POPIA Notice
Marqly is fully compliant with the Protection of Personal Information Act (POPIA). This notice explains how we comply with the eight conditions for lawful processing of personal information under South African law.
AES-256 Encrypted
Data at rest & in transit
POPIA Compliant
All 8 conditions met
SA Data Hosting
Your data stays in South Africa
What is POPIA?
The Protection of Personal Information Act (POPIA) is South Africa's comprehensive data protection law that came into full effect on 1 July 2021. It regulates the processing of personal information by public and private bodies and gives effect to the constitutional right to privacy enshrined in Section 14 of the Constitution of the Republic of South Africa, 1996.
POPIA establishes eight conditions for the lawful processing of personal information. As a responsible party, Marqly complies with all eight conditions and has implemented policies, procedures, and technical measures to ensure ongoing compliance.
The Information Regulator (South Africa) is the independent administrative body established under Section 39 of POPIA to enforce compliance, provide guidance, and handle complaints from data subjects.
Personal Information We Collect
We collect and process the following categories of personal information:
Identity & Contact
- Full name and surname
- Email address
- Phone number
- Business name and position
Business Details
- Company registration number
- Business address
- Industry and business type
- VAT / tax number
Financial Information
- Billing address
- Payment card details (via PayStack)
- Transaction history
- Invoice records
Technical Data
- IP address and geolocation
- Browser and device type
- Session and cookie data
- Platform usage analytics
Eight Conditions for Lawful Processing
POPIA requires that all processing of personal information complies with the following eight conditions. Here is how Marqly satisfies each:
Accountability (Section 8)
Marqly has implemented a comprehensive information governance framework, including policies, procedures, and systems to ensure POPIA compliance. Our Information Officer oversees all data protection activities.
Processing Limitation (Sections 9–12)
We only collect and process personal information that is adequate, relevant, and not excessive for the purposes for which it was collected. Data is collected directly from data subjects with their consent or from responsible parties under lawful agreements.
Purpose Specification (Section 13)
Personal information is collected for specific, explicitly defined, and legitimate purposes related to delivering our platform services. Data subjects are informed of these purposes at the time of collection.
Further Processing Limitation (Section 14)
Personal information is not processed in a way that is incompatible with the purpose for which it was originally collected, unless data subjects have given consent or a legal exception applies.
Information Quality (Section 15)
We take reasonable steps to ensure that personal information collected is complete, accurate, not misleading, and updated where necessary. Users can update their information directly through their account settings.
Openness (Section 17–18)
We maintain transparent documentation about our data processing activities, including this notice, our Privacy Policy, and our PAIA Manual. Data subjects are informed about what information we hold and how it is processed.
Security Safeguards (Section 19–22)
We implement technical and organizational security measures to protect personal information against loss, damage, unauthorized access, and unlawful processing. This includes encryption, access controls, and regular security audits.
Data Subject Participation (Section 23–25)
Data subjects have the right to access, correct, delete, and object to the processing of their personal information. We respond to all requests within the statutory 30-day period.
Your Rights Under POPIA
As a data subject under POPIA, you have the following rights regarding your personal information:
Right of Access (Section 23)
Request confirmation of whether we hold your personal information and request a copy.
Right to Correction (Section 24)
Request correction or deletion of inaccurate, irrelevant, or excessive information.
Right to Deletion (Section 24)
Request deletion of your personal information where retention is no longer justified.
Right to Object (Section 11(3))
Object to the processing of your personal information on reasonable grounds.
Right to Portability
Request your data in a structured, machine-readable format (JSON/CSV).
Right to Complain (Section 74)
Lodge a complaint with the Information Regulator (SA) if you believe your rights have been violated.
Data Security Measures
Marqly implements the following security measures to protect personal information, as required by Section 19 of POPIA:
Data Retention & Deletion
We retain personal information in accordance with Section 14 of POPIA (further processing limitation) and applicable legal requirements:
- Active accounts: Data retained for the duration of the account plus 90 days for transition.
- After cancellation: 90-day window for data export before permanent deletion.
- Financial records: 5 years retention as required by SARS (Section 55 of the Tax Administration Act).
- Communication records: Message logs retained for 1 year for dispute resolution and quality assurance.
You may request early deletion at any time by contacting our Information Officer. Deletion requests are processed within 30 days.
Information Officer
As required by Section 55 of POPIA, Marqly has registered an Information Officer with the Information Regulator (South Africa). The Information Officer oversees data protection compliance and handles data subject requests.
Marqly Information Officer
Email: popia@marqly.co.za
Phone: +27 (0) 11 123 4567
Address: Johannesburg, South Africa
Response time: We respond to all data subject requests within 30 days as required by POPIA.
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Breach Notification
In compliance with Section 22 of POPIA, Marqly has a breach notification policy in place. In the event of a personal information breach:
- We will notify the Information Regulator within 72 hours of becoming aware of the breach.
- Affected data subjects will be informed as soon as reasonably possible.
- Notifications will include the nature of the breach, potential consequences, and measures taken or proposed to address it.
- We maintain a breach register documenting all incidents and remediation steps.
Updates to This Notice
We may update this POPIA notice from time to time to reflect changes in our data processing practices or legal requirements. Significant changes will be communicated via email and in-app notifications.
Last updated: June 2025