Legal

Privacy Policy

Updated Sep 26, 2026Version 6

Privacy Policy

Effective Date: 2026-09-26 Version: 6 (beta) Jurisdictions covered: Canada (federal + BC, AB, ON, QC) and United States (federal + CA, VA, CO, CT, UT)

Note

This Privacy Policy is published in beta mode and may change before general availability. See Section 1 for details. For questions, contact privacy@hrdhat.site.


1. Beta Notice

HrdHat is currently offered in beta. This Privacy Policy is provided as-is and may change before general availability. Material changes will be communicated under Section 17 before they take effect. If you do not agree to use a beta service under these conditions, do not create an account.


2. Who We Are & How To Reach Us

HrdHat (operated by Pawel Mniszak as a sole proprietor) operates hrdhat.site and the HrdHat platform. Incorporation as HrdHat Inc. is planned; this Policy will be updated upon incorporation.

  • Privacy contact: privacy@hrdhat.site
  • Mailing: HrdHat c/o Pawel Mniszak, British Columbia, Canada (physical address to be listed here when finalized)
  • Privacy Officer: Pawel Mniszak serves as HrdHat's designated Privacy Officer under Quebec Law 25 section 3.1. For Quebec Law 25 inquiries, contact privacy@hrdhat.site.

3. Scope of This Policy

This Privacy Policy explains how HrdHat collects, uses, shares, and protects personal information when you:

  • Create an account on hrdhat.site or in the HrdHat mobile app (if released)
  • Use HrdHat's features (shifts, forms, timesheets, dispatch, inbox)
  • Interact with our marketing site, support channels, or transactional emails

This Policy does not cover:

  • Your employer's handling of information once it enters their Company Starter account (your employer is a separate data controller for that data — see Section 6.1 and our Company Data Processing Agreement)
  • Third-party websites linked from HrdHat

4. Information We Collect

4.1 Information You Give Us

When you create an account, we collect:

  • Email address (required for login + notifications)
  • Full name (used on forms and passport)
  • Password (stored as a bcrypt hash — we never see your plaintext password)
  • Acceptance record of the Terms of Use and Privacy Policy, with timestamp and version

When you fill out your profile, you may also provide:

  • Phone number, mailing address, trade, years of experience, certifications, work history, gear inventory, profile photo

When you use the service, you create:

  • Form submissions (FLRAs, toolbox talks, inspections, etc.) including photos and signatures you capture, and any details you give an AI feature such as Scan with AI (where you are, the tasks you picked, your trade)
  • Hazard records derived from each FLRA you complete: every task, hazard and control row you confirmed, tagged with your trade, the type of site, whether the row came from you or from an AI draft, and what you did with it (see Section 5a.2)
  • Timesheets and shift records
  • Messages in your inbox

When you subscribe to a paid plan, Stripe (our payment processor) collects your payment information. HrdHat does not see or store your card number, CVV, or bank details — we only receive a token from Stripe identifying your subscription.

4.2 Information Collected Automatically

We separate automatically-collected information into two tiers based on the legal basis and your choice.

Essential — always collected:

  • Device & browser info (browser type, OS, screen size, timezone)
  • IP address — used for security, fraud prevention, and approximate location
  • Essential cookies — authentication session (without these you cannot stay logged in)
  • Error events — when the application crashes or throws an uncaught error, we collect the error type, stack trace, and minimal context (user ID, URL path) via our error monitoring provider, Sentry. Error events do not include safety-form content, photos, signatures, messages, or other user-generated content. We collect essential errors under a "reasonable business purpose" / "service-provider" basis; this collection is necessary to keep HrdHat secure and functioning for every user.

Optional — collected only with your opt-in consent (Settings → Privacy):

  • Detailed analytics: session-interaction recordings on non-sensitive pages (via Sentry replay), page-load performance metrics (via Vercel Speed Insights), and aggregated usage patterns. Default OFF. See Section 5a.
  • Help improve Scan with AI: use of the tasks, hazards and controls you confirm on completed forms, without your name or project, to improve AI drafts for other users. Default OFF. See Section 5a.2.

Regardless of your consent setting, the following pages are excluded from all session-replay recording because they contain sensitive data that cannot be sent to our session-replay provider under our agreement with Sentry:

  • /dashboard/forms/* (all form workspaces)
  • /dashboard/timesheet/* and /shift/*
  • /fall-protection/* and /gear/*
  • /dashboard/dispatch/* and /dashboard/inbox/*
  • Any page displaying an electronic signature

4.3 Location Information

If your account includes features that use location (for example, Network Hub map pins), your approximate location may be visible to other HrdHat users. We fuzz precise coordinates to approximately 1 km before exposing them to others. You can disable location features from your profile.

