Global Privacy Policy
Last updated 22 July 2026
GoTecID (Pty) Ltd (“GoTecID”, “we”, “us”, or “our”) respects your privacy and is committed to processing personal data in accordance with global data protection laws. This Privacy Policy outlines how we collect, use, store, share, and protect personal information when you visit our website or interact with the GoTecID™ platform (“the Platform”).
1. Who We Are & Regulatory Roles
The entity responsible for processing your personal information depends on your location and how you interact with the Platform:
- Primary Controller / Responsible Party: GoTecID (Pty) Ltd (Reg. 2026/540097/07), 250 Blaauwberg Road, Table View, Cape Town, 7441, South Africa.
- Information Officer: Reghardt Venter (Registration: 2026-061677), contactable at rventer@fintecgroup.co.za or +27 64 584 3869.
- Platform Dual Role: For individual account creation and website usage, GoTecID acts as a Data Controller / Responsible Party. When an enterprise or business user (“GORG Account”) uses GoTecID to request, receive, or manage files from clients or tenants, the business is the primary Data Controller, and GoTecID operates as a Data Processor / Operator acting strictly under documented instructions.
2. Scope of Policy & Website Browsing
This website is currently informational. We do not run invasive third-party ad tracking, profiling cookies, or data brokerage tools. When you visit our website:
- Technical Data: Hosting logs may collect essential network diagnostic data (IP address, browser user-agent, access timestamps) strictly for web application firewall security and uptime monitoring.
- Local Assets: Fonts and media assets are hosted locally or via privacy-preserving edges to prevent leakages to third-party advertising networks.
3. Core Operating Principle: Sealed Envelope Model
GoTecID is a consent-driven secure document sharing platform. We secure the transmission and storage envelope; we do not inspect, alter, evaluate, or verify document contents. Uploaded documents are encrypted at rest and in transit. We function as a zero-trust custodian of sealed digital envelopes. Any health, financial, or identification records uploaded are treated as opaque, encrypted blobs and are never mined or parsed for profiling.
4. Personal Data Collected & Processing Purposes
| Category | Data Types Collected | Lawful Basis / Purpose |
|---|---|---|
| Account Data | Name, business email address, phone number, multi-factor auth credentials. | Performance of contract; Account security and identity verification. |
| Vault Files | User-uploaded identity cards, proofs of address, income records (Encrypted). | Explicit User Consent & Contract performance (Controlled document transit). |
| Sharing Audits | Recipient identifiers, timestamp of link creation, expiry parameters, access logs. | Legitimate Interest & Compliance (Providing verifiable audit trails). |
| Technical Logs | Anonymized performance metrics, API call logs, security breach prevention counters. | Legitimate Interest (Maintaining platform resilience and security). |
5. Infrastructure & Third-Party Sub-Processors
We use trusted infrastructure operators (“Processors” / “Operators”) under strict legal agreements to provide storage and backend infrastructure:
- Supabase: Secure database and backend hosting operator. Data processing agreements ensure data protection compliance and mandatory encryption protocols.
- Cloud Edge Providers: Used for secure web application firewalling and DDoS mitigation.
We do not sell, rent, or trade personal data to data brokers or advertising networks under any circumstances.
6. European Union & UK Disclosures (GDPR / UK GDPR)
If you reside in the European Economic Area (EEA) or the United Kingdom:
- Legal Bases for Processing: We process personal data under Article 6 of the GDPR based on: (a) Consent (Art. 6(1)(a)) for vault file sharing; (b) Contractual Necessity (Art. 6(1)(b)) to deliver platform features; and (c) Legitimate Interests (Art. 6(1)(f)) for fraud prevention and security enforcement.
- International Data Transfers: Where data is transferred outside the EEA/UK to servers in South Africa or other non-adequate jurisdictions, transfers are safeguarded using EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and end-to-end cryptographic encryption.
- EEA/UK Data Rights: You have the right to request access, rectification, erasure (“Right to be Forgotten”), restriction of processing, data portability, and to object to processing. Contact rventer@fintecgroup.co.za.
- Supervisory Authority: You have the right to lodge a complaint with your local EU Data Protection Authority or the UK Information Commissioner’s Office (ICO).
7. California & US State Privacy Rights (CCPA / CPRA)
This section applies to California residents and users under similar US state privacy laws (e.g., Virginia VCDPA, Colorado CPA):
- Categories Collected in Past 12 Months: Identifiers (email, IP address), Sensitive Personal Information (encrypted identity files), Internet/Network activity logs, Professional/Employment details (where uploaded).
- No Sale or Sharing: GoTecID has not sold or shared (for cross-context behavioral advertising) any personal information in the preceding 12 months.
- Right to Limit Use of Sensitive Personal Information: Sensitive identity documents uploaded to your vault are encrypted and used solely to fulfill sharing requests you initiate.
- Your Rights: You have the right to know what personal data is collected, delete your data, correct inaccurate data, and receive equal service without discrimination.
- Submitting Requests: California residents or authorized agents may submit requests to rventer@fintecgroup.co.za with the subject line “US Privacy Request”.
8. Security Safeguards & Breach Notification
We enforce multi-layered administrative, physical, and technical safeguards, including:
- AES-256 encryption at rest and TLS 1.3 encryption in transit.
- Dynamic recipient-specific watermarking and restricted screenshot viewing windows.
- Immutable, cryptographic access logs for every link view.
In the event of a confirmed security compromise affecting your personal data, we will notify affected users and applicable regulatory bodies (such as the South African Information Regulator, EU DPAs, or state attorneys general) within statutory notification timeframes.
9. Data Retention & Automated Deletion
We retain personal information only for as long as necessary to fulfill the operational purpose or meet legal requirements (e.g., statutory tax/anti-money laundering retention periods ranging from 3 to 7 years depending on jurisdiction). Once retention periods expire or access links are revoked by you, files are permanently deleted or cryptographically unlinked in accordance with strict erasure protocols.
10. Regulatory Contact Details
For questions or formal complaints regarding your personal information:
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg
Tel: 010 023 5200 · Complaints: POPIAComplaints@inforegulator.org.za
GoTecID (Pty) Ltd · Attn: Information Officer
250 Blaauwberg Road, Table View, Cape Town, 7441, South Africa
Email: rventer@fintecgroup.co.za · Tel: +27 64 584 3869
11. Updates to this Policy
We may update this Privacy Policy periodically to reflect platform capabilities or legal updates. Revisions will be published on this page with an updated timestamp.