Privacy Notice
In this Privacy Notice, we describe how Profesaas (Pty) Ltd ("Profesaas", "we", "us", or "our") collects, uses, shares, and otherwise processes personal data in connection with our websites, products, services, and other offerings (collectively, the "Services"). This Privacy Notice applies to all users of our Services, including visitors, customers, administrators, and end users.
We are committed to protecting your privacy and handling your personal data in an open and transparent manner. We process personal data in compliance with applicable data protection laws, including the Protection of Personal Information Act, 2013 (POPIA) of South Africa and, where applicable, the United Kingdom General Data Protection Regulation and Data Protection Act 2018 (together, the "UK GDPR").
Profesaas as responsible party / controller. Profesaas (Pty) Ltd is the "responsible party" (as defined in POPIA) and the "controller" (as defined in the UK GDPR) for personal data relating to our own website visitors, prospective customers, account holders, and billing contacts — for example, when you browse our website and we place cookies in your browser, when you create a Profesaas Account, subscribe to a plan, or contact us. This Privacy Notice describes that processing, the purposes and lawful bases for it, and your rights. Our registered office and contact details, and the contact details of our Information Officer, appear in Sections 19 and 20 below.
Profesaas as operator / processor. Our Services are intended for and provided to businesses and organisations — companies, NPOs, education providers, and others (our "Customers") — for professional use. Data that a Customer loads into its workspace (donor records, form submissions, case files, learner and student records, and similar "Customer Data") is processed by Profesaas on behalf of and on the documented instructions of that Customer, in our capacity as an "operator" under section 20 and 21 of POPIA and a "processor" under Article 28 of the UK GDPR. For Customer Data, the Customer is the responsible party / controller and this Privacy Notice does not replace the Customer's own privacy notice. If you are a donor, applicant, beneficiary, learner, or other end user of a Customer's workspace, please read that organisation's privacy statement and direct privacy enquiries to that organisation first; we will assist Customers in responding as their operator. The safeguards we apply to Customer Data are described in Section 7 and in the data processing terms of our Terms of Service.
1. Definitions :
-
- "Personal Data" / "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an individual (and, under POPIA, to an identifiable existing juristic person). This includes but is not limited to names, email addresses, IP addresses, device identifiers, and usage data. The term does not include aggregated or de-identified information that is maintained in a form that is not reasonably capable of being associated with or linked to an individual. This term covers "personal information" as defined in POPIA and "personal data" as defined in the UK GDPR.
- "Profesaas Account" means the account you create to access our Services.
- "Services" means the Profesaas software platform, websites, APIs, and related services.
- "Tenant" means an organisation that has subscribed to our platform and uses it to manage their operations.
- "End User" means an individual who uses the Services through a Tenant's account, including donors, applicants, beneficiaries, learners, and students recorded in a Tenant's workspace.
- "Customer Data" means personal data relating to end users that we process on behalf of and at the direction of our Customers in our capacity as an operator or processor.
- "Responsible Party" / "Data Controller" means the entity that determines the purpose of and means for processing personal data ("responsible party" under POPIA; "controller" under the UK GDPR).
- "Operator" / "Data Processor" means the entity that processes personal data on behalf of and on the instructions of the Responsible Party ("operator" under POPIA; "processor" under the UK GDPR).
- "Information Officer" means the officer designated by Profesaas under section 55 of POPIA and Chapter 10 of the Promotion of Access to Information Act, 2000 (PAIA), responsible for encouraging and ensuring our compliance with POPIA.
- "Special Personal Information" / "Special Category Data" means personal data concerning a person's religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, or criminal behaviour (POPIA section 26), and the corresponding "special category data" under Article 9 of the UK GDPR, as well as account log-in credentials in combination with any required security or access code or password.
- "Competent Person" means any person who is legally competent to consent to any action or decision being taken in respect of any matter concerning a child, as defined in POPIA.
- "Tracking Technologies" means cookies, web beacons, pixels, embedded scripts, and similar technologies used to automatically collect information when you interact with our Services.