We do not continuously track your location. We do not use location for automated attendance or surveillance.

4.4 Information From Your Employer

If you join a HrdHat company account through an invitation from your employer, your employer may have provided your email address and name to HrdHat to send the invitation. Your employer may also add you to crews, assign projects, or record work you did on their behalf. Your employer is a separate data controller for the records they collect through their Company Starter account (see Section 6.1).

4.5 Sensitive Information

HrdHat does not knowingly collect:

  • Social Insurance Numbers (Canada) or Social Security Numbers (US)
  • Bank account numbers or payment card numbers (Stripe handles these directly)
  • Government ID numbers
  • Health information beyond what you voluntarily include in a form (for example, a Fit for Duty self-check)
  • Biometric identifiers beyond your signature image, if you choose to sign electronically
  • Information about users under 18

If you discover sensitive information has been collected in error, contact privacy@hrdhat.site and we will delete it.


4.6 Certificate & Credential Documents

When you add a certification to your Worker Passport, you may upload photos of the certificate (front and back). These images often contain sensitive identifiers — your name, certificate numbers, issuing-authority details, and sometimes a photo or signature.

  • Private storage. Certificate document images are stored in a private storage bucket. They are not part of your public passport and are never displayed to other users or visitors.
  • Signed, expiring access. The images are accessible only to your signed-in account through short-lived signed links generated when you view your own certificates.
  • What is public. If your passport visibility is set to Public, only the certificate name and its validity status (Valid / Expiring / Expired) appear publicly — never the document images or certificate numbers.
  • Deletion. Deleting a certificate permanently removes its document images from storage. Deleting your account removes them with the rest of your data.

5. How We Use Your Information

We use personal information to:

  • Operate the service — authenticate you, store and serve Your Content, deliver emails, process payments
  • Draft with AI, when you ask — when you start Scan with AI or another AI feature, we send the photos and text you provide to our AI provider (Section 7) to draft suggestions for you. This happens only when you start it, and every suggestion is yours to confirm or reject. See Section 5a.2.
  • Keep the service safe — detect fraud, abuse, and security incidents; diagnose bugs and outages
  • Communicate with you — transactional emails (receipts, verification codes, password resets, plan changes), occasional product updates
  • Improve the service — diagnose bugs, measure performance, understand which features are used (not individual surveillance)
  • Comply with law — respond to legal requests, enforce our Terms, meet tax and corporate record obligations

We do not:

  • Sell your personal information
  • Send you marketing emails without your consent (transactional emails — account, billing, security — are sent regardless of marketing preference, as required to operate your account)

For detailed analytics and AI drafting and learning, see Section 5a.

  • For Canadian users: we rely on your consent when you create an account and agree to this Policy (PIPEDA Principle 3) and on the "reasonable business purpose" basis for operational and security processing.
  • For Quebec residents: specific consent under Quebec Law 25 (see Section 12).
  • For California, Virginia, Colorado, Connecticut, Utah residents: we process on the basis of contractual necessity (operating your account), legitimate interest (security, fraud prevention), and your affirmative opt-in for detailed analytics and for sharing your confirmed hazard rows to improve AI drafts.

5a. Analytics, AI Drafting and Learning, and Internal QA (What We Do With Your Content Beyond Operating the Service)

This section describes the three ways HrdHat may interact with Your Content beyond the direct operation of the service. Each has a different legal basis and a different user control. Read this before enabling the Settings toggles.

5a.1 Detailed Analytics — Opt-In Only

With your affirmative consent (Settings → Privacy → "Allow detailed analytics"):

What we collect:

  • Session-interaction recordings on non-sensitive pages (clicks, scrolls, page paths), captured by Sentry session replay
  • Page-load performance metrics, via Vercel Speed Insights
  • Aggregated usage patterns (which features are used, when, how often)

What is never collected, even if you opt in:

  • Session replays of safety-form pages, timesheets, dispatch, inbox, signatures, or gear/fall-protection pages (excluded by URL — see Section 4.2)
  • Keystroke-level capture of form inputs (inputs are masked)

Withdrawal: You may disable detailed analytics at any time. Future collection stops immediately. Recordings already captured are deleted in Sentry's ordinary retention cycle (typically 30–90 days).

