Privacy Policy (POPIA Compliant)
How we collect, use, and protect your personal information in compliance with the Protection of Personal Information Act (POPIA).
Effective Date: 29 July 2026
Last Updated: 29 July 2026
This Privacy Policy describes how Core DC Flow ("we", "us", "our", or "the Responsible Party") collects, uses, discloses, and protects personal information when you use our application and services. This policy is compiled in accordance with the Protection of Personal Information Act, 2013 (POPIA) of South Africa and applicable data protection laws.
1. Information We Collect
- Account & company information: Your name, email address, company name, and contact details provided during registration.
- Employee data: Employee names, positions, departments, employment dates, and training records managed by your company administrators. This is personal information processed on behalf of the responsible company (the Data Controller).
- Certificates & documents: Training certificates and supporting documents uploaded by authorised users within your organisation.
- Payment information: Subscription and billing data processed securely by PayFast. We do not store credit card or banking details — these are handled entirely by PayFast, our payment service provider.
- Usage data: App activity logs, audit trails, and system monitoring data used to maintain security and service quality.
2. Lawful Basis for Processing
Under POPIA, we process personal information only where we have a lawful basis, including:
- Your consent to process personal information for the purposes of providing the service.
- The performance of a contract between you and Core DC Flow (your subscription agreement).
- Compliance with legal obligations, including labour and occupational health and safety regulations.
- Our legitimate interests in operating, securing, and improving the service.
3. How We Use Your Information
- To manage employee training compliance, certification tracking, and audit reporting.
- To send automated notifications about expiring or overdue training certificates.
- To process subscription payments and manage billing (R499/month or R4,990/year via PayFast).
- To provide role-based access control and multi-tenant data isolation between companies.
- To generate compliance reports for audit and regulatory purposes.
- To improve application performance, security, and user experience.
4. Data Isolation & Security
Your data is strictly isolated by company (tenant). Users cannot access another company's data. Access within your organisation is controlled through role-based permissions: Administrator, Operations Manager, Technical Specialist, Shift Supervisor, Technician, and Read Only.
We implement appropriate technical and organisational measures to safeguard personal information, including:
- Encryption of data in transit (HTTPS/TLS) and at rest.
- Secure authentication tokens with automatic session expiry.
- Regular security reviews and access audits.
- Row-level security policies enforced at the database level.
5. Sharing & Disclosure
We do not sell or rent your personal information. We share data only with:
- PayFast: Our payment service provider, for processing subscription payments. PayFast processes payment data in accordance with its own privacy policy and PCI-DSS compliance.
- Cloud infrastructure providers: For hosting and data storage, under strict data processing agreements.
- Legal authorities: Where required by South African law or a court order.
6. Data Retention
We retain personal information for as long as your account is active or as needed to comply with legal obligations. Upon account cancellation, your data is retained for 90 days (in a read-only state) to allow for resubscription, after which it may be permanently deleted. You may request earlier deletion of your data at any time by contacting support.
7. Your Rights Under POPIA
As a data subject, you have the right to:
- Access the personal information we hold about you.
- Correct or update inaccurate or incomplete personal information.
- Request deletion of your personal information (subject to legal retention requirements).
- Object to the processing of your personal information.
- Withdraw consent for processing at any time.
- Lodge a complaint with the Information Regulator of South Africa.
To exercise any of these rights, please contact our Information Officer at jacowentzel3@gmail.com.
8. Children's Privacy
This application is intended for workplace training compliance management and is not directed at children under 18. We do not knowingly collect personal information from minors. If you believe a child has provided personal information, please contact us so we can delete it.
9. Cross-Border Transfers
Your data may be processed on cloud infrastructure located outside South Africa. Where this occurs, we ensure that adequate safeguards are in place in accordance with POPIA requirements for cross-border information transfers.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes through the application or via email. Continued use of the service after changes constitutes acceptance of the revised policy.
11. Contact Us
For questions about this Privacy Policy, or to exercise your data protection rights, please contact our Information Officer:
- Email: jacowentzel3@gmail.com
- Or visit our Contact Support page.