Hazard0

Privacy Policy

Effective date: 17 July 2026 · Version 2.0

This policy explains how Y.S. Ghoolam trading as Hazard0 (“Hazard0”, “we”, “us”) collects, uses, stores and protects personal information, in compliance with the Protection of Personal Information Act 4 of 2013 (“POPIA”).

1. Who we are

Hazard0 is a South African occupational health and safety compliance platform. For personal information you provide when creating and managing your account, Hazard0 is the responsible party. For personal information your organisation uploads about its employees (including medical surveillance records), your organisation is the responsible party and Hazard0 acts as an operator under section 20 of POPIA, processing that information only on your organisation's instructions. Our operator obligations are set out in the Data Processing Annex to our Terms of Service.

2. Information we collect

Account information: name, work email address, organisation name and details, login credentials (passwords are stored only in hashed form).

Compliance records you create: risk assessments, inspection checklists, appointment letters, incident records and related documents.

Employee records your organisation uploads: employee details and, where your organisation uses the medical module, medical surveillance records. Medical information is special personal information under section 26 of POPIA; your organisation is responsible for ensuring a lawful basis for processing it, including compliance with its obligations as an employer under the Occupational Health and Safety Act 85 of 1993.

Billing information: subscription and transaction records. We do not collect or store card details. Payments are processed by PayFast (Pty) Ltd; card information is captured and tokenised directly by PayFast.

Technical information: login timestamps and technical logs reasonably required to secure and operate the service.

3. How we use personal information

We use personal information only to: provide and operate the platform; authenticate users and secure accounts; process subscription billing through PayFast; send service and account emails (e.g. password resets, billing notices); provide support; and comply with legal obligations.

We do not sell personal information. We do not use your data for advertising. We do not use your compliance or employee records for any purpose other than providing the service to you.

4. Who we share information with

We share personal information only with: PayFast (Pty) Ltd — payment processing (subscription billing); xneelo (Pty) Ltd — our hosting provider (infrastructure only; see section 5); and authorities or courts — where disclosure is required by law. No other third parties receive personal information processed on the platform.

5. Where your data is stored

All platform data, including uploaded documents and generated PDFs, is hosted with xneelo (Pty) Ltd in a secure data centre in South Africa. Encrypted backups are made daily and are also stored in South Africa. No personal information is transferred outside the borders of South Africa.

6. Security

We apply reasonable technical and organisational measures as required by section 19 of POPIA, including: encrypted connections (HTTPS/TLS), hashed password storage, authenticated access control on all uploaded documents, per-organisation segregation of stored files, and daily backups.

7. Retention and deletion

We retain personal information for as long as your organisation maintains an active account. Following cancellation or termination, account data is retained for 60 days to allow your organisation to export its records, after which it is deleted from the live platform, save where retention is required by law. Your organisation remains responsible for complying with statutory record-retention periods that apply to employers under occupational health and safety legislation (which may require retaining certain records, such as medical surveillance records, for extended periods) — export your records before your account closes.

8. Your rights

Under POPIA, data subjects have the right to: request access to their personal information (section 23); request correction or deletion of inaccurate, out-of-date, excessive or unlawfully obtained information (section 24); object to processing (section 11(3)); and complain to the Information Regulator. Where the information concerned was uploaded by your employer, we may refer your request to your employer as the responsible party, and will assist them in responding.

To exercise any right, contact our Information Officer at privacy@hazard0.co.za.

9. Security compromises

If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and affected data subjects as soon as reasonably possible after becoming aware of the compromise, as required by section 22 of POPIA.

10. Cookies and local storage

The platform uses only strictly necessary storage: an authentication token to keep you logged in, and a service worker cache so the application loads quickly. We do not use advertising, analytics or tracking cookies. See our Cookie Notice.

11. Information Officer and Regulator

Information Officer: Y.S. Ghoolam — privacy@hazard0.co.za
Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg — enquiries@inforegulator.org.za — inforegulator.org.za

12. Changes to this policy

We may update this policy from time to time. Material changes will be notified to account holders by email or in-app notice. The current version will always be available at hazard0.co.za/legal/privacy.html.

Terms of ServicePrivacy PolicyPAIA ManualCookie Noticehazard0.co.za

© 2026 Y.S. Ghoolam trading as Hazard0. All rights reserved. Built in South Africa.