2. Why We Collect Data and What We Collect :
-
The personal data we collect depends on how you interact with us, the Services you use, and the choices you make. We collect and process personal data for the following purposes:
-
2.1 To Provide and Maintain Our Services
We collect data necessary to deliver our platform, including account information (name, email address, organization details), authentication credentials, and configuration preferences. This data is essential for creating and managing your account, providing access to platform features, processing transactions, verifying your identity and authorization, and delivering customer support.
-
2.2 Security and Fraud Prevention
We process data to protect the security of our Services and users, including IP addresses, login histories, session information, and device identifiers. This helps us detect and prevent unauthorized access, fraud, abuse, and security incidents, and to help maintain the safety, security, and integrity of our property, Services, technology assets, and business.
-
2.3 Usage Analytics and Improvement
We collect anonymized and aggregated usage data to understand how our Services are used and to improve them. This includes feature usage patterns, performance metrics, and error reports. We use this information to test, enhance, update, and monitor the Services, diagnose or fix problems, conduct research and analytics on our user base, and to improve and customize our Services to address the needs and interests of our users.
-
2.4 Communication and Direct Marketing
We use your contact information to send service notifications and, where permitted, product updates, newsletters, and promotional materials. We comply with section 69 of POPIA and, for UK recipients, the Privacy and Electronic Communications Regulations (PECR): we will only send electronic direct marketing to you if you have opted in, or if you are an existing customer whose details we obtained in the context of a sale of a similar service and you were given the opportunity to object when we collected your details. Every marketing message we send includes a working unsubscribe mechanism, and you can opt out at any time free of charge. We will not approach you for marketing consent more than once if you decline. Opting out of marketing does not affect essential service communications (billing, security, and account notices).
-
2.5 Legal Compliance
We process personal data as required by applicable laws, regulations, and legal processes, including tax obligations, regulatory reporting, and responding to lawful requests from authorities. We may also process data to enforce our Terms of Service, to resolve disputes, to carry out our obligations, and to protect our business interests and the interests and rights of third parties.
-
2.6 Managing Our Organization
We use personal data to manage our organization and its day-to-day business operations, facilitate customer relationships through benefits and services including customer support, and to fulfill any other purpose for which you provide personal data or to which you consent.
-
2.7 Types of Data We Collect
We collect personal data from different sources and in various ways when you use our Services:
Personal Data Collected Directly From You- Identity & Contact Data: First and last name, job title, organization name, email address, phone number, physical address, country or region, and communication preferences.
- Account Data: Username, password (encrypted), profile information, customer ID, user ID, account preferences, and history of services obtained or purchased.
- Transaction Data: Subscription details, payment history, invoices, and billing information. Please note we use third-party payment processors and do not store credit card details directly.
- Communication & Inquiry Data: Support tickets, feedback, correspondence, information provided in forms, chat messages, and any other information you provide when contacting us or subscribing to our communications.
- Demographic Data: Occupation, job level, or similar demographic details that may be collected when you complete a survey, register for an event, or fill out registration forms.
- Event & Survey Data: Registration information, attendee details, survey responses, and feedback provided in connection with events, webinars, or surveys.
Personal Data Collected AutomaticallyWe, and our third-party providers, automatically collect information when you visit our Services through cookies, server logs, and similar tracking technologies. This includes:
- Device & Technical Data: IP address, browser type and version, Internet service provider, device type, model and manufacturer, operating system, date and time stamps, and unique device identifiers that allow us to identify your browser or device.
- Usage Data: Pages visited, features used, time spent on pages, the site from which you came and the site to which you go when leaving our Services, how frequently you access the Services, links you click, interaction patterns, and other browsing behaviour and actions.
- Location Data: General geographic location (such as city, province, and country) derived from your IP address.
- Analytics Data: First-party usage measurements derived from our own server logs, used to understand traffic and usage trends for the Services. We do not currently use third-party analytics tools (see Section 11).
The information collected automatically allows us to improve your experience, enhance and personalize our Services, monitor and improve our platform, and improve the effectiveness of our Services and communications.
Personal Data We Infer or GenerateWe may infer new information from other data we collect, including using automated means to generate information about your likely preferences or other characteristics. For example, we may infer your general geographic location based on your IP address or your interests based on your usage patterns on our Services.
Personal Data from Other SourcesWe may obtain personal data from other sources, which we may combine with personal data we collect automatically or directly from you, including:
- From your organization: If you are an End User, your Tenant administrator may provide us with your information when setting up your account, or your employer may provide your information when engaging with our Services.
- Authentication providers: When you sign in using third-party authentication services (such as Google or LinkedIn), we receive information they share with us such as your name, email, and profile details.
- Service providers: Our service providers who perform services on our behalf, such as payment processors, analytics providers, and cloud-hosting services, may share information with us.
- Social media: When you interact with our Services through social media networks, we may receive information about you that you permit the social network to share with third parties, dependent upon your privacy settings.
- Publicly available sources: We may collect personal data from publicly available sources, third-party data providers, or through business transactions such as mergers and acquisitions.
-
When you are asked to provide personal data, you may decline. You may also use web browser or operating system controls to prevent certain types of automatic data collection. However, if you choose not to provide or allow information that is necessary for certain Services or features, those Services or features may not be available or fully functional.
3. How We Collect Data :
-
We collect personal data through the following methods:
- Directly from you: When you create an account, fill out forms, contact us, subscribe to our newsletter, submit surveys or feedback, register for events, request a product demonstration, or otherwise provide information to us.
- Automatically: When you use our Services, we automatically collect certain technical and usage data through first-party cookies and server logs, as described in Section 11. We do not currently use third-party tracking tools on our Services.
- From your organization: If you are an End User, your Tenant administrator may provide us with your information when setting up your account. If you interact with our Services through your employer or company, we may receive your information from your employer or company.
- From third parties: We may receive data from authentication providers (such as Google or LinkedIn), payment processors, analytics services, and social media platforms.
- From service providers: Our service providers who perform services on our behalf, such as cloud-hosting services, payment processors, and communications providers, may collect and share personal data with us.
- From publicly available sources: We may collect personal data from publicly available sources or third-party data providers to correct or supplement personal data we collect.
4. Children's Privacy :
-
Profesaas Accounts. Our Services are designed for organisational use. We do not knowingly create Profesaas Accounts for, or collect account or billing data directly from, children under the age of 18 for our own purposes. If we learn that account data we hold as responsible party / controller was provided by a child, we will promptly delete it. A parent, guardian, or competent person may contact us at privacy@profesaas.com to request removal.
Children's information in Tenant workspaces. We recognise that our Customers — for example schools, education funds, and social-support organisations — may lawfully record personal information of children (persons under 18) in their workspaces, such as learner and case records. For that Customer Data, the Tenant is the responsible party / controller and Profesaas is the operator / processor. Section 34 of POPIA prohibits processing children's personal information unless an exception in section 35 applies — most commonly the prior consent of a competent person (a parent or guardian), or where processing is necessary for the establishment, exercise, or defence of a right or obligation in law. It is the Tenant's responsibility to obtain competent-person consent or to ensure another section 35 ground (or, for UK data, an Article 6 and where relevant Article 8 UK GDPR basis) applies before loading children's information. We support Tenants with the technical and organisational safeguards described in Section 7, including role-based access restrictions and audit logging of access to records.
5. Transparency :
-
We are committed to being transparent about our data practices. Before or at the time of collecting personal data, we will inform you about the categories of data being collected, the purposes for which it will be used, and how you can manage your data. Where we rely on consent, we will obtain clear and affirmative consent before processing your data.
6. Sharing of Personal Data :
-
We may disclose, share, transmit, grant access to, make available, and provide personal data with and to internal and external recipients, as follows:
- Profesaas Affiliates: We may share personal data with companies owned or controlled by Profesaas, and other companies under common ownership, particularly when we collaborate in providing the Services.
