Privacy Policy
How Beacon Digital Solutions processes personal information under the Protection of Personal Information Act, 4 of 2013 (“POPIA”).
Summary in plain language
Beacon Digital Solutions plays two different roles. When we run our own website and sell our services, we are the responsible party and this policy governs how we handle your information. When our client companies use our WhatsApp-Native Field Operations Engine to coordinate their field workers, we are only an operator: the client company decides what is collected and why, and we process that data — including field worker location and voice data — strictly on that client's documented instructions. If you are a field worker or a customer of one of our clients, your first point of contact is that client company; we will always assist them in responding to you.
1. Who we are
This policy is issued by Beacon Digital Solutions (“Beacon”, “we”, “us”, “our”), a software engineering consultancy and technology provider based in Clubview, Centurion, Gauteng, South Africa. We build custom backend software and operate the WhatsApp-Native Field Operations Engine (the “Platform”), a business-to-business software service delivered over the WhatsApp Business Platform.
This policy explains how we collect, use, share, secure and retain personal information, and how you may exercise your rights under POPIA. It applies to our website, our sales and support activities, and to the Platform.
Contact details
| Legal entity | Beacon Digital Solutions |
|---|---|
| Physical address | Clubview, Centurion, Gauteng, South Africa |
| Information Officer | The Information Officer, Beacon Digital Solutions |
| info@beacondigitalsolutions.co.za | |
| Telephone | 079 258 1260 (+27 79 258 1260) |
2. Our two roles: responsible party and operator
POPIA distinguishes between a responsible party (the entity that determines the purpose of and means for processing personal information) and an operator (an entity that processes personal information for a responsible party, under that party's authority, and does not determine the purpose itself). Understanding which role we occupy tells you which section of this policy applies to you.
2.1 Where Beacon is the responsible party
We act as responsible party for personal information we collect for our own business purposes, namely:
- enquiries and demo requests submitted through our website, email or telephone;
- contact details of client and prospective client personnel used for sales, contracting and support;
- administrative account records for the named administrative users our clients register on the Platform;
- records we are required to keep for tax, accounting and statutory compliance purposes.
2.2 Where Beacon is the operator
We act only as an operator in respect of all operational data processed through the Platform on behalf of our clients. Our clients — the businesses that subscribe to the Platform — are the responsible parties for that data. This expressly includes:
- Field worker location data. Where a client's workflow requires it, field workers share their location through WhatsApp (for example, to confirm arrival at or departure from a job site). We receive, store and relay that location data solely so that the client can verify attendance, measure service levels and dispatch work. We do not determine whether location is collected, how precise it is, how long it is kept, or what it is used for — the client does. We do not perform continuous or background tracking of any individual; location is captured only when a worker actively shares it in a WhatsApp message.
- Voice data. Field workers may send WhatsApp voice notes to report on a job. We store those recordings, and where the client has enabled it, generate a text transcription so the report can be attached to the job record and searched. Voice recordings and transcriptions are processed for the sole purpose of fulfilling the client's field operations workflow. We do not use voice data for voice-print identification, biometric analysis, emotion analysis, advertising, profiling, or to train any machine learning or artificial intelligence model of our own or of any third party.
- Job and message content. Job cards, status updates, photographs, signatures, notes and the WhatsApp message threads exchanged between the client's account and its workers or customers.
- Identifiers. WhatsApp phone numbers, WhatsApp profile names and internal employee or contractor references supplied by the client.
As operator we will only process this data in accordance with section 20 and section 21 of POPIA: on the documented instruction of the responsible party, with the responsible party's knowledge and authorisation, treating it as confidential, and securing it in the manner described in section 7 below.
2.3 If you are a field worker or a client's customer
If your personal information is on the Platform because your employer, contracting principal or service provider uses it, that organisation is the responsible party and controls your data. Please direct requests for access, correction or deletion to that organisation in the first instance. If you contact us directly, we will not act unilaterally on data belonging to a client; we will refer your request to the relevant client and support them in responding to it within the timeframes POPIA requires. See our Data Deletion Instructions for the full process.
