This Privacy Policy explains how Struct Assess collects, uses, shares, stores and protects personal information, and your rights under the Protection of Personal Information Act 4 of 2013 ("POPIA"). It applies to our website, our Platform, and the services we provide. Please read it together with our End-User License Agreement, published at https://structassess.co.za/eula.
1. Who we are and who is responsible
1.1 The Responsible Party for the personal information described in this policy is [LEGAL ENTITY NAME], registration number [REGISTRATION NUMBER], trading as Struct Assess, of [Street address], Somerset West, Western Cape, South Africa.
1.2 Our Information Officer is [Information Officer name], who can be reached at info@structassess.co.za. You can contact the Information Officer about this policy, about how we handle personal information, or to exercise any of your rights.
2. What this policy covers
2.1 This policy covers personal information we process about the following people (data subjects):
2.1.1 staff users of the Platform (administrators, operators, engineers and quality reviewers);
2.1.2 clients and their contacts and representatives;
2.1.3 property owners, occupants and other people who appear in case files, site records or photographs; and
2.1.4 visitors to our website.
2.2 It does not change any separate professional or contractual duty of confidentiality we owe you.
3. Some words we use
3.1 "Personal information" means information about an identifiable, living person, and where applicable an identifiable existing organisation, as defined in POPIA.
3.2 "Processing" means anything we do with personal information, such as collecting, storing, using, sharing or deleting it.
3.3 "Operator" means a person or business that processes personal information for us, on our instruction.
3.4 "Special personal information" means the categories POPIA treats as more sensitive, and which include, for our purposes, identity numbers.
4. The personal information we collect
4.1 Staff users: name, email address, a hashed password (we cannot see the plain password), role and account status. For engineers, we also hold professional registration number and registration body, phone number, VAT registration status and VAT number, availability, specialisations and the regions and travel zones they cover.
4.2 Clients and their contacts: display name, entity type, registration number and VAT number where the client is an organisation, email and billing email, phone number, postal or physical address, notes, and for each contact person their name, role, email and phone number.
4.3 Property owners, occupants and other people captured in case files: information contained in the documents, photographs, site measurements, drawings, certificates and other material uploaded for a matter. Photographs of a property may show people, vehicles or personal belongings that happen to be present.
4.4 Payment information: proof of payment details (such as bank reference, stated amount and payment date), payment request and transaction references from our payment provider, and invoice identifiers and numbers from our accounting system. We do not store full card numbers; card payments are handled by our payment provider.
4.5 Records of activity: audit events, booking history, proposal view and acceptance records (including the name of the accepting person and when acceptance occurred), report access logs (including the date, time, action and the IP address from which a report was accessed), and secure link usage (such as access counts and the times a link was used or revoked).
4.6 Website visitors: the information you submit in our enquiry form (name, email, property address, optional phone number, the type of help you need and your message), and technical information your browser sends when you visit, such as your IP address, which our hosting provider processes to deliver and protect the site.
5. Special personal information, including ID numbers
5.1 We collect a South African identity number or passport number for a client only where it is necessary, for example to identify the correct person for invoicing, billing or verification, or to meet a legal requirement. Providing an identity number is optional in our records unless a specific purpose requires it.
5.2 We process identity numbers in line with section 27 of POPIA, which permits their processing where it is necessary for the establishment, exercise or defence of a right or obligation in law, for compliance with an obligation of law, or with your consent, and we limit their use to those purposes.
6. Where we get personal information
6.1 We collect personal information:
6.1.1 directly from you, for example when you complete an enquiry form, an intake form, a proposal acceptance or a proof-of-payment form, or when we invite you as a staff user;
6.1.2 from our engineers and staff who capture site information, measurements and photographs during an assessment; and
6.1.3 from third parties connected to a matter, such as insurers, brokers, body corporates, managing agents, estate agents or attorneys, where they provide information relevant to the assessment.
