← Back to Surveyz

Privacy Policy & POPIA Notice

Last updated: 11 April 2026  ·  Version 1.0  ·  Effective date: 11 April 2026

Plain-language summary: Surveyz collects your name, email address, and payment details to run your account. We collect survey responses on behalf of survey creators. We do not sell your data to anyone. You can request access, correction, or deletion of your data at any time by emailing privacy@surveyz.co.za.

Table of Contents

  1. Who we are and our dual role
  2. What personal information we collect
  3. Why we collect it (purpose)
  4. Third-party processors
  5. How long we keep your data
  6. How we protect your data
  7. Your rights under POPIA
  8. Cookies and tracking
  9. Children's data
  10. Data breach notification
  11. Changes to this policy
  12. Information Officer & contact

1. Who We Are and Our Dual Role

Surveyz (Pty) Ltd ("Surveyz", "we", "us") operates the survey platform available at www.surveyz.co.za.

Under POPIA we act in two distinct capacities:

2. What Personal Information We Collect

2.1 Account holders (registered users)

CategoryData collectedSource
IdentityFull name (display name)Registration form / OAuth provider
ContactEmail address, mobile number (optional)Registration form / OAuth provider
AuthenticationHashed password (BCrypt), OAuth provider IDRegistration / OAuth flow
BillingPayFast payment reference, subscription status, invoice amountsPayFast payment gateway
TechnicalIP address (in audit logs), date/time of actionsAutomatically on login and data changes
API accessAPI key (hashed)Generated on request

2.2 Survey respondents

CategoryData collectedMandatory?
IdentityName (if provided at consent gate)Optional
ContactEmail address (if provided at consent gate)Optional
Survey answersAll question responses submittedYes (purpose of the survey)
TechnicalIP address, browser user-agent, consent timestampAutomatically collected
Consent recordConsent given flag, consent IP, consent version, timestampAutomatically on acceptance

2.3 Distribution list contacts

When a survey creator imports contacts into a Distribution List, the following data is stored: name, email address, WhatsApp number. This data is provided by the survey creator, who is responsible for ensuring they have lawful basis (including consent where required) to share it with us.

3. Why We Collect It (Purpose Specification)

DataPurposeLegal basis (POPIA)
Name & emailAccount creation, authentication, support communicationContractual necessity / Consent
Mobile numberOTP authentication, optional notificationsConsent
Payment dataBilling, subscription management, invoice generationContractual necessity
IP addressSecurity audit logging, fraud prevention, rate limiting, consent forensicsLegitimate interest (security)
User-agentAbuse detection, technical diagnosticsLegitimate interest (security)
Survey responsesDelivery of the survey platform service to the survey creatorConsent (given at survey consent gate)
OAuth provider IDLinking social login to your accountConsent

We will not use your personal information for any purpose other than those listed above without obtaining fresh consent.

4. Third-Party Processors

We share your personal information with the following third parties, solely to deliver our service. Each acts as an operator under POPIA on our instruction:

ProcessorPurposeData sharedLocation
PayFast (DPO PayTech)Payment processing & subscription billingName, email, payment amountSouth Africa
Google LLCOAuth social sign-in (optional)OAuth token (provider ID & email)USA (adequacy transfers apply)
Microsoft CorporationOAuth social sign-in (optional)OAuth token (provider ID & email)USA (adequacy transfers apply)
Azure Communication ServicesTransactional email (welcome, password reset)Email address, display nameSouth Africa (Azure ZA North)
ClickSendOTP and notification SMSMobile number, OTP codeAustralia / replicated globally
PostgreSQL hosting providerDatabase hostingAll platform data at restSouth Africa (production)

We do not sell, rent, or trade personal information to any third party for marketing purposes.

5. How Long We Keep Your Data

Data typeRetention periodReason
Account data (name, email, password hash)Duration of account + 30 days after deletion requestService delivery; grace period for accidental deletion
Survey response data24 months from submission date, or until the survey creator deletes itAs disclosed in survey consent notice
Billing records (payments, invoices)5 yearsSARS tax retention requirement
Audit logs24 monthsSecurity and compliance
Password reset tokens1 hour (automatic expiry)Security
Distribution list contactsUntil deleted by the list ownerOperator role — survey creator is responsible party
Consent records5 yearsEvidence of lawful processing

6. How We Protect Your Data

7. Your Rights Under POPIA

As a data subject, you have the following rights under the Protection of Personal Information Act 4 of 2013:

7.1 Right to be notified

You have the right to be informed when your personal information is collected. We fulfil this through this Privacy Policy and through the consent gate shown before any survey.

7.2 Right of access

You may request a copy of all personal information we hold about you. Email privacy@surveyz.co.za with the subject line "POPIA Access Request". We will respond within 30 days.

7.3 Right to correction

You may update your name, email address, and mobile number at any time from your account profile. To correct billing records or survey response data, email us.

7.4 Right to erasure (right to be forgotten)

You may request deletion of your account and all associated personal information. To do so:

Note: billing records must be retained for 5 years per tax law; these will be anonymised rather than deleted.

7.5 Right to object

You may object to processing based on legitimate interest at any time. Email us at privacy@surveyz.co.za.

7.6 Right to withdraw consent

Where processing is based on your consent, you may withdraw it at any time by deleting your account or emailing us. Withdrawal does not affect the lawfulness of processing before withdrawal.

7.7 Right to lodge a complaint

If you believe your rights have been violated, you may lodge a complaint with the Information Regulator of South Africa:

8. Cookies and Tracking

Surveyz uses the following storage mechanisms:

TypeNamePurposeDuration
localStoragesr_tokenStores your JWT authentication token so you remain logged in8 hours (token expiry)
localStoragesr_userCaches your profile data to avoid repeated API callsSession
localStoragesr_themeRemembers your light/dark mode preferencePersistent

We do not use third-party tracking cookies, advertising cookies, or analytics cookies. We do not use Google Analytics or similar services.

9. Children's Data

Surveyz is not directed at children under 18. We do not knowingly collect personal information from children. If a survey creator wishes to collect data from minors, they must obtain consent from a parent or guardian and are solely responsible for doing so. Surveyz's consent gate will be shown in all cases regardless of respondent age.

10. Data Breach Notification

In the event of a data breach that is likely to prejudice your rights, we will:

To report a suspected security vulnerability, email security@surveyz.co.za.

11. Changes to This Policy

We may update this policy from time to time. We will notify registered users by email of any material changes at least 14 days before they take effect. The "Last updated" date at the top of this page will always reflect the current version. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

12. Information Officer & Contact Details

Designated Information Officer

Organisation: Surveyz (Pty) Ltd

Information Officer: [Name to be designated — see POPIA Section 55]

Email: privacy@surveyz.co.za

Postal address: [Physical address — required for Information Regulator registration]

Registration with Information Regulator: Pending registration per POPIA Section 55(1)

For all privacy-related queries, data access requests, deletion requests, or complaints, contact us at privacy@surveyz.co.za. We will acknowledge your request within 3 business days and respond fully within 30 days, as required by POPIA.

This policy is governed by the laws of the Republic of South Africa. Any disputes will be subject to the jurisdiction of the South African courts.