Default: OFF.

5a.2 AI Drafting and Learning

HrdHat offers AI features, such as Scan with AI on the Field Level Risk Assessment (FLRA), that draft form content for you to review. This section explains what happens to your data in three parts: drafting when you ask, your own history, and the one thing you can choose to share.

AI drafting, when you ask — part of operating the service:

  • When you start a scan, the photos you took for it, the details you gave (where you are, the tasks you picked, your trade, the project name) and, for context, your own past confirmed FLRA rows are sent to our AI provider, Anthropic (Section 7), which returns a draft.
  • Under Anthropic's commercial terms, what we send is not used to train Anthropic's models. Anthropic may retain inputs for a limited period for abuse and safety monitoring under those terms.
  • Every AI-drafted value is marked in the form and is not final until you confirm or change it. Your acceptance is recorded with your signature (see the Terms of Use, Section 10.7). AI drafting is not an automated decision that produces a legal effect concerning you (see Section 12).
  • Nothing is sent to Anthropic unless you start an AI feature yourself.

Your own history — always kept, used only for you:

  • When you complete an FLRA, we keep a hazard record of each task, hazard and control row you confirmed, tagged with your trade, the type of site, whether the row came from you or from an AI draft, and what you did with it. These rows are a structured copy of content already in your form.
  • We use your own records only to help you: to offer your last FLRA as the starting point for the next one on the same project, and to give the AI your own past rows as context when it drafts for you. Nobody else sees them.
  • Your hazard records are deleted with your account (Section 9).

Help improve Scan with AI — Opt-In Only:

With your affirmative consent (Settings → Privacy → "Help improve Scan with AI", also asked once after your first completed FLRA):

  • We may use your confirmed hazard records, tagged by trade and type of site but never with your name, your project, or your photos, to improve AI drafts for other users.
  • Today this works by showing the AI relevant examples drawn from consented records at drafting time. No model is trained on them. If we ever train a model on consented records, we will update this Policy and notify you before doing so.
  • Photos, signatures, messages and timesheets are never included.

Withdrawal:

  • You may turn "Help improve Scan with AI" off at any time. Sharing stops immediately for all of your records, including records created while the setting was on, because our systems check your current setting at the moment they read.
  • If a model is ever trained on consented records (which we will announce first), records already used in a training run cannot be surgically removed from that model's weights. We will not use your records in any new training run after you withdraw.
  • Aggregated, anonymized statistical derivations produced before withdrawal (for example, "X% of FLRAs mention fall protection") may remain in aggregate form only.

Default: OFF.

5a.3 Internal QA — Operational Necessity With Guardrails

From time to time, HrdHat engineers need to view real user data to diagnose production bugs that cannot be reproduced from error logs alone. We treat this as a reasonable business purpose under PIPEDA Principle 3 and as a service-provider operational function under CCPA §1798.140(e), with the following guardrails:

Access is:

  • Restricted — during beta, HrdHat has a single staff member (the founder) with production database access. Access is used only for debugging production issues that cannot be diagnosed from application error logs alone.
  • Confidentiality-bound — HrdHat staff are under written confidentiality obligations as a condition of access.

Planned during beta, before scale-up requires them:

  • Logged access auditing — a database table recording every query against production user data, including who queried, what was queried, when, and a linked support ticket or bug identifier. (Tracked in our roadmap as the admin_access_log feature.)
  • PII masking by default — in our admin and debug tooling, personal information (names, emails, signatures, photos) will be masked unless the engineer explicitly unmasks a specific field with a documented justification that is also logged.

Both controls will be implemented before HrdHat grows past a small founding team with production access, or sooner if required by applicable privacy law or regulator review.

We do not offer a Settings toggle for this because internal QA access is necessary to keep the service running reliably for every user. If you believe your data has been accessed improperly, contact privacy@hrdhat.site and we will investigate.


6. How We Share Your Information

We share personal information only in the limited circumstances below.

6.1 With Your Employer (Company Starter Account Controller)

If you are part of a Company Starter account, your employer (account owner and admins) can see records you submit through that company account — forms, timesheets, shift records, dispatch messages.

Your employer is a separate data controller for those records under PIPEDA, Quebec Law 25, and applicable US state privacy laws. HrdHat acts as a data processor for your employer's use of that data. Your employer has signed our Company Data Processing Agreement (CDPA) which governs how they process that data, what security they must maintain, and how they respond to your access, correction, and deletion rights.

