Singapore PDPA
WorkSAFE App — Privacy Policy
Last Updated: 5 August 2026
The purpose of this document (“Privacy Policy”) is to inform you how Strides Digital Pte. Ltd. (“Strides Digital”), the digital and technology arm of STRIDES, the commercial business arm of SMRT Corporation Ltd, manages Personal Data (as defined below) in connection with the WorkSAFE App (the web portal and mobile application, collectively the “App”) in accordance with the Singapore Personal Data Protection Act 2012 (“PDPA”). Please take a moment to read this Privacy Policy so that you are aware of and understand the purposes for which we collect, use and disclose your Personal Data.
The App is a workplace safety and health (“WSH”) platform provided for use by employees, contractors, and authorised personnel of SMRT Corporation Ltd and its related corporations (collectively, the “Companies”). By accessing or using the App, submitting information to us, or otherwise interacting with us, you agree and consent to Strides Digital, the Companies, and our respective representatives and/or agents (“Representatives”) (collectively referred to herein as “we”, “us” or “our”) collecting, using, disclosing and sharing your Personal Data amongst ourselves, and disclosing such Personal Data to our authorised service providers and relevant third parties in the manner set forth in this Privacy Policy.
This Privacy Policy supplements but does not supersede nor replace any other consents you may have previously provided to us or the Companies in respect of your Personal Data (including any consents provided in the course of your employment or engagement), and your consents herein are cumulative and additional to any rights which we may have under applicable law to collect, use or disclose and/or otherwise process your Personal Data.
We may from time to time update this Privacy Policy to ensure that it is consistent with our future developments, industry trends and/or any changes in legal or regulatory requirements. To the maximum extent permissible under applicable law, you agree to be bound by the prevailing terms of this Privacy Policy as updated from time to time. We will notify you of material updates in any form we deem appropriate, including by posting a notice within the App or contacting you via the contact particulars in our records. Please check back regularly for updated information on the handling of your Personal Data.
1. Personal Data
1.1 In this Privacy Policy, “Personal Data” refers to any data, whether true or not, about an individual who can be identified (a) from that data; or (b) from that data and other information to which we have or are likely to have access, including data in our records as may be updated from time to time.
1.2 Examples of such Personal Data we may collect in connection with the App include (depending on the nature of your interaction with the App):
- your name, NRIC/FIN or work pass details, employee or staff identification number, telephone number(s), email address, and organisational particulars (company, business unit, division, department, job title, and workplace safety appointments);
- information retrieved from Myinfo with your consent when you sign in or onboard using Singpass (see Section 5);
- the content of safety records you create or are named in — including incident and hazard reports, Gemba walk records, toolbox meeting records, stop-work orders, risk assessments, and witness or party details contained in them;
- photographs, videos, documents, and other attachments you upload;
- voice recordings you choose to make in the App and the text transcripts generated from them;
- messages you exchange with the App’s AI safety assistant and feedback or issue reports you submit; and
- technical data such as device type, operating system, app version, IP address, sign-in records, and usage logs;
- a push notification token issued to your device by the App’s notification service, which we store against your account so that we can send you safety alerts and status updates, and which we delete when you sign out or disable notifications; and
- where you use the “Locate” feature to fill in the site of a toolbox briefing and no known facility is nearby, the approximate geographic coordinates returned by your device or browser, which are written into the site field of that record and saved with it. This applies to both the mobile application and the web portal. Where a known facility is nearby, only its name is saved and the coordinates are discarded on your device.
2. Collection of Personal Data
2.1 Generally, we collect Personal Data in the following ways:
- when your organisation provisions your account, or when you sign in using your corporate credentials (Microsoft Entra ID single sign-on), Singpass, Google, or email and password — including organisational particulars synchronised from your employer’s corporate directory;
- when you submit any form or record within the App, including incident and hazard reports, Gemba walks, toolbox meetings, stop-work orders, risk assessments, and onboarding or declaration forms;
- when you upload photographs, videos, or documents, or record audio using the App’s voice input features;
- when you interact with the App’s AI safety assistant or use search, library, or insights features;
- when you are named in, assigned to, or notified about a safety record created by another user (for example, as a witness, reporting officer, or person involved in an incident);
- when you contact us or submit feedback, queries, or in-app issue reports;
- automatically from your device, when you enable notifications (a push notification token), when you sign in on Android (a device integrity check — see Section 6A), and, only if you tap “Locate” on the web portal, a single approximate position reading from your browser;
- when we receive your Personal Data from the Companies (as your employer or principal), business partners, public agencies, or other third parties in connection with your use of the App; and/or
- when you submit your Personal Data to us for any other reason.
