Skip to content

Approaching: Nov 20, 2026 — HCS 2024 Deadline. Get ready →

Legal

Privacy Policy

How HazComFast collects, uses, stores, and protects information across our website and platform.

Effective Date: September 25, 2026

HazComFast ("we," "our," or "the Company") is committed to protecting your privacy and maintaining the security of your information. This Privacy Policy explains how we collect, use, store, protect, and share information when you use our website and software platform (collectively, the "Platform"). This policy applies to all users of HazComFast, including visitors to our website, trial users, and paid subscribers. By accessing or using our Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy in conjunction with our Terms of Service. If you do not agree with this Privacy Policy, please discontinue use of our Platform immediately.

HazComFast is operated as an independent software service. We act as the data processor for customer data entered into the Platform. Our customers (organizations and businesses) remain the data controllers and are responsible for ensuring their data collection and processing practices comply with applicable laws. For privacy-related questions, please contact: Email: support@hazcomfast.com

Account Information

When you create an account, we collect your name, email address, company name, job title, phone number (optional), and billing information. Payment details are securely processed by Paddle.com and are not stored on our servers.

Operational Safety Data

Information entered by customers including chemical inventories, Safety Data Sheets (SDS), hazard assessments, job safety analyses, workplace inspections, and compliance documentation. This data is stored in the United States and remains the property of the customer.

Employee and Training Records

Limited employee information such as names, employee IDs, training completion dates, certification records, and acknowledgment signatures required for OSHA compliance tracking and safety program management.

Incident and Injury Data

Information about workplace incidents, near-misses, injuries, and illnesses as required for OSHA 300 Log recordkeeping. Customers are the data controller for this information and remain responsible for compliance with OSHA privacy requirements under 29 CFR 1904.29(b)(6) and 29 CFR 1904.35.

Usage and Analytics Data

We automatically collect information about how you use the Platform, including IP addresses, browser types, device information, pages visited, features used, time spent on pages, and referring URLs. This helps us improve our services and user experience.

Cookies and Tracking Technologies

This website uses Google Analytics 4 to count visits: the pages viewed, the device and browser type, and the approximate region. It sets the _ga cookie for that purpose. The site runs no advertising, and Google receives no advertising signal from it. The checkout page loads Paddle.js, with its ProfitWell script, to process payments. You can block or delete cookies in your browser settings, or install Google's opt-out add-on (https://tools.google.com/dlpage/gaoptout). The site does not change its behavior in response to a browser's Do Not Track signal.

Communications

When you contact our support team, we collect the contents of your messages, attachments, and related metadata to provide assistance and improve our services.

We use collected information for the following purposes: • Providing and maintaining the Platform and its features • Processing transactions and managing subscriptions • Sending important service updates, security alerts, and administrative messages • Providing customer support and responding to inquiries • Improving and optimizing the Platform through usage analysis • Detecting, preventing, and addressing technical issues and security threats • Complying with legal obligations and enforcing our Terms of Service • Developing new features and services based on user needs We process personal information based on the following legal grounds: contract performance, legitimate interests, legal compliance, and consent (where applicable).

Customer data is processed and stored in the United States: our database and file storage run in the us-east-1 region and our application servers in the Washington, D.C. area (iad1), on the infrastructure of our cloud service providers. Transactional e-mail is sent from a US region as well. If we ever move a component outside the United States, we will update this policy before doing so. We work with these service providers: • Vercel (website and application hosting) • Supabase (database, file storage and sign-in) • Google Analytics 4 (website visit statistics) • Paddle.com (billing and payments)

We employ comprehensive technical and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction: • TLS 1.2+ encryption for data in transit • Two-factor authentication, which an admin can require for the whole team • Secure authentication mechanisms with password requirements • Each company sees only its own records While we implement robust security measures, no system is completely secure. We encourage users to maintain strong passwords and protect their account credentials.

We share information only in the following limited circumstances: Service Providers: We share information with the vendors who perform services on our behalf (hosting, analytics, payment processing), named in section 5. Legal Requirements: We may disclose information when required by law, legal process, litigation, or government requests, or to protect our rights, property, safety, or the rights of others. Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets, customer information may be transferred. We will notify affected users of any such change in ownership or data control. With Your Consent: We may share information with third parties when you explicitly consent to such sharing.

We retain your information for as long as necessary to provide our services and fulfill the purposes outlined in this Privacy Policy: • Account information is retained for the duration of your active subscription • Safety and compliance documents are kept under a retention period set for each record type, up to 30 years for exposure records, and a document under a retention period or a legal hold cannot be deleted • You can export every record and document at any time, on every plan When a subscription is cancelled, the account switches to read-only for 90 days: your records stay visible and the export keeps working, so you leave with everything. After that, or at any time, write to support@hazcomfast.com to have your information deleted, subject to our legal obligations.

Depending on your location, you may have certain rights regarding your personal information: Access: Request copies of your personal information Correction: Update or correct inaccurate information Deletion: Request deletion of your information (subject to legal requirements) Portability: Receive your data in a portable format Objection: Object to certain processing activities Restriction: Request limited processing of your information Withdraw Consent: Withdraw previously given consent To exercise these rights, contact us at support@hazcomfast.com. Some requests may require identity verification to protect your security. You can also: • Update account information through your profile settings • Turn on two-factor authentication in your account settings • Adjust cookie preferences through browser settings

HazComFast is designed for use by businesses and workplace safety professionals. Our Platform is not intended for children under 16 years of age, and we do not knowingly collect personal information from children. If we become aware that we have collected information from a child under 16 without parental consent, we will take steps to delete such information promptly. If you believe we have collected information from a child, please contact us immediately at support@hazcomfast.com.

HazComFast serves businesses in the United States. Your information is stored and processed in the United States, as described in section 5.

We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or business operations. The "Effective Date" at the top of this policy indicates when it was last revised. For material changes that significantly affect your rights or how we handle information, we will: • Post a prominent notice on our website • Send email notifications to registered users • Provide at least 30 days' notice before changes take effect Continued use of the Platform after policy updates constitutes acceptance of the revised terms. We encourage you to review this policy periodically to stay informed about how we protect your information.

Customers using HazComFast for OSHA compliance remain responsible, as data controllers, for their own compliance with workplace safety and privacy regulations, including the OSHA recordkeeping privacy rules (29 CFR 1904.29).

Related: Terms of Service · Refund Policy