Privacy Policy
Effective date: 4 October 2026
Houssein Hassan Daher, carrying on business as "HaSafety" ("HaSafety", "we", "us"), provides a digital safety-management platform for field-level hazard assessments and compliance. This policy explains what personal information we handle, why, and your choices.
1. Who this policy is for
HaSafety is a business-to-business tool. Your employer (the "Company") decides what information is entered into HaSafety and is the controller of that information. We process it on the Company's behalf as a service provider. If you are a worker and have questions about your data, contact your Company's administrator first.
2. Information we handle
We handle the information a Company and its users enter into the platform, which may include:
- Account information: name, work email, role, trade, company, and account status.
- Safety records: hazard assessments, incidents, observations, inspections, meeting and toolbox-talk records, time cards, and similar operational data.
- Certifications: ticket names, issue and expiry dates, and any certificate images uploaded.
- Signatures: the signature you draw when you sign off on a record.
- Location, only when you choose it: if you allow it, the coordinates of where a record was signed are stamped on that record. Your device asks first, and declining does not stop you filing anything.
- Photographs attached to records by users.
We do not use tracking cookies and we do not run advertising.
3. Why we handle it
To provide the service the Company has asked for: recording safety work, warning about expiring certifications and overdue actions, producing the reports and packets a Company gives to its clients and auditors, and keeping the platform secure and working.
We do not sell personal information. We do not use it for advertising.
4. Artificial intelligence
Some features use Anthropic's Claude API to draft safety documents, and to read a photo or document when you choose to run it through one of them, such as a ticket photo. Only the data needed for that request is sent. It is processed in the United States and, per Anthropic's commercial terms, it is not used to train AI models. AI output is always a draft for a qualified person to review.
5. Sub-processors
We rely on a small set of providers to run the service:
| Provider | Purpose | Data handling |
|---|---|---|
| Google (Firebase / Google Cloud) | Database, file storage, server functions, backups | Stored and run in Canada (Montréal); encrypted in transit and at rest |
| Google (Firebase Authentication) | Sign-in accounts: name, email and password check | Processed in the United States |
| Vercel | Application hosting and delivery | Serves the app over HTTPS; holds no customer records |
| Anthropic | AI draft generation | Processed in the United States; not used to train models (commercial terms) |
| Sentry | Crash and error monitoring | Diagnostic data only; processed in the United States |
| Zoho | Outbound email (notifications, reports) | Canadian data centre |
6. Security
We protect information with encryption in transit (TLS) and at rest (AES-256), server-enforced separation between Companies, role-based access, admin-approved accounts, and automated backups and monitoring.
Access ends with the account: when a Company suspends someone, or a contractor's access period expires, the platform refuses their requests at the database — not merely in the app.
No system is perfectly secure, but we work to protect your information using industry-standard measures.
7. Data retention
We keep information for as long as the Company maintains its account, plus any period required by law. When a Company closes its account, its data is deleted from the live system; residual copies in encrypted backups age out on the normal backup cycle, currently 14 weeks. A Company may request earlier deletion.
Sign-in records
We record each successful sign-in: who signed in, when, and the general type of device used (for example "iPhone · Safari"). This is a security measure — it lets us see whether an account has been used by someone it does not belong to.
We do not record your IP address, and we do not record or estimate your location. We deliberately chose not to: network routing regularly makes a worker in one town appear to be in another, and we will not hold data that could be used to draw a false conclusion about where someone was.
These records are visible only to HaSafety's platform administrator — not to your employer — and are automatically deleted after 90 days.
Deleting your own account
You can delete your account yourself, at any time, from My status → Your account. Your login and your personal details are removed immediately and you will not be able to sign in again.
Safety records you signed are not deleted. A hazard assessment, inspection or incident report is your employer's record, not ours — they are required to keep it under occupational health and safety law and for their own audits. Your name stays on those records, because a signed safety document that cannot be attributed to anyone is not evidence of anything.
This is permitted under PIPEDA, which allows information to be retained where another law requires it. If you want those records changed or removed, that decision belongs to your employer. Contact them, or write to us and we will pass the request on.
8. Your rights
Depending on your province and role, you may have the right to access, correct, or request deletion of your personal information. Because your employer controls the data, please direct these requests to your Company administrator, who can action most of them directly in HaSafety. We will support the Company in responding.
If you are not satisfied with how a request was handled, you may contact us at the address in section 11, or the Office of the Privacy Commissioner of Canada.
9. Data location
The service runs on Google Cloud infrastructure. Safety records and files are stored in Canada (Google Cloud, Montréal region), and the service's server functions run there too. Three things are processed in the United States: sign-in accounts (Google's Firebase Authentication runs only from US data centres), AI draft generation, and error monitoring. We rely on our providers' safeguards for that cross-border processing.
10. Changes
We may update this policy. Material changes will be communicated to Company administrators, and the effective date above will change.
11. Contact
Questions about this policy or your information:
info@hasafety.ca · Houssein Hassan Daher, carrying on business as "HaSafety", Alberta, Canada. A postal address is available on request.