Hosting notice: TASC operates owner-controlled infrastructure on Amazon Web Services (AWS). Our primary hosted application environments use the Canada (Central) Region. Some optional services and service providers may process data in Canada, the United States, the United Kingdom, or other jurisdictions, as described below.

Transparency

Data & Privacy

How TASC collects, uses, discloses, stores, protects, retains, and manages personal information.

Last updated: September 6, 2026 · Version 2026-09-06-r2

At a glance

This notice is not a request for consent to optional processing. Where consent is the appropriate legal basis, TASC or the relevant Customer will present a separate, specific choice. Required processing is identified as a condition of the service where applicable.

Who is responsible for your information

The party responsible depends on the context. TASC is responsible for account administration, its public website, direct support, service security, billing references, legal-acceptance records, and information it uses for its own legitimate business purposes. An employer or other subscribing organization is generally responsible for workplace records and instructions it submits to TASC; TASC processes those records for the Customer under the service agreement. In some circumstances, both may have separate legal responsibilities.

If your request concerns workplace data supplied or controlled by a Customer, TASC may refer the request to that Customer and provide reasonable assistance. Neither this notice nor a customer instruction removes a responsibility imposed directly by applicable law.

Where your data lives

TASC's primary hosted application stack is deployed in the AWS Canada (Central) Region (ca-central-1). The table distinguishes that primary storage location from services that operate globally or in provider-dependent regions.

Layer Provider Region What it stores
Primary Database Amazon RDS for PostgreSQL Canada (AWS ca-central-1) Account, organization, safety, assessment, survey, configuration, and audit records
Application Hosting AWS Elastic Beanstalk and Amazon EC2 Canada (AWS ca-central-1) Application code, runtime processing, and temporary operational data
File Storage Amazon S3 Canada (AWS ca-central-1) Uploaded photos, media, documents, and other application objects
Content Delivery Amazon CloudFront Global edge network Encrypted web requests and limited cached web content may pass through an edge location outside Canada
Email Delivery Amazon Simple Email Service (SES) Canada (AWS ca-central-1) Email address, message content, and delivery metadata for authentication and transactional messages
Optional AI & Integrations Configured AI, identity, payment, and integration providers Canada, US, UK, or other regions Only the data needed to provide an enabled feature, such as image analysis, sign-in, billing, notifications, or a customer-selected integration
Data residency and cross-border processing

Canadian AWS hosting is the default for TASC's primary application records. TASC may also offer or use approved infrastructure in other regions, including the United States and the United Kingdom. Data may be processed outside its primary region when an optional provider, global content-delivery network, support activity, backup or recovery design, legal requirement, or customer-selected integration requires it. Information handled in another country may be subject to that country's laws and lawful access requirements. If TASC has made a specific contractual data-residency commitment to your organization, that commitment governs; otherwise, do not assume that every processing activity is confined to Canada. Contact us before onboarding if a particular residency boundary is mandatory.

Information we collect, sources, and purposes

TASC may also receive information from an authorized Customer administrator, an invited User, an identity provider, a payment provider, a Customer-selected integration, or public sources where permitted by law. TASC limits collection, use, and disclosure to identified and reasonably appropriate purposes.

Encryption

TASC applies encryption and access controls appropriate to the service and data type:

Anonymous and identified worker data

✓ Anonymous workflows are kept separate from worker identity

Some QR-code readiness checks and surveys are designed to accept a response without attaching a worker account. Aggregate reporting thresholds are applied where the product identifies a workflow as anonymous.

Other features are necessarily identified or can become linked to an account, organization, site, asset, incident, observation, training record, or safety passport. The interface identifies when sign-in, attribution, sharing, or consent is required. Employer access depends on the feature, the worker's sharing choices where applicable, organization settings, assigned permissions, and legal obligations. TASC does not describe all worker activity as anonymous.

Employer and team member data

For employer accounts and team members (supervisors, administrators, and safety professionals), TASC may store:

Organization records are logically scoped by tenant and access-controlled. TASC does not sell personal information. TASC may disclose information to authorized Customer Users; service providers and subprocessors; Customer-selected integrations; professional advisers, auditors, insurers, and transaction counterparties subject to suitable duties; or public authorities where lawfully required. TASC may also disclose information to protect rights, safety, and service integrity, or in connection with a financing, reorganization, merger, or sale subject to appropriate safeguards.

Website storage and first-party analytics

TASC uses essential cookies or similar browser storage for authentication, security, session continuity, interface preferences, and requested workflows. The service also uses limited first-party page analytics to understand aggregate traffic and improve reliability. That measurement records the requested page path, approximate time, browser and device category, coarse country or city derived from the network address, a shortened user-agent value, an origin-only referrer, and pseudonymous identifiers created with a keyed hash. The raw network address is used transiently for security and coarse geolocation and is not stored in the page-analytics record.

TASC does not use the page-analytics system for third-party behavioural advertising or to build advertising profiles. Browser requests for externally hosted fonts, icons, scripts, identity tools, maps, or media may disclose ordinary request information such as network address and user-agent data to the relevant provider. Customer-selected integrations may set or use their own storage under the provider's notice.

