1. Responsible party
AuditProCore (Pty) Ltd is the operator processing personal information on behalf of each tenant (the responsible party). Each tenant's Information Officer remains the data controller; AuditProCore acts only on the documented instructions of that tenant.
2. Categories of personal information
- · Identity data — full name, employee number, role, government department.
- · Contact data — work email address, work phone number.
- · Authentication data — password hash, session tokens, IP, user-agent.
- · Audit-trail data — actions performed in the platform, timestamps.
- · Compliance evidence — documents, sign-offs, acknowledgements you upload.
3. Purpose of processing
We process personal information solely to provide the audit, governance, and compliance services contracted by each tenant. We do not sell personal information, we do not use it to train external AI models, and we do not share it with any third party except as required by law or as necessary for service delivery (e.g. our hosting provider).
4. Cross-border transfers
Tenant data is hosted in the South Africa North Azure region by default. Cross-border transfers (e.g. to a backup or analytics region) only occur where POPIA section 72 conditions are met or where the tenant has consented in writing.
5. Retention
Records are retained per the tenant's retention schedule, with a default of seven (7) years for audit and finding records to align with PFMA / MFMA recordkeeping requirements. Soft-deleted records remain in the database with an IsDeleted flag until the tenant's retention window expires.
6. Your rights
You may exercise your POPIA rights — access, correction, deletion, objection — by contacting your tenant's Information Officer. AuditProCore (Pty) Ltd will action verified requests within 30 days. Information Regulator: inforeg@justice.gov.za.
7. Contact
Information Officer (AuditProCore): privacy@auditprocore.co.za
