| Name | Y.S. Ghoolam trading as Hazard0 (sole proprietor) |
|---|---|
| Nature of business | Software-as-a-service platform for occupational health and safety compliance management |
| Website | hazard0.co.za |
| Head of the private body | Y.S. Ghoolam (Owner) |
| Information Officer | Y.S. Ghoolam |
| Email for PAIA/POPIA requests | privacy@hazard0.co.za |
| Address | 77 Boog Street, Cape Town |
The Information Regulator has published a Guide on how to use PAIA (section 10), available in all official languages from the Information Regulator: inforegulator.org.za · enquiries@inforegulator.org.za · JD House, 27 Stiemens Street, Braamfontein, Johannesburg.
Income Tax Act 58 of 1962 and Value-Added Tax Act 89 of 1991 (tax records, where applicable); Protection of Personal Information Act 4 of 2013; Electronic Communications and Transactions Act 25 of 2002; Consumer Protection Act 68 of 2008 (where applicable).
Business and financial: accounting and banking records; tax records; agreements.
Customer and subscriber: account registration details; subscription and billing records; support correspondence.
Platform records held on behalf of customers (as operator under POPIA): compliance documentation created by customer organisations, including risk assessments, inspection checklists, appointment letters and employee medical surveillance records. Note: requests for access to these records should be directed to the customer organisation concerned, which is the responsible party; Hazard0 processes them as operator only.
Operational: technical and security logs; backup records; supplier records (hosting, payment processing).
1. Complete Form 2 (Request for Access to Record), available from inforegulator.org.za.
2. Submit it to the Information Officer at privacy@hazard0.co.za.
3. Identify the record, the right you seek to exercise or protect, and why the record is required for that purpose.
4. Proof of identity is required. If requesting on behalf of another person, proof of authority is required.
5. Prescribed fees (as per the PAIA fee regulations) may apply and will be communicated before processing.
A decision will be made within 30 days of receipt of a compliant request, as required by PAIA. Grounds for refusal are those set out in Chapter 4 of Part 3 of PAIA (including protection of third-party privacy, commercial information and legal privilege).
Purpose of processing: account administration; provision of the software service; billing; support; security; legal compliance.
Categories of data subjects and information: customers and their authorised users (contact and account details); customers' employees (identity details and, where the customer uses the medical module, medical surveillance information — processed as operator on the customer's behalf); suppliers (contact and contract details).
Recipients: PayFast (Pty) Ltd (payment processing); xneelo (Pty) Ltd (hosting). Personal information is not otherwise disclosed except as required by law.
Cross-border transfers: none. All personal information is stored in South Africa.
Security measures: encrypted transmission (HTTPS/TLS), hashed credentials, authenticated access control on stored documents, per-organisation file segregation, daily backups within South Africa.
This manual is available at hazard0.co.za/legal/paia.html and on request from the Information Officer, free of charge.