Contact Form Security
No Sweat Work Media CC
Trading as NoSweat
Registration Number: 2009/090625/23
Website: www.nosweat.co.za
Effective Date: 10 August 2026
1. Protecting Information Submitted Through Our Website
NoSweat uses online forms to help candidates, clients and other users communicate with us and access our services.
Depending on the form being used, you may provide information such as:
your name;
email address;
telephone or WhatsApp number;
company information;
professional information;
job requirements;
CV or résumé;
portfolio information;
skills and experience;
salary or rate information; and
other information relevant to your enquiry or application.
NoSweat is committed to handling information submitted through our website responsibly and in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”).
POPIA requires organisations processing personal information to implement reasonable technical and organisational measures designed to protect information against loss, unauthorised access, unlawful processing, destruction or damage. (Empowered Compliance Monitoring)
2. What Our Forms Are Used For
NoSweat website forms may be used for purposes including:
creating candidate profiles;
submitting CVs;
applying for jobs;
joining the NoSweat talent pool;
submitting hiring requirements;
posting jobs;
making client enquiries;
contacting NoSweat;
submitting privacy or compliance requests; and
other legitimate business purposes.
NoSweat’s candidate platform currently allows professionals to create profiles, upload CVs and apply for opportunities, while clients can submit hiring requirements and review suitable candidates. (No Sweat)
Information submitted through a form will be processed according to the purpose of that form and the relevant NoSweat privacy documentation.
3. Only Provide Information That Is Necessary
We encourage users to provide only the information reasonably necessary for the relevant request.
Unless specifically requested through an appropriate process, please do not enter the following into ordinary website contact forms:
account passwords;
one-time passwords or authentication codes;
PIN numbers;
complete credit or debit card information;
online banking credentials;
unnecessary identity documents;
highly sensitive medical information;
private authentication keys; or
other information unrelated to the purpose of the form.
Providing unnecessary sensitive information increases the potential consequences if information is accidentally disclosed or compromised.
4. Passwords and Authentication Codes
NoSweat should never need your password in order to respond to a contact-form enquiry.
You should never enter:
your NoSweat password;
your email password;
banking passwords;
PINs; or
multi-factor authentication codes
into a general NoSweat contact form.
If anyone claiming to represent NoSweat asks you to submit such information through a contact form, please verify the request directly with us.
5. Form Security
NoSweat takes reasonable steps intended to protect information submitted through our website.
Depending on the nature of the website functionality and systems involved, appropriate safeguards may include controls relating to:
secure transmission;
access permissions;
user authentication;
input validation;
spam and automated abuse;
system monitoring;
secure administration;
service-provider access; and
protection against common web-application attacks.
For security reasons, we do not publicly disclose detailed configurations or security architecture.
OWASP identifies proper server-side input validation as an important foundation for secure web applications and recommends that applications validate structured inputs rather than relying only on browser-side controls. (OWASP Cheat Sheet Series)
6. Protection Against Automated Abuse
Public contact forms can attract automated submissions, spam and malicious bot activity.
NoSweat may therefore use reasonable anti-abuse measures appropriate to the form and risk involved.
These may include measures such as:
submission limits;
automated-abuse detection;
behavioural controls;
challenges for suspicious requests;
server-side validation; and
other mechanisms designed to reduce automated misuse.
OWASP recommends layered anti-automation controls, which can include rate limits, behavioural signals, quotas, honeypots and CAPTCHA-type challenges where appropriate. (OWASP Cheat Sheet Series)
The precise controls used by NoSweat may change as our website and security requirements develop.
7. Input Validation
Information submitted through a website form should be treated as untrusted until appropriately validated and processed.
NoSweat aims to ensure that systems handling form submissions apply reasonable controls appropriate to the type of information being submitted.
Examples include verifying expected:
email formats;
telephone-number formats;
permitted file types;
field lengths;
dates;
numerical values; and
required fields.
OWASP recommends server-side validation because browser or client-side validation alone can be bypassed. (OWASP Cheat Sheet Series)
8. File Uploads
Certain NoSweat functionality may allow candidates to upload CVs or other professional documents.
Where file uploads are permitted, users should submit only documents relevant to the requested purpose.
Candidates should avoid unnecessarily including highly sensitive personal information in CVs, such as:
passwords;
banking credentials;
unnecessary identity numbers;
unnecessary medical information; or
other unrelated private information.
Files uploaded to NoSweat may be processed for legitimate candidate, matching, hiring and administrative purposes in accordance with our Privacy Policy.
9. Links Submitted Through Forms
Candidates may provide links to professional resources such as:
portfolios;
LinkedIn profiles;
websites;
Behance profiles;
Google Drive portfolios; or
other work examples.
Users should ensure that links they submit do not unintentionally provide public access to unrelated personal or confidential information.
NoSweat is not responsible for the privacy or security configuration of third-party websites selected by the user.
10. Contact Forms and Email
Some website submissions may generate email notifications or may be handled through NoSweat's business systems.
Because email itself can be subject to phishing, forwarding mistakes and unauthorised access, users should avoid using an ordinary contact form as a mechanism to transmit unnecessary highly sensitive information.
