eSHEQ COMPLY Back to website
Legal & Privacy

Privacy Policy

This Privacy Policy explains how eSHEQ Comply handles personal and device information across the eSHEQ Comply website, web platform and mobile application.

Effective: 9 September 2026 Last updated: 9 September 2026 App: eSHEQ Comply
eSHEQ Comply does not sell personal information. Information is processed to provide, secure, support and improve the eSHEQ Comply service, and to support legitimate safety, health, environmental, quality and compliance activities.

1. Scope and responsibility

This Privacy Policy applies to eSHEQ Comply, including the public website, web-based platform and Android mobile application. eSHEQ Comply provides software used by organisations to manage SHEQ, QHSE and EHS compliance records and workflows.

In many cases, an organisation using eSHEQ Comply determines which employee, contractor, supplier and operational information is entered into the platform. That organisation remains responsible for ensuring that it has a lawful basis and appropriate authority to capture and use that information.

2. Information we access, collect or process

The information processed depends on the modules and features used by your organisation. It may include:

Account and profile information Name, surname, email address, company, role, permissions, login details and account identifiers.
Employee and contractor records Employment, contractor, training, competency, appointment, induction, PPE, permit, licence and related compliance information entered by authorised users.
SHEQ and operational records Audits, inspections, incidents, near misses, non-conformances, risk assessments, corrective actions, findings, safety files, asset/fleet records and related evidence.
Files, photos and signatures Documents, certificates, images, attachments, photographs and signatures that users choose to capture or upload as supporting evidence.
Notifications and device information Device or push-notification tokens and basic app/device information needed to deliver notifications, maintain compatibility and support app functionality.
Technical and security information IP address, timestamps, request information, browser or device type, application logs, error information and security/audit events used to operate and protect the service.

eSHEQ Comply may also temporarily store selected information on a user's device where required for offline functionality, caching, pending uploads or improved app performance. Such data is used only for application functionality and synchronisation.

3. How we use information

We process information for purposes including:

  • creating and managing authorised user accounts and access permissions;
  • providing inspections, incidents, audits, training, document control, risk, contractor and other compliance functions;
  • storing and displaying records, evidence, attachments, photos and signatures submitted by authorised users;
  • generating reports, dashboards, reminders, alerts and compliance notifications;
  • synchronising information between the mobile app and the eSHEQ Comply platform;
  • providing customer support and resolving technical issues;
  • protecting accounts, detecting abuse, preventing unauthorised access and maintaining audit/security logs;
  • maintaining, troubleshooting and improving the reliability and performance of the service; and
  • meeting applicable legal, contractual, security and regulatory obligations.

4. Mobile app permissions and device access

The eSHEQ Comply mobile app may request access to device features only when required for a feature being used.

  • Camera / photos / files: used when a user chooses to capture, select or upload supporting evidence, documents or images.
  • Notifications: used to deliver operational alerts, reminders, assigned actions and other eSHEQ Comply notifications.
  • Device storage / local app storage: may be used for caching, offline access, pending uploads and synchronisation.
  • Network access: used to authenticate users, synchronise records, upload/download authorised files and communicate with eSHEQ Comply services.

The app does not use device access for unrelated purposes. Where Android provides a permission control, users can manage that permission through their device settings, although disabling a required permission may prevent the related feature from working.

5. When information may be shared

eSHEQ Comply does not sell personal information. Information may be made available only where necessary for operation of the service or as authorised or required, including:

  • Your organisation and its authorised users: information entered into an organisation's eSHEQ Comply environment may be available to authorised administrators, managers or other users according to configured roles and permissions.
  • Technology and infrastructure providers: trusted service providers may process limited information on our behalf to provide hosting, cloud storage, file delivery, email, system security, diagnostics or push-notification delivery. This may include cloud infrastructure services and Google services used for Android push notifications.
  • Legal or safety requirements: information may be disclosed where required by applicable law, a valid legal process, regulatory obligation, or where reasonably necessary to protect the security, rights or safety of users, organisations or the service.
  • Business administration: information may be processed by authorised personnel who require access to provide implementation, support, maintenance or account administration.

Service providers are expected to use information only for the services they provide and subject to appropriate confidentiality, security and data-protection obligations.

6. Security and protection of information

eSHEQ Comply uses technical and organisational safeguards designed to protect information against unauthorised access, loss, misuse, alteration or disclosure. These safeguards may include authentication, role-based access controls, permission restrictions, secure web connections, system monitoring, audit/security logging, controlled file access and infrastructure security measures.

No internet or electronic storage system can eliminate all risk. Users must keep login credentials confidential, use authorised devices and promptly report suspected account compromise or unauthorised access.

7. Data retention and deletion

Information is retained only for as long as reasonably necessary to provide the service, maintain authorised business and compliance records, support security and audit requirements, resolve disputes, meet contractual obligations and comply with applicable laws.

Because eSHEQ Comply is used for workplace and regulatory compliance, some records may need to be retained by the customer's organisation for legally required or operational retention periods.

Where deletion is permitted, authorised users may request deletion or correction through their organisation's eSHEQ Comply administrator or by contacting eSHEQ Comply. When a valid deletion request applies to information under our control, we will delete or de-identify the relevant information within a reasonable period, except where retention is required by law, necessary for security, fraud prevention, dispute resolution or another lawful obligation.

Cached or temporary data stored by the mobile app may also be removed by signing out, clearing application storage or uninstalling the app, subject to device behaviour and any records that have already synchronised to the organisation's eSHEQ Comply environment.

8. Your privacy rights

Depending on applicable law and your relationship with the organisation using eSHEQ Comply, you may have rights to request access to, correction of, deletion of, restriction of, or information about the processing of your personal information.

If your information was entered by your employer, contractor, client or another organisation, requests should normally first be directed to that organisation because it may control the relevant record and determine applicable legal retention requirements. You may also contact eSHEQ Comply using the details below for privacy-related enquiries.

9. International processing and service providers

eSHEQ Comply may use technology providers or infrastructure that process or store information in locations outside the user's country. Where cross-border processing occurs, reasonable measures are used to protect information and to support applicable data-protection requirements.

10. Children's privacy

eSHEQ Comply is a business and workplace compliance platform and is not designed or marketed as a service for children. Organisations using eSHEQ Comply must ensure that any information they enter is collected and processed lawfully and is appropriate for their workplace and regulatory obligations.

11. Website and contact form submissions

When you submit a form on the eSHEQ Comply website, we process the information you provide, such as your name, business email address, subject and message, in order to respond to your enquiry.

For security and abuse-prevention purposes, we may also log technical information related to the submission, including IP address, submission time, browser/device information and an approximate country or region indicator. In some cases, a third-party IP geolocation service may be used to estimate the general location associated with an IP address. This information is used to protect our systems, identify suspicious activity and reduce spam or fraudulent submissions.

We retain this technical information only for as long as reasonably necessary for security, support and operational purposes.

12. Changes to this Privacy Policy

We may update this Privacy Policy when the eSHEQ Comply service, mobile application, legal requirements or data-handling practices change. The current version will be published at this URL with an updated effective or last-updated date.

13. Privacy contact

eSHEQ Comply
Privacy and data-protection enquiries

Contact us through the official eSHEQ Comply website:
https://esheqcomply.com/#contact

Phone / WhatsApp:
+27 67 408 3030