3. Personal information we collect
3.1 As responsible party
| Category | Examples |
|---|---|
| Contact and enquiry data | Name, company name, work email address, telephone number, and the content of your enquiry or demo request. |
| Client relationship data | Names and business contact details of authorised signatories, project contacts and billing contacts. |
| Administrative account data | Console user name, email address, hashed authentication credentials, role and permission assignments. |
| Support data | Correspondence, support tickets and the diagnostic detail you choose to include in them. |
| Technical and log data | IP address, browser type, device type, pages visited and timestamps, collected through standard web server logs for security and performance purposes. |
| Billing data | Company registration and VAT details, billing address, invoice history. We do not store full payment card numbers. |
3.2 As operator, on behalf of clients
| Category | Examples |
|---|---|
| Worker identifiers | WhatsApp phone number, WhatsApp profile name, employee or contractor reference supplied by the client. |
| Location data | Latitude and longitude, accuracy radius and timestamp of a location a worker actively shares in a WhatsApp message. |
| Voice data | WhatsApp voice note audio files and, where enabled by the client, machine-generated text transcriptions of those files. |
| Job data | Job reference, description, address, assigned worker, status timeline, completion notes. |
| Media and attachments | Photographs of work performed, documents and signature images submitted through WhatsApp. |
| Message metadata | Message identifiers, delivery and read receipts, and timestamps returned by the WhatsApp Business Platform. |
| End-customer data | Where a client sends service notifications to its own customers: customer name, WhatsApp number and job reference. |
We do not seek to collect special personal information as defined in section 26 of POPIA (such as health, biometric, religious or trade union information), nor personal information of children. Clients are contractually required not to submit such information to the Platform unless expressly agreed with us in writing in advance.
4. How and why we use personal information
4.1 Purposes where we are the responsible party
- to respond to enquiries and demo requests and to provide quotations;
- to enter into and perform our contracts with clients, including provisioning and supporting the Platform;
- to authenticate administrative users and maintain security and audit trails;
- to invoice, collect payment and maintain accounting records;
- to send service and operational notices such as maintenance windows, security advisories and material changes to this policy;
- to monitor, secure, debug and improve the reliability and performance of our own systems;
- to comply with legal, regulatory, tax and audit obligations, and to establish, exercise or defend legal claims.
The lawful bases we rely on under POPIA are: performance of a contract with you or the organisation you represent (section 11(1)(b)); compliance with a legal obligation (section 11(1)(c)); our legitimate interests in operating, securing, marketing and improving our business where those interests are not overridden by your rights (section 11(1)(f)); and, where required, your consent (section 11(1)(a)).
Direct marketing. We send business-to-business communications about our services only to existing clients in respect of similar services, or where you have consented. Every marketing message includes an opt-out. You may object at any time under section 11(3) and section 69 of POPIA by emailing info@beacondigitalsolutions.co.za.
4.2 Purposes where we are the operator
We process client operational data for one purpose only: to deliver the Platform's functionality to that client under our agreement with them. In practice that means receiving and routing WhatsApp messages, creating and updating job records, storing attached media, generating the client's own reports, and pushing data into systems the client has authorised us to integrate with.
We will not, in our operator role:
- sell, rent or trade client operational data;
- use it for our own marketing, advertising, ad targeting or audience building;
- use it to train artificial intelligence or machine learning models, whether our own or a third party's;
- combine one client's data with another client's data;
- access it other than as necessary to provide support, resolve an incident, maintain security or comply with law — and then only by authorised personnel under logged access.
5. WhatsApp Business Platform and Meta
The Platform is built on the WhatsApp Business Platform provided by Meta Platforms, Inc. and its affiliates (“Meta”). Beacon Digital Solutions is an independent technology provider and is not affiliated with, endorsed by or acting on behalf of Meta.