When you exercise a privacy right (access, correction, deletion) for records your employer controls, we will direct the request to your employer and cooperate with fulfilment. For your personal profile data that is not part of your employer's records (for example, your individual account settings), HrdHat remains the controller.

6.2 With Other HrdHat Users You Choose

If you submit a form, sign a timesheet, or send a dispatch message, the intended recipient(s) see it.

6.3 With Sub-Processors (Service Providers)

We use the third-party service providers listed in Section 7 to operate HrdHat. We share only the information each provider needs to perform its service, and each is contractually required to keep data confidential and use it only for the purposes we specify.

6.4 For Legal Reasons

We may disclose personal information when we believe in good faith that disclosure is:

  • Required by law (subpoena, court order, regulator request)
  • Needed to enforce our Terms of Use
  • Needed to protect the safety of any person
  • Needed to investigate fraud, abuse, or a security incident

Where the law allows, we will notify you before disclosing your data in response to a legal request.

6.5 Business Transfers

If HrdHat merges with, is acquired by, or sells assets to another company, your personal information may be transferred as part of that transaction. We will notify you of any such transfer and of any material change to how your data is handled.

6.6 Aggregated or Anonymized Information

We may share aggregated or anonymized statistics (for example, "X% of shifts start between 6am and 7am") that cannot reasonably be used to identify you. This is not a sale of personal information.


6.7 Your Public Worker Passport

Your Worker Passport has an optional public page at a unique link (/p/your-passport-link) that you can share directly or present as a QR code.

  • What it shows (when your visibility is set to Public): your name, profile photo, trade(s), availability, general location (the town/city you typed in), bio, site-readiness flags, work history, and certificate names with their validity status.
  • What it never shows: your email address, phone number, precise coordinates, pay rates, or certificate document images.
  • Default and control. New passports default to Public so workers can be found and verified by employers. You can switch to Connections Only or Invisible at any time in Settings → Visibility; your public page stops resolving immediately.
  • Anyone with the link can view a Public passport without signing in. Treat your passport link like a business card.
  • About your profile photo. So your public page loads instantly, your passport photo is stored at a public image link tied to your account. Switching to Connections Only or Invisible stops your passport page from resolving, but it does not retroactively disable a photo link that someone already opened, saved, or cached. Your photo is removed from storage when you delete your account.

7. Sub-Processors

We currently use the following sub-processors. This list will be maintained and updated. Material additions will be announced via email before they take effect, in accordance with PIPEDA and Quebec Law 25.

| Sub-processor | Purpose | Data handled | Country of processing | DPA status | | -------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------ | ------------ | | Supabase, Inc. | Authentication, database, storage | Email, name, phone, address, photos, forms, signatures, content | United States (AWS region, by default us-east-1) | In execution | | Stripe, Inc. | Payment processing | Email, name, billing address, payment card token (we never see card details) | United States (global infrastructure) | In execution | | Sentry (Functional Software, Inc.) | Error monitoring and (with consent) session replay on non-sensitive pages | User ID, email, browser metadata, error stack traces, opt-in session replay | United States | In execution | | Vercel Inc. | Application hosting and content delivery; opt-in Speed Insights | IP address, request metadata, opt-in performance metrics | Global edge network | In execution | | Twilio SendGrid, Inc. | Transactional email delivery | Email address, email body content | United States | In execution | | Mapbox, Inc. | Map tiles and geocoding | Approximate location (map centerings), search queries | United States | In execution | | Anthropic, PBC | AI drafting, only when you start an AI feature (Scan with AI, tool-label scan): reads photos and form text to draft suggestions | Site and tool photos you take for a scan, your trade, project name, task details, and your own past confirmed FLRA rows; with consent, other users' hazard records without names or projects | United States | In execution |

DPA status legend: "Executed" means a signed Data Processing Agreement is on file. "In execution" means HrdHat has entered the provider's standard DPA workflow but signature is pending during beta. We are completing all DPAs in the current beta period.

All sub-processor contracts require:

  • Confidentiality
  • Use of data only for the purposes we specify
  • Return or deletion of data on termination
  • Equivalent protections to those in this Policy
  • Breach notification to HrdHat within the timeframe specified in the DPA

Because several sub-processors are located in the United States, your personal information is subject to cross-border transfer (see Section 10).


