Skip to privacy notice
PrivacyTermsCookies & storage

Your information

Privacy Notice

A practical account of what the current Hemp & Safety website and tools collect, where information is kept, and the choices available to you.

Current version24 August 2026
ControllerHemp and Safety Ltd · company no. 13208900
Privacy contactinfo@hempandsafety.com
On this pageWho we areInformation we useEligibility & healthEntry, Discovery & CreatorPurposes & basisServices & sharingRetentionYour rights

Who we are

Hemp and Safety Ltd (company number 13208900) is the controller for the website and the Eligibility, Entry Assessment, Discovery and Creator Review Pad processing described in this notice. Privacy enquiries and requests can be sent to info@hempandsafety.com.

Information we use

Website and enquiries

The website itself does not contain analytics or advertising trackers. If you choose an email or telephone link, your message or call is handled by your provider and the services used by Hemp & Safety. Website hosting may process normal request details such as IP address, time, browser information and the page requested.

Information you enter

  • Eligibility: the five eligibility confirmations, symptoms or context you add, and—only if you choose to save—your name, email, telephone number, consent record, result and preferred support organisation.
  • Organisation and clinic requests: organisation details, contact person, email, telephone number, website, organisation type, support description, clinic or pharmacy listing details and optional contact email.
  • Entry Assessment: organisational assessment answers, name, organisation, email, optional telephone number, generated result and any booking request or notes.
  • Discovery: assessment and refinement answers, route and readiness information, linked Entry details where you continue from Entry, and a professional-report request using the existing Discovery record.
  • Creator Review Pad: account email, optional creator profile and avatar, product and batch details, scores, descriptors, review notes, disclosures, uploaded images, label-extraction candidates and generated review-card records.

Information generated by the services

The tools generate results, report records, timestamps and references. HSI and HSI-TALK references identify a saved assessment or report. DAX means Discovery Access Key and is an additional private credential used for protected retrieval. Keep private credentials safely; knowing an HSI-style reference alone does not always grant access.

Security records may include pseudonymised access-attempt information, outcome, time and service context so misuse can be detected. These controls monitor failed attempts without placing raw credentials in the security-event record.

Eligibility and health information

The Eligibility questions include health and mental-health information. Completing the basic check does not automatically create a saved report: answers remain in the active browser journey unless you deliberately choose the optional save route.

If you save, the report can contain your contact details, answers and health-related indication. The current saved-report period is 90 days. Expiry is controlled by the service, and expired reports cannot be opened through the retrieval flow. This is the current operational period, not a statement that the law requires 90 days.

For this optional saved-report service, Hemp and Safety Ltd relies on Article 6(1)(b): the processing is necessary to provide the saved-report service you request. Because the report contains health and other special-category information, the additional condition is Article 9(2)(a) explicit consent. This consent applies only to processing the health information in the optional saved report; it is not consent to marketing or unrelated processing.

You can withdraw that explicit consent at any time by emailing info@hempandsafety.com. Include enough information to identify the report, such as your HSI-TALK reference and the contact details used to save it, but never send an organisation access credential. Once identity and the report are verified, Hemp and Safety Ltd will stop processing the saved health information on the basis of consent and make the report unavailable through the retrieval service. Withdrawal does not affect processing that was lawful before withdrawal, cannot undo access already completed by an organisation you chose, and does not automatically decide the treatment of separate security or legal records processed for another purpose.

A support organisation must use its own protected access credential together with the report’s HSI-TALK reference. The retrieval response is limited to information needed for that discussion rather than automatically disclosing every stored field, and failed access attempts are monitored. Share your report reference only with an organisation you trust.

Clinic listings have two sources. A Public information listing is compiled from publicly available provider information. An Organisation-supplied listing contains details submitted through the Hemp & Safety registration process. Inclusion is informational, not an endorsement. Providers make their own clinical decisions and you should verify current information directly with them.

Entry, Discovery and Creator

Entry Assessment

Entry saves assessment answers, respondent details, generated results and an HSI report reference in the cloud. A private DAX credential is required to retrieve the saved report. Entry also keeps functional device history so a journey and recent summaries can be restored; the current technical expiry ceiling is 30 days. “Clear device history” removes that browser history only—it does not delete cloud records.