- Service Providers: Third-party vendors who assist us in providing our Services, such as cloud hosting providers (including infrastructure provisioning and IT services), payment processors, email service providers, analytics platforms, chat functionality services, and administrative services. These providers are contractually bound to protect your data and process it only for limited and specified purposes.
- Tenant Administrators: If you are an End User, your Tenant administrator may have access to your account information and usage data within their organization's scope.
- Your Employer / Organization: If you interact with our Services through your employer or company, we may disclose your information to your employer or company, including another representative of your employer or company.
- Marketing Providers: We may coordinate and share personal data with marketing providers in order to communicate with individuals about the Services we make available, where you have consented to receive such communications.
- Analytics Providers: We work with third-party analytics providers to help us understand how our Services are used. These parties may collect information through cookies or other tracking technologies.
- Customer Service and Communication Providers: We share personal data with third parties who assist us in providing customer services and facilitating our communications with individuals that submit inquiries.
- Business Partners: We may share personal data with select business partners who provide products or services that we believe may be of interest to users of our Services, where permitted by law.
- Legal and Regulatory Bodies: We may disclose data to third parties, such as legal advisors and law enforcement, in connection with the establishment, exercise, or defence of legal claims; to comply with laws or respond to lawful requests and legal process; to protect our rights and property and those of others; to detect, suppress, or prevent fraud; to protect the health and safety of us and others; or as otherwise required by applicable law.
- Business Transfers: We may take part in or be involved with a corporate business transaction, such as a merger, acquisition, joint venture, or financing or sale of company assets. We may disclose personal data to a third party during negotiation of, in connection with, or as an asset in such a transaction. Personal data may also be disclosed in the event of insolvency, bankruptcy, or receivership.
- With Your Consent: We may disclose personal data about an individual to certain other third parties or publicly with their consent or direction.
We do not sell your personal data to third parties for monetary or other valuable consideration. Where we transfer personal data to a third party acting on our behalf, we take reasonable and appropriate steps to ensure the third party processes personal data for limited and specified purposes and in a manner consistent with our obligations.
-
Subprocessors
The following subprocessors support the delivery of the Services, for both our own processing and Customer Data we process as operator / processor. Each is bound by a written agreement imposing confidentiality and security obligations consistent with section 21 of POPIA and Article 28 of the UK GDPR:
- Microsoft Azure (Microsoft Corporation): Cloud infrastructure — application hosting, databases, and file storage, in South African and EU regions.
- Stripe: Payment processing for subscriptions and invoices. Stripe handles card details directly; we do not store full card numbers.
- SendGrid (Twilio Inc.): Delivery of transactional and, where you have opted in, marketing email.
- Twilio Inc.: SMS and WhatsApp message delivery, where a Tenant has enabled messaging features.
We will inform Customers of intended changes concerning the addition or replacement of subprocessors that process Customer Data, giving the Customer the opportunity to object as set out in our Terms of Service.
7. Security :
-
In accordance with section 19 of POPIA and Article 32 of the UK GDPR, we implement appropriate, reasonable technical and organisational measures to protect personal data against accidental or unlawful access, destruction, loss, change, alteration, disclosure, or damage, and we maintain and regularly verify these safeguards. We take into account generally accepted information security practices, the risks involved in the processing, and the nature of the personal data. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest
- Role-based access control (RBAC), so users see only what their role in a workspace permits
- Authentication controls including single sign-on and two-factor authentication
- Multi-tenant data isolation to prevent cross-tenant data access
- Audit logging, monitoring, and auditing of access to personal data
- Regular security assessments and vulnerability testing
- Employee training on data protection best practices
- Incident response procedures for data breaches
- Secure software development practices and code review
Breach NotificationWhere there are reasonable grounds to believe that personal data for which we are the responsible party has been accessed or acquired by an unauthorised person, we will notify the Information Regulator (South Africa) and the affected data subjects as soon as reasonably possible after discovery, as required by section 22 of POPIA, in a manner that allows you to take protective measures, unless a public body responsible for investigation or the Regulator requires a delay. Where the UK GDPR applies to a breach of personal data for which we are the controller, we will notify the UK Information Commissioner's Office within 72 hours of becoming aware of it where feasible, and affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. For Customer Data we process as operator / processor, we will notify the affected Customer without undue delay after becoming aware of a breach, so that the Customer can meet its own notification duties.
