Privacy Policy & POPIA Compliance Statement

Company Name: Sieben Management Consultants

Effective Date: 10 July 2026

Company Registration Number: 2025/127405/07

1. Introduction

Welcome to Easy Jobs ("we", "us", "our"). We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, process, use, and protect your personal data when you use our job card tracking and administrative modules, in compliance with the Protection of Personal Information Act (POPIA) of South Africa.

2. The Information Officer

We have appointed an Information Officer who is responsible for overseeing questions in relation to this privacy policy. If you have any questions, including requests to exercise your legal rights, please contact the Information Officer using the details set out below :

  • Information Officer: Gerald Mubatapasango
  • Email Address: privacy@siebenmgtconsult.org
  • Physical Address: 304 Walmer Boulevard, South End, Port Elizabeth 6001, South Africa

3. The Data We Collect About You

To provide our software services, we may collect, use, store, and transfer different kinds of personal data about you, which we have grouped together as follows:

  • Identity Data: First name, last name, and system role.
  • Contact Data: Email address and telephone numbers.
  • Operational Data: Job card assignments and system activity logs.
  • Technical Data: IP address, browser type, and operating system when you use our web platforms.

4. Data Security (The "Sieben Platforms" Standard)

We have implemented enterprise-grade security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way.

  • Encryption: All personal data is encrypted in transit using TLS 1.3 (HTTPS) and encrypted at rest using AES-256 encryption on our cloud servers.
  • Access Control: We utilize strict Row Level Security (RLS) policies isolated by Tenant. Users can only access data explicitly authorized within their assigned tenant organization.
  • Vendor Compliance: Our data is hosted on secure, ISO 27001-certified cloud infrastructure (AWS/Supabase), which act as compliant sub-processors under POPIA.

5. International Data Transfers

5.1 Where Your Data is Stored and Processed

To provide you with a reliable, fast, and secure experience, we use a small number of specialist service providers to host and operate our application. All personal information you provide to us is securely stored on database servers located in Frankfurt, Germany, operated by our hosting provider, Supabase. Where WhatsApp or SMS notifications are used, message content and delivery status pass through Twilio, Inc., a United States company. Where email notifications are used, message content passes through Resend, also a United States company.

5.2 Cross-Border Transfers and Your Privacy (POPIA & GDPR)

Because these servers are located outside of South Africa, your data is subject to a cross-border transfer under the Protection of Personal Information Act (POPIA). We take your privacy seriously and want to assure you that your data remains strictly protected:

  • Germany (Supabase): Germany is governed by the European Union's General Data Protection Regulation (GDPR), which is universally recognized as one of the most comprehensive and stringent data privacy frameworks in the world. Under Section 72 of POPIA, South African data may be transferred abroad if the destination country offers laws substantially similar to our own; GDPR strictly aligns with, and often exceeds, POPIA's requirements for lawful processing, data subject rights, and security safeguards.
  • United States (Twilio and Resend): The United States is not automatically recognized as offering equivalent protection under POPIA or GDPR. Both providers commit contractually to appropriate safeguards for data leaving the EU/EEA (including Standard Contractual Clauses), and we rely on those same contractual protections, together with POPIA-compliant processing agreements, to lawfully justify this transfer.

6. Your Legal Rights (The "Right to be Forgotten")

Under POPIA, you have rights regarding your personal data, including the right to request access to, correction of, or deletion of your personal data ("The Right to be Forgotten").

How to exercise this right: If you wish to access, correct, or have your data deleted, please email our Information Officer. Requests are reviewed and actioned individually, typically within a reasonable period from receipt of a verified request. Where deletion is appropriate, we remove or anonymize your Identity and Contact Data, while retaining anonymized operational values where we have a legitimate business or legal record-keeping need to do so (for example, financial records required under South African tax law).