Draft for Legal ReviewThis document is unapproved scaffolding prepared for review by a South African attorney. It is not legal advice and must not be relied upon or published until every placeholder token (e.g. {{LEGAL_ENTITY}}) is filled and the stamp is removed at sign-off.

POPIA s18 — Processing notification

Privacy Policy

How {{LEGAL_ENTITY}} collects and processes personal information through the Serve Station Job Card System. Draft for Legal Review — pending attorney sign-off.

Effective date: {{EFFECTIVE_DATE}}

This Privacy Policy is effective from {{EFFECTIVE_DATE}}.

1. Responsible party & Information Officer

Responsible party
{{LEGAL_ENTITY}} (registration {{REG_NUMBER}})
Registered address
{{REGISTERED_ADDRESS}}
Information Officer
{{IO_NAME}}
Information Officer email
{{IO_EMAIL}}
Information Officer phone
{{IO_PHONE}}
Support
{{SUPPORT_EMAIL}}

We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA). This notice is given under section 18 of POPIA.

2. Personal information we process

Depending on your role (tenant administrator, technician, or the customer named on a job card) we may process:

  • Account & identity data — name, work email, role, and authentication identifiers held by our identity provider.
  • Operational data — job cards, site addresses, the customer's name and contact details, technician notes, checklist results and photographs of work performed.
  • Sign-off data — the customer's captured signature and the consent recorded at sign-off.
  • Technical data — device, IP address, user-agent and audit-log entries (actor, IP, time) kept for security and accountability.

3. Purposes of processing

We process personal information to:

  • create, dispatch, track and complete field-service job cards;
  • authenticate users and enforce tenant (organisation) isolation;
  • generate job reports and obtain customer sign-off;
  • maintain security, audit trails and statutory records; and
  • comply with our legal obligations.

4. Lawful basis (POPIA s11)

We justify processing on one or more of the s11 grounds:

  • Contract — processing necessary to provide the service to your organisation;
  • Legitimate interests — of the responsible party or a third party, balanced against your rights;
  • Legal obligation — where the law requires it; and
  • Consent — for the customer signature/sign-off and any optional processing. Consent may be withdrawn at any time.

5. Recipients & sub-operators (POPIA s20–21)

Personal information is hosted in South Africa. We share personal information only with operators who process it on our documented instructions, for limited and defined purposes, under written operator agreements that impose confidentiality and security obligations. Our operators fall into the following categories:

  • Cloud hosting & database — application hosting and the primary database (in-country).
  • File & object storage — secure storage of photos, signatures and uploaded documents (in-country).
  • Authentication — user identity and session management.
  • Transactional email — delivery of account, invitation and notification emails.
  • Operational tooling — monitoring, backups and the deployment pipeline.

We do not sell personal information. The current operator register and signed operator-agreement status are maintained in the POPIA Information Manual — see /legal/popia.

6. Cross-border transfers (POPIA s72)

Customer data is stored in-country. Where any sub-operator processes limited personal information outside South Africa, such transfers are made under section 72 of POPIA on the basis of binding contractual terms that afford a level of protection substantially similar to POPIA, or with your consent where required.

7. Retention (POPIA s14)

We keep personal information only for as long as necessary for the purposes above, for an owner-justified retention period ({{owner-justified period}}), or as required by law. On deletion we remove both the database record and any associated stored file (for example a signature or photo blob) while preserving the immutable audit trail required for accountability.

8. Your rights (POPIA s23–25)

Subject to POPIA, you may:

  • request access to the personal information we hold about you (s23);
  • request correction or deletion of personal information that is inaccurate, irrelevant, excessive or out of date (s24);
  • object to processing on reasonable grounds (s11(3)); and
  • withdraw consent where processing relies on consent.

To exercise a right, contact the Information Officer at {{IO_EMAIL}}. We respond to verified data-subject requests within our published service level (30 days).

9. Security safeguards (POPIA s19)

We apply reasonable technical and organisational measures including tenant isolation enforced at the database (row-level security), encryption in transit (TLS), least-privilege access, short-lived signed URLs for file access, and append-only audit logging.

10. Complaints to the Regulator

If you are not satisfied with how we have handled your personal information you may complain to the Information Regulator (South Africa): The Information Regulator, JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 — POPIAComplaints@inforegulator.org.za.