Hosting notice: TASC operates owner-controlled infrastructure on Amazon Web Services (AWS). Our primary hosted application environments use the Canada (Central) Region. Some optional services and service providers may process data in Canada, the United States, the United Kingdom, or other jurisdictions, as described below.
How TASC stores, protects, and handles your data. We believe in full transparency — no jargon, no surprises.
Last updated: August 26, 2026
TASC's primary hosted application stack is deployed in the AWS Canada (Central) Region (ca-central-1). The table distinguishes that primary storage location from services that operate globally or in provider-dependent regions.
| Layer | Provider | Region | What it stores |
|---|---|---|---|
| Primary Database | Amazon RDS for PostgreSQL | Canada (AWS ca-central-1) | Account, organization, safety, assessment, survey, configuration, and audit records |
| Application Hosting | AWS Elastic Beanstalk and Amazon EC2 | Canada (AWS ca-central-1) | Application code, runtime processing, and temporary operational data |
| File Storage | Amazon S3 | Canada (AWS ca-central-1) | Uploaded photos, media, documents, and other application objects |
| Content Delivery | Amazon CloudFront | Global edge network | Encrypted web requests and limited cached web content may pass through an edge location outside Canada |
| Email Delivery | Amazon Simple Email Service (SES) | Canada (AWS ca-central-1) | Email address, message content, and delivery metadata for authentication and transactional messages |
| Optional AI & Integrations | Configured AI, identity, payment, and integration providers | Canada, US, UK, or other regions | Only the data needed to provide an enabled feature, such as image analysis, sign-in, billing, notifications, or a customer-selected integration |
Canadian AWS hosting is the default for TASC's primary application records. TASC may also offer or use approved infrastructure in other regions, including the United States and the United Kingdom. Data may be processed outside its primary region when an optional provider, global content-delivery network, support activity, backup or recovery design, legal requirement, or customer-selected integration requires it. Information handled in another country may be subject to that country's laws and lawful access requirements. If TASC has made a specific contractual data-residency commitment to your organization, that commitment governs; otherwise, do not assume that every processing activity is confined to Canada. Contact us before onboarding if a particular residency boundary is mandatory.
TASC applies encryption and access controls appropriate to the service and data type:
Some QR-code readiness checks and surveys are designed to accept a response without attaching a worker account. Aggregate reporting thresholds are applied where the product identifies a workflow as anonymous.
Other features are necessarily identified or can become linked to an account, organization, site, asset, incident, observation, training record, or safety passport. The interface identifies when sign-in, attribution, sharing, or consent is required. Employer access depends on the feature, the worker's sharing choices where applicable, organization settings, assigned permissions, and legal obligations. TASC does not describe all worker activity as anonymous.
For employer accounts and team members (supervisors, admins, HSE professionals), TASC stores:
Organization records are logically scoped by tenant and access-controlled. TASC does not sell personal information. We disclose data to service providers, customer-selected integrations, and other parties only as needed to operate the service, follow user or customer instructions, complete a transaction, protect the platform, or comply with law.
Which privacy law applies depends on the people, organization, activity, and jurisdiction involved. Relevant laws may include:
Canada's Personal Information Protection and Electronic Documents Act may apply to personal information handled in commercial activity, including information that crosses provincial or national borders. Substantially similar provincial privacy laws may also apply.
Where the UK GDPR or EU GDPR applies, individuals may have rights of access, correction, deletion, restriction, portability, or objection, subject to the law's conditions and exceptions. International transfers are handled using the mechanism required for the applicable transfer.
Where California privacy law applies, residents may have rights to know, correct, or delete personal information and to opt out of certain sharing or sales. TASC does not sell personal information. Requests may be submitted using the contact details below.
TASC does not currently hold an independent SOC 2 Type II certification. AWS and other service providers maintain their own security and compliance programs, but a provider's certification does not certify TASC itself. Current assurance information can be requested during security review.
When an AI feature is enabled, TASC may transmit an image, document, text, audio, or derived data to the AI provider configured for that feature. Processing location and provider retention depend on the provider, account controls, and selected region. VisionScan photos and analysis results may be stored with the safety record, and selected images and annotations may be retained in restricted TASC datasets for validation and model improvement. Do not submit content to an AI feature if your organization has not authorized that processing. Contact TASC before enabling AI where a particular provider, retention setting, or processing region is mandatory.
Key service-provider categories include:
The data controller responsible for personal information collected through the TASC platform is:
The Autonomous Safety Company Inc.
Ontario Corporation No. 1001568154
Incorporated in Ontario, Canada
For data access requests, deletion requests, or privacy questions: