1. Purpose and Scope
This Privacy Policy explains how HES SPACE operating under the HES Space brand ("HES SPACE," "we," "us," or "our"), collects, uses, stores, protects, discloses, and otherwise processes Personal Information in connection with the HES SPACE website, administrative portal, mobile application, and related services (collectively, the "Platform").
HES SPACE is a B2B SaaS platform designed to support occupational health and safety management, including employees, locations, documents, electronic acknowledgements and signatures, training and certificates, the Training Matrix, incidents, Safety Opportunities, Daily Hazard Assessments, Toolbox Talks, inspections, audits, observations, corrective actions, reporting, and related processes.
This Policy applies to Personal Information processed by HES SPACE in providing the Platform. Individual Customers may also maintain their own privacy notices or internal policies governing the Personal Information of their employees and other users.
2. Roles of HES Space, the Customer, and Users
2.1. Business Accounts
HES SPACE is primarily provided to organizations ("Customers"). If your HES SPACE account is created or provided by your employer or another organization, that organization may administer the account and, subject to its authority and applicable law, view, create, modify, export, retain, or delete records associated with it.
Access within the Platform is determined by roles, permissions, departments, locations, and other settings configured by the Customer. Company Admins, health and safety personnel, managers, supervisors, and other authorized persons may have different levels of access.
2.2. Customer-Managed Data
For information entered, uploaded, or created in the Platform by a Customer or its users for the Customer's business processes ("Customer-Managed Data"), HES Space generally processes that information on behalf of and in accordance with the Customer's instructions, the agreement with the Customer, this Policy, and applicable law.
The Customer is responsible for ensuring that it has the appropriate authority, notices, consents, or other lawful basis to collect and use Personal Information that it provides to HES Space.
2.3. Information Managed Directly by HES SPACE
HES SPACE may independently determine the purposes for processing certain information required to operate its own service and business, such as business account data, billing and contact information, support communications, security logs, service analytics, and information concerning use of the HES SPACE website.
3. Information We Process
3.1. Customer Account Data
- name and business contact details of Customer representatives;
- company name, job title, department, and role;
- subscription, invoicing, and payment information, where applicable;
- support requests and business communications.
3.2. User and Employee Data
- name, email address, telephone number, and employee ID;
- job title, employment type, department, location, and supervisor or manager;
- system role, permissions, account status, and other profile information.
3.3. Health & Safety and Incident Information
Depending on the modules used by a Customer, the Platform may contain Daily Hazard Assessments, Toolbox Talks, inspections, audits, observations, Safety Opportunities, hazards, near misses, corrective actions, incident reports, witness information, investigation records, injury details, injured body parts, treatment information, return-to-work-related information, comments, photographs, videos, and attachments.
Some of this information, including injury or health information, may be sensitive. Customers and Users should enter only information reasonably necessary for the relevant health and safety, compliance, or business process.
3.4. Training and Certification Data
- training assignments, course progress, quiz results, and completion status;
- certificates, certificate numbers, issue and expiry dates, and uploaded certificates;
- Training Matrix information, renewal status, and other competency or compliance information.
3.5. Documents and Electronic Acknowledgements
- documents and files uploaded by the Customer;
- Users assigned to review or sign a document;
- acknowledgement or signature status, signer name, date, and time;
- document version and related audit-trail records.
3.6. Technical and System Data
- IP address, browser, device type, operating system, and application version;
- login and session information, timestamps, error and crash logs, and security events;
- information about interaction with the Platform that is necessary for operation, support, security, and service improvement.
3.7. Activity and Audit Logs
HES Space may maintain activity logs relating to account access and actions performed within the Platform, including the creation or modification of records, administrative changes, document acknowledgements and signatures, training activity, and other relevant system events. These records may be used for security, troubleshooting, accountability, audit, compliance, and dispute resolution.
3.8. Photos, Videos, Files, and Metadata
Files uploaded to the Platform may contain embedded metadata, including creation date, device information, or location information. Users should avoid uploading unnecessary Personal Information or geolocation information that is not required for the relevant purpose.
3.9. Location Data
HES Space does not collect precise device location unless a specific Platform feature requires location access and that functionality has been appropriately enabled. If HES Space introduces features that use precise location information, appropriate notice and, where required, consent will be provided before or at the time of collection.
4. How We Obtain Information
- directly from a User when the User interacts with the Platform;
- from the Customer when a Company Admin or other authorized person creates an account, imports employee data, uploads documents or certificates, or assigns roles, locations, or training;
- automatically through use of the Platform;
- through authorized integrations and service providers, where applicable.