If you request a discussion, Hemp & Safety stores the booking details and a summary may also remain in device history. Calendly opens only after your action. Avoid adding health or other sensitive information to free-text booking notes.

Discovery

Discovery saves answers, refinement information, derived results, a free result and—where requested—the status and output of a professional-report journey. It can copy the organisation and contact context shown from a linked Entry record. A completed Discovery is retrieved using its HSI reference and DAX credential.

The browser keeps only a pending start request/session/reference identifier for an abandoned start; the current technical expiry is 24 hours. It does not store Discovery answers or the DAX there. Discovery is preliminary guidance and does not determine regulatory or licensing approval or replace professional or legal advice.

Creator Review Pad

Guest drafts are stored on the device and can be removed with “Delete drafts from this device”. The current technical expiry ceiling is 30 days. Signed-in reviews, profile information and private images are separately stored in the cloud; clearing a device draft does not erase cloud data.

For optional label extraction, the selected label image is processed using OpenAI-powered extraction to suggest visible printed package details for you to check. Hemp & Safety does not deliberately add profile or contact details to that request, and the request is made with provider storage disabled. OpenAI still processes the image to return the result. The feature does not verify authenticity, product quality, safety or medical suitability.

Why information is used

  • to provide, save and retrieve the assessment or review you request;
  • to let a chosen support organisation discuss an optional saved Eligibility report;
  • to review organisation or clinic listing requests and operate informational directories;
  • to maintain Creator accounts, private reviews, images and requested label extraction;
  • to respond to enquiries and booking requests; and
  • to secure the services, investigate failed access and maintain reliable operation.
Confirmed basis for the optional saved Eligibility reportArticle 6(1)(b) applies to providing the requested saved-report service. Article 9(2)(a) explicit consent applies to the health/special-category information in that optional saved report. The consent is separate, specific, recorded and can be withdrawn.
PurposeLawful basis
Deliver the website and its files, and keep the service reliableArticle 6(1)(f), legitimate interests. The limited request information is necessary to deliver and troubleshoot the service. It is not used for advertising or behavioural tracking.
Respond to an enquiry or requested booking stepArticle 6(1)(b), contract or steps at your request before a contract. This applies only to information necessary to handle what you asked us to do. Limited follow-up records needed to manage an issue or defend a claim rely on Article 6(1)(f).
Provide, save and retrieve Entry and Discovery assessments and reportsArticle 6(1)(b). These cloud records are necessary to provide the assessment/report service you request.
Provide Creator accounts, reviews, private images and label extraction you requestArticle 6(1)(b). Account authentication and the selected processing are necessary to provide those requested functions.
Review a clinic or organisation registration and operate an approved organisation-supplied listingArticle 6(1)(b). This is limited to the registration/listing service the organisation asks us to provide.
Maintain an accurate informational directory using public provider informationArticle 6(1)(f). We have a legitimate interest in providing a useful, accurate directory. Listings are limited to professional/public information, are not endorsements, and can be corrected or removed.
Detect misuse, protect accounts and credentials, investigate failed access and maintain security recordsArticle 6(1)(f). This limited, expected processing is necessary to secure users and the services. Security events are minimised and do not store raw private credentials.

We have recorded assessments of purpose, necessity and impact for each legitimate-interest use. Eligibility consent remains separate and is not used as a basis for any purpose in this table.

