POPIA Compliance Notice

Last updated: 24 February 2026

1. Introduction

Kujalia ERP ("Kujalia", "we", "us", or "our") is committed to protecting your personal information in accordance with the Protection of Personal Information Act, 2013 (Act 4 of 2013) ("POPIA") and its regulations. This notice explains how we collect, use, store, and share personal information when you use our cloud-based enterprise resource planning platform.

2. Responsible Party

Kujalia (Pty) Ltd is the responsible party as defined in POPIA. For any enquiries related to the processing of your personal information, you may contact us at:

3. Personal Information We Collect

We collect the following categories of personal information in the course of providing our services:

CategoryExamples
Identity informationFull name, ID or passport number, date of birth
Contact detailsEmail address, phone number, physical address
Employment informationJob title, employee number, salary, tax number, bank account details
Financial informationInvoices, payments, bank statements, transaction records
Technical informationIP address, browser type, login timestamps, session data
Business informationCompany registration, VAT number, B-BBEE level, trading name

4. Purpose of Processing

We process personal information for the following purposes:

  • Service delivery — to provide, maintain, and improve the Kujalia ERP platform, including accounting, HR, payroll, inventory, POS, and compliance modules.
  • Legal obligations — to comply with SARS, CIPC, B-BBEE, and other regulatory requirements on your behalf.
  • Contractual necessity — to perform our obligations under your subscription agreement.
  • Legitimate interest — to secure our platform, detect fraud, and improve performance.
  • Communication — to send transactional notifications, service updates, and respond to support requests.

5. Legal Basis for Processing

Under POPIA, we rely on the following lawful grounds for processing:

  • Consent (Section 11(1)(a)) — where you have provided your voluntary, specific, and informed consent.
  • Contractual obligation (Section 11(1)(b)) — where processing is necessary to fulfil our agreement with you.
  • Legal obligation (Section 11(1)(c)) — where processing is required by law (e.g. tax records, employment law).
  • Legitimate interest (Section 11(1)(f)) — where processing is necessary for our legitimate business interests, provided these are not overridden by your rights.

6. Kujalia as Operator

When you use Kujalia ERP to manage your own customer, employee, or supplier data, you are the responsible party for that information and Kujalia acts as an operator (processor) on your behalf. We process such data strictly according to your instructions and our operator agreement. We do not access, sell, or use your tenant data for any purpose other than delivering the service.

7. Sharing of Personal Information

We do not sell personal information. We may share information with:

  • Infrastructure providers — Amazon Web Services (af-south-1 region, Cape Town) for hosting and data storage.
  • Payment processors — to process subscription payments.
  • Regulatory authorities — where required by law (e.g. SARS e-filing on your behalf).
  • Professional advisors — auditors or legal counsel where necessary.

All third-party operators are bound by data processing agreements that require them to protect personal information in accordance with POPIA.

8. Cross-Border Transfers

Your data is hosted in South Africa (AWS af-south-1, Cape Town). In limited circumstances, personal information may be transferred outside the Republic in compliance with Section 72 of POPIA — for example, where the recipient is subject to equivalent data protection laws or binding agreements, or where you have provided your consent.

9. Retention of Personal Information

We retain personal information only for as long as necessary to fulfil the purpose for which it was collected, or as required by law:

  • Financial and tax records — 5 years (as required by the Tax Administration Act and Companies Act).
  • Employment records — 5 years after termination of employment (Basic Conditions of Employment Act).
  • Account data — duration of subscription plus 90 days.
  • Audit logs — 2 years.

When retention periods expire, information is securely deleted or anonymised.

10. Security Safeguards

We implement appropriate technical and organisational measures to protect personal information against loss, unauthorised access, and unlawful processing, including:

  • Encryption in transit (TLS) and at rest (AES-256).
  • Role-based access control with tenant isolation.
  • Two-factor authentication (TOTP).
  • Automated audit logging and anomaly detection.
  • Regular security assessments and dependency scanning.

For more detail, see our Security page.

11. Your Rights as a Data Subject

Under POPIA, you have the right to:

  • Access — request confirmation of whether we hold your personal information and obtain a copy (Section 23).
  • Correction — request that inaccurate, irrelevant, or misleading information be corrected or deleted (Section 24).
  • Deletion — request destruction of your personal information when we are no longer authorised to retain it (Section 24).
  • Object — object to the processing of your personal information on reasonable grounds (Section 11(3)).
  • Withdraw consent — withdraw previously given consent at any time (Section 11(2)(b)).
  • Lodge a complaint — submit a complaint to the Information Regulator (see below).

To exercise any of these rights, email privacy@kujalia.co.za. We will respond within 30 days as required by POPIA.

12. Data Breach Notification

In the event of a security compromise that poses a risk to your rights, we will notify the Information Regulator and affected data subjects as soon as reasonably possible, in accordance with Section 22 of POPIA. Our notification will include the nature of the breach, the information involved, and the measures we have taken to address it.

13. Cookies and Tracking

We use strictly necessary cookies for authentication and session management. We do not use third-party advertising or behavioural tracking cookies. No personal information is shared with advertising networks.

14. Children's Personal Information

Kujalia ERP is a business platform and is not directed at children under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected such information, we will delete it promptly.

15. The Information Regulator

If you are not satisfied with how we handle your personal information, you have the right to lodge a complaint with the Information Regulator:

  • Email: complaints.IR@justice.gov.za
  • Phone: 012 406 4818
  • Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

16. Changes to This Notice

We may update this notice from time to time. Material changes will be communicated via email or an in-app notification. The "Last updated" date at the top of this page indicates when this notice was last revised.