Privacy Notice

    Last updated: February 2026 | Compliant with POPIA (Protection of Personal Information Act)

    1. Introduction

    Appsentia ("we", "us", or "our") is committed to protecting your personal information and respecting your privacy. This Privacy Notice explains how we collect, use, store, and protect your personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA) of South Africa.

    As a workforce absenteeism analytics platform, we process sensitive employee data on behalf of our clients (companies). We act as an "operator" under POPIA when processing data on behalf of clients, and as a "responsible party" for our own user account data.

    2. Information We Collect

    Employee Data (processed on behalf of clients)

    • Employee names and employee numbers
    • Department and job title information
    • Employment dates (start date, termination date)
    • Leave records (dates, types, duration)
    • Salary information (for cost calculations only)

    User Account Data

    • Name and email address
    • Company association and role
    • Authentication credentials (encrypted)
    • Usage data and audit logs

    Technical Data

    • IP addresses and browser information
    • Access timestamps and session data
    • Device and platform information
    3. Purpose of Processing

    We process personal information for the following lawful purposes:

    • Contract Performance: To provide workforce analytics services as agreed with your employer
    • Legitimate Interest: To analyse absenteeism patterns, identify trends, and provide actionable insights
    • Legal Obligation: To comply with employment law record-keeping requirements
    • Security: To protect our systems and detect fraudulent activity

    We do not use personal information for automated decision-making that produces legal effects on individuals. All analytics are used for business insights and reporting purposes only.

    4. How We Protect Your Information

    Technical Safeguards

    • Encryption at Rest: All data stored in encrypted databases
    • Encryption in Transit: TLS 1.2+ for all communications
    • Access Control: Role-based permissions with company-level isolation
    • Audit Logging: Comprehensive logging of all data access and changes
    • Password Security: Bcrypt hashing with secure authentication

    Organisational Safeguards

    • Regular security assessments and updates
    • Incident response procedures
    • Data minimisation practices
    • Employee training on data protection
    5. Your Rights Under POPIA

    As a data subject, you have the following rights:

    Right of Access (Section 23)

    You may request confirmation of whether we hold personal information about you and request access to that information.

    Right to Correction (Section 24)

    You may request that we correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully.

    Right to Deletion

    You may request deletion of your personal information, subject to legal retention requirements.

    Right to Object (Section 11)

    You may object to the processing of your personal information on reasonable grounds.

    Right to Complain

    You may lodge a complaint with the Information Regulator if you believe your rights have been infringed.

    How to Exercise Your Rights: Contact your employer's HR department or designated Information Officer, who can facilitate your request through the platform. For user account data, contact us directly.

    6. Data Sharing and Transfers

    Third-Party Service Providers

    We use the following service providers who may process personal information:

    • Neon (Database Hosting): Secure cloud database storage
    • PayFast (Payments): Subscription payment processing (South Africa)
    • HRIS Integrations: When enabled by your employer (e.g., Payspace)

    Cross-Border Transfers

    Some data may be processed in countries outside South Africa. Where this occurs, we ensure adequate protection through contractual safeguards and security measures as required by POPIA Section 72.

    No Selling of Data

    We do not sell, rent, or trade personal information to third parties for marketing purposes.

    7. Data Retention

    We retain personal information only for as long as necessary:

    • Employee Data: Duration of employment plus 5 years (as required for employment records)
    • Leave Records: 5 years from the date of the record
    • User Accounts: Account lifetime plus 1 year after deletion
    • Audit Logs: 7 years (for compliance and security purposes)

    Upon termination of a client's subscription, data is retained for 90 days before permanent deletion, unless longer retention is required by law.

    8. Security Breach Notification

    In the event of a security breach that compromises personal information, we will:

    • Notify the Information Regulator as soon as reasonably possible
    • Notify affected data subjects where there is a risk of harm
    • Provide details of the breach and remedial measures taken
    • Take immediate steps to contain and remedy the breach

    Our incident response procedures ensure breaches are detected, contained, and reported in accordance with POPIA Section 22.

    9. Contact Information

    For Privacy Enquiries

    If you have questions about this Privacy Notice or wish to exercise your rights, please contact:

    • Email: privacy@appsentia.com
    • Support: Through the in-app support channel

    Information Regulator

    If you are not satisfied with our response, you may contact the Information Regulator:

    10. Changes to This Notice

    We may update this Privacy Notice from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:

    • Posting the updated notice on our platform
    • Updating the "Last updated" date at the top
    • Sending an email notification for significant changes

    We encourage you to review this notice periodically to stay informed about how we protect your information.

    This Privacy Notice is provided in accordance with the Protection of Personal Information Act, 2013 (POPIA) of South Africa. For technical compliance details, please refer to our full POPIA Compliance Documentation.