Privacy Policy

Official Document

Last Revised: 14 November 2023

PolicyOne ("we", "us", "our") respects your privacy and is fully committed to protecting the personal information of our clients and their respective policyholders. This Privacy Policy outlines our data handling practices.

1. POPIA Compliance Commitment

As a South African technology provider processing sensitive financial and personal data, PolicyOne strictly adheres to the provisions of the Protection of Personal Information Act, 4 of 2013 (POPIA). We implement robust technical and organisational measures to ensure data confidentiality, integrity, and availability.

2. Information We Collect

We collect and process the following categories of information:

  • Client Data: Information about our direct customers (funeral parlours, FSPs, insurers), including company registration details, director IDs, billing information, and contact details.
  • End-User Data (Policyholders): Data entered into the platform by our Clients regarding their policyholders, including names, South African ID numbers, dates of birth, addresses, next of kin details, and banking information for premium collection.
  • System Usage Data: IP addresses, browser types, login timestamps, and audit logs of actions performed within the platform.

3. How We Use the Information

Personal information is processed strictly for the following purposes:

  • To provide, operate, and maintain the PolicyOne platform.
  • To facilitate premium collections, claims processing, and SMS communications on behalf of our Clients.
  • To process subscription billing and enforce our Terms & Conditions.
  • To detect, prevent, and address technical issues, fraud, or security breaches.

4. Data Sharing and Disclosure

We do not sell, rent, or trade your data. We may share information with trusted third parties only under the following circumstances:

  • Service Providers: Payment gateways, SMS aggregators, and cloud hosting providers (e.g., AWS) who process data on our behalf under strict confidentiality agreements.
  • Legal Compliance: If requested by South African law enforcement, the Financial Sector Conduct Authority (FSCA), or under a valid court order.

5. Data Security and Retention

We employ industry-standard encryption (TLS/SSL for data in transit and AES-256 for data at rest). We retain personal data only for as long as the Client's account is active, or as required by South African financial record-keeping laws (typically 5 years post-termination).

Need a printed version or have legal questions?

Contact Legal Team