Privacy & Security
This page is maintained by Hygopest Hygiene Services to answer common security and privacy questions about the procurement portal. It describes controls that are enabled in the app today and is not an independent certification.
The portal uses email/password authentication with server-validated sessions. Session tokens are short-lived and refreshed automatically. Administrators can lock accounts, reset passwords, and enforce role-based access (Super Admin, Admin, User).
Row-level security is enforced at the database layer for every user-owned table, so users only ever see stores, orders, and site assignments that belong to them.
Account data (email, display name), procurement activity (orders, delivery confirmations), and organisation data (clients, stores, site assignments). Product and SDS documents are stored in a managed object store for compliance viewing.
We do not sell personal data and do not use it for advertising.
All traffic is served over HTTPS. Secrets and service-role credentials are held server-side and never exposed to the browser. Privileged operations run through authenticated server functions with per-request bearer validation.
Passwords are hashed by our identity provider; leaked-password detection can be enabled by the administrator.
Every privileged action — user creation, password reset, role change, store and client changes, product edits, order submission and delivery — is written to an immutable audit log with actor identity, timestamp, IP address, and a plain-English summary. Only Admins and Super Admins can view the log.
Orders and delivery notes are retained for operational and tax purposes. Audit logs are retained to support security reviews. Account deletion requests are handled by a Super Admin and remove authentication records and profile data linked to the user.
For privacy requests, security reports, or data access questions, contact info@hygopest.co.za.
Last updated 20 September 2026