2.2 If you provide us with any Personal Data relating to a third party (e.g. details of witnesses, persons involved in an incident, or other workers), by submitting such information to us, you represent to us that you have obtained the consent of such third party, or are otherwise entitled under applicable law, to provide us with their Personal Data for the purposes set out in this Privacy Policy.
2.3 You should ensure that all Personal Data submitted to us is complete, accurate, true and correct. Failure to do so on your part may result in our inability to provide you with access to the App or its features.
3. Purposes for the Collection, Use and Disclosure of Your Personal Data
3.1 Generally, we collect, use and disclose your Personal Data for the following purposes:
- operating, administering and providing the App and its features, including authenticating your identity and managing your account, roles, and access rights;
- recording, processing, routing, investigating and resolving workplace safety matters — including incident and hazard reports, Gemba walks, toolbox meetings, stop-work orders, and risk assessments — and notifying the relevant personnel of such matters;
- supporting the Companies’ compliance with the Workplace Safety and Health Act 2006 and other applicable WSH laws, regulations, codes of practice and guidelines, including incident reporting obligations to relevant authorities;
- transcribing voice recordings you choose to make, and processing content you submit, using AI services in order to provide features such as voice input, report pre-classification, guided form-filling, and the AI safety assistant (see Section 6);
- generating safety statistics, dashboards, insights and reports for the Companies, including in aggregated or de-identified form;
- responding to, processing and handling your complaints, queries, requests, feedback and suggestions, and providing user support;
- managing the administrative, business and technical operations of Strides Digital and the Companies, and complying with internal policies and procedures;
- verifying your identity and carrying out due diligence or security checks, including contractor onboarding;
- sending you service communications relating to the App — such as notifications of safety matters assigned to you, status updates on reports you have made, account and security notices, and one-time passcodes — via in-app notification, email, SMS, or messaging platforms (e.g. WhatsApp);
- preventing, detecting and investigating crime, fraud or misuse of the App, and managing the safety and security of the App and our systems (including audit logging and security testing);
- conducting audits, reviews and analysis of our internal processes, and managing and preparing reports on incidents and accidents;
- in connection with any claims, actions or proceedings (including obtaining legal advice and facilitating dispute resolution), and/or protecting and enforcing our contractual and legal rights and obligations;
- meeting or complying with any applicable rules, laws, regulations, codes of practice or guidelines issued by any legal or regulatory bodies, and/or assisting with any enquiries, requests, or investigations by relevant authorities; and/or
- any other purpose relating to or reasonably necessary for any of the above.
These purposes may continue to apply even after your employment or engagement with the Companies ends or you no longer use the App, to the extent reasonably necessary (for example, retention of incident records required by law).
3.2 In addition, depending on the nature of your relationship with us:
- If you are an employee of the Companies: your organisational particulars (name, email, employee ID, company, division, department, job title) may be synchronised from your employer’s corporate directory to provision and maintain your account, determine your access rights and safety appointments, and route safety matters to the appropriate personnel;
- If you are a contractor or external worker: we may collect and use your identity and work pass particulars (including via Singpass/Myinfo, see Section 5) to verify your identity, complete onboarding, and associate you with the correct employer, worksite, and safety records; and/or
- If you are named in a safety record (for example as a witness or person involved in an incident): your particulars will be used for the investigation, resolution and reporting of that matter.
3.3 We do not use your Personal Data collected through the App for marketing purposes, and we do not sell your Personal Data. Communications you receive from the App are service communications necessary for its workplace safety function.
4. Disclosure of Personal Data
4.1 We will take reasonable steps to protect your Personal Data against unauthorised disclosure. Subject to the provisions of any applicable law, your Personal Data may be disclosed, for the purposes listed above (where applicable), to the following entities or parties, whether located in Singapore or overseas:
- SMRT Corporation Ltd and its related corporations, including your employer or principal within the Companies, and their authorised personnel (such as safety officers, supervisors, and administrators) on a need-to-know basis consistent with their role in the App;
- agents, contractors or third-party service providers who provide services to us in connection with the App, such as cloud hosting and infrastructure, artificial intelligence and speech transcription services, email, SMS and messaging delivery, identity and authentication services, information technology, and professional support services;
- relevant government regulators, government ministries, statutory boards or authorities and/or law enforcement agencies, whether local or overseas — including the Ministry of Manpower and the Land Transport Authority — to comply with any directions, laws, rules, guidelines, regulations or schemes issued or administered by any of them (including statutory incident reporting);
- our professional advisers such as consultants, auditors and lawyers;
- any business partner, investor, assignee or transferee (actual or prospective) to facilitate business asset transactions (which may extend to mergers, acquisitions, debt or asset sales) involving Strides Digital or any of the Companies; and/or
- any other party to whom you authorise us to disclose your Personal Data.