While we strive to protect your data, no method of transmission or storage is 100% secure. We will never contact you requesting your account password, credit or debit card information, or national identification numbers. Please note that email sent over the Internet may not be secure and should not be used to communicate confidential or sensitive personal data to us.
We encourage you to use strong passwords and protect your account credentials. You are responsible for maintaining the confidentiality of your account credentials and for any activities that occur under your account.
8. Data Retention :
-
We store the personal data we collect about you for no longer than necessary for the purposes set out in this Privacy Notice, and in accordance with our legal obligations and legitimate business interests. When data is no longer needed, it is securely deleted or anonymized. We also consider the volume, nature, and sensitivity of your personal data, as well as any potential risk of harm from unauthorized use or disclosure of that personal data.
The criteria used to determine our retention periods depend on the legal basis under which we process the personal data:
- Contract: Where we process personal data based on a contract, we generally retain your personal data for the duration of the contract plus an additional limited period necessary to comply with law or that represents the statute of limitations for legal claims that could arise from the contractual relationship.
- Legitimate Interests: Where we process personal data based on our legitimate interests, we generally retain such information for a reasonable period based on the particular interest, taking into account your fundamental interests and your rights and freedoms.
- Consent: Where we process personal data based on your consent, we generally retain your data until you withdraw your consent, or otherwise for the period necessary to fulfill the underlying agreement with you.
- Legal Obligation: Where we process personal data based on a legal obligation, we generally retain your data for the period necessary to fulfill the legal obligation, including tax, accounting, and regulatory reporting requirements.
- Legal Hold: We may need to retain information beyond our typical retention period where we face threat of legal claim or intent to establish a claim. In that case, we will retain the information until the hold is removed, which typically means the claim or threat of claim has been resolved.
Specific retention periods include:
- Account Data: Retained for the duration of your Profesaas Account and for a reasonable period thereafter for legal and operational purposes, after which it is deleted or de-identified.
- Transaction Data: Retained for the period required by applicable tax and financial regulations (generally at least five years under South African tax law).
- Customer Data (Tenant workspaces): Retained for as long as the Tenant's subscription is active and processed only on the Tenant's instructions. On termination of a subscription, the Tenant has a 30-day window to export its Customer Data, after which we delete the workspace data, unless retention of specific records is required by law. This mirrors the export and deletion terms in our Terms of Service.
- Usage Data: Anonymised and aggregated data may be retained indefinitely for analytics purposes.
- Communication Data: Retained for as long as necessary to resolve inquiries and for quality assurance.
9. Location of Your Information and International Transfers :
-
The Services are hosted on Microsoft Azure, with our primary data storage and processing in Azure's South African regions and, for certain workloads and backups, Azure regions in the European Union. Personal data may also be accessed from, or transferred to, other countries where we or our subprocessors (Section 6) operate — for example, payment data processed by Stripe and email delivery via SendGrid may involve processing in the United States.
POPIA (section 72). We only transfer personal information outside South Africa where one of the conditions in section 72 of POPIA is met: the recipient is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection upholding principles substantially similar to POPIA's conditions for lawful processing (including onward-transfer restrictions); the data subject consents; the transfer is necessary for the performance or conclusion of a contract; or the transfer is for the data subject's benefit and consent is not reasonably practicable to obtain but would likely be given. Our subprocessor agreements impose such binding protections.
