← Back to login Promage

Privacy Policy

Effective and last updated: 27 July 2026 · Version 2026-07-27

1. Purpose and scope

This Policy explains how Promage Consulting (“Promage”) processes personal information when providing its construction, workforce, payroll, attendance, asset, site, document, biometric, GPS, reporting, and data-assistant services. It applies to dashboard users, subscribing organisations, employees and contractors whose information is managed in Promage, and people who contact us.

Promage and the subscribing organisation may have different roles under South Africa’s Protection of Personal Information Act, 4 of 2013 (“POPIA”). The subscribing organisation generally determines why its workforce and project information is entered and acts as the responsible party for that information. Promage processes that information to provide the contracted platform and may also act as a responsible party for account security, service administration, legal compliance, and its own operational records.

2. Information processed

  • Accounts and access: names, usernames, business contact details, company and site assignments, roles, privileges, password hashes, authentication and session records.
  • Workforce and employment: identity and contact details, employment terms, contracts, addresses, banking details, attendance, clock records, leave, wages, payroll, signatures, attachments, qualifications, and emergency or employment-related records entered by authorised users.
  • Biometric and liveness information: consent evidence, facial reference and sample images, face-template information, challenge results, quality information and liveness scores where the subscribing organisation enables face enrollment. This is sensitive information and must only be collected for a defined, authorised workforce-verification purpose.
  • Projects and operations: site diaries, photographs, issues, labour, plant, materials, production, BOQ, certificates, costs, assets, maintenance and related business records.
  • Location and device information: assigned-site information, asset GPS telemetry and geofence events where enabled; IP address, browser, operating system, user agent, device labels, timestamps and security logs.
  • Communications and support: messages, notifications, support requests and audit records.
  • AI requests: questions submitted to the Data Assistant and the permitted company data used to answer them. Access controls remain applicable to AI-assisted results.

3. Why and on what basis we process information

Information is processed only when there is an applicable lawful basis, including performance of a service or employment-related contract, compliance with legal obligations, protection of legitimate operational or security interests, or specific and informed consent where consent is legally required. Accepting this Policy is an acknowledgment of the notice; it is not blanket consent for every processing activity.

  • Provide, secure, administer and support the dashboard and user accounts.
  • Perform customer-authorised construction, employment, payroll, attendance, safety, asset and reporting functions.
  • Maintain auditability, prevent misuse, investigate incidents and enforce access restrictions.
  • Comply with tax, employment, safety, accounting, record-keeping, court or regulatory obligations.
  • Improve reliability and usability using aggregated or appropriately minimised operational information.

Where information is mandatory, failure to provide it may prevent the relevant account, employment, verification, payroll or project function from operating. Optional fields and optional cookies are identified separately.

4. Sharing, operators and international processing

Information may be disclosed to authorised personnel of the subscribing organisation; contracted hosting, storage, email, security, support, mapping, GPS, document or AI service providers acting under appropriate obligations; professional advisers; regulators, courts or authorities where lawfully required; and a successor in a properly controlled business transfer. Promage does not sell personal information.

Where a provider processes information outside South Africa, Promage or the responsible subscribing organisation must use a lawful transfer mechanism and reasonable contractual and security safeguards. Customers must not enable integrations or upload information unless they are authorised to do so.

5. Cookies and local browser storage

  • Essential: authentication, CSRF protection, security, session continuity and storage of privacy choices. These are required and cannot be switched off while using the authenticated dashboard.
  • Analytics: optional measurement intended to understand product usage. It remains off unless selected.
  • Marketing: optional campaign measurement or personalised announcements. It remains off unless selected.

Optional-cookie consent is separate from acceptance of the Terms. Optional scripts must not be activated unless the corresponding preference is enabled. Users can request that optional preferences be changed; essential session information is removed or expires through logout and configured retention.

6. Retention

Information is retained only for the period needed for the stated purpose, contractual commitments, legitimate audit and security needs, or applicable employment, tax, safety and other legal retention duties. Retention differs by record type and customer instruction. When retention is no longer justified, information is securely deleted, de-identified or placed beyond use, subject to lawful backup cycles and preservation obligations.

7. Security and incidents

Promage uses role- and site-based access controls, password hashing, secure session settings, HTTPS in production, input validation, parameterised database access, audit logging, and operational safeguards appropriate to the nature of the service. No system is risk-free. Suspected compromise is investigated and affected responsible parties, data subjects and the Information Regulator are notified where POPIA requires it.

Users must protect credentials, use only authorised accounts, promptly report suspected misuse, and avoid downloading or sharing records beyond their authority.

8. Your rights

Subject to POPIA and PAIA, a data subject may request confirmation and access, correction or deletion of inaccurate or unlawfully held information, object to certain processing, request restriction where appropriate, withdraw consent without affecting earlier lawful processing, and complain to the Information Regulator. Identity and authority may be verified before a request is fulfilled. Some requests may be limited by legal retention, another person’s rights, privilege, security, or other lawful grounds.

9. Children and authorised workforce use

The dashboard is intended for authorised business users and is not directed to children. Customers must not enter children’s information unless they have a specific lawful purpose and all required authority and safeguards.

10. Contact and complaints

Privacy questions and data-subject requests may be sent to support@promage.co.za or raised by telephone at +27 67 705 0269. Workforce information requests should normally also be directed to the subscribing employer or organisation that entered the information.

You may complain to the Information Regulator South Africa through its published channels at inforegulator.org.za.

11. Policy changes

Material changes receive a new version and users may be required to acknowledge that version before their next login. A record of the version, time and account acceptance is retained. Continued access alone is not used as a substitute where a fresh acknowledgment or consent is required.