BEEZONE™
TermsPrivacySubscriptionsSupport
Open workspace
Privacy and POPIA Notice

How BEEZONE handles personal information

This notice explains BEEZONE’s responsible-party and operator roles, what we process, why, where it goes and the rights available under POPIA.

Effective and last updated: 5 August 2026
Our two POPIA roles

BEEZONE is the responsible party for account, billing, website and support information. For company-workspace or verification case-file content controlled by a Customer, BEEZONE acts as operator for that Customer.

1. Responsible party and Information Officer

BEEZONE PTY LTD, registration 2014/147239/07, is the responsible party for personal information it determines how and why to process. Portia Mudau is BEEZONE’s Information Officer. Privacy requests may be sent to portia@bee-zone.co.za or info@bee-zone.co.za.

2. Information we process

  • Account information: name, work email, authentication records, role, access scope and session/security records.
  • Company and billing information: entity details, addresses, contacts, VAT and purchase-order details, product, invoice and payment status. Full card details are handled by Paystack and are not stored by BEEZONE.
  • Verification-agency information: agency identity and accreditation details, team assignments, client contacts, verification plans, claim registers, samples, evidence-submission status, issues and close-out activity.
  • Platform activity: audit events, IP-derived security records, device/browser information, uploads, changes, approvals and support interactions.
  • Client-controlled content: workforce, director, shareholder, supplier, beneficiary, training, remuneration, race, gender, disability and related evidence that an authorised client chooses to process for B-BBEE or Employment Equity purposes.

3. Purpose and lawful basis

We process information to create and secure accounts, provide licensed workspaces, calculate and report authorised results, process orders, issue invoices, provide support, keep audit records, prevent fraud, improve reliability, meet legal duties and establish or defend legal claims.

Depending on the context, processing is necessary to perform a contract, comply with law, pursue legitimate interests that do not unjustifiably affect privacy, protect a legitimate interest of a data subject, or is based on consent where consent is required. Special personal information is processed only under an applicable POPIA authorisation and the Customer’s documented instructions.

4. Client responsibility and BEEZONE as operator

A Customer deciding to upload personal information must establish a lawful basis, provide required notices, respect objections and data-subject rights, keep the information relevant and accurate, and instruct BEEZONE lawfully. BEEZONE processes that information only to provide and secure the contracted service, under the Customer’s authority, a data-processing agreement where applicable, or as required by law.

A verification agency controls which measured entities and contacts it invites, which elements and transactions it samples, and which evidence it requests. The agency must determine whether it acts as responsible party or as an operator for the measured entity, document the required authority and instructions, and use confidential/manual-view handling where uploading is not appropriate.

Customers should not send passwords, card details or confidential employee files by ordinary email. Use the controlled workspace and its role, scope and evidence controls.

5. Sharing and service providers

Information is shared only as reasonably necessary with authorised Customer users; measured-entity contacts invited to a protected verification case file; Cloudflare for application hosting, database, file storage and security; Paystack for card payments; configured transactional-email providers; professional advisers, auditors and insurers; and regulators, courts or law-enforcement bodies where lawfully required.

Providers receive only the access needed for their function and are subject to contractual or legal safeguards. BEEZONE does not sell personal information.

6. Cross-border processing

Some infrastructure or service-provider processing may occur outside South Africa. Where POPIA section 72 applies, BEEZONE uses a lawful transfer basis and reasonable contractual, organisational and technical safeguards intended to provide an adequate level of protection.

7. Retention and deletion

Account and Customer content is retained for the active relationship and thereafter only for as long as reasonably needed for authorised retrieval, legal duties, disputes, security, backup cycles and documented Customer instructions. Billing, tax, contract and audit records are generally retained for at least five years or any longer period required by law.

When information is no longer required or authorised, it is deleted, destroyed, de-identified or restricted in accordance with POPIA and operational backup cycles. A Customer may request an agreed export or deletion process, subject to authority, technical feasibility and lawful retention.

8. Security safeguards and incidents

BEEZONE uses reasonable technical and organisational safeguards including access roles and organisational scope, password hashing, secure session cookies, hashed expiring client-link tokens, controlled private storage, evidence integrity hashes, server-side permission checks, audit records, payment-provider separation and encrypted transport. No online service is risk free.

If there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, BEEZONE will investigate and notify the responsible party, Information Regulator and affected data subjects as applicable under POPIA. Report suspected incidents promptly through the Support page.

9. Your POPIA rights

Subject to POPIA and proof of identity, a data subject may ask whether BEEZONE holds personal information about them; request access; ask for correction, deletion or restriction; object to certain processing; withdraw consent where processing relies on consent; and complain to the Information Regulator.

If the information belongs to a Customer-controlled company workspace or verification case file, BEEZONE may direct the request to the relevant company or agency Customer and assist that Customer as operator. Official objection and correction/deletion forms are available from the Information Regulator.

10. Cookies and automated outputs

BEEZONE uses essential session and security cookies required to sign users in, preserve authorised access and protect the service. The platform generates calculations, indicative scorecards and recommendations from Customer inputs and configured rules, but those outputs are not B-BBEE certificates, verification conclusions or decisions that create legal effects for an individual and must be reviewed by authorised people.

11. Questions and complaints

Contact BEEZONE first at info@bee-zone.co.za or portia@bee-zone.co.za. You may also lodge a complaint through the Information Regulator complaints service.

12. Notice updates

This notice may be updated when processing, providers, law or the service changes. The effective date above identifies the version. Material changes will be communicated through the platform or registered contact details where reasonably practicable.

BEEZONE PTY LTDRegistration 2014/147239/07 · VAT 4330308018Ground Floor, Mac Mac Building, Maxwell Office Park, Magwa Crescent, Waterval City, Midrand, 2090, South Africa
info@bee-zone.co.za+27 10 013 3400