Privacy Policy
Last updated: 13 July 2026
1. Introduction
Phillip-Juan van der Berg, trading as POPIAdesk ("we", "us", or "our"), operates the POPIAdesk platform ("Service"). We are committed to protecting your personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA) and the Electronic Communications and Transactions Act, 2002 (ECTA).
This Privacy Policy explains what personal information we collect, how we use it, who we share it with, how long we keep it, and what rights you have.
2. Responsible Party
Phillip-Juan van der Berg (trading as POPIAdesk)
Bellville, Western Cape, Republic of South Africa
Information Officer: privacy@popiadesk.co.za
3. Personal Information We Collect
We collect the following categories of personal information:
3.1 Information you provide
- Account details: name, email address, organisation name, and password (stored as a salted hash - we never store your password in plain text). If you enable two-factor authentication, we store your authenticator secret (encrypted) and one-time backup codes (hashed).
- Organisation profile:registration number, industry, employee count, B-BBEE level, and compliance-related flags (e.g. whether you process children's data, conduct cross-border transfers, or do direct marketing).
- Document data: information you enter into compliance document wizards (e.g. information officer name, data categories, retention periods).
- Assessment responses: answers to readiness assessments and gap analyses.
- Data subject requests: requester name, email, and ID number hash for DSR processing.
- Supplier records: supplier name, contact email, DPA status.
- Payment records: transaction references, plan, and amounts. We never store your card details; PayFast handles payment data directly.
- Contact form: your name, email address, and message. We verify the submission for abuse, email it to us, and reply to you; we do not store contact-form messages in a database.
Providing your account details is mandatory to create and use the Service. Providing an email address for the free scanner, assessment, or contact form is voluntary; if you do not, we cannot send you those results or reply to you.
3.2 Information collected automatically
- Audit logs: action type, timestamp, IP address, and entity references for security and compliance purposes.
- Usage events: individual events linked to your account id (for example: registered, completed a tour, generated a document, upgraded). We aggregate these into counts to operate and improve the Service. This happens on our own servers - no third-party analytics, no advertising identifiers.
- Server logs and rate-limiting records: IP addresses and request metadata, kept briefly for security and abuse prevention.
- Error tracking: if we enable error monitoring, anonymised error reports are processed via Sentry for service reliability. Error monitoring is currently disabled. No personal information is deliberately included.
3.3 Free scanner and assessment data
Our free public website compliance scanner collects the website address (URL) you submit, the email address you provide to receive the report, and the IP address of the request. Our free public POPIA assessment collects the email address you provide, your computed compliance score and risk level, and the IP address of the request. We use this information only to run the scan or assessment, to apply rate limiting and prevent abuse, and to email you the result. This data is not used to market to you.
3.4 Information we process on behalf of our customers (as operator)
When a member of the public submits a data subject request through a customer's public request portal, that information (name, email, an optional ID number stored only as a hash, and the request description) is processed on behalf of that customer. For this information the customer organisation is the responsible party and POPIAdesk acts as an operator under sections 20 and 21 of POPIA. Requests to access, correct, or delete that information should be directed to the customer organisation named on the portal.
4. Purpose of Processing
We process your personal information for these specific purposes:
- Service delivery: to create your account, generate compliance documents, process assessments, manage DSRs, and provide the Service (legal basis: contract).
- Billing: to process subscription payments via PayFast (legal basis: contract).
- Security: to maintain audit logs, detect fraud, and protect the Service (legal basis: legitimate interest).
- Service emails: to send verification emails, password resets, invitation links, and trial reminders (legal basis: contract).
- Service improvement: we keep first-party records of how the Service is used as individual usage events linked to your account id (for example sign-ups, documents generated, feature usage), which we aggregate into counts to operate and improve the Service. This happens on our own servers - no third-party analytics services, no tracking cookies, no advertising identifiers (legal basis: legitimate interest).
- Legal compliance: to comply with applicable laws and respond to lawful requests (legal basis: legal obligation).
5. Third-Party Sharing
We share personal information only with the following categories of third parties, and only to the extent necessary:
- PayFast (Pty) Ltd: payment processing. We do not store your credit card details - PayFast handles all payment data directly. See PayFast Privacy Policy.
- Resend (US provider; EU sending region): transactional email delivery. Only your email address and email content are shared.
