PRIVACY POLICY

Last Updated: January 2026

This Privacy Policy describes how VuzoPay (Pty) Ltd ("VuzoPay", "we", "us", or "our") collects, uses, discloses, and protects personal information in accordance with the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) ("POPIA") and other applicable South African laws. By using our services, you consent to the data practices described in this policy.

1. Information We Collect

1.1 Personal Information

We collect the following categories of personal information:

  • Identity Information: Full names, ID numbers, passport numbers, date of birth, nationality, gender, and photographs
  • Contact Information: Physical addresses, email addresses, telephone numbers, and WhatsApp numbers
  • Employment Information: Job titles, employment dates, salary information, tax numbers, UIF numbers, and employment contracts
  • Financial Information: Bank account details, payment history, and payroll records
  • Background Check Information: Criminal records, credit history, employment references, and educational qualifications

1.2 Automatically Collected Information

We automatically collect certain information when you use our platform:

  • Usage Data: IP addresses, browser type, device information, pages visited, and time spent on pages
  • Cookies and Similar Technologies: Session cookies, authentication tokens, and analytics data
  • Log Data: System logs, error reports, and security event logs

2. Legal Basis for Processing

We process personal information on the following legal grounds:

  • Consent: You have given explicit consent for processing your personal information for specific purposes
  • Contractual Necessity: Processing is necessary to perform our contractual obligations to provide payroll and HR services
  • Legal Obligation: Processing is required to comply with South African labour laws, tax regulations, UIF requirements, and other statutory obligations
  • Legitimate Interests: Processing is necessary for our legitimate business interests, such as fraud prevention, system security, and service improvement

3. How We Use Your Information

3.1 Primary Purposes

  • Process payroll and generate payslips
  • Calculate and remit statutory deductions (UIF, PAYE, SDL)
  • Manage leave applications and accruals
  • Generate and manage employment contracts
  • Conduct background screening and verification checks
  • Facilitate WhatsApp communications for payslip delivery and leave requests

3.2 Secondary Purposes

  • Provide customer support and respond to inquiries
  • Improve and optimize our services through analytics
  • Detect and prevent fraud, security breaches, and unauthorized access
  • Send service notifications, updates, and administrative messages
  • Comply with legal obligations and respond to lawful requests from authorities

4. Information Sharing and Disclosure

We may share your personal information with the following third parties:

  • Service Providers: Google Cloud Platform (hosting), ThisIsMe (background checks), WhatsApp Business API (communications), and payment processors
  • Government Authorities: SARS (tax compliance), Department of Labour (UIF submissions), Department of Home Affairs (identity verification), and SAPS (criminal record checks)
  • Legal and Regulatory Bodies: When required by law, court order, or regulatory requirement
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity

We ensure all third parties are bound by appropriate data protection agreements and process personal information only for specified purposes.

5. Data Security Measures

We implement comprehensive security measures to protect your personal information:

  • Encryption: All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption
  • Access Controls: Role-based access controls, multi-factor authentication, and regular access reviews
  • Infrastructure Security: Data stored on Google Cloud Platform infrastructure in South Africa with enterprise-grade security
  • Monitoring: 24/7 security monitoring, intrusion detection systems, and regular security audits
  • Backups: Regular encrypted backups with disaster recovery procedures
  • Employee Training: All employees undergo regular data protection and security awareness training

6. Data Retention

We retain personal information for the following periods:

  • Payroll Records: 5 years from the date of last employment, as required by the Basic Conditions of Employment Act
  • Tax Records: 5 years from the date of submission, as required by the Income Tax Act
  • Employment Contracts: 3 years after termination of employment
  • Background Check Results: 1 year from the date of the check, unless required for ongoing employment
  • Account Information: Duration of active subscription plus 1 year after cancellation

After the retention period expires, we securely delete or anonymize personal information unless longer retention is required by law or for legitimate business purposes.

7. Your Rights Under POPIA

As a data subject, you have the following rights:

  • Right to Access: Request confirmation of whether we hold your personal information and obtain a copy
  • Right to Correction: Request correction of inaccurate or incomplete personal information
  • Right to Deletion: Request deletion of personal information where there is no legal basis for continued processing
  • Right to Object: Object to processing of personal information for direct marketing or other purposes
  • Right to Restriction: Request restriction of processing in certain circumstances
  • Right to Data Portability: Receive your personal information in a structured, commonly used format
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
  • Right to Complain: Lodge a complaint with the Information Regulator of South Africa

To exercise any of these rights, contact our Information Officer at info@vuzopay.com. We will respond to your request within 30 days.

8. Cookies and Tracking Technologies

We use cookies and similar technologies for:

  • Essential Cookies: Required for authentication, security, and basic functionality
  • Analytics Cookies: Help us understand how users interact with our platform
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings. Note that disabling essential cookies may affect platform functionality.

9. International Data Transfers

All personal information is stored and processed within South Africa on Google Cloud Platform infrastructure. We do not transfer personal information outside of South Africa except where necessary for specific services (e.g., WhatsApp communications) and only with appropriate safeguards in place, including standard contractual clauses and adequacy assessments.

10. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us immediately at info@vuzopay.com.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. We will notify you of material changes by email or through a prominent notice on our platform. Your continued use of our services after such notification constitutes acceptance of the updated Privacy Policy.

12. Contact Information

For privacy-related inquiries, requests, or complaints, contact:

Information Officer: VuzoPay (Pty) Ltd

Email: info@vuzopay.com

Phone: +27 (0) 11 123 4567

Postal Address: VuzoPay (Pty) Ltd, P.O. Box 12345, Johannesburg, 2000, South Africa

You may also lodge a complaint with the Information Regulator of South Africa at www.justice.gov.za/inforeg/

Acknowledgment

By using VuzoPay's services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.