Privacy Policy
Last updated: PLACEHOLDER: DATE OF PUBLICATION
This Privacy Policy explains how KuddeSoft (“KuddeSoft”, “we”, “us”, “our”) collects, uses, stores, discloses and protects personal information in connection with this marketing website located at PLACEHOLDER: WEBSITE DOMAIN (the “Site”). This Policy does not cover the separate feedlot/livestock management software product that KuddeSoft licenses to its clients, which is deployed on isolated, client-specific infrastructure and governed by the applicable client’s own agreement and (if applicable) that client’s own privacy notices to its end users.
This Policy is issued in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”).
1. Who we are (Responsible Party)
KuddeSoft is the “responsible party” under POPIA for the personal information described in this Policy.
- Registered company name: PLACEHOLDER: FULL REGISTERED COMPANY NAME
- Company registration number: PLACEHOLDER: CIPC REGISTRATION NUMBER
- Physical/registered address: PLACEHOLDER: PHYSICAL BUSINESS ADDRESS
- Contact email for privacy queries: PLACEHOLDER: PRIVACY CONTACT EMAIL
Information Officer
In terms of section 55 of POPIA, KuddeSoft has designated an Information Officer responsible for compliance with POPIA and for handling requests and complaints relating to personal information.
- Information Officer: PLACEHOLDER: NAME OF INFORMATION OFFICER
- Contact details: PLACEHOLDER: INFORMATION OFFICER EMAIL / PHONE
- Registration with the Information Regulator: PLACEHOLDER: CONFIRM INFORMATION OFFICER HAS BEEN REGISTERED WITH THE INFORMATION REGULATOR (inforegulator.org.za) — REQUIRED BEFORE THE INFORMATION OFFICER MAY PERFORM THIS FUNCTION
If you are unable to reach our Information Officer, or are not satisfied with our response, you have the right to lodge a complaint with the Information Regulator of South Africa:
- Website: inforegulator.org.za
- Email: complaints.IR@justice.gov.za
- Physical address: PLACEHOLDER: CONFIRM CURRENT INFORMATION REGULATOR ADDRESS AT TIME OF PUBLICATION, AS IT HAS RELOCATED PREVIOUSLY
2. Scope — what this Policy covers
This Policy applies only to personal information collected through the KuddeSoft marketing website, namely:
- Leads submitted through the contact form or package/pricing sign-up forms.
- Client accounts created through a third-party sign-in provider on the client portal.
- Billing information processed for self-serve subscriptions via a third-party payment provider.
- Admin/staff accounts used internally by KuddeSoft personnel.
- Cookies used to operate login sessions, described in full in our Cookie Policy.
We do not currently run any analytics, advertising, or behavioural tracking on this Site, and we do not use cookies for those purposes.
3. What personal information we collect
3.1 Contact-form and package-signup leads
- Full name
- Email address
- Company name
- Phone number (optional)
3.2 Self-serve client accounts (third-party sign-in)
Client portal accounts are created and authenticated through a supported third-party sign-in provider. When you sign in, we receive and store:
- A unique account identifier from that provider
- Email address
- Name
- Avatar/profile picture URL
We do not receive or store your password with that provider. Authentication is handled entirely by the provider; we never see or store your login credentials. The specific provider used is identified on the sign-in screen itself, and full technical detail is available on request (see section 13).
3.3 Billing information
When you subscribe to a paid package, payment is processed by a licensed third-party payment service provider. KuddeSoft does not collect, transmit, or store full card numbers. Our payment provider tokenises card details and returns to us only:
- Card brand (e.g. Visa, Mastercard)
- Last 4 digits of the card
- Card expiry date
- A customer reference code and subscription reference code
All charges are processed and settled in South African Rand (ZAR).
3.4 Admin/staff accounts
For internal KuddeSoft staff who administer the Site, we hold:
- Email address
- A securely hashed password (never stored or transmitted in plain text)
- Two-factor authentication (2FA) enrolment data
This is an internal system and is not customer-facing.
3.5 Cookies
Strictly necessary session cookies for keeping you logged in (admin and client portals) and a short-lived OAuth security cookie. See our Cookie Policy for full detail. We do not use analytics, advertising, or tracking cookies.
4. Why we process your personal information (purpose and lawful basis)
In accordance with section 11 of POPIA, we only process personal information where at least one lawful basis applies:
| Purpose | Personal information used | Lawful basis (POPIA s 11) |
|---|---|---|
| Responding to enquiries and providing quotes | Lead details | Legitimate interest in operating our business / steps prior to entering a contract |
| Creating and operating your client portal account | Third-party sign-in account data | Necessary to perform our contract with you |
| Billing and subscription management | Tokenised billing data | Necessary to perform our contract with you; compliance with legal (tax/financial recordkeeping) obligations |
| Operating admin accounts | Staff login and 2FA data | Legitimate interest in securing our systems; employment-related processing |
| Keeping you securely logged in | Session and OAuth cookies | Necessary to perform our contract with you / legitimate interest in Site security |
We do not use your personal information for automated decision-making that produces legal or similarly significant effects, and we do not sell personal information to third parties.
5. Conditions for lawful processing (POPIA Chapter 3)
We process personal information in line with POPIA’s eight conditions for lawful processing:
- Accountability — KuddeSoft is responsible for compliance with these conditions.
