Skip to main content

Legal · BETIHUT-LEGAL-PRIV

Privacy Notice

Entity
AUTOMAIZE SOLUTIONS LTD
Reg. No.
HE 480609
Effective
18 August 2026
Status
Version 2.0 · Effective

This Privacy Notice (the "Notice") explains how AUTOMAIZE SOLUTIONS LTD ("Automaize", "we" or "our") processes personal data in connection with the Betihuti websites, portals and iOS and Android applications (together, the "Apps") and the Betihuti service (the "Service").

This Notice is issued in accordance with Regulation (EU) 2016/679 (the "GDPR") and applicable national data-protection and electronic-communications laws in Cyprus.

1.Controllers, processor relationship and contact details

  1. 1.1AUTOMAIZE SOLUTIONS LTD, Registration No. HE 480609, is the Betihuti operator and an independent controller for its service administration, platform accounts and authentication, app delivery, platform security and fraud prevention, consent and AI-accountability evidence, technical support, moderation and technology compliance.
  2. 1.2Where a customer organization controls a workflow, the applicable DPA or order must identify whether Automaize acts as processor or independent controller for that specific processing.
  3. 1.3An employer Customer remains an independent controller for its workplace-safety programme, its occupational health-and-safety and employment-law obligations, its communications with the people it enrols, and its decisions about site access, fitness for work and permission to perform a task.
  4. 1.4You may contact the Betihuti Privacy Lead at privacy@betihuti.com. Automaize is responsible for responding to requests concerning its processing and will route customer-controlled requests where necessary.
  5. 1.5Following a documented Article 37 GDPR assessment dated 16 July 2026, we have not appointed a Data Protection Officer because the current pre-operation processing does not involve large-scale regular and systematic monitoring or large-scale processing of special-category data. A Privacy Lead is available through the published privacy contact. We will reassess this conclusion before material scale, biometric identification or other high-risk processing is introduced.

2.Interpretation

  1. 2.1In this Notice, "personal data", "processing", "controller", "processor", "data subject" and "supervisory authority" have the meanings given to them in the GDPR.
  2. 2.2References to "you" are to the individual whose personal data we process, whether a website visitor, a worker, contractor or visitor enrolled by a Customer, or a representative of a Customer.
  3. 2.3Headings are included for convenience only and do not affect the interpretation of this Notice.

3.Scope of this Notice

  1. 3.1This Notice applies to visitors to our websites, users of the Betihuti mobile applications, workers, contractors and site visitors enrolled in a Customer's safety programme, and representatives of prospective and existing Customers.
  2. 3.2Where Automaize acts as a processor on behalf of a Customer, the relevant Customer's own privacy notice governs that Customer-controlled processing. This Notice describes the independent-controller processing performed by Automaize and explains the processing chain used to deliver the Service.
  3. 3.3This Notice does not apply to third-party websites, products or services that may be linked from the Website, which are governed by their own privacy notices.

4.Categories of personal data we process

Depending on how you interact with us, we process the following categories of personal data:

  1. 4.1Identity, authentication and contact data, including your name, email address, optional telephone number, account/user identifiers, authentication-provider identifiers and account credentials. We do not receive your password from Apple or Google.
  2. 4.2Worker profile data, including your optional profile photo, job title and position, department, site and team assignment, languages, emergency contact where you provide one, and the personal identifiers your employer is required to hold to operate its safety programme.
  3. 4.3Safety-competence data, including training enrolments and completions, assessment results, certificates, qualifications and their expiry, instructor submissions and toolbox or shift briefing acknowledgements.
  4. 4.4Occupational health data, including medical-fitness declarations, examination outcomes and restrictions recorded by your employer. This is special-category personal data within the meaning of Article 9 GDPR: it is processed only where a lawful basis under Article 9 applies — typically occupational-medicine or health-and-safety obligations under Union or Member State law — is restricted to the roles that genuinely require it, and is withheld from general workplace roles.
  5. 4.5Workplace activity data, including site presence and gate scans, work and entrance permits, equipment and personal protective equipment issued to you, inspections, work-journal entries, notification history and messages exchanged through the Service.
  6. 4.6Safety event data, including incidents and near misses you report or are named in, investigations, corrective actions assigned to you and emergency roll-call responses. Where your employer enables anonymous reporting and you use it, the report is not attributed to you through the reporting channel.
  7. 4.7Technical, security and consent-evidence data, including IP address or a minimized IP-derived region/prefix, browser and device information, app version, session and consent subject identifiers, push-notification tokens, policy versions and hashed IP/user-agent evidence.
  8. 4.8Optional analytics and diagnostics data, including first-party product interactions and mobile crash/performance reports. These transports are off by default and are enabled only after a current choice has been recorded by the consent service; they are not used for advertising or cross-company tracking.
  9. 4.9Communications data, including the content of enquiries, support requests, safety messages and our responses to them.
  10. 4.10AI accountability data, including the inputs, outputs, reasoning, model and prompt versions and human-review history needed to explain and audit an automated output.

