โ† Back to SecurityHub

Privacy Policy

POPIA-aligned ยท Last updated: 1 June 2026

Template notice: review with your Information Officer / counsel before go-live.

1. Who we are

SecurityHub processes personal information in line with the Protection of Personal Information Act, 2013 (POPIA). Each tenant organisation is the responsible party for the personal information it captures; SecurityHub acts as an operator on its behalf.

2. What we process

Account details (name, email, phone), authentication data, and the operational data you enter (clients, sites, guards, PSIRA registrations, shifts, invoices, etc.). Guard biometric/photo data is captured only where you choose to use those features.

3. Why we process it

To provide and secure the Service, to bill you, to meet legal/regulatory obligations (including PSIRA-related record-keeping you operate), and to support you.

4. Security

Data is logically isolated per tenant, transmitted over TLS, passwords are hashed (BCrypt), and privileged access supports two-factor authentication. Access is logged.

5. Your rights (data subjects)

You may request access to, correction of, or deletion of personal information. Organisation administrators can export their tenant's data at any time from Company Settings โ†’ Your data (POPIA export). Individuals should direct requests to the responsible tenant organisation.

6. Retention

We retain data for as long as your account is active or as required by law. On termination, data may be deleted after a reasonable export window.

7. Sharing

We do not sell personal information. We share it only with sub-processors needed to run the Service, and only as instructed by the responsible tenant.

8. Contact

Direct privacy queries to your tenant's Information Officer, or the platform administrator for platform-level matters.