Legal

Privacy Policy

Last updated: August 6, 2026

A GDPR-based privacy standard
We apply the GDPR principles of transparency, purpose limitation, data minimisation, storage limitation, security and accountability as our baseline. Local law may give you additional rights. Accessing the site from a country does not by itself determine which law applies.

Who we are

This website is operated by Myaser HSE Hub ("we", "us", "our"). Myaser HSE Hub is the controller for the personal data described in this policy. For privacy questions or rights requests, contact [email protected].

What we collect through the contact form

When you submit the contact form, we receive:

  • An optional preferred form of address, which may be a first name, initials or an alias
  • Your email address
  • The topic you selected
  • The message you wrote
  • Your optional consent choice for occasional future communications
  • A small amount of limited technical data, including a submission timestamp and a non-reversible keyed digest derived from network and browser signals, used only to prevent spam and abuse

We do not require a legal or full name. We do not want names or identifying details about injured people, witnesses or other case participants. Do not place that information in the message field.

We do not currently use advertising trackers, analytics scripts or non-essential cookies. Essential hosting and security systems may process network and device data needed to deliver and protect the site.

Account, learning and certificate data

If you create an account, we process your first name, last name, verified email address, password authentication record, optional country, acceptance of the Privacy Policy and Terms, authentication timestamps and security metadata. Supabase Auth stores and verifies the password credential. Myaser HSE Hub does not receive or store your readable password.

For registered learners, we store courses started, completed lessons, the last lesson, completion percentage, assessment attempts and scores, completion date and certificate eligibility. When the completion conditions are met, we store the profile name associated with the verified email account, course, issue date, score, certificate ID and certificate status. Email verification does not independently verify a person's legal identity. A public verification request exposes only the certificate holder's profile name, course title, issue date, certificate ID and validity.

Guest activity may be kept in the browser's local storage. It is not a registered account, is not synchronized to Supabase and does not qualify for a certificate.

What the HSE Guide processes

The HSE Guide is available only to a signed-in user with a verified email address. When you use it, your question, selected jurisdiction, selected purpose, optional industry description and up to 12 recent conversation messages are sent through our Vercel function to the Google Gemini API to generate an answer and, where available, retrieve source links.

The HSE Hub does not write Guide conversations to its database. Conversation text remains in browser memory until you reset the conversation, reload or close the page. We store only a per-account daily request counter for abuse and quota control, and automatically remove those counters after 31 days. Under Google's free Gemini API tier, submitted content and generated responses may be used by Google to improve its products. Do not use the Guide for personal, medical, confidential, privileged or identifiable incident information.

Never submit the name of an injured person, witness or other case participant. Replace people with neutral roles such as “injured worker”, “operator” or “witness A”. Remove medical information, employee numbers, contact details, exact addresses, photographs of identifiable people, confidential investigation material, trade secrets and legally privileged information.

Why we use it

  • Responding to your inquiry — the core reason we collect this data at all.
  • Preventing spam and abuse — limited technical signals help the form reject automated and abusive submissions before they reach us.
  • Optional future communications — only if you actively ticked the consent checkbox, we may send occasional emails about free HSE resources. We do not send these if the box was left unchecked.
  • Generating an HSE Guide response — processing the prompt and selected context is necessary to provide the answer you requested.
  • Providing learner accounts — authenticating users, preserving requested course progress, storing account-owned risk assessments and issuing verifiable certificates.
  • Steps requested by you and legitimate interests — processing your email, optional form of address, topic and message allows us to respond to the inquiry you chose to send.
  • Consent — for the optional future-communications checkbox specifically; you can withdraw this at any time (see "Your rights" below).
  • Legitimate interest — for the limited technical anti-spam data, our legitimate interest is keeping the form usable and free of abuse, balanced against your privacy.
  • Your requested service and legitimate interests — processing HSE Guide prompts provides the answer you requested and supports secure operation and abuse prevention. The Guide is not intended to process special-category, medical or case-identifying data.
  • Contract and requested pre-contract steps — account authentication, saved progress and certificates provide the account service you request. Security, fraud prevention and certificate integrity also support our legitimate interests.

Who else processes this data

We use a small number of third-party services to run this site and deliver your message. We don't sell or share your data for advertising purposes.