5.Sources of personal data

  1. 5.1Directly from you, when you complete training, submit a declaration or evidence, report a safety concern, acknowledge a briefing or contact us.
  2. 5.2Automatically, through your use of the Apps and Service, from essential session/security technology and, only after recorded consent, optional first-party analytics and mobile diagnostics.
  3. 5.3From the Customer that enrolled you, which supplies your employment, site, role and safety-requirement data, and from training providers, medical examiners and certifying bodies it uses; and from Apple or Google where you choose that authentication.

6.Google Calendar data

The Google Calendar integration is optional and is initiated by a Customer user who chooses to connect a work calendar so that safety meetings, briefings and inspections can be scheduled without clashes.

  1. 6.1When you connect Google Calendar, Betihuti accesses your Google account identifier and email address, OAuth authorization credentials, busy time ranges, and the owned calendar events needed to create, retrieve, update or cancel a meeting event. We do not request access to Gmail, Drive, Contacts or unrelated Google services.
  2. 6.2We use Google Calendar availability only to calculate conflict-free meeting slots. Busy windows are processed transiently and are not retained after the available slots have been calculated. We do not access the titles, descriptions, attendees or other content of unrelated calendar events through the free/busy request.
  3. 6.3We use owned-event access only to create and synchronize meeting events requested through Betihuti, add the agreed participants and conferencing information, reconcile event status, and update or cancel those events when the meeting changes.
  4. 6.4Access and refresh tokens are encrypted at rest with authenticated encryption and protected by access controls. We retain limited connection and subscription metadata, and the related booking retains the provider event identifier, scheduled time, participants and meeting details needed to operate and audit the booking.
  5. 6.5We do not sell Google user data, use it for advertising, share raw availability with other users, or use Google Calendar data to train or improve generalized artificial-intelligence or machine-learning models. Scheduled event details are shared only with the invited participants and service providers necessary to operate and secure the integration.
  6. 6.6You can disconnect Google Calendar from Workspace Integrations. Disconnecting attempts to revoke provider access, removes the stored access and refresh tokens, stops future calendar access, and revokes the local notification subscription. Existing events remain in your Google Calendar, and limited booking or audit records may remain under the retention and legal-hold rules in this Notice. You may request deletion of remaining personal data through your account settings or contact privacy@betihuti.com for assistance.
  7. 6.7Betihuti's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7.Purposes and legal bases of processing

We process personal data only where a lawful basis under Article 6 (and, where relevant, Article 9) GDPR applies, as set out below:

