?
LegalBenchPowerDebt Review Onboarding & Case Management

DRAFT — not yet reviewed by an attorney

This Privacy Policy was generated as a starting-point draft and has not yet been reviewed by a South African attorney or checked against the Information Regulator's current guidance. Do not treat it as a compliant POPIA notice until that review is complete and this banner is removed.

Privacy Policy

Last updated: [FILL IN: LEGAL_EFFECTIVE_DATE]

This Privacy Policy explains how [FILL IN: COMPANY_LEGAL_NAME in .env] (registration number [FILL IN: COMPANY_REG_NUMBER in .env]), registered address [FILL IN: COMPANY_ADDRESS in .env] ("we", "us"), processes personal information in connection with the LegalBenchPower platform (the "Service"), in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA").

1. Two roles, two kinds of personal information

It matters, under POPIA, whose personal information this is and in what capacity we hold it:

If you are a debt review client and have a question about how your information is used, please contact the law firm or practice that submitted your application in the first instance — they hold primary responsibility for it. If you can't reach them, you may also contact us using the details in Section 9.

2. What we collect

CategoryExamplesCollected from
Client identity & contactFull name, SA ID number, phone, email, address, marital statusClient, via intake form
Financial informationEmployer, employment type, gross/net/other income, dependants, debts, expensesClient and Customer's staff
Case documentsGenerated Form 16/17.1 drafts, uploaded signed scans, signature imagesGenerated by the Service; uploaded by client
Signing metadataIP address, browser user agent, timestamp, document hash at signingAutomatically captured during e-signature
Account credentialsEmail address, hashed password (never the plaintext password)Client/staff, at registration
Usage/audit dataWho viewed or changed a case record, and whenAutomatically captured
Technical/log dataRequest timestamps, response status, IP addressAutomatically captured by the server

3. Why we process it

The lawful bases relied on are, as applicable: the client's consent (captured at registration/intake), performance of Customer's contract with its client, Customer's/our legitimate interests in operating and securing the Service, and compliance with a legal obligation.

4. Who we share it with

5. Cross-border transfers

Where any sub-processor stores or processes personal information outside South Africa, we take steps required by POPIA section 72 before that transfer occurs (e.g. a contract imposing equivalent protection, or another recognised basis). [TODO: list actual hosting/SMTP sub-processor locations here once confirmed, and confirm with an attorney whether an explicit cross-border transfer mechanism is needed.]

6. How long we keep it

We retain personal information for as long as Customer's account is active, plus a retention period after a matter/case is closed, to meet professional record-keeping obligations that apply to legal/debt-counselling practices (which can require several years of retention) and our own legal, accounting, or dispute-resolution needs. Exact retention periods are set out in the Data Retention Policy referenced in the Operator Agreement with each Customer. Customer may request deletion of specific client records earlier, subject to any retention Customer itself is legally required to observe.

7. Security measures

We apply technical and organisational measures appropriate to the sensitivity of this data, including: encryption in transit (TLS/HTTPS) between your browser and our server; password hashing (bcrypt, never storing plaintext passwords); CSRF protection on every form submission; rate limiting on public and authentication endpoints; role-gated access to staff functions; a per-case audit log of staff access and changes; and periodic, integrity-checked backups. No system is completely secure, and we will notify affected Customers without undue delay if we become aware of a security compromise affecting their clients' personal information, in accordance with POPIA section 22 and the Operator Agreement.

8. Your rights

Subject to POPIA, a data subject may request: confirmation of whether we hold personal information about them, access to it, correction or deletion of inaccurate, irrelevant, excessive, or unlawfully processed information, and may object to processing on reasonable grounds. Where we act as operator on Customer's behalf, we will direct such a request to Customer, who is best placed to action it, unless you ask us to handle it directly and Customer authorises that. You may also lodge a complaint with the Information Regulator of South Africa (inforegulator.org.za).

9. Our Information Officer

Name: [FILL IN: INFO_OFFICER_NAME in .env] · Email: [FILL IN: INFO_OFFICER_EMAIL in .env]. [TODO: this Information Officer has not yet been registered with the Information Regulator — do this before relying on this page for a real customer.]

10. Cookies

We use a small number of strictly necessary cookies: a session cookie identifying a logged-in client or staff account, and a CSRF-protection cookie. Both are cleared on logout or expiry. We do not currently use analytics, advertising, or third-party tracking cookies.

11. Changes to this policy

We may update this policy from time to time; material changes will be notified in the same way as changes to the Terms of Service.

12. Contact

Privacy questions: [FILL IN: PRIVACY_CONTACT_EMAIL in .env].