4.2 Your Personal Data is hosted on cloud infrastructure located in Singapore. Where any disclosure or processing involves a transfer of Personal Data outside Singapore, we will take steps to ensure that the recipient is bound by legally enforceable obligations to provide the transferred Personal Data a standard of protection at least comparable to that under the PDPA.
4.3 We may also share information in aggregate or anonymised form (such as aggregated safety statistics) with the abovementioned parties.
5. Singpass and Myinfo
5.1 If you choose to sign in or onboard using Singpass, we will, with your consent given through the Singpass/Myinfo consent screen, retrieve from Myinfo the specific data items shown to you at the point of consent (which may include your name, NRIC/FIN, gender, date of birth, nationality, registered address, contact details, employer name, and work pass particulars). We use this data solely to verify your identity and complete your onboarding and account setup.
5.2 Myinfo data is retrieved in accordance with the terms of the Singpass ecosystem administered by GovTech Singapore. We retain only the data items reasonably necessary for the purposes in Section 3 and handle them with the safeguards described in Section 7.
6. AI Features, Voice Input and Transcription
6.1 Certain features of the App use artificial intelligence services — including the AI safety assistant, report pre-classification, guided form-filling, and speech-to-text transcription of voice recordings you choose to make. Content you submit to these features is processed by Microsoft Azure OpenAI Service and Microsoft Azure AI Speech, services operated by Microsoft Corporation. No other third party receives this content.
6.1.1 Where this processing takes place. Speech-to-text transcription of your voice recordings is performed on Microsoft resources located in the Southeast Asia region. The AI safety assistant and other text-generation features use a Microsoft “global” model deployment: your request may be processed at a Microsoft datacentre in any country in which the model is hosted, chosen by Microsoft for capacity and availability. Such transfers are subject to the safeguards described in Sections 4.2 and 6.3.
6.2 The content sent to these services comprises: (a) voice recordings you make for dictation or for toolbox briefing capture; (b) questions and messages you type to the AI safety assistant, together with the safety documents retrieved in order to answer them; (c) report text you write or dictate while using guided form-filling; and (d) the site recorded against a toolbox briefing, which is included with the transcript when a summary of that briefing is generated. Where you used “Locate” and no known facility was nearby, that site value consists of your approximate coordinates (see Section 6A.3), and those coordinates are sent to the service as part of the site value. Before your typed content is sent, the App automatically removes identifiers it detects, including NRIC/FIN numbers, telephone numbers, email addresses, dates of birth, staff identification numbers and payment card numbers. Voice recordings and the site value are transmitted as recorded or entered and cannot be redacted in the same manner.
6.3 Microsoft processes this content as our data intermediary, solely in order to return the result to us. It is not permitted to use the content to train generalised AI models, and is bound by legally enforceable obligations to afford the content a standard of protection equal to or greater than that which we are required to provide under the PDPA.
6.4 We obtain your consent within the App before any such content is sent. The first time you use a feature that shares content with these services, the App displays a notice identifying the data to be sent and naming the recipients, and the feature will not operate unless you agree. You may withdraw your agreement at any time under Settings → Privacy and AI, after which the App ceases sending content to these services; the remainder of the App continues to function and reports may be completed manually.
6.5 AI-generated output (such as transcripts and suggested classifications) is provided to assist you and the Companies’ safety personnel; material safety decisions remain subject to human review.
6A. Push Notifications, Device Integrity and Location
6A.1 Push notifications. If you enable notifications, your device is issued a push notification token by Firebase Cloud Messaging, a service operated by Google LLC. We store that token against your account so that we can send safety alerts and status updates to your device, and Google transmits those messages on our behalf. The token identifies your device installation, not you personally. We delete it when you sign out, when the token is replaced, or when you disable notifications in your device settings.
6A.2 Device integrity (Android). When you sign in on an Android device, the App asks the Google Play Integrity API to confirm that it is a genuine, unmodified installation. Google returns a signed attestation which we record server-side to help us detect tampered or automated clients. The check reports on the app and the device, not on you; it does not affect your ability to sign in, and it is not used to build any profile of you.
