Privacy Policy

Last updated: 2026-08-20

1. Data controller

PreventiveHQ, trading as PreventiveHQ ("we", "us"), operates https://preventivehq.com and is the data controller for the personal data processed through it (the "responsible party" under POPIA). You can reach the controller at support@preventivehq.com.

2. Data we collect

3. Lawful bases for processing

We process personal data only where we have a lawful basis: performance of a contract (delivering your purchase), legitimate interests (securing and improving the service), consent where we have asked for it (recorded with a timestamp, source, and policy version), and legal obligations such as tax and accounting records. This applies under both the EU/UK GDPR and South Africa's POPIA.

4. Retention

Personal data is kept only for defined retention periods and is then deleted or anonymised, unless a legal hold (for example a dispute or a tax obligation) requires us to keep it longer. Consent evidence is retained for as long as the processing relies on it. Order and tax records are retained for the statutory periods that apply in South Africa and in the jurisdictions where tax is remitted.

5. Your rights (GDPR + POPIA)

You may request access to, correction of, or deletion of your personal data, ask for a portable copy, object to or restrict processing, and withdraw consent at any time. Send any data subject request (DSAR) to support@preventivehq.com from the email address on the account. We verify your identity before acting and respond within 30 days of a verified request.

You may also lodge a complaint with your EU/UK supervisory authority or, in South Africa, with the Information Regulator.

6. Payment processing and sub-processors

Purchases are processed by Dodo Payments, which acts as the merchant of record — the seller of record for your purchase. Dodo collects the payment, calculates and remits VAT/sales tax, and appears as the descriptor on your bank or card statement. Payment details you enter at checkout go to Dodo, not to us.

We also use a small set of sub-processors for hosting, transactional email, and privacy-respecting analytics. Each is bound by a data-processing agreement and may only process personal data on our documented instructions.

7. International transfers

Where personal data is transferred outside your jurisdiction, we rely on adequacy decisions or standard contractual clauses and apply the same safeguards described in this policy.

8. Cookies

We use only the cookies required to run the service (session, security, theme preference). We do not use third-party advertising cookies.

9. Security

Data is encrypted in transit, access follows least privilege, and the application enforces a strict content security policy. No method of transmission or storage is perfectly secure, but our controls are reviewed and tested continuously.

10. Changes to this policy

We update this policy when the service or the law changes. Material changes are announced on https://preventivehq.com before they take effect; the "last updated" date above always marks the current version.

11. Contact

Privacy questions and data subject requests: support@preventivehq.com.