Legal

Privacy Policy & POPIA Notice

Effective date: [INSERT DATE]

1. Introduction

Moonlighter Group (Pty) Ltd ("AzaniaSCM", "we", "us", or "our") is committed to protecting the privacy and personal information of all individuals who interact with our platform. We operate in full compliance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and the associated regulations issued by the Information Regulator of South Africa.

This Privacy Policy & POPIA Notice explains how we collect, use, disclose, store, and protect personal information when you use the AzaniaSCM procurement platform, related services, and websites (collectively, the "Service"). By accessing or using the Service, you acknowledge that you have read and understood this policy.

Moonlighter Group (Pty) Ltd is the responsible party as defined in POPIA and is accountable for ensuring that personal information is processed in accordance with the law. Our Information Officer oversees compliance with this policy and POPIA.

2. Information We Collect

2.1 Account Information

When you register for an AzaniaSCM account, we collect your full name, email address, telephone number, job title, password (stored in hashed form), and organisation affiliation. We may also collect a profile photograph if you choose to upload one.

2.2 Organisation Information

For organisation accounts, we collect the organisation's registered name, registration number (e.g., CIPC registration), physical address, postal address, tax identification number, industry classification, and details of authorised representatives and directors. This information is necessary to establish and verify the legal entity using the platform.

2.3 Procurement Data

The Service facilitates procurement workflows. In doing so, we process: tender documents, bid submissions, supplier profiles, evaluations and scoring data, contract documents, purchase orders, invoices, delivery records, and related communications. This data may contain personal information of employees, directors, and representatives of both buyers and suppliers.

2.4 Usage Data

We automatically collect certain information when you use the Service, including IP address, browser type and version, operating system, device identifiers, pages viewed, actions taken, timestamps, referring URLs, and session duration. This data is used for security, analytics, and service improvement purposes.

3. How We Use Your Information

We process personal information only for the purposes described below and as otherwise permitted by law:

3.1 Service Delivery

To provide, operate, maintain, and improve the AzaniaSCM platform and its procurement features, including user account creation, tender management, bid evaluation, supplier directory access, contract management, and reporting.

3.2 Account Management

To create and manage your user account, authenticate your identity, provide customer support, send service-related notifications, and manage your preferences and settings.

3.3 Regulatory Compliance

To comply with applicable South African legislation, including but not limited to the Public Finance Management Act, the Preferential Procurement Policy Framework Act, the Broad-Based Black Economic Empowerment Act, the Companies Act, and tax legislation including the Value-Added Tax Act and Income Tax Act.

3.4 Audit and Record-Keeping

To maintain immutable audit logs of all platform activities for accountability, dispute resolution, and regulatory audit purposes. Audit logs are retained in accordance with applicable retention schedules.

3.5 Communication

To communicate with you regarding your account, the Service, updates, security alerts, and administrative messages. We may also send you information about new features or services, but you may opt out of marketing communications at any time.

3.6 Legal Obligations

To respond to lawful requests from courts, tribunals, regulatory authorities, and law enforcement agencies, and to establish, exercise, or defend legal claims.

3.7 Security

To detect, prevent, and respond to fraud, unauthorised access, security incidents, and other potentially prohibited or illegal activities, and to protect the rights, property, and safety of AzaniaSCM, our users, and the public.

4. Legal Bases for Processing

We process personal information under one or more of the following lawful bases as set out in section 11 of POPIA:

4.1 Contractual Necessity

Processing is necessary to perform a contract to which you are a party, or to take steps at your request prior to entering into a contract. This includes providing the Service, managing your account, and fulfilling procurement workflows.

4.2 Legal Obligation

Processing is necessary to comply with a legal obligation to which we are subject. This includes compliance with South African tax, financial reporting, and public procurement legislation.

4.3 Legitimate Interest

Processing is necessary for our legitimate interests or those of a third party, provided that such interests are not overridden by your rights and freedoms. Our legitimate interests include: improving the Service, ensuring platform security, preventing fraud, and conducting internal analytics. We conduct a Legitimate Interest Assessment (LIA) before relying on this basis.

