1. Scope & Legal Framework
HumanicDesk ("Company", "We", "Us", or "Our") operates as a digital product agency and embedded software engineering venture builder. We are headquartered and registered in South Africa, serving clients locally across Johannesburg, Cape Town, and Durban, as well as international enterprise clients across North America, the United Kingdom, Europe, and Asia-Pacific.
This Privacy Policy explains how we collect, process, store, and safeguard personal and organizational data in full compliance with:
- South Africa: Protection of Personal Information Act No. 4 of 2013 ("POPIA") and the Promotion of Access to Information Act No. 2 of 2000 ("PAIA").
- European Union & United Kingdom: General Data Protection Regulation ("EU/UK GDPR") (Regulation 2016/679).
- International Jurisdictions: Applicable local data protection statutes for cross-border engineering client engagements.
2. Information We Collect
Depending on your interaction with HumanicDesk β as a website visitor, prospective client, or contracted enterprise receiving embedded engineering pods β we collect the following categories of data:
Corporate & Contact Data
Full names, corporate email addresses, direct phone numbers, job titles, billing details, VAT numbers, and corporate registration codes.
Technical & Code Telemetry
Repository integration metadata, IP addresses, continuous integration logs, developer access tokens, and portal usage analytics.
Audit & Strategy Diagnostics
Architectural assessment inputs, product roadmaps, submitted code snippets for risk auditing, and sprint velocity performance metrics.
3. Lawful Basis for Processing
In accordance with POPIA Section 11 and GDPR Article 6, HumanicDesk processes personal data exclusively under lawful conditions:
- Contractual Performance: Fulfilling master services agreements, onboarding embedded delivery pods, and executing engineering sprints.
- Legitimate Interest: Safeguarding software security, optimizing platform performance, preventing fraud, and delivering product audits.
- Legal Obligation: Complying with South African statutory record-keeping obligations under the Companies Act 71 of 2008 and SARS tax directives.
- Explicit Consent: Where you opt-in to technical whitepapers, architectural updates, or diagnostic audit requests.
4. Data Hosting & Cross-Border Transfers
HumanicDesk maintains primary data infrastructure in South African hyperscale cloud environments (AWS Cape Town af-south-1 and Microsoft Azure South Africa North) alongside multi-region redundancy in Europe and the US.
Cross-Border Transfer Safeguards (POPIA Section 72 & GDPR Chapter V)
When data is transferred outside South Africa or the EU/EEA to facilitate global client pods, transfers are bound by Standard Contractual Clauses (SCCs), binding corporate rules, and verified adequacy decisions. We enforce zero transfer to third-party countries lacking adequate legal protections.
5. Data Subject Rights (POPIA & GDPR)
Under South Africa's POPIA (Sections 23β25) and global data laws, you possess enforceable rights regarding your personal information:
6. Technical & Operational Security
We enforce strict administrative, physical, and technical controls to guarantee data confidentiality, integrity, and availability:
- Encryption Standard: AES-256 encryption at rest and TLS 1.3 in transit across all environments.
- Identity Access: Multi-Factor Authentication (MFA), Role-Based Access Control (RBAC), and least-privilege SSH/VPN keys.
- Breach Notification: Mandatory notification within 72 hours under POPIA Section 22 and GDPR Article 33 in the unlikely event of a security incident.
7. Data Retention & Destruction
We retain personal data only for as long as necessary to fulfill contractual services, resolve disputes, or satisfy legal statutory retention periods (typically 5 years for financial records under South African law). Upon expiration of retention periods, data is permanently shredded or anonymized using NIST SP 800-88 guidelines.
8. Statutory Information Officer & Inquiries
HumanicDesk has registered a designated Information Officer pursuant to POPIA Section 55 and PAIA Section 17. For any privacy requests, data access inquiries, or regulatory notices, please contact:
POPIAComplaints@inforegulator.org.za