- Processing limitation — we only process information lawfully, minimally, and with your awareness/consent where required.
- Purpose specification — information is collected for the specific, defined purposes set out in section 4 above, and not repurposed incompatibly.
- Further processing limitation — information is not further processed in a manner incompatible with the purpose for which it was collected.
- Information quality — we take reasonable steps to keep personal information accurate, complete, and up to date.
- Openness — this Policy documents what we process and why.
- Security safeguards — see section 8 below.
- Data subject participation — see section 6 below (your rights).
6. Your rights as a data subject
Under POPIA, you have the right to:
- Be notified that personal information about you is being collected;
- Establish whether we hold personal information about you, and request access to it;
- Request correction, updating, or deletion of inaccurate, irrelevant, excessive, outdated, incomplete, or unlawfully obtained personal information;
- Object, on reasonable grounds, to the processing of your personal information;
- Object to processing for purposes of direct marketing;
- Not be subject solely to automated decision-making that materially affects you;
- Lodge a complaint with the Information Regulator; and
- Institute civil proceedings for breach of POPIA’s provisions.
To exercise any of these rights, contact our Information Officer using the details in section 1. We will respond within the timeframes required by POPIA.
7. Sharing your information — sub-processors and third parties
We share limited personal information with categories of service providers, each acting as an “operator” (processor) under POPIA, or as an independent responsible party where noted, strictly for the purposes described in this Policy:
- Sign-in / authentication provider — for authenticating client portal accounts. This provider acts as an independent responsible party for its own authentication service and processes data under its own privacy policy.
- Payment service provider — for processing subscription payments and card tokenisation. This provider acts as an independent responsible party for payment processing, subject to its own privacy policy and applicable payment-industry security standards.
- Hosting/infrastructure provider — operating our Site infrastructure, acting as an operator on our behalf.
- Email delivery provider — where used, for sending lead-notification and transactional email.
We do not sell, rent, or trade personal information to third parties for their own marketing purposes. The specific identity of each provider is not published here; it is available on request — see section 13 (Contact us).
7.1 Cross-border transfers (POPIA section 72)
Some of our service providers may process personal information on servers located outside South Africa. Where personal information is transferred to a foreign country, we rely on one or more of the grounds in section 72 of POPIA, which permits such a transfer where, among other things: the recipient is subject to a law, binding corporate rules, or binding agreement that provides an adequate level of protection substantially similar to POPIA’s conditions and to section 72 itself; the transfer is necessary for the performance of a contract between you and us (e.g. processing your subscription payment or authenticating your login); or you have consented to the transfer.
- Our sign-in and payment providers maintain their own cross-border data transfer safeguards (e.g. standard contractual clauses, industry security certifications); details are available on request.
- PLACEHOLDER: CONFIRM FINAL HOSTING REGION/PROVIDER AND WHETHER ANY OTHER CROSS-BORDER TRANSFER OCCURS VIA HOSTING
We otherwise host Site infrastructure and data in/from South Africa by default, as described in section 9.
8. Security safeguards
In line with section 19 of POPIA, we implement appropriate technical and organisational measures to protect personal information against loss, unauthorised access, interference, or disclosure, including:
- HTTPS/TLS encryption in transit;
- Hashed (never plain-text) storage of admin passwords;
- Mandatory two-factor authentication (2FA) for admin/staff accounts;
- HttpOnly, Secure (in production) session cookies;
- No storage of raw card numbers — all card data is tokenised by our payment provider;
- Access controls restricting who at KuddeSoft may view personal information.
No security measure is perfect. If we become aware of a security compromise involving your personal information that gives rise to a reasonable belief that unauthorised access has occurred, we will notify the Information Regulator and affected data subjects as required by section 22 of POPIA, as soon as reasonably possible.
9. Where your information is stored
The Site and its associated data are hosted on infrastructure controlled by KuddeSoft, operated from South Africa by default. PLACEHOLDER: CONFIRM FINAL CLOUD PROVIDER AND SERVER REGION ONCE FINALISED — UPDATE THIS SECTION AND SECTION 7.1 IF SERVERS ARE NOT LOCATED IN SOUTH AFRICA.
10. Retention
We retain personal information only for as long as necessary to fulfil the purposes described in this Policy, or as required by law (e.g. financial/tax recordkeeping obligations under South African law), after which it is securely deleted or anonymised. PLACEHOLDER: CONFIRM SPECIFIC RETENTION PERIODS, e.g. lead data retained for X months if no conversion; billing records retained for X years per tax law.
11. Children’s information
The Site and product are intended for business use by adults acting on behalf of agribusiness clients. We do not knowingly collect personal information from children as defined in POPIA.
12. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices or legal requirements. The “Last updated” date at the top of this page indicates when it was last revised. Material changes will be highlighted on this page.
13. Contact us
For any questions about this Policy, to exercise your rights, or to request the specific identity of a named category of service provider referred to in section 7, contact:
- Information Officer: PLACEHOLDER: NAME
- Email: PLACEHOLDER: EMAIL
- Physical address: PLACEHOLDER: ADDRESS
This document is a starting draft prepared based on legal research into POPIA, the ECT Act, and related South African law. It is not a substitute for review and sign-off by a South African admitted attorney before publication.