UK GDPR. Where we transfer personal data of UK data subjects out of the United Kingdom, we rely on UK adequacy regulations where the destination is covered, and otherwise on appropriate safeguards — the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses — together with transfer risk assessments and supplementary measures where needed. If you wish to inquire further about the safeguards we use, please contact us at privacy@profesaas.com.
10. Third-Party Links :
-
Our Services may include links to third-party websites, plug-ins, and applications. Except where we post, link to, or expressly adopt or refer to this Privacy Notice, this Privacy Notice does not apply to, and we are not responsible for, any personal data practices of third-party websites and online services or the practices of other third parties. To learn about the personal data practices of third parties, please visit their respective privacy notices. We encourage you to always review and, if necessary, adjust your privacy settings on third-party websites and services before sharing information and/or linking or connecting them to our Services.
11. Cookies and Tracking Technologies :
-
We keep our use of cookies deliberately minimal. We use first-party cookies and server logs to operate the Services; we do not use advertising or cross-site tracking cookies. The cookies we set are:
- Essential Cookies: Required for the operation of our Services — the session cookie that keeps you signed in, the CSRF cookie that protects forms against cross-site request forgery, and security-related cookies. These cannot be disabled as they are necessary for the Services to function, and they do not require consent under PECR.
- Preference Cookies and Local Storage: Remember choices such as your light/dark theme and interface settings so the Services look the same when you return.
We do not currently set analytics or marketing cookies, and we do not permit third parties to set advertising cookies through our Services. If we introduce analytics cookies in the future, we will update this Notice and, where required, ask for your consent before setting them.
Managing Your Cookie Preferences: You may control your cookies and tracking technologies in the following ways:
- Browser Controls: Your browser or device may have settings that determine what information we and other websites collect. You can configure your browser to refuse all cookies, accept only certain cookies, or notify you when a cookie is set.
- Device Settings: You can withdraw permission for Services to access your device features through your device's settings menu.
Please note that disabling certain cookies may affect the functionality of our Services. These choices are specific to the device or browser you are using. If you access our Services from other devices or browsers, take these actions from those devices or browsers to ensure your choices apply to the data collected when you use them.
12. Your Privacy Rights :
-
You have rights in respect of your personal data under both POPIA and, where it applies, the UK GDPR. Where we act as operator / processor for a Tenant's Customer Data, please direct your request to that Tenant first; we will assist the Tenant in responding.
Rights under both POPIA and the UK GDPR- Right of Access (POPIA s23; UK GDPR Art 15): To obtain confirmation, free of charge, of whether we hold personal data about you, and a copy of that data together with information about its recipients, purposes, and retention. Access requests under POPIA are handled in accordance with our PAIA manual (see below).
- Right to Correction (POPIA s24; UK GDPR Art 16): To have inaccurate, irrelevant, excessive, out-of-date, incomplete, or misleading personal data corrected.
- Right to Deletion / Erasure (POPIA s24-25; UK GDPR Art 17): To have personal data destroyed or deleted where its continued retention is no longer authorised or justified, subject to legal obligations that may require us to retain certain records.
- Right to Object (POPIA s11(3); UK GDPR Art 21): To object, on reasonable grounds relating to your particular situation, to processing based on legitimate interests, and to object to direct marketing at any time and for any reason.
- Right not to be subject to Automated Decision-Making (POPIA s71; UK GDPR Art 22): Not to be subject to a decision producing legal or similarly significant effects based solely on automated processing, subject to limited exceptions (see Section 16).
- Right to Withdraw Consent: Where processing is based on consent, to withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal.
Additional rights under the UK GDPR- Right to Restrict Processing (Art 18): To require us to limit processing in certain circumstances, such as while the accuracy of the data is contested.
- Right to Data Portability (Art 20): To receive personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
How to exercise your rights. Email privacy@profesaas.com (or our Information Officer at dpo@profesaas.com). We may need to verify your identity before acting on a request, which may require us to ask for additional information. Response times: where the UK GDPR applies, we respond within one month of receipt (extendable by up to two further months for complex or numerous requests, in which case we will tell you within the first month); where POPIA applies, we respond within a reasonable time and in accordance with the timelines in POPIA and PAIA. Requests are free of charge, except where applicable law permits a prescribed fee for access requests.
