Open workspaceHow BEEZONE handles personal information
This notice explains BEEZONE’s responsible-party and operator roles, what we process, why, where it goes and the rights available under POPIA.
Effective and last updated: 5 August 20261. Responsible party and Information Officer
BEEZONE PTY LTD, registration 2014/147239/07, is the responsible party for personal information it determines how and why to process. Portia Mudau is BEEZONE’s Information Officer. Privacy requests may be sent to portia@bee-zone.co.za or info@bee-zone.co.za.
2. Information we process
- Account information: name, work email, authentication records, role, access scope and session/security records.
- Company and billing information: entity details, addresses, contacts, VAT and purchase-order details, product, invoice and payment status. Full card details are handled by Paystack and are not stored by BEEZONE.
- Verification-agency information: agency identity and accreditation details, team assignments, client contacts, verification plans, claim registers, samples, evidence-submission status, issues and close-out activity.
- Platform activity: audit events, IP-derived security records, device/browser information, uploads, changes, approvals and support interactions.
- Client-controlled content: workforce, director, shareholder, supplier, beneficiary, training, remuneration, race, gender, disability and related evidence that an authorised client chooses to process for B-BBEE or Employment Equity purposes.
3. Purpose and lawful basis
We process information to create and secure accounts, provide licensed workspaces, calculate and report authorised results, process orders, issue invoices, provide support, keep audit records, prevent fraud, improve reliability, meet legal duties and establish or defend legal claims.
Depending on the context, processing is necessary to perform a contract, comply with law, pursue legitimate interests that do not unjustifiably affect privacy, protect a legitimate interest of a data subject, or is based on consent where consent is required. Special personal information is processed only under an applicable POPIA authorisation and the Customer’s documented instructions.
4. Client responsibility and BEEZONE as operator
A Customer deciding to upload personal information must establish a lawful basis, provide required notices, respect objections and data-subject rights, keep the information relevant and accurate, and instruct BEEZONE lawfully. BEEZONE processes that information only to provide and secure the contracted service, under the Customer’s authority, a data-processing agreement where applicable, or as required by law.
A verification agency controls which measured entities and contacts it invites, which elements and transactions it samples, and which evidence it requests. The agency must determine whether it acts as responsible party or as an operator for the measured entity, document the required authority and instructions, and use confidential/manual-view handling where uploading is not appropriate.
Customers should not send passwords, card details or confidential employee files by ordinary email. Use the controlled workspace and its role, scope and evidence controls.
6. Cross-border processing
Some infrastructure or service-provider processing may occur outside South Africa. Where POPIA section 72 applies, BEEZONE uses a lawful transfer basis and reasonable contractual, organisational and technical safeguards intended to provide an adequate level of protection.
7. Retention and deletion
Account and Customer content is retained for the active relationship and thereafter only for as long as reasonably needed for authorised retrieval, legal duties, disputes, security, backup cycles and documented Customer instructions. Billing, tax, contract and audit records are generally retained for at least five years or any longer period required by law.
When information is no longer required or authorised, it is deleted, destroyed, de-identified or restricted in accordance with POPIA and operational backup cycles. A Customer may request an agreed export or deletion process, subject to authority, technical feasibility and lawful retention.
8. Security safeguards and incidents
BEEZONE uses reasonable technical and organisational safeguards including access roles and organisational scope, password hashing, secure session cookies, hashed expiring client-link tokens, controlled private storage, evidence integrity hashes, server-side permission checks, audit records, payment-provider separation and encrypted transport. No online service is risk free.
If there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, BEEZONE will investigate and notify the responsible party, Information Regulator and affected data subjects as applicable under POPIA. Report suspected incidents promptly through the Support page.
9. Your POPIA rights
Subject to POPIA and proof of identity, a data subject may ask whether BEEZONE holds personal information about them; request access; ask for correction, deletion or restriction; object to certain processing; withdraw consent where processing relies on consent; and complain to the Information Regulator.
If the information belongs to a Customer-controlled company workspace or verification case file, BEEZONE may direct the request to the relevant company or agency Customer and assist that Customer as operator. Official objection and correction/deletion forms are available from the Information Regulator.
11. Questions and complaints
Contact BEEZONE first at info@bee-zone.co.za or portia@bee-zone.co.za. You may also lodge a complaint through the Information Regulator complaints service.
12. Notice updates
This notice may be updated when processing, providers, law or the service changes. The effective date above identifies the version. Material changes will be communicated through the platform or registered contact details where reasonably practicable.