7. Why we are allowed to process it (lawful bases)
7.1 We rely on the grounds for lawful processing in section 11 of POPIA, namely:
7.1.1 to conclude and perform a contract with you or the client you represent;
7.1.2 to comply with an obligation imposed on us by law, for example keeping accounting and tax records;
7.1.3 to protect a legitimate interest of yours;
7.1.4 to pursue our legitimate interests or those of a third party, such as running our business, securing the Platform, preventing fraud and defending or exercising legal rights, balanced against your interests; and
7.1.5 with your consent, where we ask for it.
8. What we use personal information for (purposes)
8.1 We process personal information to:
8.1.1 respond to enquiries and prepare proposals;
8.1.2 carry out structural assessments and prepare, deliver and store Reports;
8.1.3 manage matters, bookings, cases, documents and communications;
8.1.4 issue invoices, request and reconcile payments, and keep financial records;
8.1.5 create, send and manage secure links, and control and audit access to them;
8.1.6 operate, secure, support and improve the Platform and our website;
8.1.7 keep audit trails and access logs for security, accountability and dispute resolution; and
8.1.8 comply with our legal, regulatory and professional obligations.
9. Further processing
9.1 If we use personal information for a new purpose, we will make sure the new purpose is compatible with the purpose it was collected for, as required by section 15 of POPIA, or we will get your consent or rely on another lawful ground.
10. Who we share personal information with
10.1 We share personal information only where necessary, with:
10.1.1 our staff and engineers who need it to do their work;
10.1.2 Intuit (QuickBooks Online), our accounting and invoicing provider (see section 11);
10.1.3 Peach Payments, our payment provider, to process payments and payment links;
10.1.4 our email provider, to send transactional messages and secure links;
10.1.5 our file storage provider, which stores documents, photographs and Reports for a matter;
10.1.6 Cloudflare, which hosts and protects our website and Platform;
10.1.7 Google Fonts, which serves fonts to your browser when you visit our marketing website, and which in doing so receives your browser's IP address as part of the request; and
10.1.8 professional advisers, authorities or other third parties where we are required or permitted by law, or to establish, exercise or defend a legal right.
10.2 The providers in clauses 10.1.2 to 10.1.7 that process personal information for us do so as our operators or as independent parties under their own terms, and we require operators to keep it secure and to process it only on our instruction, as required by section 21 of POPIA. We do not sell personal information.
11. QuickBooks Online integration
11.1 If we connect our Struct Assess account to your, or the client's, QuickBooks Online company, this section explains what that connection does. This section is provided so that Intuit's reviewers and our users understand the integration.
11.2 What we access: within the connected QuickBooks company, we create and read invoices, and we read and, where needed, create the customer records that those invoices require. We access this only to raise and reconcile invoices for deposits and final payments.
11.3 What we store: the OAuth tokens for the connection, the QuickBooks company identifier (realm ID), the invoice identifiers and numbers we create, and the sync status and any last error for the connection.
11.4 What we do not do: we do not sell QuickBooks data, we do not use it for advertising, and we do not access anything in the QuickBooks company beyond what is needed for invoicing.
11.5 On disconnect: when the QuickBooks connection is removed, we revoke and delete the stored OAuth tokens. We keep the invoice identifiers and numbers as part of our financial records for the retention periods described in section 15, because they form part of our accounting records.
11.6 Your use of Intuit services is also governed by Intuit's own terms of service and privacy statement, which are available from Intuit.
11.7 QuickBooks and Intuit are trademarks of Intuit Inc., registered in the United States and other countries. Struct Assess is an independent business and is not affiliated with, endorsed by or sponsored by Intuit Inc.
12. Sending information outside South Africa
12.1 Some of our providers, including QuickBooks Online (Intuit), Cloudflare, our email provider, our file storage provider and Google Fonts, process or store personal information on servers outside South Africa. This means personal information may be transferred across borders.
12.2 We make these transfers in line with section 72 of POPIA, which means we only transfer personal information to a recipient in another country where the recipient is subject to a law, binding rules or a binding agreement that provides an adequate level of protection similar to POPIA, where the transfer is necessary to perform or conclude a contract in your interest, or where you have consented.