  • Resend — transmits the email generated from your contact form submission to our inbox. Resend acts as our email delivery processor for this purpose.
  • Vercel — hosts this website and runs the serverless function that handles the contact form submission.
  • Google Gemini API — processes HSE Guide prompts to generate responses and, where available, provide source-search capabilities. Google's free-tier terms allow submitted content and responses to be used to improve its products.
  • Supabase — provides account authentication and the PostgreSQL database used for profiles, progress, assessment records and certificates.

How long we keep it

  • Ordinary contact inquiries: deleted from the operating mailbox no later than 12 months after the last substantive contact, unless an earlier deletion request applies or continued retention is necessary for a documented legal claim or obligation.
  • Optional communications list: retained until consent is withdrawn or after 24 months without engagement, whichever occurs first. A minimal suppression record may be retained to ensure a person who opted out is not contacted again.
  • HSE Guide in this website: conversation text is held only in browser memory until reset, reload or tab closure. The HSE Hub does not keep a conversation database. Per-account daily request counters are automatically removed after 31 days.
  • Abuse-prevention counters: pseudonymous keyed digests and request counters used to protect login, contact, assessment, certificate and account endpoints are automatically removed after 31 days. The application does not store the raw network address in this table.
  • Google Gemini API: Google controls its own service logs and free-tier product-improvement processing under its published terms and privacy documentation. Do not submit personal or confidential information.
  • Security and hosting logs: retained according to the shortest period available in the applicable provider configuration that remains necessary for security, service delivery and incident investigation.
  • Active learner account: profile, progress, assessment and certificate records are retained while the account remains open so the requested service continues.
  • Account deletion: the production deletion function removes the Supabase Auth user and cascades deletion to the profile, progress, assessment history and certificates. Public certificate verification then stops. Provider backups and security logs may expire later under the provider's documented retention cycle.

We review retained inquiries at least quarterly and delete or anonymise information that is no longer needed. A legal hold temporarily overrides the normal schedule only for information relevant to the specific claim or legal duty.

International processing

Vercel, Resend, Google and Supabase may process data outside your country, including outside the EEA or UK. Where EU or UK data-protection law requires a transfer safeguard, we rely on the provider's applicable data-processing terms and recognised contractual or adequacy safeguards. You may ask us for information about the safeguard relevant to your data. A visitor's country of access does not guarantee that processing occurs in that country.

Your rights

Depending on where you're located, you generally have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your data
  • Restrict how we process it
  • Object to our processing of it
  • Receive portable data where the legal conditions for portability apply
  • Withdraw consent at any time for optional communications
  • Complain to your relevant data protection authority if you believe we've mishandled your data (in the UK, this is the Information Commissioner's Office)

To exercise a right, email [email protected]. We may request proportionate information to verify that the request concerns your data. Under GDPR, we normally respond without undue delay and within one month, subject to lawful extensions. Withdrawing optional consent stops future optional communications. It does not affect the lawful handling of an inquiry already submitted.

Rights in other countries

Privacy laws differ by location and may provide additional rights, such as rights to know, access, correct, delete, opt out of certain disclosures, limit certain uses or appeal a decision. We do not sell personal data, share it for cross-context behavioural advertising or use it for targeted advertising. If a law applicable to your relationship with us grants an additional right, you may exercise it using the same email address. This statement does not claim that every privacy law applies merely because the website can be opened in a country.

Automated decisions

The HSE Guide generates educational text, but it does not make legal or similarly significant decisions about individuals. Do not use its output to decide employment, discipline, medical treatment, insurance, legal liability or access to services.

Security and data minimisation

We limit submitted fields, cap request sizes, use encrypted HTTPS connections, restrict processor access through service credentials, apply abuse controls and avoid a chatbot conversation database. No online service can promise absolute security. If we become aware of a personal-data breach, we will assess and notify affected people and authorities where applicable law requires it.

Children

The site is intended for professionals and higher-education learners, not children. We do not knowingly request personal data from children. If you believe a child submitted personal information, contact us so we can assess and delete it.

Not for confidential or emergency information

The contact form and HSE Guide are general educational and inquiry channels. Do not use them for names of case participants, confidential records, medical information, emergencies or highly sensitive information. If you have a genuine emergency, contact local emergency services and responsible site personnel directly.

This site links to external sources — including news articles we aggregate and reference — that are operated independently of us. Once you leave our site, that external site's own privacy practices apply, not this policy.

Changes to this policy

We review this policy when data practices, providers or applicable requirements materially change. The “Last updated” date identifies the current version. Material changes will be presented prominently where appropriate.