Privacy Policy
Last Updated: 16 August 2025
1. Introduction
Welcome to Has App Ltd (“we”, “us”, or “our”). We are committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Health and Safety software and training services, including The Health & Safety App (the "App") and our IOSH-approved workshops (the "Services").
By using our Services, you agree to the collection and use of information in accordance with this policy.
2. Data We Collect
We collect personal data to provide and improve our Services. The types of data we collect depend on how you interact with us:
A. Users of The Health & Safety App:
- Account Information: Name, email address, company name, and password when you create an account.
- Usage Data: Information on how you use the App, such as features accessed, forms completed, and time spent on the platform. This helps us improve functionality.
- Device Information: We may collect information about the device you use to access the App, including the hardware model, operating system, and unique device identifiers.
- Client Data: Any information you voluntarily input into the app, such as risk assessments, audit details, and accident reports.
B. Workshop Participants:
- Registration Information: Name, job title, company, email address, and phone number to register you for a workshop.
- Participation Details: Records of your attendance, course progress, and assessment results for administration and certification.
3. How We Use Your Data
We use the data we collect for the following purposes:
- To Provide and Improve Our Services: We use your data to operate the App, manage workshops, and continually enhance the user experience and functionality of our offerings.
- Workshop Administration: We use participant data to manage workshop logistics, send course materials, communicate updates, and issue certifications upon successful completion.
- IOSH Partnership: As an approved IOSH provider, we are required to share workshop participant data with IOSH for the sole purpose of workshop administration, quality assurance, and certification.
- Communication: To send you service-related announcements, marketing communications (where you have opted-in), and respond to your inquiries.
4. Data Sharing and Disclosure
We do not sell your personal data. We only share it in the following circumstances:
- With IOSH: We share necessary workshop participant data with IOSH as required for their administration and certification processes.
- With Third-Party Service Providers: We may engage third-party companies to perform services on our behalf, such as payment processing, cloud hosting, email marketing, or data analytics. These providers are contractually obligated to protect your data and are not permitted to use it for their own purposes.
- For Legal Reasons: We may disclose your information if required by law or in response to valid requests by public authorities (e.g., a court or a government agency).
5. Data Security
We implement robust technical and organizational security measures to protect your personal data from unauthorized access, use, or disclosure. These measures include:
- Encryption: We encrypt sensitive data both in transit (using TLS/SSL) and at rest.
- Access Controls: We enforce strict access controls, ensuring that only authorized personnel with a legitimate business need can access personal data.
- Regular Security Reviews: We regularly review and update our security protocols and infrastructure to protect against emerging threats.
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected.
- For Workshop Participants: We retain data for a reasonable period after workshop completion to handle any certification inquiries and for our administrative records, in line with IOSH requirements.
- For App Users: We retain your data as long as your account is active or as needed to provide you with our services. We may also retain data to comply with legal obligations or resolve disputes.
7. Your Data Protection Rights
Under data protection law, you have rights we need to make you aware of. The rights available to you depend on our reason for processing your information.
- Right to Access: You have the right to request copies of your personal data.
- Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- Right to Erasure: You have the right to request that we erase your personal data, under certain conditions.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
To exercise any of these rights, please contact us at the email address below.
8. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:
HAS APP LTD
Email: info@hasapp.co.uk
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date.
This policy serves as a foundation for your privacy practices. It is important to ensure full compliance with all relevant data protection regulations, such as GDPR or CCPA. Consultation with a legal expert is recommended.