5. How We Use Personal Information
- creating, authenticating, supporting, and administering accounts;
- managing employees, roles, departments, and locations;
- supporting incident reporting, inspections, audits, DHAs, Toolbox Talks, observations, and corrective actions;
- managing training, certificates, renewals, and the Training Matrix;
- managing documents, acknowledgements, signatures, and audit trails;
- sending service notifications, account activation and password-reset communications, training and certificate reminders, and documents requiring action;
- generating PDFs, dashboards, reports, and other Customer-requested functionality;
- providing customer support, troubleshooting, monitoring service performance, and improving the product;
- protecting the Platform and preventing unauthorized access, fraud, misuse, and security incidents;
- performing contractual and legal obligations, resolving disputes, and protecting legal rights.
We seek not to use Personal Information for a materially new and incompatible purpose without an appropriate lawful basis and, where required, additional notice or consent.
6. Required Information
Certain Personal Information may be required to create an account or use particular HES Space functions. If required information is not provided, the relevant function may not be available. For example, an email address may be required for account activation or password recovery, while certain employee details may be required to assign training, certificates, documents, or other records.
7. Consent and Other Lawful Bases
Where applicable law requires consent, HES Space or the relevant Customer will seek a form of consent appropriate to the nature and sensitivity of the information, the purpose of processing, and the reasonable expectations of the individual. More explicit consent may be required for sensitive information.
In some circumstances, processing may be permitted or required without consent, including to perform an agreement, comply with a legal obligation, protect security, or in other circumstances permitted by law.
8. How We Disclose Personal Information
8.1. Customers and Authorized Users
Information may be accessible to the Customer and its Authorized Users according to the roles, permissions, and organizational structure configured by the Customer.
8.2. Service Providers and Subprocessors
HES Space may use service providers for hosting, data storage, email delivery, authentication, notifications, analytics, monitoring, customer support, payment processing, cybersecurity, and other functions required to provide the Platform.
We seek to limit service-provider access to what is necessary for the relevant function and to use appropriate contractual, confidentiality, and security safeguards.
8.3. Legal Requirements and Protection of Rights
We may disclose information where required or permitted by law, including to respond to a lawful court or governmental request, comply with regulatory requirements, investigate fraud or security issues, or protect the rights, property, or safety of HES Space, Customers, Users, or others.
8.4. Business Transactions
If HES Space is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar corporate transaction, Personal Information may be disclosed or transferred as part of that transaction, subject to applicable law and appropriate confidentiality safeguards.
8.5. Sale of Personal Information
HES Space does not sell Personal Information for monetary consideration. If our practices materially change, this Policy and any required privacy controls will be updated in accordance with applicable law.
9. International Data Transfers
Some service providers may process or store information outside the province or outside Canada. In those circumstances, information may be accessible to competent authorities under the laws of the jurisdiction in which it is processed.
HES Space seeks to apply appropriate contractual, organizational, and technical safeguards to cross-border processing in accordance with applicable law.
10. Data Retention and Deletion
HES Space retains Personal Information only for as long as reasonably necessary for the identified purposes, provision of the Platform, performance of agreements, legitimate business needs, and applicable legal or regulatory requirements.
Retention periods may differ for account records, training records, certificates, incident reports, signed documents, inspections, audit trails, security logs, and billing records. HES Space may establish separate retention schedules, and retention of Customer-Managed Data may also depend on the Customer's lawful instructions.
Deactivating or removing a User's access does not necessarily result in the immediate deletion of all related records.
10.1. When Deletion May Be Restricted
HES Space or the Customer may be unable to delete certain information where retention is reasonably necessary to:
- comply with legal or regulatory obligations;
- maintain occupational health and safety, training, and competency records;
- preserve signed documents, acknowledgements, and audit trails;
- maintain incident, investigation, inspection, or audit records;
- support security, fraud prevention, debugging, or system integrity;
- establish, exercise, or defend legal claims;
- resolve disputes or enforce agreements;
- support other lawful recordkeeping purposes.
After the applicable retention period expires, information should be deleted, securely destroyed, or, where appropriate, de-identified in accordance with applicable procedures.
11. Security and Confidentiality
HES Space applies or seeks to apply reasonable administrative, technical, and organizational safeguards proportionate to the nature, volume, and sensitivity of the information and the relevant risks.
These measures may include role-based access controls, authentication, secure communications, logging, monitoring, backup and recovery measures, controlled administrative access, and other appropriate safeguards.
