Privacy
Our formal privacy policy is being prepared with legal counsel before public launch. The summary below describes exactly how the system works today, in plain language.
What we collect
Account details for the people who sign in (name, email). Records you enter about your equipment: what it is, where it is, when it expires, and the inspections performed on it. If you use certification tracking, records about employees who are not users of the software — their name, role, site, and the certifications they hold.
Employees who are not users
Before you can add a person to certification tracking, the software requires you to confirm you have that person's permission to store their information. That confirmation is recorded with your name, the date, and the exact wording you agreed to, and it appears in your activity log and your exports.
Where it is stored
In Canada, encrypted in transit and at rest. Your records are private to your organization: access is enforced at the database level, not only in the interface, so another customer cannot read your data even if the application had a bug.
What we never do
We do not sell your data. We do not share it with advertisers. We do not use it to train machine-learning models. We do not publish your equipment locations — there is no public directory and no unauthenticated way to look up where anything is. We never give your safety provider access to your records on our own initiative; that only ever happens where you have switched it on yourself, section by section (see below).
Sharing with your safety provider
If you joined through a safety provider in our partner network, you can choose to let them see your records — separately for each section (training and certificates, first aid, defibrillators, fire equipment, PPE, equipment inspections). Nothing is shared unless you turn it on. For each section you choose whether they can view your records, or also add and update them so they can file a certificate or an inspection after doing the work. Where you share training records, that includes the names of the people who hold them and the dates those qualifications expire. Everyone at that provider can see what you have shared, because the permission is given to the company rather than to a named individual. You can withdraw any section at any time, or disconnect from the provider entirely, and their access stops immediately. We keep a record of what was shared and when it was withdrawn, so you can answer that question later if your own auditor asks it. A provider can never grant themselves access to an organization you created, and can never delete your records. There is one case where a provider does start with access: where they set the account up for you before you had a login of your own. They made those records, so there was nobody to ask — but the moment you take over the account you can see exactly what they can reach, withdraw any of it, or disconnect them entirely, and from that point they can never widen their own access again.
Support access
Our support staff can access account data when needed to resolve an issue. Every such access is logged. Any correction we make is recorded under our own name in your activity log — never disguised as one of your users.
Reminder emails
We email the people you nominate about equipment and certifications that need attention. Every message has a working unsubscribe. Reminders may include a link to a supplier; if you follow it we record that a click happened so the supplier can attribute it, and we do not send them your records.
How long we keep it
Compliance records are kept for seven years, so an audit years later still has its evidence. When you close your organization, reminders stop immediately and it disappears from ReadyRegistry — we keep the records themselves under that retention period rather than erasing them straight away, because a closed organization is still the subject of any audit covering the years it was open. If you want them erased outright, ask us and we will do it, and confirm when it is done.
Getting your data
You can export everything your organization has entered, at any time, without asking us: it is under Settings → Your data. If someone whose certifications you track wants to know what is held about them, that export contains it.
Questions about privacy, or a request about your own information: hello@readyregistry.ca
