Home About The Experience Detailing Franchise Training Contact
Book Now
Legal

Privacy Policy

How SafeTouch SA (Pty) Ltd collects, uses, shares, stores and protects your personal information, in line with POPIA, the CPA and ECTA.

DRAFT, for review by a qualified South African attorney before publication. Placeholders in [SQUARE BRACKETS] must be completed. SafeTouch operates a franchise system; FASA/CPA-specific terms must be verified against the signed Franchise Disclosure Document and Agreement.

Effective date: [EFFECTIVE DATE]

Last updated: [LAST UPDATED DATE]

1. Introduction

1.1 This Privacy Policy explains how SafeTouch SA (Pty) Ltd (registration number [COMPANY REGISTRATION NUMBER]) ("SafeTouch", "we", "us" or "our") collects, uses, shares, stores and protects your personal information when you engage with us, including when you visit our website at safetouch.co.za (the "Website"), request a quote or booking, apply to become a franchisee, contact us, or use our customer, franchisee or operator app/portal (the "App").

1.2 We are committed to processing personal information lawfully, fairly and transparently in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and, where applicable, the Consumer Protection Act 68 of 2008 ("CPA") and the Electronic Communications and Transactions Act 25 of 2002 ("ECTA").

1.3 By using the Website or App, or by submitting your personal information to us, you acknowledge that you have read and understood this Privacy Policy. Where the law requires your consent for a particular processing activity, we will obtain it separately.

2. Who we are and how to contact us

2.1 Responsible Party (Operator/Controller): SafeTouch SA (Pty) Ltd

2.2 Registered address: [REGISTERED ADDRESS]

2.3 Physical/operating address: [PHYSICAL ADDRESS]

2.4 Operating areas: Ballito (KwaZulu-Natal) and Johannesburg (Gauteng), South Africa.

2.5 Email: info@safetouch.co.za

2.6 Telephone: [PHONE NUMBER]

2.7 Information Officer: [INFORMATION OFFICER NAME]
Email: [INFORMATION OFFICER EMAIL, e.g. privacy@safetouch.co.za]
Our Information Officer is registered with the Information Regulator and is responsible for ensuring our compliance with POPIA. You may contact the Information Officer for any privacy-related query, request or complaint.

3. The personal information we collect

We collect different categories of personal information depending on how you interact with us:

3.1 Customers (booking, quote and contact forms)

  • Name and surname;
  • Contact details (email address, mobile/telephone number);
  • Service address and access details (the premises where the vehicle will be detailed);
  • Vehicle details (make, model, registration, condition);
  • Booking and service history, preferences and special instructions;
  • Payment-related information processed by our third-party card terminal/payment provider (we do not store full card numbers);
  • Records of communications between you and us.

3.2 Job records (audiovisual records of service)

As part of our documented service-quality and inspection process, we create and retain:

  • Video footage of each detailing job; and
  • A set of approximately ten (10) photographs per job,

which records the condition of the vehicle before and after service and may incidentally capture portions of your premises. These records protect both you and us by providing an accurate inspection record of the vehicle's pre-existing condition and the work performed. Where such footage or images identify an individual, they constitute personal information and are handled in accordance with this Policy.

3.3 Franchise applicants (special note, sensitive information)

If you apply to become a SafeTouch franchisee, we collect additional and more sensitive information, which may include:

  • Identity/passport number and a copy of your identity document;
  • Financial standing information (proof of funds, bank details, credit information, income/asset information);
  • Employment and business history;
  • Information obtained from, and your consent to, background and criminal-record checks conducted by us or our appointed third-party screening providers.

Certain of this information falls within the special personal information and/or criminal-behaviour categories under sections 26–33 of POPIA. We process it only where one of the lawful grounds in POPIA applies, typically your explicit consent, the conclusion or performance of a franchise agreement, or the establishment, exercise or defence of a right or obligation in law. You may withdraw consent at any time, subject to the consequence that we may be unable to progress your application.

3.4 App / portal users (customers, franchisees, operators)

  • Account credentials and profile information;
  • Role-based information (e.g. operator job assignments, franchisee territory data);
  • Booking, scheduling and service records;
  • Device, log and usage information (including IP address and access times) collected via the App and its supporting API;
  • Location information where reasonably required to fulfil a "we come to you" booking (only with the appropriate basis or consent).

3.5 Website visitors

  • Technical information automatically collected via cookies and analytics (see clause 9), such as IP address, browser type, pages visited and referral source.

4. How and why we collect personal information, and our lawful basis (POPIA)

4.1 We collect personal information directly from you (via forms, the App, email, telephone or in person at the service location) and, where applicable, from third parties such as background-check providers (for franchise applicants, with your consent).