Access to Personal Information by HES Space personnel and service providers should be limited to persons who reasonably require access to perform their duties and may be subject to confidentiality and security obligations.
No system can guarantee absolute security. HES Space does not warrant that a security incident or unauthorized access will never occur.
12. Privacy and Security Breaches
If HES Space becomes aware of a breach of security safeguards, we assess the nature of the information, the circumstances of the event, the likelihood of misuse, and the potential risk to individuals. Where applicable law requires notification to a regulator, Customer, affected individual, or another party, HES Space will take the required steps within the applicable timeframe.
HES Space may maintain records of privacy and security breaches in accordance with applicable legal requirements and internal incident-management procedures.
13. Notifications and Communications
HES Space may send operational or service-related communications necessary to operate the Platform, including account activation, email verification, password reset, security alerts, training assignments, certificate-expiry reminders, documents requiring review or signature, assigned forms, and system notices.
For these processes, HES Space may process email addresses, account identifiers, security tokens, and related technical information.
Marketing communications, if used, will be managed with appropriate consent and opt-out mechanisms as required by applicable law. Opting out of marketing communications does not necessarily stop service or security notices.
14. Cookies and Similar Technologies
The HES Space website and web application may use cookies and similar technologies. Depending on the actual configuration, these may include:
- Essential Cookies — authentication, session management, and security;
- Preference Cookies — language, display, and remembered settings;
- Analytics Cookies — understanding service use and performance, where such tools are enabled.
Disabling essential cookies may prevent login or other authenticated functions from operating correctly. Where consent is required for non-essential cookies, HES Space will provide an appropriate mechanism.
15. Third-Party Content, Links, and Integrations
The Platform may contain links, integrations, or embedded content provided by third parties, including training materials or other services. Those third parties may process information under their own privacy practices. HES Space does not control the independent privacy practices of third parties.
This section applies only to third-party features and integrations actually made available through the Platform.
16. Aggregated and De-identified Data
HES Space may create and use aggregated or de-identified information for product analytics, performance analysis, security, benchmarking, feature development, and improvement of the user experience, provided that such information is not used to identify a specific individual in a manner prohibited by law.
17. Individual Privacy Rights
Depending on applicable law, an individual may have the right to ask whether their Personal Information is being processed, request access to it, request correction of inaccuracies, and, in certain circumstances, request deletion, a copy of the information, or other actions provided by law.
17.1. Identity Verification
Before fulfilling a request for access, correction, export, or deletion, HES Space or the applicable Customer may take reasonable steps to verify the identity and authority of the requester and may request additional information reasonably necessary to locate the relevant records.
17.2. Employee Requests Concerning Customer-Managed Data
Where a request concerns information controlled by an employer or other Customer, HES Space may direct the requester to that Customer or act on the Customer's lawful instructions. This may apply to employee records, certificates, training, incidents, documents, and other Customer-Managed Data.
17.3. Limitations
Privacy rights are not absolute. Access, correction, export, or deletion may be restricted where permitted or required by law, necessary to protect the rights of others, or inconsistent with the proper retention of legal, compliance, security, or occupational health and safety records.
18. Children's Privacy
HES Space is an enterprise platform and is not intended for use by children as a consumer service. We do not seek to knowingly collect children's Personal Information without a lawful basis and any required authorization. If we become aware that such information has been provided unlawfully, we may take steps to delete it or restrict its processing.
19. Changes to This Privacy Policy
We may update this Policy to reflect changes to the Platform, service providers, business practices, or applicable law. The current version should identify its version number and Effective Date.
If changes are material, HES Space may provide more prominent notice through the Platform, email, or another appropriate channel. If a new practice requires additional consent, consent will be obtained where required by law.
HES Space may retain previous versions of this Policy for audit and transparency purposes.
20. Privacy Governance and Complaints
HES Space designates an individual or role responsible for privacy compliance. Users may contact us with questions, requests concerning access or correction, or complaints regarding our privacy practices.
We seek to review privacy inquiries and complaints within a reasonable period and in accordance with applicable law.
21. Applicable Privacy Laws
HES Space processes Personal Information in accordance with privacy laws applicable to the particular activity, information, organization, and jurisdiction. In Canada, this may include the Personal Information Protection and Electronic Documents Act (PIPEDA) and other applicable federal or provincial privacy requirements.
The application of a particular privacy law, including to employee information, depends on the jurisdiction, nature of the organization, and circumstances of the processing. This Policy should not be interpreted as stating that the same privacy statute applies to every Customer or every type of employee record.
22. Version History
Version 1.0 — Effective Date 12.08.2026 — Initial Privacy Policy.