POPIA-aligned ยท Last updated: 1 June 2026
Template notice: review with your Information Officer / counsel before go-live.
SecurityHub processes personal information in line with the Protection of Personal Information Act, 2013 (POPIA). Each tenant organisation is the responsible party for the personal information it captures; SecurityHub acts as an operator on its behalf.
Account details (name, email, phone), authentication data, and the operational data you enter (clients, sites, guards, PSIRA registrations, shifts, invoices, etc.). Guard biometric/photo data is captured only where you choose to use those features.
To provide and secure the Service, to bill you, to meet legal/regulatory obligations (including PSIRA-related record-keeping you operate), and to support you.
Data is logically isolated per tenant, transmitted over TLS, passwords are hashed (BCrypt), and privileged access supports two-factor authentication. Access is logged.
You may request access to, correction of, or deletion of personal information. Organisation administrators can export their tenant's data at any time from Company Settings โ Your data (POPIA export). Individuals should direct requests to the responsible tenant organisation.
We retain data for as long as your account is active or as required by law. On termination, data may be deleted after a reasonable export window.
We do not sell personal information. We share it only with sub-processors needed to run the Service, and only as instructed by the responsible tenant.
Direct privacy queries to your tenant's Information Officer, or the platform administrator for platform-level matters.