Legal
Privacy Policy
Last updated: July 18, 2026
This Privacy Policy explains how AfrikSafe HSE-HUB ("we", "us", "our") collects, uses, discloses, and safeguards personal data when you use our websites, applications, and services (the "Service"). It also describes your rights and how to exercise them.
1. Scope & our role
The Service is a business-to-business (B2B) platform used by organizations ("Customers") to capture and manage health, safety, and environment (HSE) reports. Two roles are relevant under data-protection law:
- Customer data (processor role). For the data a Customer and its authorized users submit into the Service — including reports, comments, attachments, and the personal data they may contain — the Customer is the controller and we act as a processor, handling that data on the Customer's documented instructions under our agreement with them (including any Data Processing Addendum).
- Account & billing data (controller role). For account registration, authentication, billing, support, and operating the Service, we act as a controller. This Policy governs that processing and informs users about processing carried out on Customers' behalf.
If you interact with the Service as an employee or user of a Customer, please also review that Customer's own privacy notice; they determine why and how your report data is processed within their account.
2. Information we collect
Information you provide
- Account data: name, work email, password (stored only as a salted hash), organization, role, department, preferred language, and time zone.
- Content you submit: reports (hazards, near-misses, incidents, accidents, and related records), risk ratings, corrective actions, comments, and file attachments. These may contain personal data — and, depending on what a Customer records, potentially sensitive data such as injury or health information.
- Communications: messages you send us (e.g., support or contact-form submissions).
Information collected automatically
- Usage & device data: IP address, browser and device type, pages viewed, and actions taken, used for security, diagnostics, and improving the Service.
- Audit logs: a record of security-relevant actions (who did what, and when) maintained to ensure integrity and accountability.
- Cookies:strictly necessary cookies for authentication and session management, and a cookie storing your language preference. We do not use advertising or cross-site tracking cookies. See "Cookies" below.
Information from third parties
- Single sign-on (SSO): if you sign in with Google or Microsoft, we receive basic profile information (name, email) to create or match your account.
- Payments: our payment processor (Stripe) provides billing status and limited transaction metadata. We do not receive or store full payment card numbers.
3. How we use personal data
- To provide, operate, secure, and maintain the Service;
- To authenticate users and enforce role-based access and tenant isolation;
- To process subscriptions, billing, and seat enforcement;
- To send transactional notifications (assignments, mentions, status changes, closures, escalations, and export-ready alerts) according to user preferences;
- To provide support and respond to your requests;
- To detect, prevent, and investigate fraud, abuse, and security incidents;
- To comply with legal obligations and enforce our agreements;
- To improve and develop the Service using aggregated or de-identified data.
4. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies to our controller processing, we rely on:
- Performance of a contract — to provide the Service you or your organization requested;
- Legitimate interests — to secure, maintain, and improve the Service, and to communicate about it, balanced against your rights;
- Legal obligation — to meet accounting, tax, and other legal requirements;
- Consent — where required (e.g., certain optional communications), which you may withdraw at any time.
For data processed on a Customer's behalf, the Customer is responsible for establishing the legal basis for that processing.
5. How we share data & sub-processors
We do not sell personal data. We share it only as needed to run the Service, with vetted service providers ("sub-processors") bound by confidentiality and data-protection obligations:
| Sub-processor | Purpose | Region |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, and object storage | United States |
| Stripe | Subscription billing & payment processing | United States / global |
| Resend | Transactional email delivery | United States |
| Machine-translation provider | Optional EN/FR translation of content (when enabled) | Self-hosted / provider region |
We may also disclose data to comply with law, respond to lawful requests, protect our rights and users' safety, or in connection with a merger, acquisition, or asset sale (with notice where required).
6. International data transfers
We and our sub-processors may process data in the United States and other countries. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and equivalent mechanisms.
7. Data retention
Customer contentis retained for as long as the Customer's account is active and according to the retention period the Customer configures. On termination, Customer content is deleted or returned in accordance with our agreement, subject to backup rotation and legal-hold requirements. Account and billing data is retained as long as needed to provide the Service and to meet legal, tax, and accounting obligations, after which it is deleted or de-identified.
8. Security
We apply technical and organizational measures designed to protect personal data, including encryption in transit and at rest, database-level tenant isolation (Row-Level Security), least-privilege access, an immutable audit trail, and time-boxed, audited administrative access. See our Security overview for details. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your rights
Depending on your location, you may have the right to access, correct, delete, or receive a portable copy of your personal data; to object to or restrict certain processing; and to withdraw consent. EEA/UK residents may lodge a complaint with a supervisory authority. California residents may exercise rights under the CCPA/CPRA, including the rights to know, delete, correct, and opt out of "sharing" — we do not sell or share personal data for cross-context behavioral advertising, and we will not discriminate against you for exercising your rights.
Because much data is processed on a Customer's behalf, we may direct your request to the relevant Customer (controller) and assist them in responding. To exercise rights for data we control, or for help routing a request, contact us at privacy@hse-reporting-platform.com. We may need to verify your identity before acting.
10. Cookies
We use only strictly necessary cookies (for sign-in sessions and CSRF protection) and a preference cookie that remembers your language. These are required for the Service to function and cannot be disabled through a consent banner without breaking core functionality. We do not use analytics or advertising cookies.
11. Children
The Service is intended for workplace use by adults and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be indicated by updating the "Last updated" date and, where appropriate, by additional notice. Your continued use of the Service after changes take effect constitutes acceptance.
13. Contact us
For privacy questions or requests, contact privacy@hse-reporting-platform.com. If you are an EEA/UK data subject, you may also contact our EU/UK representative or your local supervisory authority.