Services, recipients and international processing

Service or recipientCurrent role in the journey
Supabase (processor)Provides cloud database, authentication, private file storage and Edge Function infrastructure. The project’s primary data region is London, UK. Supabase and its subprocessors may also process or access information elsewhere under its data-processing terms; restricted transfers are covered by its UK Addendum arrangements.
OpenAI (processor for the API service)Processes a selected Creator label image to suggest visible printed details when the optional extraction action is used. Processing may occur in the United States and other listed subprocessor locations. OpenAI’s data-processing terms use the EU standard contractual clauses as amended by the UK Addendum for relevant UK restricted transfers.
IONOS (hosting processor)Hosts the static public website and may process normal technical request logs and service-continuity backups under the DPA incorporated into the account’s terms. IONOS describes its web-hosting infrastructure as geo-redundant European infrastructure and may use subprocessors under corresponding data-protection obligations. The account does not evidence a particular data centre, so we do not claim a more specific location.
jsDelivr (processor)Uses a global content-delivery network to deliver the Supabase browser library used by Entry, Discovery and Creator. It receives normal request metadata when that file loads. Its data-processing terms include the UK Addendum for relevant restricted transfers.
Calendly (processor for Hemp & Safety booking data)Opens as a separate booking service after an Entry user chooses to continue. Calendly processes data in the United States and other jurisdictions. Its terms use the UK Extension to the EU-US Data Privacy Framework where applicable, with contractual clauses and the UK Addendum as fallbacks. Calendly’s own notice also applies to information entered there.
Support organisationsAn approved organisation can retrieve the limited saved Eligibility report you choose to share, using both required credentials.
Clinics and external websitesSeparate organisations receive normal request information and anything you submit after you follow their external link. Their own privacy terms apply.
Email and telephone servicesHandle messages or calls when you choose the contact links.

Some service-provider processing or access occurs, or may occur, outside the UK. European Economic Area destinations are covered by UK adequacy regulations. Where another destination is not covered by UK adequacy regulations, the relevant provider terms identified above use contractual safeguards such as the UK Addendum, or an applicable UK extension to an adequacy arrangement. You may contact us for more information about a relevant safeguard. We do not claim a more precise IONOS location than its evidenced European web-hosting position.

The current launch code contains no analytics, behavioural advertising or tracking service, and Hemp & Safety does not use these journeys for an evidenced marketing purpose.

How long information is kept

InformationCurrent evidenced position
Optional saved Eligibility reportAvailable for 90 days. Expired records are included in a weekly manual purge. This purge is an operational process, not an automated deletion promise.
Entry device historyTechnical expiry ceiling of 30 days, plus a clear-device-history control. This is not the cloud retention period.
Discovery pending-start identifierTechnical expiry of 24 hours and removal once no longer needed by the start flow.
Creator device draftsTechnical expiry ceiling of 30 days, plus a delete-device-drafts control. Signed-in cloud reviews are separate.
Entry and Discovery cloud records12 months after the assessment or report was last updated, then included in a monthly manual purge, unless an open support, rights or dispute matter requires a temporary hold.
Creator account and active contentKept while the account and content are active. Creator content can be deleted through the available controls; verified account closure and any remaining authentication-record deletion are completed manually.
Organisation registrations and listingsPending records are kept while reviewed. Rejected or withdrawn application/contact records are kept for 12 months after the final decision, then manually deleted. Approved organisation-supplied listings are kept while active. Public-information listings are reviewed at least annually and corrected or removed when no longer accurate.
Enquiries and booking requests12 months after final contact or the booking outcome, then manually deleted, unless an open issue or claim requires a temporary hold.
Application security and access events90 days, then included in a monthly manual purge, unless an event is being investigated.
Provider platform logs and backupsKept according to the provider service configuration and lifecycle. We do not export platform logs for longer retention. A deleted item may remain in a continuity backup until that backup is overwritten; backups are not used as an archive, and a deletion is reapplied if a backup is restored.

The cloud deletion schedules above require an authorised operator to run the relevant purge or erasure process; they are not currently automated. Records on a temporary hold are reviewed when the matter closes and are then returned to the ordinary schedule.

Your choices and rights

Depending on the circumstances, you may have rights to ask for access, correction, deletion, restriction, objection or portability. In particular, you may object to processing based on Article 6(1)(f) legitimate interests. You may withdraw the explicit consent for health information in an optional saved Eligibility report at any time using the privacy email above. Withdrawal is as easy as giving consent and does not affect the lawfulness of processing carried out before withdrawal. Not every right applies in the same way to every processing activity, and we may need to verify your identity before acting.

For browser-only information, use the relevant Entry or Creator clear control where available, or your browser controls. Those actions do not delete cloud information. For a cloud-data or privacy request, email info@hempandsafety.com and include the relevant HSI reference if you still have it—but never email a private DAX or organisation credential.

You can also complain to the UK Information Commissioner’s Office. See ICO data-protection complaints.

Cookies & Local StorageTerms of UseReturn home

Hemp & Safety

HomeApps & HelpLibraryCreators
info@hempandsafety.com
PrivacyTermsCookies & storage