Skip to main content

POPIA-Aligned Data Protection Statement

Last updated: 2026/05/13

Privacy Practices Reviewed
Important Notice

This statement describes Tenders SA's current privacy and data protection approach. It is provided for transparency and user confidence.

It does not constitute legal advice, a formal POPIA certification, an independent audit report, or a guarantee that every operational process is legally compliant in all circumstances.

Where Tenders SA publishes evidence-backed trust badges, those badges are shown through the Trust Center and are limited to the specific evidence reviewed.

Trust Center Evidence

Tenders SA maintains a Trust Center where platform trust signals are explained separately from legal policy pages. The Trust Center is used to show public evidence summaries for platform identity, privacy approach, hosting location, security infrastructure, and tender data transparency.

View related trust evidence:

Data Protection Review

Tenders SA periodically reviews its data protection practices, hosting configuration, access controls, privacy notices, user rights handling, and platform safeguards.

Where an external legal, technical, or compliance review is completed, we will identify the reviewer, review date, scope, and public evidence available to users.

At present, this page explains our current privacy approach and operational safeguards. It should not be read as a formal compliance certificate.

POPIA Principles for Lawful Processing

We design our data handling around the eight conditions for lawful processing as outlined in POPIA:

1. Accountability

We take responsibility for personal information under our control and have designated an information officer to oversee privacy practices.

2. Processing Limitation

Personal information is processed lawfully and minimally, only for specified purposes with appropriate consent or legal basis.

3. Purpose Specification

We collect personal information for explicit, defined purposes and notify data subjects of these purposes at the time of collection.

4. Further Processing Limitation

Any additional processing is compatible with the original purpose and data subjects are notified of significant changes.

5. Information Quality

We maintain accurate, complete, and up-to-date personal information, with verification and correction procedures.

6. Openness

We maintain transparency about our data processing activities through comprehensive privacy notices.

7. Security Safeguards

Technical and organizational measures protect personal information against unauthorized access, loss, or damage.

8. Data Subject Participation

Data subjects can access, correct, and object to processing of their personal information through established procedures.

Information Officer / Privacy Contact

We have designated an information officer to oversee privacy practices and handle data subject requests.

Responsibilities

  • Oversee data protection strategy
  • Handle data subject requests
  • Maintain privacy documentation

Contact for Privacy Concerns

For any privacy-related questions or data subject requests, please contact us at [email protected].

What Information We Process

Depending on how users interact with Tenders SA, we may process account information, contact details, company profile information, tender preferences, saved opportunities, application support data, billing and subscription records, support messages, notification preferences, usage logs, and security-related records.

We aim to collect only the information needed to provide tender discovery, tender matching, account management, communication, payment, support, security, and platform improvement services.

Why We Process Information

We process information to operate user accounts, provide tender discovery and matching tools, support company profiles, send requested notifications, manage subscriptions, provide customer support, secure the platform, improve service quality, and comply with financial or legal recordkeeping obligations.

Lawful Processing Approach

Tenders SA processes personal information only where there is a lawful reason to do so. Depending on the user interaction, this may include consent, contract or service delivery, legal obligations, and legitimate business interests.

Consent

Consent may apply to optional marketing communications, newsletters, and optional profile features.

Contract or Service Delivery

Contract or service delivery may apply to account creation, tender matching, recommendations, subscriptions, payment processing, support, and platform tools.

Legal Obligations

Legal obligations may apply to financial records, tax records, payment records, audit logs, and security records.

Legitimate Business Interests

Legitimate business interests may apply to fraud prevention, platform security, analytics, service improvement, and operational reliability, provided those interests do not unfairly override user rights.

Hosting and Data Residency

Tenders SA uses cloud infrastructure to operate the platform and deliver tender discovery, account, notification, matching, subscription, and support services.

Where applicable, core platform hosting is configured to support South African data residency through AWS South Africa infrastructure. Some third-party services, such as payment providers, email delivery providers, analytics tools, monitoring tools, or AI service providers, may process limited information outside South Africa depending on their own infrastructure, contractual terms, and technical requirements.

We aim to minimise unnecessary data transfers and use service providers that support appropriate security, confidentiality, and operational safeguards.

AI-Assisted Processing

Tenders SA may use AI-assisted systems to summarise tender information, classify opportunities, extract requirements, support tender matching, generate recommendations, and help users prepare tender applications.

