POPIA Notice

Protection of Personal Information Act, 2013 ยท Last updated: 8 September 2026

This Notice explains how StakeholderConnect collects, uses, and protects personal information in line with POPIA.

1. The Responsible Party

StakeholderConnect (the "Platform"), operated from South Africa, is the responsible party for the personal information processed through the Platform and is accountable for compliance with the Protection of Personal Information Act, 2013 (POPIA).

2. Personal Information We Process

We process the personal information necessary to provide the Platform: name and surname, email address, role, organisation, contact details, and project-related records you or your administrator enter. We also process limited technical data (IP address, timestamps) for security and audit purposes.

3. Purposes & Lawful Basis

We process personal information to create and administer accounts, enforce role-based access, deliver project management and stakeholder governance features, maintain audit trails, and meet legal obligations. Processing is carried out with the consent of the data subject, to perform a contract, and to comply with legal duties.

4. Role-Based Access & Project Isolation

Access to personal and project information is restricted by role and by project membership at the data layer. A user may only view records their assigned role and project membership permit. Access is logged.

5. Sharing & Third Parties

We do not sell personal information. Information is shared only with authorised users per the access controls above, with cloud service providers under appropriate data-protection terms, and where required by law. Email and calendar integrations use connected accounts solely to send the messages and events you initiate.

6. Cross-Border Transfers

The Platform is hosted on cloud infrastructure that may process data outside South Africa. Where this occurs, we rely on standard contractual clauses and provider commitments to maintain POPIA-equivalent protection.

7. Retention

We retain personal information only as long as necessary for the purposes set out here, to meet legal or audit obligations, or as required for project record-keeping. Recycle-bin and archive features allow administrators to recover or remove records.

8. Security Safeguards

We apply encryption in transit and at rest, role-based access control, audit logging, and regular backups. Despite safeguards, no system is perfectly secure; we act promptly on reported incidents.

9. Your Rights

You may request access to, correction of, or deletion of your personal information, and may object to or restrict certain processing. To exercise these rights, contact the administrator or the contact details below. We respond within a reasonable period.

10. Direct Marketing & Cookies

We do not send unsolicited direct marketing without consent. The Platform uses essential cookies and local storage for authentication and usability; non-essential tracking is disabled unless you enable it.

11. Automated Processing

The Platform uses AI-assisted features (e.g. report drafting, risk suggestions). These assist users but do not make binding decisions about you without human review. You may opt not to use these features.

12. Data Subject Complaints

If you believe your rights under POPIA have been infringed, you may lodge a complaint with the Information Regulator (South Africa) at inforeg@inforegulator.org.za. We encourage you to contact us first so we can resolve your concern.