POPIA Privacy Notice
Effective date: March 11, 2026. Last updated: March 11, 2026. This notice is provided in alignment with the Protection of Personal Information Act, 4 of 2013 (“POPIA”) and describes how Bwiser processes personal information in South Africa.
1. Who We Are
Bwiser provides an operational platform that connects Drivers, Stations/Merchants, and operational and finance teams to support approvals, secure voucher issuance, redemption, settlement, and audit visibility. In POPIA terms, Bwiser is generally the Responsible Party for personal information processed to operate the Platform. In certain scenarios, where we process personal information strictly on behalf of a Merchant/Station or another partner under written instructions, we may act as an Operator.
2. What This Notice Covers
This notice explains what personal information we collect, why we collect it, how we use it, who we share it with, how we protect it, and what rights you have as a data subject. This notice should be read with our Privacy Policy, which provides additional detail on our processing activities, including cookies and technical logs.
3. Categories of Personal Information
The categories of personal information we process depend on whether you are a Driver, Merchant/Station user, or Admin. We may process:
- Identity and contact information: names, email address, phone number, username, and identifiers you provide.
- Address and location information: address text, latitude/longitude, and location-derived information used for operational matching and fraud controls.
- Account and authentication information: password hash, sessions, remember-me identifiers, device identifiers (where implemented), and login metadata.
- Operational information: voucher applications, approvals, voucher codes, redemptions, settlement events, station selections, and audit logs.
- Payment and repayment information: payment references, transaction outcomes, and tokenised payment method metadata (not full card numbers).
- Compliance documents: documents you upload for onboarding or compliance (for example, licences, identity documents, and business documents).
- Communications: support tickets, emails, and messages you send to us.
- Technical information: IP address, browser and device information, performance logs, and security event logs.
We do not intentionally process “special personal information” as defined by POPIA unless required by law or strictly necessary for a permitted purpose, and then only with appropriate safeguards.
4. Purposes for Processing
We process personal information for purposes including:
- Creating and administering accounts for Drivers, Merchants/Stations, and Admins.
- Processing voucher applications, approvals, issuance, redemption verification, and settlement operations.
- Performing risk, fraud, and operational checks to protect the Platform and users.
- Processing repayments and reconciling payment outcomes.
- Providing support, responding to queries, and resolving disputes.
- Meeting legal and regulatory obligations (including recordkeeping and responding to lawful requests).
- Maintaining security, auditing access, investigating incidents, and enforcing policies.
- Improving the Platform, including performance monitoring and error remediation.
5. Lawful Grounds / Justification
POPIA allows processing where a lawful basis exists. Depending on the context, our processing may be justified because:
- It is necessary to perform a contract with you or to take steps at your request prior to entering into a contract.
- It is necessary to comply with legal obligations.
- It protects your legitimate interests or ours (for example, security and fraud prevention), where permitted.
- You have provided consent (where processing is based on consent, you may withdraw it, subject to limitations).
Where consent is required (for example, for certain optional cookies or marketing communications), we provide a choice and record your preference. Some processing is necessary to operate the Platform and cannot be opted out of if you wish to use core features.
6. Recipients and Sharing
We may share personal information with recipients in order to operate the Platform, such as:
- Stations/Merchants involved in a voucher application or redemption, limited to what is necessary to complete the transaction.
- Payment and banking partners (for example, payment gateways) to process repayments, authorisations, and transaction outcomes.
- Service providers who host or support the Platform (for example, cloud and infrastructure providers), under confidentiality and security obligations.
- Professional advisors (legal, auditors) where required for compliance and governance, subject to confidentiality.
- Authorities or regulators where we are legally required to do so, or where it is lawful and necessary to protect rights and safety.
We do not sell personal information. We aim to share only what is necessary, and we apply contractual safeguards to Operators.
7. Cross-Border Transfers
Some service providers may process information outside South Africa. Where we transfer personal information cross-border, we take reasonable steps to ensure that the recipient is subject to laws, binding corporate rules, or agreements that provide an adequate level of protection as required by POPIA, and that appropriate security safeguards are in place.
8. Information Quality
You are responsible for keeping your information accurate and up to date. If your information is incorrect, this can affect voucher approvals, communications, repayment processing, and operational matching (such as station selection).
9. Security Safeguards
We implement appropriate technical and organisational measures to protect personal information. Controls may include:
- Access control, role-based permissions, and least-privilege principles.
- Encryption in transit (TLS) and protective handling of sensitive fields where appropriate.
- Audit logging for important operational events (applications, approvals, redemptions, repayments).
- Monitoring, alerting, and incident response processes.
- Vendor due diligence and contractual protections with Operators.
No system is perfectly secure. You also play a role by protecting your credentials, using strong passwords, and avoiding sharing sensitive information through insecure channels.