Privacy-by-design principles

Applicable privacy frameworks

Which privacy law applies depends on the person, Customer, activity, sector, and jurisdiction. TASC does not claim that every listed law applies to every use. Relevant law may include:

🇨🇦 PIPEDA (Canada)

Canada's Personal Information Protection and Electronic Documents Act may apply to personal information handled in commercial activity, including information that crosses provincial or national borders. Substantially similar provincial privacy laws may also apply.

Provincial Canadian privacy laws

Private-sector privacy laws in Québec, Alberta, and British Columbia may apply, and sector-specific laws may apply elsewhere. Customers must tell TASC before onboarding if their sector or jurisdiction requires a particular assessment, agreement, residency boundary, or authorization.

🇬🇧 UK GDPR and 🇪🇺 EU GDPR

Where the UK GDPR or EU GDPR applies, individuals may have rights of access, correction, deletion, restriction, portability, or objection, subject to the law's conditions and exceptions. International transfers are handled using the mechanism required for the applicable transfer.

🇺🇸 CCPA (California)

Where California privacy law applies, residents may have rights to know, correct, or delete personal information and to opt out of certain sharing or sales. TASC does not sell personal information. Requests may be submitted using the contact details below.

Compliance & certifications

Transparency note on SOC 2

TASC does not currently hold an independent SOC 2 Type II certification. AWS and other service providers maintain their own security and compliance programs, but a provider's certification does not certify TASC itself. Current assurance information can be requested during security review.

Third-party AI processing — VisionScan and AI features

When an AI feature is enabled, TASC may transmit an image, document, text, audio, or derived data to the provider configured for that feature. Processing location and provider retention depend on the provider, account controls, and selected region. Inputs and results may be stored with the relevant safety record. TASC will not place Customer content into a separate model-training or improvement dataset unless the use is separately enabled under a signed agreement and supported by any notice, authority, and consent required by law. Do not submit content to an AI feature unless the Customer has authorized that processing. Contact TASC before enabling AI where a particular provider, retention setting, or processing region is mandatory.

Human review is required

AI analyses, readiness scores, rankings, and recommendations may be incomplete, inaccurate, or affected by context not available to the system. TASC does not use these outputs to make final employment decisions. Customers must provide qualified human review, consider accommodation and relevant context, and provide notice, explanation, challenge, or review rights where required. Outputs must not be the sole basis for an adverse employment, disciplinary, medical, or fitness-for-work decision.

Key service-provider categories include:

Retention, deletion, and de-identification

Retention varies by record type, Customer configuration, contract, legal requirement, security need, and backup cycle. Customer-facing retention settings may archive supported records; they do not necessarily delete them or override legal holds, audit integrity, incident-investigation duties, or backup handling. Customers are responsible for selecting retention periods appropriate to their workplace, sector, collective agreements, litigation holds, and law.

When information is no longer reasonably required, TASC will delete it, de-identify it, or restrict it from ordinary use under the applicable process. Residual encrypted backup copies may remain until the backup cycle expires and are not restored for ordinary business use. TASC may retain limited security, transaction, acceptance, and audit evidence where reasonably necessary to establish, exercise, or defend legal rights or comply with law.

Your choices and privacy rights

Subject to identity verification, applicable law, lawful exceptions, and whether a Customer controls the record, a person may ask to access or correct personal information, withdraw consent where processing depends on consent, challenge compliance, or request deletion, export, restriction, or objection where the applicable law provides that right. Withdrawing consent does not affect prior lawful processing and may prevent TASC or the Customer from providing a feature that reasonably requires the information.

Workers should first use available product controls or contact the organization responsible for the workplace record. TASC will assist or route the request where appropriate. A person may also complain to the Office of the Privacy Commissioner of Canada or the applicable provincial, territorial, or international privacy regulator.

Security incidents and breach notification

TASC maintains processes to assess suspected unauthorized access, use, or disclosure. TASC will notify affected Customers and individuals, and report to regulators or other organizations, when and as required by applicable law or a signed agreement. Customers must promptly notify TASC of suspected compromised accounts, exports, devices, credentials, or Customer-controlled integrations and cooperate with containment and legally required notices.

Communications and minors

TASC sends authentication, security, support, billing, and other service messages needed to administer the account. Commercial electronic messages are sent only where TASC has a lawful basis and include identification and an unsubscribe method where required. Unsubscribing from marketing does not stop essential account or safety-service messages.

Employer accounts are for adults. TASC is not directed to children and should not be used to collect a minor's personal information unless the Customer has confirmed the use is lawful, necessary, appropriately noticed, and authorized. Contact TASC before onboarding minors.

Privacy Officer, questions, complaints, and requests

TASC has designated a Privacy Officer for information for which TASC is responsible:

The Autonomous Safety Company Inc.
Ontario Corporation No. 1001568154
Incorporated in Ontario, Canada

For a privacy question, complaint, access or correction request, consent withdrawal, or deletion request:

TASC will investigate privacy complaints fairly and will not retaliate for a good-faith privacy request. A current mailing address for formal privacy correspondence is available on request.

Changes to this notice

TASC may update this notice as practices, providers, features, or laws change. The page will identify the effective date. TASC will provide additional notice before a material new use or disclosure and will obtain consent where consent is required. Earlier versions and related acceptance evidence are retained where reasonably necessary for accountability.