POPIA-Aligned Data Protection Statement
Last updated: 2026/05/13
Privacy Practices ReviewedThis statement describes Tenders SA's current privacy and data protection approach. It is provided for transparency and user confidence.
It does not constitute legal advice, a formal POPIA certification, an independent audit report, or a guarantee that every operational process is legally compliant in all circumstances.
Where Tenders SA publishes evidence-backed trust badges, those badges are shown through the Trust Center and are limited to the specific evidence reviewed.
Tenders SA maintains a Trust Center where platform trust signals are explained separately from legal policy pages. The Trust Center is used to show public evidence summaries for platform identity, privacy approach, hosting location, security infrastructure, and tender data transparency.
View related trust evidence:
Tenders SA periodically reviews its data protection practices, hosting configuration, access controls, privacy notices, user rights handling, and platform safeguards.
Where an external legal, technical, or compliance review is completed, we will identify the reviewer, review date, scope, and public evidence available to users.
At present, this page explains our current privacy approach and operational safeguards. It should not be read as a formal compliance certificate.
We design our data handling around the eight conditions for lawful processing as outlined in POPIA:
1. Accountability
We take responsibility for personal information under our control and have designated an information officer to oversee privacy practices.
2. Processing Limitation
Personal information is processed lawfully and minimally, only for specified purposes with appropriate consent or legal basis.
3. Purpose Specification
We collect personal information for explicit, defined purposes and notify data subjects of these purposes at the time of collection.
4. Further Processing Limitation
Any additional processing is compatible with the original purpose and data subjects are notified of significant changes.
5. Information Quality
We maintain accurate, complete, and up-to-date personal information, with verification and correction procedures.
6. Openness
We maintain transparency about our data processing activities through comprehensive privacy notices.
7. Security Safeguards
Technical and organizational measures protect personal information against unauthorized access, loss, or damage.
8. Data Subject Participation
Data subjects can access, correct, and object to processing of their personal information through established procedures.
We have designated an information officer to oversee privacy practices and handle data subject requests.
Responsibilities
- Oversee data protection strategy
- Handle data subject requests
- Maintain privacy documentation
Contact for Privacy Concerns
For any privacy-related questions or data subject requests, please contact us at [email protected].
Depending on how users interact with Tenders SA, we may process account information, contact details, company profile information, tender preferences, saved opportunities, application support data, billing and subscription records, support messages, notification preferences, usage logs, and security-related records.
We aim to collect only the information needed to provide tender discovery, tender matching, account management, communication, payment, support, security, and platform improvement services.
We process information to operate user accounts, provide tender discovery and matching tools, support company profiles, send requested notifications, manage subscriptions, provide customer support, secure the platform, improve service quality, and comply with financial or legal recordkeeping obligations.
Tenders SA processes personal information only where there is a lawful reason to do so. Depending on the user interaction, this may include consent, contract or service delivery, legal obligations, and legitimate business interests.
Consent
Consent may apply to optional marketing communications, newsletters, and optional profile features.
Contract or Service Delivery
Contract or service delivery may apply to account creation, tender matching, recommendations, subscriptions, payment processing, support, and platform tools.
Legal Obligations
Legal obligations may apply to financial records, tax records, payment records, audit logs, and security records.
Legitimate Business Interests
Legitimate business interests may apply to fraud prevention, platform security, analytics, service improvement, and operational reliability, provided those interests do not unfairly override user rights.
Tenders SA uses cloud infrastructure to operate the platform and deliver tender discovery, account, notification, matching, subscription, and support services.
Where applicable, core platform hosting is configured to support South African data residency through AWS South Africa infrastructure. Some third-party services, such as payment providers, email delivery providers, analytics tools, monitoring tools, or AI service providers, may process limited information outside South Africa depending on their own infrastructure, contractual terms, and technical requirements.
We aim to minimise unnecessary data transfers and use service providers that support appropriate security, confidentiality, and operational safeguards.
Tenders SA may use AI-assisted systems to summarise tender information, classify opportunities, extract requirements, support tender matching, generate recommendations, and help users prepare tender applications.
