Security & Data Handling Statement: SMP 365
Effective Date: 9 May 2026
This Security & Data Handling Statement applies to all SMP 365 software products, services, applications, and Microsoft Marketplace offerings provided by SMP 365 SAAS Pty Ltd.
Systems Covered
This statement governs the security protocols for our entire suite, including:
-
Operations: Permit to Work, LMS, Contractor Management, Travel Management.
-
Risk & Safety: ICAM + AI Assisted Investigations, Risk Management, Incident Management, EMS, Psychosocial Risk Management.
-
Analytics: Hazardous Goods Management, Action Management, Dashboards & Analytics, Safety Mobile Applications.
1. Microsoft-Native Security Architecture
SMP 365 is designed as a Microsoft-integrated business application. Our systems operate primarily within your existing customer-controlled Microsoft environments, including Microsoft 365, SharePoint Online, Microsoft Azure, and Microsoft Entra ID. This allows you to leverage your existing enterprise security investments and compliance controls.
2. Customer-Controlled Tenancy
You retain full control over your data environment. SMP 365 systems respect your internal policies regarding:
-
User permissions and authentication.
-
Data retention and Microsoft Purview settings.
-
Audit logging and tenant governance.
3. SharePoint-Native Architecture
By utilizing SharePoint and Microsoft 365 technologies, SMP 365 solutions inherit world-class platform capabilities, including role-based permissions, comprehensive audit histories, and Microsoft identity integration.
4. Customer Ownership of Data
You own your data. SMP 365 does not claim ownership over any operational records, investigations, permits, training records, or uploaded evidence stored within your Microsoft environment.
5. Configurable AI Services
Customers have the power to enable or disable AI-assisted functionality. When active, we utilize Azure AI Services (OpenAI, Speech, Document Intelligence) to provide insights, transcriptions, and summarizations within your environment.
6. AI-Assisted Output Disclaimer
AI-generated outputs are assistive tools only.
-
They may contain inaccuracies and require human verification.
-
They do not constitute legal advice or regulatory certification.
-
Final operational decisions remain the sole responsibility of the customer.
7. Microsoft Security Inheritance
Our architecture allows customers to apply enterprise-grade tools directly to their SMP 365 data, including:
-
Microsoft Entra ID & MFA
-
Conditional Access & Microsoft Defender
-
Microsoft Purview & Sentinel
8. Security Controls
SMP 365 employs commercially reasonable security practices, including:
-
Encrypted HTTPS communications.
-
Role-based access controls (RBAC).
-
Secure API authentication and Azure infrastructure.
9. Data Processing & Hosting
Data is processed within your Microsoft 365 environment or customer-selected Microsoft Azure regions. This ensures you maintain control over data residency and jurisdictional compliance.
10. Third-Party Services
SMP 365 integrates seamlessly with Microsoft 365, SharePoint Online, Microsoft Graph, Azure AI Services, and the Microsoft Power Platform.
11. Security Incident Reporting
Security is a shared responsibility. Please promptly report any suspected unauthorized access or platform misuse to our team:
-
Email: support@smp365.com
-
Website: www.smp365.com
12. Regulatory Considerations
While our systems support ISO-aligned frameworks, customers are responsible for ensuring their own compliance with local workplace safety legislation, privacy laws, and operational regulations.
13. Changes to This Statement
SMP 365 may update this statement periodically to reflect new platform enhancements or changes in the Microsoft ecosystem.
14. Contact Information
SMP 365 SAAS Pty Ltd Global Microsoft-Integrated Safety & Risk Software Provider
Address: Level 2, 1 Prowse Street West Perth WA 6005 Australia
Email: support@smp365.com Web: www.smp365.com
