Capacity Connect Privacy Policy
This Privacy Policy explains how Capacity Connect (Pty) Ltd, registration number 2025/583267/07 ("Capacity Connect"), processes personal information in operating the Capacity Connect platform, in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA"). It forms part of the Platform Terms and Conditions. Defined terms used but not defined here have the meanings given in those Terms.
1. Who we are and our role
1.1 Capacity Connect is the responsible party for the personal information it processes to operate the platform, including account, Firm and representative data, verification data, and platform audit records.
1.2 In respect of certain content that a Firm uploads or generates in an Engagement, Capacity Connect acts as an operator processing that content on behalf of the Firm, which remains the responsible party for it. Each Firm must ensure it has a lawful basis for the personal information it processes through the platform.
1.3 Our Information Officer can be contacted at admin@capacity-connect.com.
2. The personal information we process
2.1 Account and representative data: names, designations, email addresses, and login and authentication data of Firm representatives.
2.2 Firm and verification data: entity registration details, professional registration numbers, professional indemnity insurance declarations and certificates, VAT registration status and number, FICA declarations and related officer details, and POPIA declarations.
2.3 Transactional data: Jobs, Quotes, Engagement Letters, Milestones, invoices, and bank and payout details captured for settlement.
2.4 Evidence and audit data: Acceptance Events, letter events, per-field signature timestamps, letter-viewed events, IP addresses, user agents, cryptographic hashes, and the Communication of Record.
2.5 Technical data: device, browser and usage data collected to operate and secure the platform.
3. Why we process it, and our lawful basis
3.1 We process personal information to admit and verify Firms, to operate matching, quoting, contracting, invoicing and settlement, to maintain the evidence records that give the platform legal effect, to communicate operationally, to comply with law, and to secure and improve the platform.
3.2 Our lawful bases under POPIA include the conclusion and performance of a contract with the Firm, compliance with an obligation in law, our legitimate interests and those of the Firms in a functioning and evidenced marketplace, and, where required, consent. The evidence and audit records in clause 2.4 are processed on the basis of contract performance and legitimate interest, being necessary to establish the legal effect of acceptances and signatures.
4. Sharing and sub-processors
4.1 We share personal information with the sub-processors necessary to operate the platform: our hosting and database provider (Supabase), our transactional email provider (Resend), and our payment processor (Paystack). Each processes personal information on our instruction or, in the case of Paystack, as a responsible party in its own right for the payments it handles.
4.2 We may share personal information where required by law, to establish, exercise or defend a legal claim, or with a successor-in-title on a transfer of the business, subject to this Policy.
4.3 When two Firms contract on the platform, the identity and contact details of each Firm and its representatives are visible to the other to enable the Engagement. This is a necessary part of contracting and is subject to the confidentiality obligations in the Terms.
5. Cross-border processing
5.1 Our hosting and database infrastructure is located in the European Union (Supabase, regions eu-west-2 and eu-west-3), and our transactional email is sent through infrastructure in the European Union (Resend, region eu-west-1). Personal information is therefore processed outside the Republic of South Africa.
5.2 Section 72 basis. We transfer personal information across borders in accordance with section 72 of POPIA on the basis that (a) the recipients are subject to a law or binding agreement that upholds principles for the reasonable processing of the information that are substantially similar to the conditions in POPIA, the European Union data protection regime providing such protection, and (b) our agreements with these providers bind them to process personal information only on our instruction and to protect it to a standard consistent with POPIA. The transfers are also necessary for the performance of our contract with the Firm.
6. Security
6.1 We apply reasonable technical and organisational measures to protect personal information, including access controls, encryption in transit, and the integrity controls that produce the platform hashes and audit records.
6.2 No system is completely secure, and we cannot guarantee absolute security.
7. Breach notification
7.1 Where there are reasonable grounds to believe that personal information for which we are responsible has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected data subjects as soon as reasonably possible after becoming aware, in accordance with section 22 of POPIA.
7.2 Where a breach occurs at a sub-processor, including Paystack, that processor must notify us without undue delay, and we will make the notifications required of us as responsible party. Where the affected data is data for which a Firm is the responsible party, we will notify that Firm so that it can meet its own notification obligations.
8. Retention
8.1 We retain financial records, including invoices and settlement records, for 7 (seven) years, to match the retention period applicable under tax legislation.
8.2 We retain account and Firm data for as long as the Firm has an account and for a reasonable period thereafter to deal with residual obligations and claims.
8.3 Evidence records. Acceptance Events, letter events, signature evidence and the Communication of Record are retained for the period necessary to establish and defend the legal effect of the acceptances, signatures and Engagements they evidence, being not less than 7 (seven) years from the conclusion of the relevant Engagement, on the lawful basis of our and the Firms legitimate interest in maintaining reliable legal evidence and, where applicable, compliance with law.
9. Data subject rights
9.1 Subject to POPIA, a data subject may request access to their personal information, request correction or deletion, object to processing, and lodge a complaint. Requests may be made to admin@capacity-connect.com.
9.2 Deletion and the evidence records. Where a deletion request is made, we will delete or de-identify personal information that we are not required or entitled to retain. We will, however, retain the evidence records described in clause 8.3 notwithstanding a deletion request, on the lawful basis that their retention is necessary for the establishment, exercise or defence of a right or obligation in law and for compliance with an obligation in law. We will confine that retention to what is necessary for those purposes.
9.3 A data subject may lodge a complaint with the Information Regulator (South Africa), whose contact details are published at inforegulator.org.za.
10. Changes to this Policy
10.1 We may update this Policy. Where we do, we will bump the version and notify Firms in the platform, and where required prompt re-acceptance.
