Privacy Policy

Version 1 · Effective 2026-10-01

Draft under legal review — this document takes effect on its effective date.

This Privacy Policy explains how Safety-MC, a product of BLCCS, LLC (“Safety-MC”, “we”) collects and uses information on the safety-mc.com website and in the Safety-MC portal. Version 1, effective 2026-10-01.

1. Who we are and our role

Safety-MC provides a workplace safety platform to employers (“Customers”). For information entered into a Customer’s portal, the Customer decides what is collected and why; Safety-MC processes it on the Customer’s behalf to provide the Service. For the public website and demo requests, Safety-MC decides how information is used.

2. Information we collect

  • Identity and roster data supplied by your employer: name, work email, role, department, home location, employment dates. Sign-in is handled by Microsoft Entra External ID; we do not receive or store passwords.
  • Engagement records: which briefings, trainings and courses you opened, scroll and audio-playback progress, acknowledgments, knowledge-check answers and scores, and the date, time, device type, browser and IP address of those actions.
  • Incident and inspection reports you or others file: workplace injury or illness details (which may include health information), witness statements, photos, vehicle accident details including GPS-tagged photos and other-party information, and vehicle inspection results.
  • Fleet and insurance data: vehicle identifiers and insurance ID cards uploaded by your employer, and fleet data from Samsara if your employer connects it.
  • Assistant conversations: questions you ask the in-portal Safety Assistant and its answers.
  • Acceptances and approvals: the version of the terms you accepted, approvals of AI content and OSHA filings, with the time and IP address.
  • Website and demo requests: name, work email, company, phone and message submitted through the contact form, and basic, cookie-less page-view measurements.

3. How we use information

To provide and secure the Service; generate safety content tailored to your employer’s program; send the notifications and reminders your employer has enabled; produce the records, reports and OSHA filings your employer requests; provide support; and respond to demo requests and questions. We do not sell personal information or use it for third-party advertising.

4. Sensitive information in incident reports

Injury and illness reports can include medical details. Within the portal these are visible only to the reporter and the administrators your employer designates. Reports marked as privacy cases hide the injured person’s name on the OSHA 300 Log. Names, addresses, physicians and treatment facilities are never included in electronic submissions to OSHA.

5. AI processing

To generate content, Safety-MC sends your employer’s department profiles, topics, course plans, uploaded training documents and, for the assistant, the results of look-ups in your employer’s portal data to Anthropic (text generation) and OpenAI (narration and translation) under their business terms. Personal information is not included in briefing or course generation.

6. Service providers (subprocessors)

  • Microsoft Azure — hosting, database, file storage, key management, malware scanning, sign-in (Entra External ID) and email delivery (Azure Communication Services).
  • Anthropic — AI text generation.
  • OpenAI — AI narration and translation.
  • Samsara — fleet data, only when your employer connects its own Samsara account.
  • OSHA Injury Tracking Application — a government recipient, only when your employer authorizes a filing.

7. Retention

Compliance records (briefing acknowledgments, training completions, incident reports, inspections, approvals) are retained for the life of your employer’s subscription, including after an employee leaves, because they document the employer’s safety program. OSHA 300A summaries are kept for the five-year period the regulation requires. After a subscription ends, your employer may export its records for 60 days, after which we delete or de-identify them unless the law requires longer retention. Demo-request records are kept for up to two years.

8. Security

Each Customer’s data is separated at the database level and that separation is enforced in code and covered by automated tests. Data is encrypted in transit and at rest, integration credentials are encrypted, uploads are validated and malware-scanned, and access is invite-only. No system is perfectly secure; we will notify affected Customers of a breach as the law requires.

9. Your choices and rights

If you are an employee, direct requests to access, correct or delete your information to your employer, which controls the portal; Safety-MC will assist your employer in responding. If you contacted us through the website, you may ask us to correct or delete your request record at the address below. Where privacy laws give you additional rights, we honor them as they apply.

10. Cookies

The portal uses a session cookie to keep you signed in. The website uses no advertising or tracking cookies; page-view measurement, if enabled, is cookie-less.

11. Children

The Service is for workplaces and is not directed to children under 16.

12. Changes to this policy

We may update this policy. Material changes take effect on the stated effective date and are announced in the portal.

13. Contact

Privacy questions: info@safety-mc.com.