4.4 Consent

Where we rely on consent as the lawful basis for processing, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing that occurred prior to withdrawal. Consent will be obtained in a clear, specific, informed, and unequivocal manner.

5. Information Sharing

5.1 Third-Party Processors

We may share personal information with trusted third-party service providers who process data on our behalf, including cloud hosting providers, payment processors, and analytics services. All third-party processors are bound by written agreements that require them to implement appropriate technical and organisational security measures and to process personal information only on our documented instructions.

5.2 Legal Requirements

We may disclose personal information where required by law, regulation, court order, or governmental directive, or where disclosure is necessary to protect our rights, your safety, or the safety of others, investigate fraud, or respond to a lawful request from a public authority.

5.3 Business Transfers

In the event of a merger, acquisition, reorganisation, sale of assets, or bankruptcy, personal information may be transferred as part of the transaction. We will notify you of any such change in ownership or control of your personal information.

5.4 No Sale of Personal Information

We do not sell, rent, or lease personal information to third parties for their marketing purposes. We will not share your personal information with third parties for independent use without your explicit consent.

6. Data Security

We implement robust technical and organisational measures to protect personal information against unauthorised access, alteration, disclosure, or destruction:

6.1 Encryption at Rest

All personal information stored in our databases is encrypted at rest using AES-256 (Advanced Encryption Standard with 256-bit keys), an industry-standard encryption algorithm approved for use by government agencies worldwide.

6.2 Encryption in Transit

All data transmitted between your device and our servers is encrypted using TLS 1.3 (Transport Layer Security), the latest and most secure version of the TLS protocol. We do not support older, deprecated TLS versions.

6.3 Tenant Isolation

AzaniaSCM operates a multi-tenant architecture with strict logical tenant isolation. Each organisation's data is segregated through unique tenant identifiers and access controls, ensuring that one organisation's data cannot be accessed by another organisation's users.

6.4 Role-Based Access Control (RBAC)

Access to personal information is restricted to authorised personnel on a need-to-know basis through role-based access controls. Administrative access to production systems is limited, logged, and subject to regular review.

6.5 Immutable Audit Logs

All access to and modifications of personal information are recorded in tamper-proof, immutable audit logs. These logs are retained for the duration specified in our retention schedule and are available for inspection by authorised personnel and regulators.

7. Data Retention

7.1 Configurable Retention Policies

AzaniaSCM provides configurable data retention policies that allow organisation administrators to set retention periods appropriate to their procurement workflows and legal obligations. Default retention periods are based on South African public procurement record-keeping requirements.

7.2 POPIA Minimisation Principle

In accordance with the minimisation principle under POPIA, we do not retain personal information for longer than is necessary to achieve the purpose for which it was collected, unless a longer retention period is required or permitted by law. We regularly review the data we hold and delete or anonymise information that is no longer required.

7.3 Archival and Deletion

When data reaches the end of its retention period, it is either archived to a secure, access-restricted storage tier or permanently deleted, depending on organisational policy and legal requirements. Archived data remains subject to the same security controls and access restrictions. Deletion is performed using secure erasure methods that render data unrecoverable.

8. Your Rights Under POPIA

Under POPIA, you have the following rights in respect of your personal information:

8.1 Right of Access

You have the right to request confirmation of whether we hold personal information about you, and to request access to that information. Upon request, we will provide you with a description of the personal information we hold, the purposes for which it is processed, and the categories of recipients to whom it may be disclosed. You may request access to your personal information by contacting our Information Officer.

8.2 Right to Correction

You have the right to request the correction or updating of personal information that is inaccurate, incomplete, misleading, or out of date. We will accommodate reasonable requests for correction within a reasonable timeframe.

8.3 Right to Deletion

You have the right to request the deletion or destruction of personal information that is no longer necessary for the purpose for which it was collected, or where you have withdrawn your consent and there is no other legal ground for processing. Deletion requests may be declined where retention is required by law or for the establishment, exercise, or defence of legal claims.