- Each client connects its own WhatsApp Business Account to the Platform through Meta's Embedded Signup flow, and grants us permission to send and receive messages on that account's behalf. The client remains the owner of that account and may revoke our access at any time from its Meta Business Settings, or by asking us to disconnect it.
- Messages sent to and from WhatsApp necessarily transit Meta's infrastructure and are also subject to Meta's own terms and privacy practices, which we do not control. Please see the WhatsApp Privacy Policy.
- We access only the data and permissions necessary to operate the Platform, we use Meta platform data solely to provide the service to the client that authorised it, and we do not transfer Meta platform data to any data broker, advertising network or information reseller.
- Where a client disconnects its WhatsApp Business Account or terminates its subscription, we cease processing that account's data and delete or return it as described in section 8 and in our Data Deletion Instructions.
6. Who we share personal information with
We do not sell personal information. We share it only in the following circumstances, and in each case under contractual terms requiring confidentiality and appropriate security safeguards.
| Recipient | Purpose |
|---|---|
| The client responsible party | Operational data on the Platform is made available to the client organisation that owns it, through its console and API. |
| Meta Platforms, Inc. | Transmission and delivery of WhatsApp messages via the WhatsApp Business Platform. |
| Cloud hosting and infrastructure providers | Hosting of application servers, databases and encrypted object storage for media files. |
| Transcription service providers | Where a client enables voice note transcription, conversion of audio to text under contract terms that prohibit the provider from retaining or reusing the audio for its own purposes, including model training. |
| Client-authorised integrations | ERP, accounting, payroll or scheduling systems that the client instructs us to send its data to. |
| Professional advisers | Auditors, accountants and legal advisers bound by professional confidentiality. |
| Authorities and courts | Where disclosure is required by law, court order or a lawful regulatory request. Where we lawfully may, we notify the affected responsible party first. |
| Successors in a business transaction | In a merger, acquisition or sale of assets, subject to this policy continuing to apply to the transferred information. |
7. Cross-border transfers
We prioritise hosting personal information in South Africa or, where that is not available for a given service, in a jurisdiction offering an adequate level of protection. Certain of our sub-processors — including Meta and some cloud infrastructure providers — process data outside South Africa.
Where personal information is transferred across borders, we do so in accordance with section 72 of POPIA, relying on one or more of the following: the recipient being subject to a law, binding corporate rules or binding agreement that provides substantially similar protection to POPIA; the transfer being necessary for the performance of a contract with the data subject or in the data subject's interest; or the consent of the data subject. Clients may request details of the current hosting locations and sub-processors applicable to their deployment by emailing info@beacondigitalsolutions.co.za.
8. How we secure personal information
In line with section 19 of POPIA, we maintain appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unauthorised destruction of personal information and unlawful access to or processing of it. Our controls include:
- Encryption in transit. TLS 1.2 or higher for all traffic between clients, our services, Meta and our sub-processors.
- Encryption at rest. Databases, backups and media object storage (including voice notes and photographs) are encrypted at rest using industry-standard algorithms.
- Access control. Role-based access control, least-privilege provisioning, individual named accounts, and mandatory multi-factor authentication for administrative and production access.
- Tenant isolation. Each client's data is logically segregated and scoped so it cannot be queried across tenant boundaries.
- Secrets management. API credentials and access tokens, including WhatsApp Business Platform tokens, are stored in a managed secret store and never in source control.
- Logging and monitoring. Audit logging of administrative and data-access events, with alerting on anomalous activity.
- Secure development. Code review, dependency vulnerability scanning, environment separation between development, staging and production, and no use of production personal information in test environments.
- Backups and recovery. Encrypted, access-controlled backups with documented restoration procedures.
- People. Written confidentiality undertakings for all personnel and contractors, and access revoked promptly on role change or departure.
- Sub-processor diligence. Written operator agreements imposing security obligations equivalent to our own.
Security compromises. If we have reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we will notify the affected responsible party without undue delay after becoming aware, provide the information they need to assess the incident, and support their notifications to the Information Regulator and affected data subjects as required by section 22 of POPIA. Where we are the responsible party, we will make those notifications ourselves.