PAIA manual. Our manual published under section 51 of the Promotion of Access to Information Act, 2000 (PAIA) describes how to request access to records we hold, the prescribed forms, and applicable fees. It is available from our Information Officer on request at dpo@profesaas.com.
You also have the right to lodge a complaint with a supervisory authority: the Information Regulator (South Africa) — see Section 21 — or, for UK data subjects, the UK Information Commissioner's Office — see Section 22.
13. Lawful Bases for Processing :
-
Every processing activity we undertake as responsible party / controller rests on a lawful basis under Article 6 of the UK GDPR and a corresponding justification under section 11 of POPIA. The table below maps the bases we rely on to the processing they cover:
Lawful basis UK GDPR POPIA What it covers Performance of a contract Art 6(1)(b) s 11(1)(b) Creating and administering your Profesaas Account and workspace, providing the Services, processing subscriptions and payments, and providing support under our Terms of Service. Legal obligation Art 6(1)(c) s 11(1)(c) Retaining tax, accounting, and billing records; responding to lawful requests from regulators and authorities; breach notification duties. Legitimate interests Art 6(1)(f) s 11(1)(f) Securing the Services (fraud and abuse prevention, access logging), first-party usage measurement to improve the platform, responding to enquiries, and marketing similar services to existing customers subject to opt-out. We balance these interests against your rights and you may object (Section 12). Consent Art 6(1)(a) s 11(1)(a) Newsletters and electronic direct marketing to non-customers (POPIA s 69 / PECR), optional non-essential cookies if introduced, and any other processing where we ask you first. You may withdraw consent at any time. POPIA section 11(1)(d) (protection of a legitimate interest of the data subject) and 11(1)(e) (public-law duty) may apply in exceptional cases, such as breach notifications made to protect you. For Customer Data, the Tenant determines and is responsible for the lawful basis; we process on the Tenant's instructions.
14. Control Over Your Information :
-
You may control your information in the following ways:
- Browser or Device Controls: Your browser or device may have controls that determine what information we and other websites collect, usually via a "Settings" menu. You can configure your browser to refuse cookies, manage tracking technologies, and control permissions for our Services to access your device features. These choices are specific to the device or browser you are using.
- Email Communication Preferences: You can stop receiving promotional email communications from us by clicking on the "unsubscribe" link provided in such communications. You may not opt out of service-related communications (e.g., account verification, transactional communications, changes/updates to features of the Services, technical and security notices).
- Push Notifications: If applicable, you can stop receiving push notifications from us by changing your preferences via your device's Settings menu.
- Modifying or Deleting Your Information: If you have any questions about reviewing, modifying, or deleting your information, you can contact us directly at privacy@profesaas.com. We may not be able to modify or delete your information in all circumstances.
- Account Settings: You may update your account information and preferences at any time by logging into your Profesaas Account and accessing your account settings.
15. Special Personal Information and Special Category Data :
-
Our own processing. For the data we process as responsible party / controller, we collect little that is sensitive — chiefly account log-in credentials in combination with any required security or access code or password allowing access to your Profesaas Account. We use such information only where necessary and proportionate:
- For performing services you have requested
- For the operation and security of our platform
- For detecting security incidents, fraud, and other illegal actions
We do not use or disclose sensitive personal information to infer characteristics about you or for purposes beyond what is necessary and proportionate to provide the Services.
Special personal information in Tenant workspaces. Tenants — particularly social-support organisations, education funds, and education providers — may record special personal information of the people they serve, learners, and other data subjects in their workspaces, such as health information relevant to services they provide, or race or ethnic origin where required for statutory reporting or affirmative-action purposes. For that Customer Data, the Tenant is the responsible party / controller and Profesaas is the operator / processor.
