This page explains how FixrBuddy approaches the Protection of Personal Information Act, 2013 (POPIA) in connection with our property operations platform. It is written for property operators, staff users, tenants, residents, visitors, and other individuals whose personal information may appear in FixrBuddy.
POPIA applies to responsible parties and operators in South Africa. In most deployments, your property organisation decides what to collect and why; FixrBuddy provides the software used to store and process that information under the organisation’s direction.
This statement describes our current practices and intentions. It does not constitute legal advice, and it should not be read as a certification or guarantee of compliance in every scenario. Organisations using FixrBuddy remain responsible for their own POPIA obligations.
Accountability
For limited information FixrBuddy collects directly (for example website enquiries, newsletter sign-ups, and commercial correspondence with us), FixrBuddy may act as a responsible party under POPIA for that information only.
When we process personal information on behalf of a property operator using the platform, we generally act as an operator and the customer is usually the responsible party for workspace data. In those cases, the customer determines the primary purposes of processing; we process data to provide the Service according to their instructions and any agreement between us.
We try to maintain internal practices that may help support POPIA-related expectations and publish this page together with our Privacy Policy and Terms & Conditions. Nothing on this page should be read as an admission of legal non-compliance or as legal advice.
Privacy contact
For FixrBuddy-related privacy and POPIA enquiries (including access, correction, deletion, or complaints about information we control):
- Email: admin@fixrbuddy.co.za (subject line: POPIA enquiry)
- Website: www.fixrbuddy.co.za
- Application: app.fixrbuddy.co.za
Tenants, residents, and visitors should first contact their property operator (the responsible party for workspace data). We will aim to assist operators within a reasonable time when requests are routed through them or lawfully directed to us.
When contacting us, include enough detail for us to understand your request (for example your name, the property or organisation involved, and the type of record you are asking about). We may need to verify identity before responding.
Processing limitation
We generally process personal information for operational purposes related to the FixrBuddy Service, which may include:
- User authentication and role-based access control
- Maintenance, inspections, assets, calendar, and operational reporting
- Visitor check-in/out, policies, and host notifications
- Lease preparation, e-signing, and document storage
- Billing, invoices, arrears, and finance exports
- Team messaging, attachments, and notifications (in-app, web push, SMS, email where enabled)
- Customer support, implementation, migration, and security monitoring
We do not sell personal information. Marketing communications from FixrBuddy to business contacts are generally sent only where there is an appropriate basis (such as consent or an existing enquiry relationship), with a way to opt out.
Customers who enable SMS, email, or push notifications for operational messages remain responsible for ensuring those communications comply with POPIA and other applicable rules for their recipients.
Purpose specification
Purposes are described in this statement, the Privacy Policy, customer agreements, and in-product context (for example when a tenant submits a maintenance ticket or a visitor is checked in at reception).
We aim not to use workspace personal information for unrelated purposes without an appropriate lawful basis and, where required, notice to affected parties. If we materially change how we process information we control as responsible party, we will update our public documentation where practical.
Further processing limitation
Further processing may be compatible with the original purpose when it reasonably supports the same operational, security, or legal objectives — for example retaining audit logs to investigate a disputed maintenance assignment or exporting billing records for a Customer’s finance team.
Portfolio analytics and reports are intended for the Customer’s own use within their workspace. Where we use aggregated or de-identified information to improve the Service, we aim to apply safeguards so individuals are not reasonably identifiable from that aggregated data.
Information quality
Customers control most data entered into FixrBuddy, including bulk imports of users, properties, rooms, and assets. Authorised Users can update profile and operational records where their role permits.
We encourage Customers to review imported spreadsheets before go-live, to correct outdated tenant or visitor records promptly, and to limit custom fields to information that is relevant to property operations.
Openness
Documentation available to data subjects includes:
- This POPIA information page
- Privacy Policy (categories of data, sharing, retention, rights)
- Terms & Conditions (acceptable use and responsibilities)
Security safeguards
The Service may include features intended to help protect information, such as:
- Role-based permissions — view, edit, delete, and export rights per module for admin, manager, staff, security, resident, and custom roles (where configured)
- Workspace separation — separation between customer organisations in a multi-tenant environment
- Activity history — logs on certain workflows (for example maintenance ticket changes), where enabled
- Access controls — sign-in for app access and session handling
- HTTPS — encryption in transit for web and app traffic in normal operation
- Operational logging — technical logs that may support security and reliability
Customers are responsible for protecting User credentials, configuring roles appropriately, and removing access when staff leave. Shared devices at reception or security desks should be logged out when not in use.
Descriptions on this page are general and may change as the Service evolves. They are not a promise of a particular security outcome or certification.