AI-assisted processing is used to improve platform functionality and user experience. It does not replace official tender source documents, government notices, issuing organisation instructions, or user verification of final tender requirements.

Where personal or company profile information is used to support matching or recommendations, it is processed for platform service delivery and user-requested functionality.

Security Safeguards

Tenders SA applies technical and organisational safeguards designed to protect personal information against unauthorised access, loss, misuse, alteration, or disclosure.

Technical Safeguards

  • HTTPS for data in transit
  • Access controls
  • Password hashing
  • Role-based permissions

Organisational Safeguards

  • Production access restrictions
  • Logging and monitoring
  • Backup controls
  • Incident response procedures

Security controls are reviewed periodically and improved as the platform evolves.

View Security Evidence
User Rights

Users may contact Tenders SA to request access to personal information, correction of inaccurate information, deletion where legally appropriate, objection to direct marketing, or clarification about how their information is processed.

To help us process a request, users should provide their name, account email address, request type, and enough detail for us to identify the relevant account or record.

We may need to verify identity before making account or data changes. We aim to respond within a reasonable period and in line with applicable POPIA requirements.

Right to Access

Request confirmation of whether we process your personal information.

Right to Correction

Request correction of inaccurate or incomplete information.

Right to Deletion

Request deletion where legally appropriate.

Right to Object

Object to processing for direct marketing.

Additional Data Subject Rights

Right to Data Portability

Request your personal information in a structured, machine-readable format.

Right to Lodge Complaints

Lodge complaints with the Information Regulator if you believe your rights have been violated.

How to Exercise Your Rights

To exercise any of these rights, please contact us:

  1. Contact [email protected]
  2. Provide your full name and contact details for verification
  3. Clearly specify which right you wish to exercise
  4. Include any relevant details to help us locate your information

We will respond to your request within a reasonable period.

Third-Party Service Providers

We engage carefully selected third-party service providers to help us operate the platform and deliver services.

ProviderPurposeLocation
PayPalPayment processingUnited Kingdom
ResendEmail deliveryUnited States
CloudflareContent delivery and securityGlobal network
AWSCloud infrastructureSouth Africa

Service providers are bound by contractual terms that require appropriate security and confidentiality measures.

Retention and Deletion

We retain personal information only as long as necessary for the purposes for which it was collected, or as required by law.

Data CategoryRetention PeriodLegal Basis
Account InformationUntil account deletionService provision
Application Data7 yearsTax compliance
Financial Records7 yearsTax compliance
Communication Logs3 yearsDispute resolution
Security Logs2 yearsSecurity
Information Regulator

The Information Regulator is South Africa's independent body responsible for overseeing compliance with POPIA and handling data protection complaints.

Contact Information

Website: https://inforegulator.org.za

Email: [email protected]

Phone: 012 406 4818

Complaint Process

  1. Submit complaint in writing to the Regulator
  2. Include all relevant documentation
  3. Allow time for initial assessment
  4. Cooperate with any investigation
  5. Receive written decision with findings

When to Contact the Regulator

Contact the Information Regulator if you believe we have violated your POPIA rights or if you are not satisfied with our response to your data protection concerns.

Related Policies and Documents

This POPIA-Aligned Data Protection Statement should be read in conjunction with our other legal and privacy documents:

Complaints and Privacy Contact

If you believe your personal information has been handled incorrectly, please contact us first so we can investigate and respond.

Privacy Contact

Physical Address

Managa Complex
Shoprite USave Street
Thohoyandou, Limpopo, 0950

External Complaint Option

You may also contact the Information Regulator of South Africa if you are not satisfied with the outcome of your complaint.

Review Cycle and Updates

We regularly review and update our data protection approach to ensure continued alignment with regulatory requirements and industry best practices.

Update Process

  • Regular review of privacy practices
  • Policy updates as needed
  • User notification for significant changes

Notification of Changes

We will notify you of any material changes to our privacy approach through email notifications and prominent notices on our website before changes take effect.

Contact Information

For any privacy or data protection questions, please contact us:

Privacy Inquiries

Physical Address

Managa Complex
Shoprite USave Street
Thohoyandou, Limpopo, 0950

Business Hours: Monday to Friday, 9:00 AM - 5:00 PM SAST

This statement is governed by and construed in accordance with the laws of South Africa, including the Protection of Personal Information Act, 2013.