Privacy Policy
Last updated: [DATE] · Draft for review
This policy explains what personal information [Legal entity name] (“BPONitro”) collects, why, and your rights. It should be read with our POPIA / PAIA notice.
Information we collect
- Account data: your name, email, password (stored only as a hash), and profile details you provide (skills, location, languages).
- Connected-platform tokens: when you connect a third-party account, we store the access credentials encrypted and use them only to act on your behalf at your direction.
- Usage and engagement data: opportunities matched, proposals, messages routed through the blind relay, and engagement/payment records needed to run the Service.
- Billing data: handled by our payment provider; we do not store full card numbers.
- Technical data: log and device data for security and reliability.
Why we use it (lawful basis)
To provide the Service and perform our contract with you; to secure the platform and prevent fraud; to comply with legal obligations; and, where relevant, on the basis of your consent (which you may withdraw). We do not sell your personal information.
Sharing
We share personal information only with processors who help us run the Service (hosting, email delivery, payment processing, object storage) under appropriate safeguards, and with the third-party platforms you choose to connect — acting through your own account. Our blind relay is designed so that a client and a provider do not see each other’s contact details unless you choose to share them.
Cross-border transfers
Some processors may store data outside South Africa. Where they do, we take steps required by POPIA to ensure comparable protection.
Retention
We keep personal information for as long as your account is active and as required to meet legal, tax, and audit obligations (including our tamper-evident ledger of engagement events), then delete or de-identify it.
Your rights
You may access, correct, or delete your personal information, object to processing, and request a data export. We provide account data export and erasure tools; erasure preserves only the minimum, de-identified records needed for the integrity of the audit ledger and for legal compliance. To exercise a right, contact our Information Officer (see the POPIA / PAIA notice).
Security
We use encryption for connected-platform credentials, hashed passwords, role-based access controls, and an append-only audit ledger. No system is perfectly secure; we will notify you and the Information Regulator of a compromise as required by law.
Contact
Information Officer: [name], [email]. Postal address: [address].