  1. 7.1To create and administer your account and to provide the Service — Article 6(1)(b) (performance of a contract to which you are party).
  2. 7.2To operate your employer's safety programme — recording the training, qualifications, medical-fitness outcomes, equipment issue, permits, site presence and safety events that programme requires — Article 6(1)(b), and Article 6(1)(c) and Article 9(2)(b) GDPR where the processing carries out an occupational health-and-safety obligation under Union or Member State law. Any recording of a briefing or spoken report is activated only after your specific consent.
  3. 7.3To determine, at the moment you attempt it, whether you are authorised and fit to enter a site, operate an asset or perform a task, and to show the responsible supervisor the requirement that is unmet — Article 6(1)(b) and Article 6(1)(c), and Article 9(2)(b) for the medical-fitness element. Where you use an optional feature that shares your record beyond the Customer that enrolled you, that sharing rests on your specific, withdrawable consent under Article 6(1)(a).
  4. 7.4To secure the Service and to prevent fraud, abuse and misuse — Article 6(1)(f) (our legitimate interest in protecting users and the integrity of the Service).
  5. 7.5To maintain, improve and develop the Service using optional first-party analytics or mobile diagnostics only after your recorded consent, and using aggregated or de-identified operational evidence wherever practicable — Article 6(1)(a) and, for necessary service-security analysis, Article 6(1)(f).
  6. 7.6To send you service-related communications and, where you have opted in, marketing communications — Article 6(1)(b) and (f), and Article 6(1)(a) for marketing.
  7. 7.7To comply with our legal and regulatory obligations — Article 6(1)(c).
  8. 7.8We do not sell personal data, use Google Analytics or Vercel Analytics, or use your safety records, reports or assistant conversations to train models for purposes unrelated to providing the Service. We do not send optional product events, Sentry browser telemetry or Firebase Crashlytics reports before the applicable consent gate is open.

8.Automated decision-making and profiling

  1. 8.1The Service evaluates your recorded training, qualifications, medical-fitness status, equipment issue and permit state against the requirements your employer has set for a site, asset or task, and produces a readiness or authorisation outcome. Automated processing is not automatically an Article 22 decision; Article 22 applies where a decision is based solely on automated processing and has legal or similarly significant effects.
  2. 8.2The outcome is protective by design: where a requirement is unmet the Service withholds authorisation rather than granting it, and it is never used to withhold authorisation without telling you which requirement was unmet. Where such an outcome is solely automated and has a legal or similarly significant effect on you — for example by preventing you from working — we and the relevant Customer must identify a valid Article 22(2) condition and provide the safeguards required by Article 22(3), including meaningful human intervention.
  3. 8.3We apply safeguards to keep the evaluation fair and inspectable: everyone assigned the same role at the same site is evaluated against the same published requirement set; the outcome names the specific requirement that was unmet and the record and expiry date behind it, rather than a bare score; and the outcome changes as soon as the missing evidence is recorded.
  4. 8.4You have the right to obtain human intervention, to express your point of view and to contest any automated outcome. Where a human review changes the outcome, the revised result replaces the automated one in your record. Further detail is set out in our AI Transparency Notice.

9.Marketing communications

  1. 9.1Where you have given your consent, or where otherwise permitted by law, we may send you communications about features, content and opportunities that may be of interest to you.
  2. 9.2You may withdraw your consent and opt out of marketing communications at any time, without charge, by using the unsubscribe mechanism in the relevant communication or by contacting us. Opting out of marketing does not affect service communications necessary to operate your account.

10.Disclosure of personal data

We disclose personal data only as necessary and to the following categories of recipient:

  1. 10.1The Customer that enrolled you, whose authorised roles receive the parts of your safety record their duties require, with medical-fitness information restricted to the roles that genuinely need it; and, where you attend the site of another contractor or site operator, that organization, which receives the authorisation outcome and the identity data needed to admit you rather than your underlying health evidence.
  2. 10.2Apple or Google when you deliberately choose their sign-in service, and Firebase Cloud Messaging when you opt into device notifications. Those providers also process data under their own user-facing privacy terms where they act independently.
  3. 10.3Processors and service providers (sub-processors) that host data, assist AI assessment, support scheduling, process payments, monitor security and deliver communications on our behalf under written contracts imposing data-protection obligations consistent with Article 28 GDPR.
  4. 10.4Professional advisers, auditors and insurers, where necessary and subject to confidentiality.
  5. 10.5Competent authorities, courts and regulators, where we are required to do so by law or to establish, exercise or defend legal claims.
  6. 10.6A successor entity, in connection with a merger, acquisition or reorganisation, subject to this Notice.

11.International transfers

  1. 11.1Our default is to host worker personal data within the European Economic Area (the "EEA").
  2. 11.2Where personal data is transferred to a country outside the EEA, we rely on an adequacy decision of the European Commission or, in its absence, on appropriate safeguards under Article 46 GDPR, principally the Standard Contractual Clauses together with any supplementary measures required following a transfer impact assessment.
  3. 11.3You may request a copy of the relevant safeguards by contacting us at the address in clause 1.

