Version 2026-08-13 · Last updated: August 13, 2026
This Privacy Policy explains how Migna Safety Solutions LLC (“Migna,” “we,” “us”) collects, uses, and protects information in connection with the Migna health & safety application (the “Service”). Migna is sold to organizations (“Customers”) that use it to run their safety programs.
For the worker and safety records entered into the Service, the Customer (the employer) is the data controller and decides what is collected and why; Migna acts as a processor that stores and processes that information on the Customer’s behalf and under its instructions. If you are a worker or employee and have a question about your information, please contact your employer, who administers the account. This policy also applies to Migna as controller for the limited account information we need to provide and support the Service.
To provide the Service, we store information you enter, which may include:
We use this information solely to operate and support the Service for your organization: recording and reporting safety data, computing compliance and analytics, sending weather/crew alerts and reminder and summary emails you configure, providing AI-assisted features, and maintaining security. We do not sell personal information and do not use Customer Data to train AI models.
The Service relies on the following providers, which process data on our behalf:
We will maintain a current list of sub-processors and notify account admins of material changes.
We operate a public demonstration instance that anyone may enter without an account. It is a separate installation with its own database: it holds no customer data, and nothing entered there reaches a customer’s instance. Visitors share a single limited account, so anything typed in is visible to other visitors, and the whole instance is erased and reloaded with sample data every night. Do not enter real personal information, real injury records or anything confidential into a demo.
Customer Data is stored in your dedicated database instance. We retain records for as long as your organization maintains an account. Certain safety records are subject to legal recordkeeping requirements — for example, OSHA requires injury and illness records (Forms 300, 300A, 301) to be retained for five (5) years — and you are responsible for meeting those obligations. On termination, you may export your data for thirty (30) days, after which we may delete it, except where longer retention is required by law or reasonably needed for backups, security, or dispute resolution.
We apply administrative and technical safeguards appropriate to the Service, including: each Customer’s data isolated in its own single-tenant database; passwords stored using salted scrypt hashing; signed, HTTP-only session cookies; tiered role-based access control (Super Admin, admin, user); enforced session secrets in production; rate limiting on authentication and AI endpoints; and encryption in transit (TLS) with encryption at rest provided by our hosting and database providers. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify affected account admins without undue delay and as required by law.
Depending on your jurisdiction, individuals may have rights to access, correct, delete, or restrict the processing of their personal information. Because we process worker and safety data on behalf of the employing organization, we will refer individual requests to the relevant Customer and assist that Customer in responding. Customers and app users may contact us at the address below.
The Service is intended for workplace use by adults and is not directed to children under 16.
We may update this policy from time to time and will communicate material changes to account admins. The “last updated” date above reflects the current version.
Questions or privacy requests: info@mignasafetysolutions.com, Migna Safety Solutions LLC, Miami, FL.