6A.3 Location. The App only reads your position when you tap “Locate” while filling in the site of a toolbox briefing. It is never read in the background, and the App requests only approximate (not precise) location from your device. The reading is matched against a list of facilities held on your device or in your browser; no location is sent to any mapping or geocoding service in order to perform that match.
If a facility is close enough, only its name is saved and the coordinates are discarded. If none is close enough, your approximate coordinates are written into the site field of that briefing record and saved with it, as described in Section 1.2, and are included when a summary of that briefing is generated by the services named in Section 6 (see Section 6.2). This applies to both the mobile application and the web portal. The site field remains editable, so you may replace the coordinates with a site name before or after starting the briefing. You may also decline or withdraw location access at any time, in your device or browser settings, and type the site name instead.
6A.4 These services are provided to us under Google’s Cloud and Firebase terms of service, which incorporate Google’s data processing terms. We send only the minimum each feature requires — a device token in the case of notifications, and an app attestation in the case of the integrity check. Neither contains your name, identification number, or the content of any safety record, and neither is used to build a profile of you. Any transfer of this data outside Singapore is subject to Section 4.2.
7. Protection, Retention and App Permissions
7.1 We implement administrative, technical and physical safeguards to protect your Personal Data, including encryption of data in transit and at rest, role-based access controls, audit logging, and regular security assessments.
7.2 We retain Personal Data only for so long as it is reasonably necessary for the purposes set out in Section 3, or as required by applicable law (including WSH record-keeping obligations), after which we will delete, destroy or anonymise it. To request deletion of your account, see Delete your WorkSAFE account.
7.3 The mobile application requests the following device permissions, each only when you use the corresponding feature: camera and photo library (to attach photographs and videos to safety records), microphone (voice input and transcription), notifications (safety alerts and status updates), approximate location (only when you tap “Locate” to fill in the site of a toolbox briefing — never in the background, and see Section 6A.3, which explains that the coordinates are saved when no known facility is nearby), and biometric unlock (Face ID, Touch ID or fingerprint, used only to unlock a session already stored on your device — the biometric itself is held by your device’s operating system and is never seen by, sent to, or stored by us). You may withdraw these permissions at any time in your device settings; the related features will be unavailable but the rest of the App will continue to function.
8. Deemed Consent
8.1 In addition to the matters set forth above, subject to and in accordance with applicable law, you shall be deemed to have consented to us collecting, using, disclosing and sharing amongst ourselves your Personal Data, and disclosing such Personal Data to our authorised service providers and relevant third parties:
- where, in response to a request for your Personal Data in connection with identified purposes, you voluntarily provide such Personal Data to us for such purpose(s) and it is reasonable that you would voluntarily provide such Personal Data; and
- where the collection, use and/or disclosure of your Personal Data is reasonably necessary for the conclusion and/or performance of a contract between you and us, or any other organisation entered into at your request, which may include recipients of your Personal Data not indicated in this Privacy Policy.
9. Other Bases for Handling or Processing Your Personal Data
9.1 In addition to and without limiting the consents you have provided, where permitted by applicable law, we may collect, use and/or disclose your Personal Data without consent where we meet the requirements under applicable law, including:
- for our legitimate interests or the legitimate interests of another person, including without limitation: workplace safety and the prevention of injury; any investigations or proceedings; fraud detection and prevention; managing an employment or engagement relationship; obtaining legal services; and detection and prevention of misuse of the App; and
- where collection, use or disclosure is necessary to respond to an emergency that threatens the life, health or safety of any individual.
10. Contacting Us — Questions, Feedback, Withdrawal of Consent, Access and Correction
10.1 If you:
- have any questions or feedback relating to your Personal Data or this Privacy Policy;
- would like to withdraw your consent to any use of your Personal Data as set out in this Privacy Policy; or
- would like to obtain access to or make corrections to your Personal Data records,
please contact us via our support channel at worksafe.support@stridesdigital.com.
10.2 If your Personal Data was provided to us by your employer or another third party, you may also need to direct queries, access or correction requests to that party.
10.3 If you withdraw your consent to any or all collection, use and/or disclosure of your Personal Data, depending on the nature of your request, we may not be in a position to continue to provide you access to the App. Because the App supports the Companies’ statutory workplace safety obligations, certain records containing your Personal Data (such as incident reports) may need to be retained and processed notwithstanding a withdrawal of consent, where such processing without consent is permitted or required under applicable law. Our legal rights and remedies are expressly reserved.
11. Governing Law
11.1 This Privacy Policy shall be governed in all respects by the laws of Singapore.