8.4 Right to Object

You have the right to object to the processing of your personal information on grounds relating to your particular situation, where processing is based on our legitimate interests or those of a third party. Upon receiving an objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims.

8.5 Complaint to the Information Regulator

If you believe that we have infringed your rights under POPIA, you have the right to lodge a complaint with the Information Regulator of South Africa. The Information Regulator can be contacted at:

The Information Regulator (South Africa)
JD House, 27 Siemert Road, Johannesburg, 2094
Email: complaints.IR@justice.gov.za
Website: https://inforegulator.org.za

We encourage you to contact our Information Officer first so that we may attempt to resolve your complaint before you escalate to the Information Regulator.

9. International Data Transfers

9.1 Where Data Is Stored

AzaniaSCM primarily stores and processes personal information within data centres located in the Republic of South Africa. Our primary cloud infrastructure is hosted within South African data centres to ensure compliance with local data residency requirements.

9.2 Safeguards for Cross-Border Transfers

Where personal information is transferred to a country outside of South Africa — for example, to a third-party processor or for disaster recovery purposes — we ensure that appropriate safeguards are in place, including:

  • Verification that the recipient country has adequate data protection laws, as assessed in accordance with section 72 of POPIA;
  • Binding contractual clauses that require the recipient to maintain substantially similar data protection standards to those provided under POPIA;
  • Implementation of appropriate technical and organisational security measures by the recipient; and
  • Compliance with any additional requirements prescribed by the Information Regulator for cross-border transfers.

We will not transfer personal information to a country or territory that does not provide adequate protection for data subject rights without first obtaining your explicit consent or establishing appropriate safeguards as required by POPIA.

10. Cookies and Tracking

10.1 Essential Cookies Only

The AzaniaSCM platform uses only cookies that are strictly necessary for the operation of the Service. These include session cookies for authentication, security cookies for fraud prevention, and preference cookies for user interface customisation. No non-essential cookies are placed on your device.

10.2 No Third-Party Tracking

We do not use third-party tracking cookies, advertising cookies, analytics cookies from external providers, or any other tracking technologies that monitor your activity across websites. We do not engage in behavioural profiling or targeted advertising.

You may configure your browser to block or delete cookies, though doing so may affect the functionality of the Service. Where cookies are used, we will request your consent in accordance with POPIA and applicable regulations, except for cookies that are strictly necessary for the Service to function.

11. Children's Privacy

The AzaniaSCM Service is not directed at children under the age of 18 years. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to delete that information promptly. If you believe that a child has provided us with personal information, please contact our Information Officer immediately.

12. Changes to This Policy

We may update this Privacy Policy & POPIA Notice from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Where we make material changes to this policy, we will provide at least 30 days' prior notice before the changes take effect. Notice will be provided via email to the address associated with your account and through a prominent announcement on the AzaniaSCM platform.

Material changes include, but are not limited to: changes to the categories of personal information we collect, changes to the purposes for which we process your information, changes to how we share your information, and changes to your rights under this policy.

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.

13. Contact

13.1 Information Officer

If you have any questions, concerns, or requests regarding this Privacy Policy & POPIA Notice or our processing of your personal information, please contact our Information Officer:

Information Officer
Moonlighter Group (Pty) Ltd
Email: information.officer@moonlighter.co.za
Telephone: [INSERT TELEPHONE NUMBER]
Physical Address: [INSERT PHYSICAL ADDRESS]
Postal Address: [INSERT POSTAL ADDRESS]

We will respond to all requests within a reasonable timeframe and in any event within the period prescribed by POPIA (30 calendar days, extendable by a further 30 days where reasonably necessary).

13.2 Information Regulator

You may also contact the Information Regulator directly:

The Information Regulator (South Africa)
JD House, 27 Siemert Road, Johannesburg, 2094
Email: complaints.IR@justice.gov.za
Website: https://inforegulator.org.za
Telephone: 010 023 5207