9. Retention
We keep personal information only for as long as necessary for the purpose it was collected for, or for as long as the law requires.
- Operational data (operator role): retained for the term of the client's subscription, in accordance with the retention period configured by that client. On termination, data is deleted or returned as set out in section 10 and our Data Deletion Instructions.
- Voice notes and media: retained per the client's configured retention setting; where no setting is specified, our default is deletion 12 months after the associated job is closed.
- Location check-ins: retained per the client's configured retention setting; our default is 12 months after capture.
- Enquiry and prospect data: retained for up to 24 months from the last meaningful contact, unless you ask us to delete it sooner.
- Contracts, invoices and tax records: retained for at least five years as required by South African tax, companies and financial legislation.
- Security and audit logs: retained for up to 12 months.
When a retention period expires, we delete the information or de-identify it irreversibly so that it can no longer be linked to an identifiable person. Encrypted backups are purged on their normal rotation cycle, which does not exceed 90 days beyond the deletion date.
10. Your rights under POPIA
Subject to the conditions and exceptions in POPIA, you have the right to:
- Be notified that your personal information is being collected, and that it has been accessed by an unauthorised person (sections 18 and 22).
- Request access to the personal information we hold about you and confirmation of whether we hold any (section 23). A prescribed fee may apply to access requests.
- Request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained (section 24).
- Object to processing on reasonable grounds, and to object at any time to processing for direct marketing (sections 11(3) and 69).
- Withdraw consent where processing is based on consent, without affecting the lawfulness of processing already carried out.
- Not be subject to a decision based solely on automated processing that has legal consequences for you (section 71). The Platform does not make such decisions.
- Complain to the Information Regulator, and to institute civil proceedings regarding an alleged interference with the protection of your personal information (sections 74 and 99).
To exercise any of these rights where Beacon is the responsible party, email info@beacondigitalsolutions.co.za with the subject line “POPIA Request”. We will acknowledge within 5 business days and respond substantively within 30 days, extending only where POPIA permits and telling you if we do. We may ask for proof of identity before acting, to protect you against disclosure to the wrong person.
Where Beacon is the operator, we will forward your request to the responsible party client within 5 business days and assist them in fulfilling it. Full step-by-step instructions, including for deletion, are on our Data Deletion Instructions page.
Information Regulator (South Africa)
| Authority | The Information Regulator (South Africa) |
|---|---|
| Complaints email | POPIAComplaints@inforegulator.org.za |
| General enquiries | enquiries@inforegulator.org.za |
| Website | inforegulator.org.za |
11. Cookies and website analytics
This website is a static marketing site. It does not set advertising or cross-site tracking cookies and does not build advertising profiles of visitors. Our web server keeps standard access logs (IP address, user agent, requested URL, timestamp) for security, abuse prevention and performance troubleshooting. Fonts and stylesheets are loaded from third-party content delivery networks, which may receive your IP address as a technical necessity of serving those files.
The authenticated Platform console uses strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. These cannot be disabled without breaking the service.
12. Children
The Platform is a business tool intended for use by adults in the course of employment or contracting. We do not knowingly collect personal information of children as defined in POPIA. If you believe a child's information has been submitted to us, contact us and we will investigate and delete it where appropriate.
13. Changes to this policy
We may update this policy to reflect changes in our services, technology or legal obligations. The effective date at the top of this page always reflects the current version. Where a change materially affects how we process personal information, we will notify clients by email to their registered administrative contact at least 14 days before it takes effect. Continued use of the Platform after the effective date constitutes acceptance of the updated policy.
14. Contact us
Questions, requests or complaints about this policy or our handling of personal information can be sent to our Information Officer:
Beacon Digital Solutions
Attention: The Information Officer
Clubview, Centurion, South Africa
Email: info@beacondigitalsolutions.co.za
Telephone: 079 258 1260
Related documents: Terms of Service · Data Deletion Instructions