Elite Health & Safety

Privacy Policy

Last updated: 30 September 2026

This Privacy Policy explains how Elite Health & Safety Ltd (company number SC878365, registered in Scotland) (“Elite H&S”, “we”, “us”, “our”) collects, uses, stores and protects personal data when you use Lanyard, our online health & safety management system (“Lanyard”).

We are committed to protecting your privacy and handling your data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Our two roles

We handle personal data in two different capacities.

As controller we decide why and how data is used: our own business contacts and enquiries, our staff and associates, your billing and account contacts, your Lanyard account and sign-in records, our access and security logs, and the reports and assessments we issue in our own name.

As processor we act on a client organisation’s instructions: the records that organisation keeps in Lanyard about its own workers, subcontractors, sites and incidents, including training records, sign-offs, accident and near-miss reports and health surveillance documents. For those records the client organisation is the controller and we handle them under a written data processing agreement.

If you work for one of our client organisations and you want to exercise your data protection rights over records they keep in Lanyard, contact your employer first. They are the controller. We will help them respond.

2. Health information

Some of what Lanyard holds is special category data about health: injuries recorded in accident and near miss reports, RIDDOR notifications, health surveillance outcomes and fitness for work information. The law treats this as more sensitive and so do we. Where we hold it as a processor, the client organisation is responsible for identifying its Article 9 condition and for holding an Appropriate Policy Document where one is needed. Where we hold health information about our own staff, we rely on Schedule 1, Part 1, paragraph 1 of the Data Protection Act 2018 and we hold an Appropriate Policy Document, available on request.

3. Who to contact

For any privacy question or to exercise your rights, contact us at info@elitehealthandsafety.co.uk. Registered office: 443 Dumbarton Road, Clydebank, Scotland, G81 4DU. We are registered with the UK Information Commissioner’s Office as a data controller under registration reference ZC229599. Where a question concerns records a client organisation keeps in Lanyard, we will pass it to that organisation, because it is the controller for those records.

4. The data we collect

The table below shows what we hold and, for each category, whether we hold it as controller or on a client organisation’s instructions as processor.

CategoryExamplesOur role
Account & identityName, email, job title, telephone, login credentials, role/permissions.Controller
Client & site dataCompany details, sites, contacts, and the health & safety records you manage in Lanyard (assessments, documents, training records, actions, reports).Processor, for the client organisation that keeps them
Delegate & training dataNames, and certificates/training records for people you enrol on courses.Processor, for the organisation that enrols them
Accident, incident and health recordsAccident, near miss and hazard reports including injury detail, RIDDOR notifications, health surveillance outcomes and fitness for work information (see section 2).Processor, for the client organisation that records them
Reports and assessments we issueFire risk assessments, inspection reports and other deliverables we sign in our own name and under our own professional competence.Controller
Billing & payment dataMembership tier, invoices, Direct Debit reference and mandate status. We do not store full bank details. Direct Debit is handled by GoCardless; card/bank data is never held by us.Controller
Accounting data (QuickBooks)Your company name, billing contact and address, and the invoices we raise to you, held in our own QuickBooks Online accounts system so that we can invoice you and record what has been paid (see section 8).Controller
Usage & technicalLog data, device/browser information and actions taken in Lanyard, used for security and to operate the service.Controller

5. How we use your data

Records we hold as processor are used only to run Lanyard for the client organisation that keeps them, and on that organisation’s instructions. We do not use them for our own purposes, and we never use anyone’s data for advertising or sell it.

6. Legal bases

Where we act as controller we rely on: contract (to provide Lanyard and our services to you); legitimate interests (to run, secure and improve the service, and to keep the evidence of the professional work we have signed); legal obligation (accounting, health & safety, tax); and consent where specifically requested (which you may withdraw at any time). For special category health data about our own staff we also rely on the condition in section 2.

Where we act as processor we do not choose a legal basis of our own. The client organisation is the controller, it identifies the lawful basis and any Article 9 condition, and we process on its documented instructions under our data processing agreement with it.

7. How we share data

We do not sell your data. We share it with the providers below, under contract and only as needed to run Lanyard and our services.

Processors acting on our instructions

ProviderPurpose
SupabaseSecure database, authentication and file storage, in the United Kingdom (hosting Lanyard’s data).
Microsoft 365Email delivery for every message Lanyard sends, including sign-in links, certificates and reminders, and document storage.
Netlify, Inc.Website hosting and serving Lanyard application, United States. Netlify is self-certified under the UK Extension to the EU-US Data Privacy Framework, and uses the European Commission’s standard contractual clauses where the framework does not apply.
Anthropic PBC (United States)Reads documents and certificates you upload so Lanyard can fill in their details, checks uploaded documents and site photographs against the requirement they evidence, and drafts text you ask it to. Data is sent only when those features are used. Transfers to the US rely on the UK International Data Transfer Addendum with Anthropic’s data processing terms.
IONOSHosting for our automation and document rendering service, Germany.
DocuSignElectronic signature of agreements and sign-offs, United States, under the UK International Data Transfer Addendum.
Mitti (formerly SafetyCulture)Inspections carried out on site, Australia, under the UK International Data Transfer Addendum. The provider renamed itself from SafetyCulture to Mitti in August 2026; it is the same company and the same service.

