Protection of Personal Information (POPI) Policy

Last Updated: July 9, 2026

INTERNAL AND EXTERNAL PROTECTION OF PERSONAL INFORMATION POLICY DOCUMENTING OPERATIONAL PROCEDURES TO FULFILL THE EIGHT CONDITIONS FOR LAWFUL PROCESSING MANDATED BY POPIA.

1. Operational Framework for Zero-Budget Lean SaaS

This policy codifies how Plinth-Cloud (Pty) Ltd integrates data privacy regulations into its daily operations on a lean budget, without requiring massive legal capital. In our streamlined structure, the platform founder serves as the legally accountable Information Officer, using software automation to handle routine requirements and manually addressing exceptional data conditions.

2. Processing Principles

We guarantee that personal data is processed lawfully, and in a reasonable manner that does not infringe on the privacy of data subjects. Data is collected for specific, explicitly defined, and lawful purposes related to our property management services.

3. Verbatim Consent Interface Protocols

To satisfy Condition 2 (Processing Limitation), Plinth hardcodes mandatory consent confirmation checkboxes across all primary platform interaction screens. These text sequences are stored in the database along with a timestamp, IP address, and browser signature to create a clear audit trail:
  1. Landlord Signup Consent Interface Text
  2. The platform displays and requires the checking of the following text elements before creating an administrator profile:
    • I consent to Plinth processing my personal information for the purpose of property management services.
    • I consent to my banking details being shared with payment gateway providers (Stitch, Ozow) for payment processing.
    • I confirm I have authority to provide tenant information and will obtain tenant consent before adding them to the platform.
  3. Tenant Invite Consent Interface Text
    The platform requires the checking of the following text items before granting access to a tenant workspace link:

    [Landlord Name] has invited you to Plinth for property: [Address]. Before you can access the portal, you must consent to:

    • I consent to Plinth processing my personal information for property management purposes (payment processing, maintenance requests, communication).
    • I consent to my payment information being processed by the payment gateway provider.
    • I understand I can withdraw consent at any time by contacting the Information Officer at compliance@plinthcloud.com.
  4. Tenant Screening Consent Interface Text
  5. The platform isolates background checks behind an explicit, independent confirmation screen:
    • I consent to Plinth conducting a credit check with the registered credit bureau for tenant screening purposes.
    • I understand this is a 'soft' inquiry and will not affect my credit score.
  6. Algorithmic Data Minimization & Retention Schedule
  7. To satisfy Condition 3 (Purpose Specification) and Condition 4 (Further Processing Limitation), the database architecture limits information storage to the minimum required for operational delivery. The following table defines our official data minimization retention schedule:
    Data CategoryRetention PeriodDefinitive Retention Period
    Landlord Profile DataAccount identity, access token routing, communication channels.Retained until full account deletion request is finalized.
    Landlord Bank DetailsNever stored in raw database format. Passed securely to payment gateway for tokenization account linking.Instant discard; raw credentials are never saved.
    Tenant Identity DataLease profile tracking, automated communication routing.Duration of active lease contract plus 3 years for legal protection.
    Tenant Bank DetailsNever stored in raw format. Stitch manages the payment mandate loops.Masked reference strings only (e.g., FNB Cheque ****1234).
    Payment Transaction LogsFinancial matching metrics and reporting generation.Lease duration plus 3 years to satisfy SARS tax record guidelines.
    Lease DocumentsExecuted contract storage and historical confirmation loops.Retained for 3 years following the official end of the lease.
    Maintenance RequestsService tracking history and landlord maintenance validation.Duration of lease agreement plus 1 year.
    Credit Screening ProfilesTenant application screening background checks.PASS/FAIL outcome marker only; full file deleted within 6 months.
    Consent Records & LogsCompliance validation history and automated audit trails.Permanent retention to meet statutory regulatory mandates.
    Plinth Match LogsAuto-reconciliation engine decision matching histories.Automatically purged after 12 months from execution date.
    Unmatched Bank DepositsSuspense ledger rows awaiting manual matching fallbacks.Automatically purged after 6 months from receipt date.
  8. Automated 'Plinth Match' Engine POPIA Alignment
  9. The platform's automatic bank statement reconciliation engine ('Plinth Match') processes transaction variables using a secure SafeLink OAuth pipeline. To satisfy data minimization principles, the pipeline reads only the minimal metadata required for ledger confirmation: the transaction amount, bank reference string, payment date, and associated bank sort code. No full transaction history is stored.

    In accordance with Condition 8 (Data Subject Participation), users can completely opt out of automated reconciliation matching through their profile settings panel, causing the system to fallback immediately to manual matching workflows.

  10. Verbatim Regulatory Data Breach Email Template
  11. To satisfy Condition 7 (Security Safeguards) and ensure prompt compliance with Section 22 of POPIA, the Information Officer will submit the following pre-drafted incident report to the Information Regulator via inforeg@justice.gov.za within seventy-two (72) hours of confirming any security incident:

    To: inforeg@justice.gov.za

    Subject: Data Breach Notification — Plinth Core

    Date of breach: [date]

    Date discovered: [date]

    Nature of breach: [unauthorized access / data exposure / system compromise]

    Number of data subjects affected: [number]

    Type of data involved: [categories]

    Steps taken to contain: [summary of RLS lockdown / access token revocation]

    Steps taken to notify affected parties: [summary of system communications]

    Contact: [Information Officer Name, compliance@plinth.co.za, phone]

    Signed: [Information Officer]

  12. Data Subject Rights Automation Sequences
  13. Compliance operations run through automated software features built directly into the core platform, minimizing the need for manual oversight:
    • Access Requests: Users click an integrated 'Download My Data' button in their settings panel. The system queries all tables for that user ID, builds a structured JSON/CSV file, and emails it to the user with zero human intervention.
    • Correction Requests: Managed via a self-service profile dashboard, allowing users to update their identity fields and contact parameters instantly.
    • Deletion Sequences: Triggered by a 'Delete My Account' dashboard control. The system sets a soft- delete flag, initiates a 30-day grace period, and then uses a scheduled database job to permanently purge all data rows from production systems.

Ready to Simplify Property Management?

Join other South African landlords who've made the switch.

No credit card required
Cancel anytime
POPIA compliant

Built for South African landlords.