4.2 We process personal information only where we have a lawful basis under section 11 of POPIA, namely one or more of the following:

PurposeLawful basis under POPIA
Providing quotes and performing detailing servicesPerformance of, or steps to conclude, a contract with you
Creating video and photo job records for inspection and dispute protectionOur legitimate interests and the protection of a legitimate interest of the data subject; consent where required
Processing paymentsPerformance of a contract; legal obligation
Assessing and processing franchise applications (incl. ID, financial and background checks)Explicit consent; performance of/steps to a franchise agreement; establishment, exercise or defence of a right in law
Marketing communicationsConsent (and, for existing customers, the limited direct-marketing allowance in section 69 of POPIA)
Operating the App, security and fraud preventionLegitimate interests; legal obligation
Complying with tax, accounting and other legal dutiesLegal obligation

5. How we use your personal information

We use personal information to:

  • 5.1 respond to enquiries and provide quotes;
  • 5.2 schedule, perform and record detailing services at your premises;
  • 5.3 take and retain video footage and photographs as an inspection and quality record;
  • 5.4 process payments via our card terminal/payment provider;
  • 5.5 assess, screen and administer franchise applications and agreements;
  • 5.6 operate, secure and improve the App, Website and our services;
  • 5.7 send service-related communications and, where permitted, marketing;
  • 5.8 handle complaints, disputes and insurance or liability matters; and
  • 5.9 comply with our legal and regulatory obligations.

6. Sharing your personal information with third parties

6.1 We do not sell your personal information. We share it only as necessary and under appropriate safeguards, including with:

  • Payment processor(s), our third-party card-terminal/payment provider [PAYMENT PROVIDER NAME], to process cashless payments;
  • Background-check / screening providers, for franchise applicants, with your consent;
  • Hosting and App/technology providers, including our website host, App developer and API/cloud infrastructure provider [HOSTING/APP PROVIDER NAME(S)];
  • Operators and franchisees, each territory may be serviced by an independent franchisee or operator under the SafeTouch system, who will receive the booking and access information needed to perform your service;
  • Professional advisors, accountants, auditors, attorneys and insurers, where required;
  • Authorities, where required by law or to protect our rights.

6.2 Where we share information with an operator or processor that handles it on our behalf, we put in place a written agreement requiring them to process the information only for the agreed purpose, to maintain confidentiality, and to apply appropriate security measures, as required by sections 20–21 of POPIA.

7. The eight POPIA conditions for lawful processing

We process personal information in line with the eight conditions for lawful processing under POPIA, namely: (1) Accountability; (2) Processing limitation (lawfulness, minimality and consent/justification); (3) Purpose specification; (4) Further processing limitation; (5) Information quality; (6) Openness; (7) Security safeguards; and (8) Data subject participation.

8. Your rights as a data subject (POPIA)

8.1 Subject to POPIA, you have the right to:

  • be notified that we are collecting your information, and where it was collected from another source;
  • access the personal information we hold about you;
  • request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained;
  • object, on reasonable grounds, to the processing of your personal information;
  • object to direct marketing and to withdraw consent to it at any time;
  • not be subject to a decision based solely on automated processing that has legal or similarly significant effects, except as permitted by law; and
  • complain to the Information Regulator (see clause 8.4).

8.2 To exercise any of these rights, contact our Information Officer (clause 2.7). We may require verification of your identity and, where the law permits, the prescribed POPIA request form may be used. We will respond within a reasonable period.

8.3 We will not unfairly discriminate against you for exercising your rights, although certain services (for example, processing a franchise application) may not be possible without the necessary information.

8.4 Complaints to the Information Regulator:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 (P.O. Box 31533, Braamfontein, 2017)
General enquiries: enquiries@inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
Website: https://inforegulator.org.za

9. Cookies and analytics

9.1 The Website uses cookies and similar technologies to operate, secure and improve the Website and to understand how it is used. These include strictly necessary cookies and, where you consent, analytics cookies (for example, [ANALYTICS PROVIDER, e.g. Google Analytics]).

9.2 You can manage or disable cookies through your browser settings, although some features may not function correctly as a result. Where required, we will request your consent via a cookie banner.

10. Data retention

10.1 We keep personal information only for as long as necessary to fulfil the purposes set out in this Policy, or as required or permitted by law (for example, tax and company-law record-keeping obligations).

10.2 Indicative retention periods:

  • Customer booking and service records: [RETENTION PERIOD, e.g. 5 years];
  • Video footage and job photographs: [RETENTION PERIOD, e.g. 6–12 months, unless required for a dispute or claim];
  • Franchise application records (including ID, financial and background-check data): [RETENTION PERIOD], after which unsuccessful-applicant data is securely deleted or de-identified unless retention is required by law.

10.3 When personal information is no longer required, we securely destroy, delete or de-identify it.

11. Security safeguards

11.1 We take reasonable, appropriate technical and organisational measures to protect personal information against loss, damage, unauthorised access and unlawful processing, including access controls, encryption in transit where appropriate, secure hosting and staff confidentiality obligations.

11.2 In the event of a security compromise affecting your personal information, we will notify you and the Information Regulator as required by section 22 of POPIA.

12. Cross-border transfers

12.1 Some of our service providers (for example, App hosting, cloud infrastructure or analytics) may process personal information outside South Africa. Where we transfer personal information across borders, we do so only in accordance with section 72 of POPIA, for example, where the recipient is subject to laws or binding agreements providing an adequate level of protection, or where you have consented, or where the transfer is necessary to perform a contract with you.

13. Children's information

We do not knowingly collect the personal information of children (persons under 18) without the consent of a competent person, except as permitted by POPIA.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The current version, with its effective date, will always be available on the Website. Material changes will be communicated where reasonably practicable.

15. How to contact us / lodge a request

For any privacy query, access or correction request, or to withdraw consent, contact:
Information Officer: [INFORMATION OFFICER NAME]
Email: [INFORMATION OFFICER EMAIL] / info@safetouch.co.za
Address: [PHYSICAL ADDRESS]