12.Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, after which it is deleted or anonymised:

  1. 12.1Account and profile data is retained while your account is active. The standard account-deletion request immediately disables sign-in and queues permanent erasure of the account, profile, photo and uploaded-document objects, messages, push tokens and related product data without support-agent approval. Records your employer is required by occupational health-and-safety law to keep are retained by that employer as controller for the period the law requires, and erasing your account does not shorten that statutory period.
  2. 12.2Certificates and supporting documents you upload are retained while the qualification they evidence remains current and for the statutory record-keeping period that follows. Assistant conversations and any recorded briefing or spoken report follow the approved 90-day schedule unless they are erased earlier through account deletion, or a valid legal hold pauses the relevant deletion.
  3. 12.3AI decision audit rows and the associated minimized consent proof are retained without direct account or safety-record links for the approved five-year accountability period, then scheduled for secure deletion. A legal hold may extend only the records within its scope.
  4. 12.4Non-personal technical documentation, quality-management and conformity evidence required for the AI system is maintained separately for the legally required period, which may be ten years under the EU AI Act; it is not used to extend the five-year retention of worker-level decision evidence.
  5. 12.5Cookie and mobile-analytics consent events normally expire after 395 days; the account link is removed during account deletion. Auth session cookies last up to seven days, the language preference up to one year, and consent cookies up to 395 days.
  6. 12.6Technical and security logs are retained for a limited period for security and troubleshooting. We minimize identifiers and do not treat necessary hosting/security logs as optional product analytics.
  7. 12.7You may request erasure before these periods expire, subject to a documented legal obligation or legal hold. We confirm a deletion request in the app and retain an anonymized completion ticket as evidence.

13.Your rights

Subject to the conditions and exceptions in the GDPR, you have the following rights in relation to your personal data:

  1. 13.1the right of access to your personal data and to obtain a copy of it;
  2. 13.2the right to rectification of inaccurate or incomplete personal data;
  3. 13.3the right to erasure (the "right to be forgotten");
  4. 13.4the right to restriction of processing and the right to object to processing carried out on the basis of legitimate interests;
  5. 13.5the right to data portability;
  6. 13.6the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal; and
  7. 13.7the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
  8. 13.8You may exercise these rights through your privacy settings or by contacting us at privacy@betihuti.com. We will respond within one month of receipt of your request, which period may be extended by two further months where necessary, in accordance with Article 12 GDPR. We do not charge a fee unless a request is manifestly unfounded or excessive.

14.Right to lodge a complaint

  1. 14.1If you consider that our processing of your personal data infringes data-protection law, you have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection (https://www.dataprotection.gov.cy), which is the supervisory authority in the Republic of Cyprus, or with the supervisory authority of your EEA place of residence or work.
  2. 14.2You do not need to determine which authority is competent before contacting Automaize about your concern.
  3. 14.3We would, however, appreciate the opportunity to address your concerns before you approach the supervisory authority, and encourage you to contact us in the first instance.

15.Cookies and similar technologies

  1. 15.1The websites use cookies and similar technologies as described in our Cookie Policy, which forms part of this Notice. The native mobile apps do not use browser cookies for app operation; their optional analytics/diagnostics preference is recorded through the same consent service.

16.Security

  1. 16.1We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR, including encryption of data in transit and at rest, access controls operating on a least-privilege basis, monitoring and a documented incident-response process. Further detail is set out in our Security Statement.

17.Children

  1. 17.1The Service is intended for persons who are at or above the minimum working age applicable in their jurisdiction. We do not knowingly collect personal data from children, and we will delete such data if we become aware that we hold it.

18.Links to other websites

  1. 18.1The Website may contain links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you.
  2. 18.2We do not control those third-party websites and are not responsible for their privacy practices. We encourage you to read the privacy notice of every website you visit.

19.Changes to this Notice

  1. 19.1We may amend this Notice from time to time to reflect changes in the Service, our practices or applicable law. The version in force is identified by the effective date stated at the head of this document.
  2. 19.2Where changes are material, we will provide notice within the Service or by email before they take effect. Your continued use of the Service after the effective date constitutes acknowledgement of the amended Notice, save where your consent is required.