Sections 26 to 33 of POPIA prohibit processing special personal information unless a general authorisation under section 27 applies (including the data subject's consent; processing necessary for the establishment, exercise, or defence of a right or obligation in law; or processing for historical, statistical, or research purposes with appropriate safeguards) or one of the specific authorisations in sections 28 to 33 applies to the category concerned. Under the UK GDPR, an Article 9(2) condition is additionally required for special category data. It is the Tenant's responsibility to ensure such an authorisation or condition exists before loading special personal information; Profesaas processes it only on the Tenant's instructions and protects it with the safeguards in Section 7, including role-based access restrictions, encryption, and audit logging. Children's personal information is addressed in Section 4 (POPIA sections 34 and 35).
16. Automated Decision-Making :
-
We do not use automated decision-making, including profiling, to make decisions that produce legal or similarly significant effects concerning you without human involvement. You accordingly have the protections of section 71 of POPIA and Article 22 of the UK GDPR: you will not be subject to such solely automated decisions except in the narrow circumstances those provisions permit. If our practices change in the future, we will update this Privacy Notice and provide you with appropriate notice, including information about the logic involved, how to obtain human intervention, express your point of view, and contest the decision.
17. Do Not Sell or Share Personal Data :
-
We do not sell your personal data to third parties for monetary or other valuable consideration. We do not share your personal data with third parties for cross-context behavioural advertising purposes. If our practices change in the future, we will update this Privacy Notice and provide you with the ability to opt out of such sale or sharing.
18. Changes to This Notice :
-
We will update this Privacy Notice from time to time. When we make changes to this Privacy Notice, we will change the effective date at the beginning of this Privacy Notice. If we make material changes to this Privacy Notice, we will notify individuals by email to their registered email address, by prominent posting on our Services, or through other appropriate communication channels. All changes shall be effective from the date of publication unless otherwise provided. We encourage you to review this notice periodically.
19. Contact Us :
-
All general questions and comments about this Privacy Notice or other privacy-related matters may be directed to us using the contact details below:
Profesaas (Pty) Ltd
Email: privacy@profesaas.com
Address: 292 Surrey Road, Ferndale, Johannesburg, 2194
Website: profesaas.com
20. Information Officer / Data Protection Contact :
-
If you wish to make a complaint about how we have handled your personal data, or have concerns about our data processing practices, please contact our Information Officer, who also serves as our data protection contact for UK GDPR purposes:
Information Officer (Data Protection Contact)
Profesaas (Pty) Ltd
Email: dpo@profesaas.com
Address: 292 Surrey Road, Ferndale, Johannesburg, 2194
In terms of section 55 of POPIA, our Information Officer is responsible for encouraging and ensuring our compliance with POPIA, dealing with requests made under POPIA and PAIA, and working with the Information Regulator on investigations. As required by POPIA and the Regulator's guidance, our Information Officer is registered with the Information Regulator (South Africa) before taking up these duties. The Information Officer also oversees our compliance with the UK GDPR and other applicable data protection legislation.
21. POPIA-Specific Provisions (South Africa) :
-
Under the Protection of Personal Information Act (POPIA), you have the right to submit a complaint to the Information Regulator regarding alleged interference with the protection of your personal information, or to institute civil proceedings:
Information Regulator (South Africa)
Email: enquiries@inforegulator.org.za
Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Website: inforegulator.org.za
22. UK GDPR-Specific Provisions (United Kingdom and EEA) :
-
If you are located in the United Kingdom, you have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
If you are located in the European Economic Area (EEA), you may contact your local data protection authority; a list of EEA authorities is available on the European Commission's website.
Under the UK GDPR, you also have the right to object to any processing based on our legitimate interests where there are grounds relating to your particular situation. There may be compelling reasons for continuing to process your personal data, and we will assess and inform you if that is the case. You can object to marketing activities for any reason. If you wish to exercise any of these rights, please contact us using the details provided in Sections 19 and 20 above.