Data subject participation
Data subjects may request:
- Confirmation whether we hold personal information about them
- Access to records or a description of information held
- Correction of inaccurate, incomplete, or misleading information
- Deletion where law allows (subject to legal retention and ongoing contract needs)
- Objection to processing on reasonable grounds relating to their particular situation
Where we are involved, we will try to respond within a reasonable period, subject to POPIA and practical limits. Complex requests involving a Customer workspace may require coordination with the responsible party, which can extend timelines if the Customer must locate or approve changes to records.
We may decline or limit requests where the law permits (for example where information is legally privileged, relates to another person’s rights, or cannot be deleted while a legitimate retention obligation exists).
Categories of data subjects and personal information
| Data subject | Examples in FixrBuddy |
|---|---|
| Staff & operators | Names, emails, phones, roles, messages, assignments, inspection and maintenance activity |
| Tenants & residents | Profiles, lease context, room allocation, tickets, documents, billing, notices |
| Visitors | Identity fields, check-in/out, host linkage, policy outcomes, notification metadata |
| Signers & guarantors | Lease e-signing identity, signature events, PDF records |
| Website contacts | Contact form and newsletter details processed by FixrBuddy as responsible party |
Special personal information (as defined in POPIA) should only be uploaded if the Customer has a lawful basis and appropriate safeguards. Core FixrBuddy workflows do not require special categories such as health or biometric data; if a Customer chooses to store such information in custom fields or attachments, that is at the Customer’s discretion and risk.
Children and student housing
Student housing Customers may process information about minors (for example resident students under 18). The Customer must ensure an appropriate lawful basis (such as institutional authority, contract, or parental consent, as applicable to their context) and should avoid collecting more information than the accommodation relationship requires.
FixrBuddy provides operational tools; we do not set residence rules, disciplinary procedures, or campus privacy policies on behalf of Customers.
Direct marketing
FixrBuddy may send product updates or offers to business contacts where we believe we have an appropriate basis (such as consent or an existing enquiry relationship). Marketing messages will usually include a way to opt out where practicable. Customers using SMS/email modules for visitor or operational notices are responsible for their own compliance with POPIA and other applicable rules.
Cross-border information flows
Some subprocessors or infrastructure providers may process or store data outside South Africa. Where that occurs, we may take such steps as we consider appropriate under applicable law, which could include contractual terms with providers. Customers may contact us for general information via admin@fixrbuddy.co.za; specific arrangements may be addressed in customer agreements.
Retention and deletion
Retention periods depend on the type of information, the Customer’s agreement, and legal requirements. General guidelines include:
- Active workspaces: data retained while the Customer subscription is active and as needed for the modules in use
- After termination: Customer data deleted or returned per agreement, subject to backup cycles (which may extend up to approximately 90 days) and legal hold requirements
- Security logs: retained for a limited period to help investigate incidents and maintain system integrity
- Website enquiries: retained as long as reasonably needed to respond and maintain ordinary business records
Customers should export records they wish to keep before termination where the product and their permissions allow. FixrBuddy is not a long-term archive service unless otherwise agreed in writing.
Security compromises
If we become aware of a security compromise involving personal information under our control, we may take such steps as we consider appropriate under applicable law, which could include notifying the Information Regulator or affected parties where we believe notification is required.
Where an incident may affect Customer workspace data we process as operator, we will try to inform the Customer in a reasonable timeframe so the Customer can assess its own response. FixrBuddy does not act on behalf of Customers in their regulator or data-subject notifications unless separately agreed in writing.
Operator agreements with Customers
Enterprise and portfolio Customers may request a written agreement covering processing instructions, subprocessors, security, data subject requests, incidents, and deletion. Standard terms reference privacy topics at a high level; any specific commitments are normally set out in a separate contract if agreed.
Customers are responsible for their own privacy notices to tenants and staff and for deciding whether to mention FixrBuddy or other systems in those notices.
Customer responsibilities
Because Customers usually control workspace data, they are responsible for matters such as:
- Providing appropriate privacy notices to tenants, visitors, and staff
- Configuring roles so Users access only the modules and records they need
- Using visitor and messaging features in line with building policies and applicable law
- Handling data subject requests for information they control in the workspace
- Maintaining the security of their accounts and notifying us if they suspect misuse or unauthorised access
Complaints to the Information Regulator
If you are not satisfied with our response, you may complain to the Information Regulator (South Africa):
- Website: www.inforegulator.org.za
- Email: enquiries@inforegulator.org.za
Limitations of this statement
This page is a high-level transparency document. It does not list every subprocessor, every technical control, or every jurisdictional variation that may apply to a specific Customer deployment. Those details may be addressed in customer agreements or upon written request where appropriate.
Laws and regulator guidance change over time. We may update practices or this page without prior notice. Public documentation is intended as a general overview only and may not reflect every detail of a specific deployment or contract.
Updates
We review this statement when our processing practices or applicable law changes. The date at the top indicates the latest revision. Previous versions are not routinely published on the website; you may contact us if you need to confirm when a particular section last changed.