AI-assisted processing is used to improve platform functionality and user experience. It does not replace official tender source documents, government notices, issuing organisation instructions, or user verification of final tender requirements.
Where personal or company profile information is used to support matching or recommendations, it is processed for platform service delivery and user-requested functionality.
Tenders SA applies technical and organisational safeguards designed to protect personal information against unauthorised access, loss, misuse, alteration, or disclosure.
Technical Safeguards
- HTTPS for data in transit
- Access controls
- Password hashing
- Role-based permissions
Organisational Safeguards
- Production access restrictions
- Logging and monitoring
- Backup controls
- Incident response procedures
Security controls are reviewed periodically and improved as the platform evolves.
View Security EvidenceUsers may contact Tenders SA to request access to personal information, correction of inaccurate information, deletion where legally appropriate, objection to direct marketing, or clarification about how their information is processed.
To help us process a request, users should provide their name, account email address, request type, and enough detail for us to identify the relevant account or record.
We may need to verify identity before making account or data changes. We aim to respond within a reasonable period and in line with applicable POPIA requirements.
Right to Access
Request confirmation of whether we process your personal information.
Right to Correction
Request correction of inaccurate or incomplete information.
Right to Deletion
Request deletion where legally appropriate.
Right to Object
Object to processing for direct marketing.
Right to Data Portability
Request your personal information in a structured, machine-readable format.
Right to Lodge Complaints
Lodge complaints with the Information Regulator if you believe your rights have been violated.
How to Exercise Your Rights
To exercise any of these rights, please contact us:
- Contact [email protected]
- Provide your full name and contact details for verification
- Clearly specify which right you wish to exercise
- Include any relevant details to help us locate your information
We will respond to your request within a reasonable period.
We engage carefully selected third-party service providers to help us operate the platform and deliver services.
| Provider | Purpose | Location |
|---|---|---|
| PayPal | Payment processing | United Kingdom |
| Resend | Email delivery | United States |
| Cloudflare | Content delivery and security | Global network |
| AWS | Cloud infrastructure | South Africa |
Service providers are bound by contractual terms that require appropriate security and confidentiality measures.
We retain personal information only as long as necessary for the purposes for which it was collected, or as required by law.
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Account Information | Until account deletion | Service provision |
| Application Data | 7 years | Tax compliance |
| Financial Records | 7 years | Tax compliance |
| Communication Logs | 3 years | Dispute resolution |
| Security Logs | 2 years | Security |
The Information Regulator is South Africa's independent body responsible for overseeing compliance with POPIA and handling data protection complaints.
Contact Information
Complaint Process
- Submit complaint in writing to the Regulator
- Include all relevant documentation
- Allow time for initial assessment
- Cooperate with any investigation
- Receive written decision with findings
When to Contact the Regulator
Contact the Information Regulator if you believe we have violated your POPIA rights or if you are not satisfied with our response to your data protection concerns.
This POPIA-Aligned Data Protection Statement should be read in conjunction with our other legal and privacy documents:
If you believe your personal information has been handled incorrectly, please contact us first so we can investigate and respond.
Privacy Contact
Physical Address
Managa Complex
Shoprite USave Street
Thohoyandou, Limpopo, 0950
External Complaint Option
You may also contact the Information Regulator of South Africa if you are not satisfied with the outcome of your complaint.
We regularly review and update our data protection approach to ensure continued alignment with regulatory requirements and industry best practices.
Update Process
- Regular review of privacy practices
- Policy updates as needed
- User notification for significant changes
Notification of Changes
We will notify you of any material changes to our privacy approach through email notifications and prominent notices on our website before changes take effect.
For any privacy or data protection questions, please contact us:
Privacy Inquiries
Physical Address
Managa Complex
Shoprite USave Street
Thohoyandou, Limpopo, 0950
Business Hours: Monday to Friday, 9:00 AM - 5:00 PM SAST
This statement is governed by and construed in accordance with the laws of South Africa, including the Protection of Personal Information Act, 2013.