13. Cookies and browser storage
13.1 Our marketing website does not use tracking or advertising cookies. It uses only what is essential to serve and secure the site.
13.2 The Platform (the signed-in web application and secure links) stores authentication tokens in your browser's storage so that you can stay signed in and use the service. These are essential to the service and are not used for advertising.
14. How we keep information secure
14.1 We take reasonable technical and organisational measures to protect personal information, as required by section 19 of POPIA. These include:
14.1.1 encryption of data in transit;
14.1.2 role-based access, so staff users only see what their role requires;
14.1.3 audit logs and access logs that record key actions;
14.1.4 secure links that are time-limited and can be revoked; and
14.1.5 logging of the IP address from which a Report is accessed.
14.2 No system can be guaranteed to be completely secure. We keep our measures under review and improve them over time. We describe here the measures we actually apply and do not claim safeguards we do not have.
15. How long we keep information, and deletion
15.1 We keep personal information for as long as it is needed for the purposes described in this policy, and for the periods the law requires, as contemplated by section 14 of POPIA.
15.2 Retention periods include, among others:
15.2.1 accounting records, kept for at least seven years under the Companies Act 71 of 2008;
15.2.2 tax records, kept for at least five years under the Tax Administration Act 28 of 2011; and
15.2.3 professional engineering records, including Reports, kept for the period reasonably required to manage professional liability arising from the assessment.
15.3 During these periods we normally deactivate rather than immediately delete a record. Deactivation means the record is retained but is no longer active in day-to-day use.
15.4 When personal information is no longer needed and no retention period requires us to keep it, we delete, destroy or de-identify it in a way that prevents it from being reconstructed.
15.5 You may ask us to delete personal information about you. We will do so where we are not required or entitled by law to keep it. Where we must keep it for a retention period, we will restrict its use and delete it when the period ends. See section 16 for how to make a request.
16. Your rights
16.1 Under POPIA you have the right to:
16.1.1 be told what personal information we hold about you and to access it (section 23);
16.1.2 ask us to correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained (section 24);
16.1.3 object, on reasonable grounds, to our processing of your personal information (section 11(3));
16.1.4 object to processing for direct marketing (section 69, and see section 17 below); and
16.1.5 complain to the Information Regulator (see section 21).
16.2 To exercise a right, contact our Information Officer using the details in section 24. We may need to verify your identity before we act. We will respond within a reasonable time and as the law requires. Access requests are handled in line with the Promotion of Access to Information Act 2 of 2000 (see section 22), and a prescribed fee may apply to certain requests.
17. Direct marketing
17.1 We do not send unsolicited electronic marketing. If we ever send you marketing by electronic communication, we will do so only where the law allows, and every message will let you opt out. You can also ask us at any time to stop, using the details in section 24.
18. Children
18.1 The Platform and our services are intended for use by adults and are not directed at children under 18. We do not knowingly collect personal information of a child except where it appears incidentally in a case file for a matter, and where it does we process it under the same protections described in this policy.
19. Automated decision-making
19.1 We do not make decisions about you that have legal or similarly significant effects based solely on automated processing.
20. If a security breach happens
20.1 If there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected people as soon as reasonably possible, as required by section 22 of POPIA, unless the law requires us to delay in order to protect an investigation.
21. Complaints to the Information Regulator
21.1 If you are not satisfied with how we handle your personal information, you may complain to the Information Regulator:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: complaints.IR@justice.gov.za
22. PAIA manual
22.1 We maintain a manual under the Promotion of Access to Information Act 2 of 2000, which describes the records we hold and how to request access to them. You can request a copy of the manual, and make access requests, using the details in section 24.
23. Changes to this policy
23.1 We may update this policy from time to time. When we do, we will change the effective date at the top and publish the updated version at https://structassess.co.za. Where a change is material, we will bring it to your attention where reasonably practical.
24. How to contact us
Struct Assess
Attention: Information Officer, [Information Officer name]
[Street address], Somerset West, Western Cape, South Africa
Email: info@structassess.co.za
Telephone: +27 21 851 4816
Website: https://structassess.co.za