10. Retention
We keep personal information only as long as necessary for the purposes described in this notice, unless a longer retention period is required or permitted by law. Retention periods vary by category, for example:
- Security and audit logs may be retained to support investigations and compliance.
- Financial and repayment records may be retained to support reconciliation, audits, and disputes.
- KYC documents may be retained in line with compliance and governance requirements.
When retention is no longer required, we take reasonable steps to delete, de-identify, or anonymise personal information, subject to technical and lawful constraints (such as backup retention windows).
11. Automated Decision-Making
Some Platform decisions may be supported by automated checks (for example, fraud and risk signals, data validation, and operational rules). Where such checks are used, we aim to apply appropriate safeguards and allow for escalation or review in higher-risk or disputed cases. Final decisions may involve human review depending on the workflow.
12. Your Rights as a Data Subject
Subject to POPIA and other applicable laws, you may request:
- Access to personal information we hold about you.
- Correction or updating of inaccurate or incomplete information.
- Deletion of information where it is no longer lawfully required to be retained.
- Objection to processing in certain circumstances.
- Withdrawal of consent (where processing is based on consent).
Requests may require identity verification. We may refuse or limit requests where a lawful ground applies (for example, where disclosure would prejudice another person’s rights, compromise security, or conflict with legal obligations).
13. Complaints
If you have a concern about how we process personal information, please contact us first so we can address it. If the issue is not resolved to your satisfaction, you may lodge a complaint with the Information Regulator (South Africa) in accordance with POPIA. We can provide relevant details and supporting information upon request.
14. How to Submit a POPIA Request
If you want to exercise your rights (access, correction, deletion where lawful, objection, or withdrawal of consent where applicable), you can submit a request to our Information Officer contact channel. To help us process requests efficiently, include:
- Your full name and the email/phone number used on the Platform.
- The specific right you want to exercise and what outcome you are requesting.
- Any context (for example, the page, voucher ID, repayment reference, or timeframe) that helps us locate the relevant information.
We aim to respond within a reasonable time. Some requests may take longer if they are complex or involve consultation with third parties (for example, where records contain other data subjects’ information).
15. Identity Verification
To protect users and prevent unauthorised disclosure, we may verify your identity before responding to a request. This may involve confirming account identifiers and, in higher-risk cases, requesting additional verification. We will not ask you to share your password. If you receive a suspicious request for credentials, treat it as a potential phishing attempt and contact support.
16. Operators, Confidentiality, and Vendor Controls
Where Bwiser uses Operators (service providers) to host or support the Platform, we aim to ensure they are bound by confidentiality and security obligations. Operators are permitted to process personal information only for the purposes we specify and must implement appropriate safeguards. We also aim to limit data shared with Operators to what is necessary.
Where Bwiser processes personal information on behalf of a Merchant/Station under their instructions, we implement safeguards appropriate to an Operator role, and we apply contractual and operational controls to prevent unauthorised use.
17. Cookies and Communications
The Web experience uses cookies for security, authentication, and session management. Optional analytics cookies may be used where enabled and where a lawful basis exists. We also send essential operational communications (for example, security notices, voucher status updates, and repayment reminders) necessary to provide the Platform. Promotional marketing, where used, will include an opt-out option.
18. Special Personal Information and Children
POPIA provides additional protections for “special personal information” (such as information about health, biometric information, or criminal behaviour) and for the personal information of children. Bwiser does not intentionally request special personal information unless it is strictly necessary for a permitted purpose and appropriate safeguards are in place. The Platform is generally intended for adult users. If we become aware that we have processed a child’s personal information without appropriate authority, we will take steps to delete it or handle it in accordance with applicable law.
19. De-identification and Analytics
Where we use analytics for performance monitoring or service improvement, we aim to minimise personal information in those datasets. In some cases, information may be aggregated or de-identified so that it is not reasonably re-identifiable. Where de-identification is used, it is applied to reduce privacy risk while still allowing operational learning (for example, identifying slow pages, frequent errors, or drop-offs in onboarding).
De-identified information may still be subject to security safeguards and governance controls. Where information remains personal information under POPIA, it is treated accordingly.
20. Contact
For privacy requests and POPIA-related enquiries, contact: [email protected].
Where a request overlaps with PAIA (for example, a request for access to records held by a private body), we may guide you to the PAIA request process described in our PAIA Manual. We may also refuse or limit a request where a lawful ground applies, including where disclosure would reveal another person’s personal information, confidential commercial information, or security-sensitive internal controls.
If you are requesting correction of information, please include the corrected details and any supporting proof where appropriate (for example, updated contact details or corrected address information). Correct information helps us reduce operational risk and ensures voucher and repayment workflows function correctly.
Note: This POPIA Notice is provided for transparency and operational readiness and does not constitute legal advice.