Privacy Notice
Last updated: February 2026 | Compliant with POPIA (Protection of Personal Information Act)
Appsentia ("we", "us", or "our") is committed to protecting your personal information and respecting your privacy. This Privacy Notice explains how we collect, use, store, and protect your personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA) of South Africa.
As a workforce absenteeism analytics platform, we process sensitive employee data on behalf of our clients (companies). We act as an "operator" under POPIA when processing data on behalf of clients, and as a "responsible party" for our own user account data.
Employee Data (processed on behalf of clients)
- Employee names and employee numbers
- Department and job title information
- Employment dates (start date, termination date)
- Leave records (dates, types, duration)
- Salary information (for cost calculations only)
User Account Data
- Name and email address
- Company association and role
- Authentication credentials (encrypted)
- Usage data and audit logs
Technical Data
- IP addresses and browser information
- Access timestamps and session data
- Device and platform information
We process personal information for the following lawful purposes:
- Contract Performance: To provide workforce analytics services as agreed with your employer
- Legitimate Interest: To analyse absenteeism patterns, identify trends, and provide actionable insights
- Legal Obligation: To comply with employment law record-keeping requirements
- Security: To protect our systems and detect fraudulent activity
We do not use personal information for automated decision-making that produces legal effects on individuals. All analytics are used for business insights and reporting purposes only.
Technical Safeguards
- Encryption at Rest: All data stored in encrypted databases
- Encryption in Transit: TLS 1.2+ for all communications
- Access Control: Role-based permissions with company-level isolation
- Audit Logging: Comprehensive logging of all data access and changes
- Password Security: Bcrypt hashing with secure authentication
Organisational Safeguards
- Regular security assessments and updates
- Incident response procedures
- Data minimisation practices
- Employee training on data protection
As a data subject, you have the following rights:
Right of Access (Section 23)
You may request confirmation of whether we hold personal information about you and request access to that information.
Right to Correction (Section 24)
You may request that we correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully.
Right to Deletion
You may request deletion of your personal information, subject to legal retention requirements.
Right to Object (Section 11)
You may object to the processing of your personal information on reasonable grounds.
Right to Complain
You may lodge a complaint with the Information Regulator if you believe your rights have been infringed.
How to Exercise Your Rights: Contact your employer's HR department or designated Information Officer, who can facilitate your request through the platform. For user account data, contact us directly.
Third-Party Service Providers
We use the following service providers who may process personal information:
- Neon (Database Hosting): Secure cloud database storage
- PayFast (Payments): Subscription payment processing (South Africa)
- HRIS Integrations: When enabled by your employer (e.g., Payspace)
Cross-Border Transfers
Some data may be processed in countries outside South Africa. Where this occurs, we ensure adequate protection through contractual safeguards and security measures as required by POPIA Section 72.
No Selling of Data
We do not sell, rent, or trade personal information to third parties for marketing purposes.
We retain personal information only for as long as necessary:
- Employee Data: Duration of employment plus 5 years (as required for employment records)
- Leave Records: 5 years from the date of the record
- User Accounts: Account lifetime plus 1 year after deletion
- Audit Logs: 7 years (for compliance and security purposes)
Upon termination of a client's subscription, data is retained for 90 days before permanent deletion, unless longer retention is required by law.
In the event of a security breach that compromises personal information, we will:
- Notify the Information Regulator as soon as reasonably possible
- Notify affected data subjects where there is a risk of harm
- Provide details of the breach and remedial measures taken
- Take immediate steps to contain and remedy the breach
Our incident response procedures ensure breaches are detected, contained, and reported in accordance with POPIA Section 22.
For Privacy Enquiries
If you have questions about this Privacy Notice or wish to exercise your rights, please contact:
- Email: privacy@appsentia.com
- Support: Through the in-app support channel
Information Regulator
If you are not satisfied with our response, you may contact the Information Regulator:
- Website: www.justice.gov.za/inforeg/
- Email: complaints.IR@justice.gov.za
We may update this Privacy Notice from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:
- Posting the updated notice on our platform
- Updating the "Last updated" date at the top
- Sending an email notification for significant changes
We encourage you to review this notice periodically to stay informed about how we protect your information.
This Privacy Notice is provided in accordance with the Protection of Personal Information Act, 2013 (POPIA) of South Africa. For technical compliance details, please refer to our full POPIA Compliance Documentation.