Privacy Policy
Last updated: [FILL IN: LEGAL_EFFECTIVE_DATE]
This Privacy Policy explains how [FILL IN: COMPANY_LEGAL_NAME in .env] (registration number [FILL IN: COMPANY_REG_NUMBER in .env]), registered address [FILL IN: COMPANY_ADDRESS in .env] ("we", "us"), processes personal information in connection with the LegalBenchPower platform (the "Service"), in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA").
1. Two roles, two kinds of personal information
It matters, under POPIA, whose personal information this is and in what capacity we hold it:
- Debt review clients' personal information (name, South African ID number, contact details, address, marital status, employment and income details, dependants, and details of their debts) is submitted by, or on behalf of, the law firm/debt-counselling practice that is our customer ("Customer"). For this information, Customer is the responsible party under POPIA, and we act as an operator, processing it only on Customer's documented instructions and for the purpose of providing the Service — see the separate Operator Agreement entered into with each Customer, which governs this processing in more detail than this page.
- Account and staff information for people who log into the Service directly (name, email address, role, login activity) is processed by us as responsible party, for the purposes described below.
If you are a debt review client and have a question about how your information is used, please contact the law firm or practice that submitted your application in the first instance — they hold primary responsibility for it. If you can't reach them, you may also contact us using the details in Section 9.
2. What we collect
| Category | Examples | Collected from |
|---|---|---|
| Client identity & contact | Full name, SA ID number, phone, email, address, marital status | Client, via intake form |
| Financial information | Employer, employment type, gross/net/other income, dependants, debts, expenses | Client and Customer's staff |
| Case documents | Generated Form 16/17.1 drafts, uploaded signed scans, signature images | Generated by the Service; uploaded by client |
| Signing metadata | IP address, browser user agent, timestamp, document hash at signing | Automatically captured during e-signature |
| Account credentials | Email address, hashed password (never the plaintext password) | Client/staff, at registration |
| Usage/audit data | Who viewed or changed a case record, and when | Automatically captured |
| Technical/log data | Request timestamps, response status, IP address | Automatically captured by the server |
3. Why we process it
- To operate the debt review case workflow: intake, affordability assessment, document generation, e-signature collection, and creditor-response tracking — on Customer's instructions, for Customer's clients' benefit, in pursuit of the client's own debt review application under the NCA.
- To authenticate account holders and secure the Service.
- To send operational emails (status updates, signing links, password resets) — not marketing.
- To maintain an audit trail for compliance and dispute-resolution purposes.
- To detect and prevent abuse (e.g. rate limiting login/registration/intake endpoints).
- To comply with our own legal obligations (e.g. responding to a lawful request from a regulator or court).
The lawful bases relied on are, as applicable: the client's consent (captured at registration/intake), performance of Customer's contract with its client, Customer's/our legitimate interests in operating and securing the Service, and compliance with a legal obligation.
4. Who we share it with
- Credit providers named in a client's Form 17.1 proposal, once Customer's advocate authorises it for dispatch — this is the normal, expected operation of the debt review process itself.
- Sub-processors who support the Service's infrastructure: our hosting provider, and an email delivery service (for outbound notification email). See the current sub-processor list at [operator agreement / sub-processor list — TODO: link once published]. We do not sell personal information, and do not share it for marketing purposes.
- Regulators, courts, or law enforcement, where we are legally compelled to do so.
5. Cross-border transfers
Where any sub-processor stores or processes personal information outside South Africa, we take steps required by POPIA section 72 before that transfer occurs (e.g. a contract imposing equivalent protection, or another recognised basis). [TODO: list actual hosting/SMTP sub-processor locations here once confirmed, and confirm with an attorney whether an explicit cross-border transfer mechanism is needed.]
6. How long we keep it
We retain personal information for as long as Customer's account is active, plus a retention period after a matter/case is closed, to meet professional record-keeping obligations that apply to legal/debt-counselling practices (which can require several years of retention) and our own legal, accounting, or dispute-resolution needs. Exact retention periods are set out in the Data Retention Policy referenced in the Operator Agreement with each Customer. Customer may request deletion of specific client records earlier, subject to any retention Customer itself is legally required to observe.
7. Security measures
We apply technical and organisational measures appropriate to the sensitivity of this data, including: encryption in transit (TLS/HTTPS) between your browser and our server; password hashing (bcrypt, never storing plaintext passwords); CSRF protection on every form submission; rate limiting on public and authentication endpoints; role-gated access to staff functions; a per-case audit log of staff access and changes; and periodic, integrity-checked backups. No system is completely secure, and we will notify affected Customers without undue delay if we become aware of a security compromise affecting their clients' personal information, in accordance with POPIA section 22 and the Operator Agreement.
8. Your rights
Subject to POPIA, a data subject may request: confirmation of whether we hold personal information about them, access to it, correction or deletion of inaccurate, irrelevant, excessive, or unlawfully processed information, and may object to processing on reasonable grounds. Where we act as operator on Customer's behalf, we will direct such a request to Customer, who is best placed to action it, unless you ask us to handle it directly and Customer authorises that. You may also lodge a complaint with the Information Regulator of South Africa (inforegulator.org.za).
9. Our Information Officer
Name: [FILL IN: INFO_OFFICER_NAME in .env] · Email: [FILL IN: INFO_OFFICER_EMAIL in .env]. [TODO: this Information Officer has not yet been registered with the Information Regulator — do this before relying on this page for a real customer.]
10. Cookies
We use a small number of strictly necessary cookies: a session cookie identifying a logged-in client or staff account, and a CSRF-protection cookie. Both are cleared on logout or expiry. We do not currently use analytics, advertising, or third-party tracking cookies.
11. Changes to this policy
We may update this policy from time to time; material changes will be notified in the same way as changes to the Terms of Service.
12. Contact
Privacy questions: [FILL IN: PRIVACY_CONTACT_EMAIL in .env].