- Cloudflare (Turnstile): abuse prevention on our public forms (contact form and public request portal). Cloudflare, a US company, receives IP address and browser signals to distinguish humans from bots.
- Sentry (currently disabled): error monitoring. When enabled, anonymised error data only - no personal information is deliberately included.
- Backblaze B2: access-controlled document storage (generated PDFs), hosted in the EU.
- Hetzner Online GmbH: cloud hosting for the application and database, in Germany (EU).
We do not sell, rent, or trade your personal information to any third party.
6. Cross-Border Transfers
Your personal information is hosted primarily with Hetzner in Falkenstein, Germany, and generated documents are stored with Backblaze B2 in the European Union. Some of the operators listed in section 5 (for example our email provider) may also process limited data outside South Africa. Because this processing occurs outside South Africa, POPIA treats it as a cross-border transfer. We rely on the contractual safeguards in our agreements with these operators, as permitted by section 72 of POPIA.
7. Data Retention
We retain your personal information as follows:
- Active accounts: data is retained for as long as your account is active and your subscription is current.
- After cancellation: you have 30 days to export your data. After 60 days, all organisation data is permanently deleted.
- Unused trial accounts: if nobody signs in for 12 months, we email a notice; the account and its data are deleted 30 days later unless you sign in.
- Free scanner and assessment data: anonymous scan records are deleted after 90 days. Scans and assessments run from an account are kept with the account.
- Audit logs: retained for 12 months for security and compliance purposes, then automatically purged.
- Account deletion: upon request, your account and all associated data will be deleted within 30 days. Records we are required to keep by law (such as payment records) are retained for the period the law requires.
8. Security Safeguards
We implement appropriate technical and organisational measures:
- Encryption in transit (TLS); encrypted off-site backups.
- Row-level security (RLS) in our database ensuring strict tenant isolation.
- Salted password hashing (bcrypt) with breach detection: chosen passwords are checked against known-breach lists using a privacy-preserving (k-anonymity) lookup, so we never send your full password anywhere.
- JWT-based session management with token version checks.
- PayFast signature validation, source-IP restriction, and server-to-server postback confirmation on payment webhooks.
- Audit logging of account activity and changes to your data.
- IP-based access restrictions on API endpoints where applicable.
9. Your Rights (POPIA Data Subject Rights)
Under POPIA, you have the right to:
- Access: request confirmation of whether we hold your personal information and obtain a copy.
- Correction: request correction of inaccurate or incomplete personal information.
- Deletion: request deletion of your personal information. You can delete your account at any time from your profile settings.
- Objection: object to the processing of your personal information for direct marketing or on grounds relating to your particular situation.
- Data portability: export your data (documents, assessments, DSR records, data maps, supplier records, and audit logs) from your profile settings.
- Complaint: lodge a complaint with the Information Regulator if you believe your rights have been violated.
To exercise any of these rights, email privacy@popiadesk.co.za or use the self-service options in your account settings.
10. Cookies
POPIAdesk uses only essential cookies required for the Service to function (authentication session cookies). We do not use tracking cookies, analytics cookies, or advertising cookies.
Our public contact form and request portal use Cloudflare Turnstile for abuse prevention, which may set its own cookie to distinguish humans from bots.
If we introduce non-essential cookies in future, we will obtain your consent before setting them.
11. Breach Notification
In the event of a personal information breach that poses a risk to you, we will:
- Notify the Information Regulator within 72 hours of becoming aware of the breach, lodged through the Regulator's eServices portal.
- Notify affected data subjects as soon as reasonably possible.
- Provide details of the nature of the breach, potential consequences, and measures taken.
12. Children's Information
POPIAdesk is not directed at children under 18 and we do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without appropriate consent, we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes; where a change expands how we process existing customers' personal information, we will give at least 30 days notice by email. The latest version will always be available at this page.
14. Information Regulator
If you are unsatisfied with how we handle your personal information, you may lodge a complaint with:
The Information Regulator (South Africa)
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
eServices portal (preferred): eservices.inforegulator.org.za
Email: POPIAComplaints@inforegulator.org.za
Website: inforegulator.org.za
15. Contact Us
For any questions about this Privacy Policy or to exercise your data subject rights, contact us at:
Information Officer: privacy@popiadesk.co.za
General enquiries: hello@popiadesk.co.za