Please see our Email Exposure Risk page for further information about email-related security.
11. Candidate Information
When candidates submit information to NoSweat, it may be used to:
create or maintain a candidate profile;
assess professional experience;
match the candidate with opportunities;
process job applications;
communicate about work;
facilitate interviews; and
present relevant candidate information to appropriate clients.
NoSweat’s current platform enables candidates to create profiles and upload CVs as part of applying for freelance and full-time opportunities. (No Sweat)
For more information, please see our Privacy Policy and POPIA & Data Protection page.
12. Client Information
Clients may submit information including:
company details;
contact information;
job requirements;
required skills;
start dates;
salaries or budgets; and
other information needed to identify suitable talent.
NoSweat currently asks clients to provide information such as role, skills, experience level, start date and salary or budget so suitable candidates can be identified. (No Sweat)
Clients should avoid entering confidential business information that is not necessary to fulfil the particular hiring request.
13. Spam and Malicious Submissions
Website forms must not be used to:
send spam;
distribute malware;
attempt unauthorised system access;
submit fraudulent information;
impersonate another person;
transmit unlawful material;
harvest information;
interfere with website operation; or
conduct automated attacks against NoSweat systems.
NoSweat may block, restrict, investigate or delete submissions reasonably suspected of being abusive or malicious.
14. Cross-Site Request and Web Application Risks
Modern websites can face attacks designed to manipulate forms or cause unintended requests.
Where relevant to the particular functionality, website applications should use appropriate controls against common threats such as:
cross-site scripting;
injection;
cross-site request forgery;
malicious input; and
automated abuse.
OWASP recommends anti-CSRF measures for functionality where an attacker could cause an authenticated user's browser to perform an unwanted action and also stresses that input validation forms part of a broader defence rather than being the sole protection against web attacks. (OWASP Cheat Sheet Series)
NoSweat does not publish detailed technical implementations of these controls.
15. Third-Party Form and Technology Providers
NoSweat may use external technology providers to support:
website hosting;
forms;
CRM functionality;
cloud processing;
communications;
security; and
other website operations.
Where a provider processes personal information on NoSweat's behalf, appropriate privacy, confidentiality and security requirements should apply according to the provider's role.
Third-party systems may also have their own security and privacy practices.
16. If You Submit Information by Mistake
If you accidentally submit information through a NoSweat form that you believe should not have been provided, contact us as soon as possible.
Please identify:
the form used;
approximately when it was submitted;
the email address or name used in the submission; and
the information you would like us to investigate.
Do not repeat the sensitive information unnecessarily in your follow-up message.
Contact:
Subject:
CONTACT FORM PRIVACY REQUEST
17. Suspected Contact Form Security Issue
If you believe that:
a NoSweat form has been tampered with;
information entered into a form may have been intercepted;
a fake NoSweat form is being used;
a form is behaving unexpectedly;
your submission may have gone to the wrong recipient;
you discover a security vulnerability; or
personal information submitted through a form may have been compromised,
please contact us immediately.
Sebastian van ’t Hoff
Information Officer
Email: sebastian@nosweat.co.za
Telephone / WhatsApp: +27 81 818 2053
Please use the subject:
URGENT: CONTACT FORM SECURITY
Do not publicly publish vulnerability details before giving NoSweat a reasonable opportunity to investigate the issue.
18. Security Compromises
If NoSweat determines that personal information submitted through a contact form has been subject to a security compromise, the matter will be handled under our Data Breach & Security Compromise Response Plan.
POPIA requires responsible parties to maintain safeguards against unlawful access and, where a security compromise occurs, provides for notification to the Information Regulator and affected persons in accordance with section 22. (Empowered Compliance Monitoring)
19. Your POPIA Rights
Depending on the circumstances, you may have rights to:
ask whether NoSweat holds personal information about you;
request access;
request correction;
request deletion where legally appropriate;
object to certain processing;
withdraw consent where consent applies; and
lodge a privacy complaint.
Requests can be directed to:
Sebastian van ’t Hoff
Information Officer
sebastian@nosweat.co.za
The South African Information Regulator provides prescribed forms and procedures for exercising POPIA rights and lodging complaints. (Empowered Compliance Monitoring)
20. Related Security and Privacy Information
For more information, please review:
Privacy Policy
POPIA & Data Protection
Cookie Policy
Email Exposure Risk
Data Breach & Security Compromise Response Plan
Record of Processing Activities (ROPA)
Information Officer Registration & Contact Details
21. Changes to This Page
NoSweat may update this page as:
website functionality changes;
new forms are introduced;
technology providers change;
security risks develop;
legislation or regulatory guidance changes; or
our security practices evolve.
The current version will be published on www.nosweat.co.za.
22. Contact NoSweat
For privacy and contact-form security matters:
No Sweat Work Media CC
Trading as NoSweat
Registration Number: 2009/090625/23
Information Officer: Sebastian van ’t Hoff
Email:sebastian@nosweat.co.za
Telephone / WhatsApp: +27 81 818 2053
Website:www.nosweat.co.za
For suspected security problems, use:
URGENT: CONTACT FORM SECURITY