8. Cookies & Similar Technologies

HrdHat uses:

  • Essential cookies — authentication session (you cannot log in without this), CSRF protection, cookie-preference state
  • Optional performance/analytics cookies — Vercel Speed Insights + Sentry session replay. These are dropped only after you opt in via Settings → Privacy → "Allow detailed analytics."

We do not use:

  • Advertising cookies
  • Third-party analytics cookies for marketing purposes (no Google Analytics, no Meta pixel, etc.)

Your browser can be configured to reject non-essential cookies. Rejecting essential cookies will prevent you from logging in.

EU/UK visitors: HrdHat is not currently marketed in the EU or UK. If we begin offering the service to EU/UK residents, we will add a GDPR-compliant consent management platform before dropping any non-essential cookies for EU/UK visitors.


9. Data Retention

We keep personal information only as long as we need it:

  • Account data (email, name, passport): kept while your account is active, and for up to 30 days after account deletion for backup restoration.
  • Forms, timesheets, photos, signatures: kept for the longer of (a) as long as your account is active, or (b) 7 years — a conservative retention period that meets or exceeds applicable provincial retention requirements for construction and employment records. Specific retention periods vary by record type and province. If you delete your account, we delete these records after 30 days unless your employer's Company Starter account retains them as part of their records (in which case your employer becomes the controller of those records — see Section 6.1).
  • Hazard records (Section 5a.2): kept while your account is active and deleted with your account. Records you shared under "Help improve Scan with AI" stop being read the moment you turn the setting off, and are deleted with your account like the rest.
  • Uploaded files: files in My Uploads are deleted with your account. Files you uploaded to a company or project stay with that company as controller of those records (see Section 6.1).
  • Payment records: kept for 7 years to comply with Canadian and US tax law, regardless of account deletion.
  • Error logs and security audit logs: kept for up to 90 days.
  • Internal QA access logs (Section 5a.3): once implemented, kept for 2 years for internal audit and regulator production.
  • Session replay recordings (Section 5a.1): kept for Sentry's default retention period (typically 30–90 days) and deleted on consent withdrawal.

You can request deletion of specific records at any time (see Section 11).


10. Cross-Border Data Transfers

Your personal information is processed in Canada and the United States.

Under Canadian law (PIPEDA) and Quebec Law 25, we are required to assess and disclose cross-border transfers:

  • Supabase, Stripe, Sentry, Vercel, SendGrid, Mapbox, and Anthropic process data in the United States. By using HrdHat, you acknowledge that your personal information may be accessed from the United States.
  • We contractually require US-based sub-processors to protect your data to a standard equivalent to PIPEDA. US law enforcement may in some circumstances compel disclosure of data stored in the US (for example, under FISA §702 or the CLOUD Act); we will notify you of any such request unless legally prohibited.
  • For Quebec residents: HrdHat is preparing a Privacy Impact Assessment consistent with Quebec Law 25 Article 17 requirements during beta. When complete, it will cover sensitivity, purpose, contractual safeguards, destination legal framework, and proportionality, and will be on file and available to the Commission d'accès à l'information on request at privacy@hrdhat.site.

11. Your Privacy Rights (All Users)

You can exercise the following rights at any time:

  • Access a copy of the personal information we hold about you (via Settings → Privacy → Export My Data)
  • Correct inaccurate personal information (via your profile and account settings, or by emailing privacy@hrdhat.site)
  • Delete your account and associated personal information (via Settings → Privacy → Delete Account)
  • Withdraw consent to optional processing at any time (toggles in Settings → Privacy; see limitations in Section 5a.2)
  • Object to processing based on legitimate interest
  • Port your data — your export is provided in a common, machine-readable format

To exercise any right, email privacy@hrdhat.site. We will respond within 30 days (PIPEDA) or the timeframe required by your provincial/state law, whichever is shorter.

If you are part of a Company Starter account and your request concerns records your employer controls, we will direct the request to your employer and cooperate with fulfilment per Section 6.1 and the CDPA.

