Privacy policy
1. Who we are
1.1 Recruit 360 is operated by [registered entity name], registration number [company registration number], of [registered address, South Africa].
1.2 Our Information Officer, appointed under section 55 of the Protection of Personal Information Act 4 of 2013 (POPIA), is [appointed Information Officer], contactable at support@recruit360.co.za.
2. Two different roles, and which one applies
2.1 This is the point most software privacy policies blur, so we will be plain about it.
| Whose information | Who decides how it is used | Which document governs it |
|---|---|---|
| Your staff — the people who sign in to a workspace — and our billing contacts and website visitors | We are the responsible party | This policy |
| Candidates, client contacts and everyone else recorded inside a customer’s workspace | The customer is the responsible party; we are its operator | The data processing addendum, and the customer’s own candidate-facing policy |
2.2 Candidates applying through a workspace’s careers portal are given that workspace’s own notice at the point of application. We do not decide what a customer does with its candidate data, and we do not use it for our own purposes.
3. What we process about you
- Account information — name, work email address, job title, profile photograph if you upload one, your role in the workspace, and your notification and display preferences.
- Authentication information — a hashed password, second-factor enrolment, session and device records, and the record of your acceptance of our terms, which includes the version, time, IP address and browser user agent.
- Usage and security records — sign-in events, the audit trail of significant actions taken in the workspace, IP addresses, and error and performance logs.
- Billing information — the organisation’s billing contact, invoices, subscription history, and the last four digits and expiry of a card. We never see or store a full card number; it is tokenised by our payment gateway.
- Support correspondence — what you tell us when you ask for help, and our replies.
- Content you connect — where you connect a mailbox or calendar, metadata about those messages and events so that they can be shown in context. Message bodies and attachments are fetched from your provider when you open them and are stored only when you deliberately keep one.
4. Why we process it, and on what basis
| Purpose | Lawful basis under POPIA |
|---|---|
| Providing the service you have subscribed to | Performance of a contract with you or with your employer (section 11(1)(b)) |
| Billing, invoicing and collecting payment | Contract, and our legitimate interests (section 11(1)(f)) |
| Security, fraud prevention, audit trails and tenant isolation | Legitimate interests, and section 19 security safeguards |
| Support and service notices | Contract |
| Keeping records the law requires us to keep | Legal obligation (section 11(1)(c)) |
| Product announcements you can switch off | Consent, or legitimate interests where you are an existing customer |
4.1 We do not sell personal information. We do not use your workspace data to train models for anyone else, and we do not build a shared candidate pool out of our customers’ data.
5. Who we share it with
5.1 We use a small number of service providers, each bound by contract to process only on our instructions. The current list, and the countries they operate in, is maintained in Annexure A of the data processing addendum, which is the authoritative version and is updated on notice.
5.2 Beyond those providers, we share personal information only with professional advisers under duties of confidence, with an acquirer if our business is sold (on notice, and subject to this policy), and where a law, a court order or a regulator compels it.
6. Sending information outside South Africa
6.1 Some of our providers operate outside South Africa. Where personal information leaves the country we rely on section 72 of POPIA: the recipient is bound by contractual terms giving effect to principles substantially similar to POPIA, including restrictions on onward transfer.
6.2 The country in which each provider processes information is listed in Annexure A of the data processing addendum.
7. How long we keep it
- While you are a user — for as long as your account is active in a workspace.
- After a workspace ends — the workspace stays read-only for 30 days and is then deleted, including files in storage. We keep only the organisation name, the billing contact, the subscription dates and the fact of deletion.
- Billing and tax records — five years, as required by the Companies Act 71 of 2008 and the Tax Administration Act 28 of 2011.
- Terms acceptances — for as long as the agreement they evidence could be relied on, because a signature you can no longer produce is not evidence of anything.
- Security logs — 12 months, unless a specific incident requires longer.
- Backups — overwritten on an ordinary cycle not exceeding 35 days.
8. How we protect it
8.1 Every table in the database enforces row-level security, so a workspace’s data is separated from every other workspace at the database level rather than by application code alone.
8.2 Traffic is encrypted in transit and data is encrypted at rest. Mailbox credentials are encrypted with a separate key. Access to production by our staff is limited, is granted for a limited time, and is logged.
8.3 If a security compromise affects personal information, we will notify the Information Regulator and the affected responsible party as soon as reasonably possible after establishing the scope, as section 22 of POPIA requires.
9. Your rights
9.1 Under POPIA you may:
- ask what personal information we hold about you and get a copy;
- ask us to correct or delete information that is wrong, misleading, excessive or no longer needed;
- object to processing based on legitimate interests;
- withdraw consent where consent is the basis, without affecting what was done before;
- complain to the Information Regulator (South Africa) at inforegulator.org.za.
9.2 Write to support@recruit360.co.za. We will respond within 30 days. We may ask you to verify your identity, and we will say so if a request cannot be met in full and why.
9.3 If your request concerns a candidate record inside a customer’s workspace, we will refer you to that customer, who is the responsible party for it, and we will assist them to answer you.
10. Cookies and tracking
10.1 We set cookies to keep you signed in and to keep your session secure. They are necessary for the service to work and cannot be switched off while you use it.
10.2 We do not use advertising cookies, third-party analytics trackers or cross-site tracking pixels on this site or in the application.
11. Children
11.1 The service is for workplace use by adults. We do not knowingly create accounts for children, and a customer must not record a child’s personal information in a workspace except where the law permits and its own notice covers it.
12. Changes
12.1 We may update this policy. Where a change materially affects how we use your personal information we will tell workspace owners in advance and, where required, ask for renewed acceptance on sign-in.