International data transfers
Our infrastructure providers may process and store data outside Pakistan. Where this occurs, we take steps to ensure an appropriate level of protection consistent with this policy and applicable law.
10. Your rights and choices
If you are a Field Worker or dashboard user of a Customer using Safetify, requests to access, correct, or delete your personal information should generally be directed to your employer (the Customer), who controls that data; we will assist our Customers in fulfilling such requests. If you contact us directly through this website, you may ask us to access, correct, or delete the information you provided by emailing us at the address below.
11. Children's privacy
The Service is intended for use by working adults in a professional field-operations context and is not directed to, or knowingly used by, children.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date above, and where appropriate, communicated to Customers directly.
13. Contact us
Questions or requests regarding this Privacy Policy can be sent to info@devtine.com.