Protection of Personal Information (POPI) Policy
Last Updated: July 9, 2026
INTERNAL AND EXTERNAL PROTECTION OF PERSONAL INFORMATION POLICY DOCUMENTING OPERATIONAL PROCEDURES TO FULFILL THE EIGHT CONDITIONS FOR LAWFUL PROCESSING MANDATED BY POPIA.
1. Operational Framework for Zero-Budget Lean SaaS
This policy codifies how Plinth-Cloud (Pty) Ltd integrates data privacy regulations into its daily operations on a lean budget, without requiring massive legal capital. In our streamlined structure, the platform founder serves as the legally accountable Information Officer, using software automation to handle routine requirements and manually addressing exceptional data conditions.
2. Processing Principles
We guarantee that personal data is processed lawfully, and in a reasonable manner that does not infringe on the privacy of data subjects. Data is collected for specific, explicitly defined, and lawful purposes related to our property management services.
3. Verbatim Consent Interface Protocols
- Landlord Signup Consent Interface Text
- I consent to Plinth processing my personal information for the purpose of property management services.
- I consent to my banking details being shared with payment gateway providers (Stitch, Ozow) for payment processing.
- I confirm I have authority to provide tenant information and will obtain tenant consent before adding them to the platform.
- Tenant Invite Consent Interface TextThe platform requires the checking of the following text items before granting access to a tenant workspace link:
[Landlord Name] has invited you to Plinth for property: [Address]. Before you can access the portal, you must consent to:
- I consent to Plinth processing my personal information for property management purposes (payment processing, maintenance requests, communication).
- I consent to my payment information being processed by the payment gateway provider.
- I understand I can withdraw consent at any time by contacting the Information Officer at compliance@plinthcloud.com.
- Tenant Screening Consent Interface Text
- I consent to Plinth conducting a credit check with the registered credit bureau for tenant screening purposes.
- I understand this is a 'soft' inquiry and will not affect my credit score.
- Algorithmic Data Minimization & Retention Schedule
- Automated 'Plinth Match' Engine POPIA Alignment
- Verbatim Regulatory Data Breach Email Template
- Data Subject Rights Automation Sequences
- Access Requests: Users click an integrated 'Download My Data' button in their settings panel. The system queries all tables for that user ID, builds a structured JSON/CSV file, and emails it to the user with zero human intervention.
- Correction Requests: Managed via a self-service profile dashboard, allowing users to update their identity fields and contact parameters instantly.
- Deletion Sequences: Triggered by a 'Delete My Account' dashboard control. The system sets a soft- delete flag, initiates a 30-day grace period, and then uses a scheduled database job to permanently purge all data rows from production systems.
| Data Category | Retention Period | Definitive Retention Period |
|---|---|---|
| Landlord Profile Data | Account identity, access token routing, communication channels. | Retained until full account deletion request is finalized. |
| Landlord Bank Details | Never stored in raw database format. Passed securely to payment gateway for tokenization account linking. | Instant discard; raw credentials are never saved. |
| Tenant Identity Data | Lease profile tracking, automated communication routing. | Duration of active lease contract plus 3 years for legal protection. |
| Tenant Bank Details | Never stored in raw format. Stitch manages the payment mandate loops. | Masked reference strings only (e.g., FNB Cheque ****1234). |
| Payment Transaction Logs | Financial matching metrics and reporting generation. | Lease duration plus 3 years to satisfy SARS tax record guidelines. |
| Lease Documents | Executed contract storage and historical confirmation loops. | Retained for 3 years following the official end of the lease. |
| Maintenance Requests | Service tracking history and landlord maintenance validation. | Duration of lease agreement plus 1 year. |
| Credit Screening Profiles | Tenant application screening background checks. | PASS/FAIL outcome marker only; full file deleted within 6 months. |
| Consent Records & Logs | Compliance validation history and automated audit trails. | Permanent retention to meet statutory regulatory mandates. |
| Plinth Match Logs | Auto-reconciliation engine decision matching histories. | Automatically purged after 12 months from execution date. |
| Unmatched Bank Deposits | Suspense ledger rows awaiting manual matching fallbacks. | Automatically purged after 6 months from receipt date. |
The platform's automatic bank statement reconciliation engine ('Plinth Match') processes transaction variables using a secure SafeLink OAuth pipeline. To satisfy data minimization principles, the pipeline reads only the minimal metadata required for ledger confirmation: the transaction amount, bank reference string, payment date, and associated bank sort code. No full transaction history is stored.
In accordance with Condition 8 (Data Subject Participation), users can completely opt out of automated reconciliation matching through their profile settings panel, causing the system to fallback immediately to manual matching workflows.
To: inforeg@justice.gov.za
Subject: Data Breach Notification — Plinth Core
Date of breach: [date]
Date discovered: [date]
Nature of breach: [unauthorized access / data exposure / system compromise]
Number of data subjects affected: [number]
Type of data involved: [categories]
Steps taken to contain: [summary of RLS lockdown / access token revocation]
Steps taken to notify affected parties: [summary of system communications]
Contact: [Information Officer Name, compliance@plinth.co.za, phone]
Signed: [Information Officer]
Ready to Simplify Property Management?
Join other South African landlords who've made the switch.
Built for South African landlords.