Independent controllers, not our sub-processors

Two providers act as controllers in their own right, not as our sub-processors, because they determine their own purposes under financial regulation and their own scheme rules. GoCardless Ltd (United Kingdom) processes your billing contact and bank mandate details to set up and collect Direct Debits, and for its own anti money laundering and fraud prevention duties. Its own privacy notice applies to that processing. Intuit Limited (QuickBooks Online) processes your company name, billing contact, address and the invoices we raise to you, in our own accounts system, as an independent controller.

ProviderPurpose
GoCardlessDirect Debit mandate setup and payment collection, and its own regulatory duties.
Intuit QuickBooksOur accounts system: holds your billing details and the invoices we raise to you, and tells Lanyard when an invoice has been paid.

We may also disclose data where required by law or to protect our rights and the safety of others. A full and current list of sub-processors is available on request.

Staff access to your account

Named members of Elite staff can open your organisation’s portal account as if they were you, to help with a support request or to verify records you have asked us to check. Each time this happens we record who did it, when, and the reason they gave, and we keep that record for 12 months. You can ask us for the record of who has accessed your account and we will provide it. When we demonstrate the portal to prospective customers we use demonstration accounts containing made-up data only. Real client information is never used for sales demonstrations.

Guest sign-off links

When someone signs a toolbox talk or form through a guest link, we record the name they type, their employer and job role if given, and the time. That record joins the roster of the client organisation that sent the link, which is the controller for it.

8. QuickBooks Online data

Elite Health & Safety keeps its accounts in QuickBooks Online (Intuit). You do not connect your own QuickBooks, or any other accounts system, to Lanyard, and Lanyard never reads your company’s accounting data. When we raise an invoice to you, Lanyard sends our QuickBooks your company name, billing contact and address and the invoice lines through Intuit’s official API, and reads back whether that invoice has been paid so that your Lanyard billing page shows the right balance. Only our staff can connect or disconnect that link, from the staff side of Lanyard. Intuit acts as an independent controller for that data, not as our sub-processor (see section 7). We use this data solely to invoice you and record payment; we do not use it for advertising and do not sell it. Our use of Intuit’s APIs adheres to the Intuit Developer terms and API policies.

9. Security

Data is protected in transit and at rest. Access is controlled by role-based permissions and database Row-Level Security, so each client account can only access its own records. We follow good-practice safeguards; however, no system is completely secure, and you are responsible for keeping your login credentials confidential.

10. International transfers

Some providers may process data outside the UK. Where they do, we rely on appropriate safeguards (such as UK adequacy regulations or standard contractual clauses). Anthropic processes data in the United States under the UK International Data Transfer Addendum, as set out in section 7.

11. How long we keep your data

We keep personal data for as long as we need it and then for any period the law requires. Health and safety records carry unusually long statutory periods, so some are kept for decades.

RecordHow long we keep it
Accident, incident and near miss records3 years from the date of the report, or until an injured person’s 21st birthday where they were under 18.
Health surveillance records for hazardous substances, asbestos and lead40 years from the last entry.
Training records and certificatesFor the duration of employment plus 6 years.
Invoices and accounting records6 years after the tax year.
Sign-in and security logs12 months.

When a membership ends, the records we hold for that client move to an archive. They are kept, retrievable on request, for the periods above, and are no longer added to or used for anything else. The client can instruct us to delete or return them at any time and that instruction is followed. We never make the return of records conditional on payment.

Our full retention schedule is available on request.

12. Your rights

Under UK GDPR you have the right to access, correct, erase, restrict or object to processing of your personal data, and to data portability. You can download your company's records at any time from Documents in Lanyard. To exercise any right, contact info@elitehealthandsafety.co.uk. Where the records concerned are ones a client organisation keeps in Lanyard, that organisation is the controller, so contact your employer first and we will help them respond (see section 1). You may also complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.

13. Complaints

If you are unhappy with how we have handled your personal data, you can complain to us at info@elitehealthandsafety.co.uk or in writing to our registered office. We will acknowledge your complaint within 30 days, look into it, and answer you without undue delay. You can complain by email, by post, or by using the complaint form we will send you on request. You may also complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk at any time, whether or not you have complained to us first.

14. Cookies

Lanyard uses only essential cookies/local storage needed to keep you signed in and operate the service. We do not use advertising or third-party tracking cookies.

15. Changes

We may update this policy from time to time. The “last updated” date above shows the latest version, and material changes will be notified through Lanyard.