If you believe we have not met our obligations, you may file a complaint with:

  • Canada (federal): Office of the Privacy Commissioner of Canada — priv.gc.ca
  • British Columbia: Office of the Information and Privacy Commissioner for BC — oipc.bc.ca
  • Alberta: Office of the Information and Privacy Commissioner of Alberta — oipc.ab.ca
  • Ontario: Information and Privacy Commissioner of Ontario — ipc.on.ca
  • Quebec: Commission d'accès à l'information — cai.gouv.qc.ca
  • California: California Privacy Protection Agency — cppa.ca.gov

12. Quebec Residents — Law 25 Specifics

In addition to the rights in Section 11, Quebec residents have the following rights under the Act respecting the protection of personal information in the private sector (as amended by Law 25):

  • Right to data portability in a structured, commonly used technological format
  • Right to be informed of any automated decision that uses your personal information to produce a legal effect concerning you, and to request that a human review such a decision
  • Right to cease dissemination and to de-index (right to be forgotten) where required by Quebec law
  • Right to information about cross-border transfers — see Section 10. Our Article 17 PIA is in preparation during beta; once complete it will be on file and available to the CAI on request.

Automated decision-making: HrdHat does not currently make automated decisions that produce a legal effect concerning you. AI drafting (Section 5a.2) produces suggestions that you review and accept or reject, including the high-risk work flag on an FLRA; the decision is yours, and a human (you) makes it every time. If we begin to use AI-trained models to produce decisions with a legal effect in the future (for example, automatically flagging a timesheet as suspicious), we will notify you and provide the rights under Quebec Law 25 Article 65 before doing so.

Private right of action: Quebec Law 25 allows you to take legal action, including a class action, against any business that violates your privacy rights under Quebec law.


13. California Residents — CCPA/CPRA

In addition to the rights in Section 11, California residents have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to know what personal information we have collected in the last 12 months
  • Right to delete personal information we have collected, subject to exceptions (tax, security, legal obligations)
  • Right to correct inaccurate personal information
  • Right to limit the use of Sensitive Personal Information (SPI). HrdHat does not use SPI beyond operational necessity.
  • Right to opt out of "sale" or "sharing" of personal information for cross-context behavioral advertising. HrdHat does not sell or share personal information for advertising.
  • Right to opt out of Automated Decision-Making Technology (ADMT) as defined by California Privacy Protection Agency regulations. HrdHat does not currently use ADMT to produce significant decisions about you; AI drafting produces suggestions you accept or reject yourself. If that changes, we will notify you and provide the opt-out mechanism required by law.
  • Right to non-discrimination for exercising any CCPA right

To exercise, email privacy@hrdhat.site with "CCPA Request" in the subject line. We will verify your identity before fulfilling the request.


14. Virginia, Colorado, Connecticut, Utah Residents

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA) have the same access, correction, deletion, and portability rights as in Section 11, plus the right to opt out of targeted advertising and sale of personal information. HrdHat does not engage in either.

Requests: email privacy@hrdhat.site with the subject line identifying your state.


15. Children's Privacy

HrdHat is intended for users 18 and older. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a user under 18, we will delete it.

If you are a parent or guardian and believe your child under 18 has provided personal information to HrdHat, please contact privacy@hrdhat.site immediately.


16. Security

We use industry-standard measures to protect your personal information.

Currently in place:

  • Encryption in transit (TLS 1.2+) for all communication between your device and HrdHat
  • Encryption at rest for database and storage systems (via Supabase)
  • Password hashing (bcrypt)
  • Row-level security on the database to enforce access control
  • Vulnerability monitoring via Sentry

Planned during beta (see Section 5a.3 for context):

  • Logged access auditing — a record of every internal-QA query against production user data
  • PII masking by default in admin and debug tooling

No system is perfectly secure. You are responsible for keeping your password confidential. If you suspect your account has been compromised, notify us immediately at hello@hrdhat.site.

Breach Notification

In the event of a data breach that creates a real risk of significant harm, we notify affected individuals and the relevant privacy regulator as required by PIPEDA (Canada), each applicable provincial law, and each applicable US state law. We aim to notify affected individuals within 72 hours of becoming aware of a reportable breach where reasonably feasible.


17. Changes to This Privacy Policy

We may update this Policy from time to time. When we make a material change, we will:

  • Notify you by email at the address on your account
  • Post a notice in the app before the change takes effect
  • Update the "Effective Date" and "Version" at the top of this document
  • Retain previous versions for your reference

Continued use of the service after the change means you accept the updated Policy.


18. Contact

  • Privacy requests: privacy@hrdhat.site
  • Security concerns: hello@hrdhat.site
  • General support: hello@hrdhat.site
  • Legal notices: hello@hrdhat.site

HrdHat (operated by Pawel Mniszak, sole proprietor) British Columbia, Canada