LEGAL

Privacy Policy

How TimeWorks Data Solutions collects, uses and safeguards personal information under the Protection of Personal Information Act 4 of 2013 (POPIA).

Effective date: 3 April 2026

Legal Documents

  • Privacy Policy
  • PAIA Manual
  • Cookie Policy
  • Website Disclosures
  • Terms and Conditions
  • Hardware Sales Terms
  • Rental Agreement Terms
  • Software Terms
  • Refund and Returns
  • Disclaimer

1. Identity of the Responsible Party

TimeWorks Data Solutions (Pty) Ltd is the Responsible Party for the purposes of POPIA. We determine the purpose and means of processing your personal information.

Company Name: TimeWorks Data Solutions (Pty) Ltd

Registration Number: 2016/209939/07

VAT Number: 4230305817

Physical Address: 13A Geelhout Crescent, Plattekloof, Western Cape, 7500

Telephone: 0861 736 767

Email: Contact us

Privacy Email: privacy@timeworksdata.co.za

Information Officer: Tauhier Sylvester

2. What Personal Information We Collect

2.1 As Responsible Party - Website Visitors and Leads

When you interact with our website or enquire about our products and services, we may collect:

  • Full name and contact details (phone number, email address)
  • Business name, trading name and physical address
  • Information submitted through contact forms, demo booking requests and support tickets
  • Website usage data collected via cookies (see our Cookie Policy)
  • IP address and browser information for security and analytics purposes
  • Communication records including emails and support correspondence

2.2 As Operator - POS Client Data

When we provide POS software and support services to our clients (who are themselves Responsible Parties), we act as an Operator. In this capacity we may process:

  • Employee names and usernames required to set up and operate the POS system
  • Customer transaction records within the POS database
  • Loyalty programme data if the client has enabled that feature
  • Business financial and sales data stored within the POS system

Where we act as Operator, we process this data solely on the instruction of the client and in accordance with a written Operator agreement.

3. Purpose of Processing

We process personal information only for the following specific and lawful purposes:

  • Responding to enquiries: To answer questions submitted through our website or by phone or email
  • Demo bookings: To schedule and conduct product demonstrations
  • Providing POS services: To install, configure, maintain and support POS software and hardware under contract
  • Invoicing and billing: To generate invoices, process payments and maintain financial records
  • Technical support: To diagnose and resolve issues with hardware or software
  • Direct marketing: To send product updates, promotions and relevant communications, only where you have given explicit consent
  • Legal compliance: To meet obligations under South African law including SARS requirements, the Companies Act and PAIA
  • Website security and improvement: To monitor for security threats and improve our website

4. Legal Basis for Processing

We rely on one or more of the following conditions when processing personal information:

  • Consent: You have given us clear consent to process your data for a specific purpose, such as receiving marketing communications
  • Contractual necessity: Processing is necessary to perform a contract with you, or to take steps at your request before entering into a contract
  • Legal obligation: Processing is required for us to comply with a legal obligation, such as maintaining tax records
  • Legitimate interest: Processing is necessary for our legitimate business interests, provided these interests do not override your rights. This includes fraud prevention, website security and product improvement

5. Third Parties and Operators

We may share personal information with trusted third parties who assist in delivering our services. All such third parties are bound by written agreements that require them to protect personal information in line with POPIA Section 21.

  • Payment gateways: We use PCI-DSS compliant third-party payment processors. Card data is never stored on TimeWorks systems or servers.
  • Cloud hosting providers: Our systems and backups may be hosted on cloud infrastructure. These providers are subject to data processing agreements.
  • Accounting integrations: Where clients use integrations with accounting software, data sharing is limited to what is necessary for the integration to function.
  • Technical support contractors: We may use vetted contractors who access client systems only for authorised support purposes.

We do not sell personal information to third parties. We do not share personal information for any purpose other than those listed above.

6. Cross-Border Transfers

Some of the cloud services we use may store or process data on servers located outside South Africa. Where this occurs, we take steps to ensure that the receiving country or organisation provides an adequate level of protection, or we put appropriate safeguards in place such as data processing agreements that include standard contractual clauses.

You may request details of the specific third-party services that may involve cross-border transfers by contacting us at privacy@timeworksdata.co.za.

7. Data Retention

We retain personal information only for as long as necessary for the purpose for which it was collected, or as required by law:

  • Client and contract records: 5 years from the end of the contract, in line with SARS requirements
  • Support tickets and correspondence: 3 years from the date of resolution
  • Marketing consent records: For the duration of the marketing relationship plus 3 years
  • Website enquiries not converted to clients: 12 months from the date of last contact
  • Invoices and financial records: 5 years from the date of issue

When records are no longer required, we securely delete or anonymise them.

8. Security Measures

We implement reasonable technical and organisational measures to protect personal information against loss, unauthorised access, disclosure, alteration and destruction. These measures include:

  • Encryption of data in transit using TLS/HTTPS
  • Access controls that limit who can view personal information to authorised staff only
  • Regular staff training on data protection obligations
  • A documented incident response procedure
  • Secure disposal of physical documents containing personal information
  • Regular review of our security practices

No method of electronic storage or transmission is 100% secure. If you believe your personal information may have been compromised, please contact us immediately.

9. Your Rights as a Data Subject

Under POPIA, you have the following rights in relation to your personal information:

  • Right of access: You may request a description of the personal information we hold about you and details of how it is used
  • Right to correction: You may request that we correct inaccurate, incomplete or outdated personal information
  • Right to deletion: You may request that we delete your personal information where it is no longer necessary for the purpose it was collected, subject to any legal retention obligations
  • Right to object: You may object to the processing of your personal information, including for direct marketing purposes
  • Right to complain: You may lodge a complaint with the Information Regulator if you believe we have not handled your personal information lawfully

To exercise any of these rights, contact our Information Officer at privacy@timeworksdata.co.za. We will respond within 30 days.

10. Breach Notification

In the event of a security compromise that is likely to affect your personal information, we will notify you and the Information Regulator as soon as we are reasonably certain that a breach has occurred, in accordance with POPIA Section 22 and the 2025 notification amendments. Notifications will be sent to the contact details you have provided to us.

11. Cookies and Tracking

Our website uses cookies and similar tracking technologies. Please read our Cookie Policy for full details on what cookies we use, why we use them, and how you can manage them.

12. Direct Marketing

We will only send you marketing communications if you have given us explicit consent to do so. Each marketing communication will include a clear and easy way to opt out. If you opt out, we will remove you from our marketing list promptly and will not send further marketing communications unless you provide consent again.

To opt out of marketing communications at any time, contact us at privacy@timeworksdata.co.za or use the unsubscribe link in any marketing email.

13. Contact and Complaints

For any questions, requests or concerns about this Privacy Policy or about how we handle your personal information, contact our Information Officer:

Information Officer: Tauhier Sylvester

Email: privacy@timeworksdata.co.za

Phone: 0861 736 767

Address: 13A Geelhout Crescent, Plattekloof, Western Cape, 7500

If you are not satisfied with our response, you may lodge a complaint with the Information Regulator of South Africa:

Information Regulator (South Africa)

Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Email: complaints.IR@inforegulator.org.za

Website: www.inforegulator.org.za

This Privacy Policy was last updated on 3 April 2026. We may update this policy from time to time. The current version will always be available on this page.

Ready to Upgrade?

Let's find the right POS setup
for your business.

Book a Free Demo Explore Rentals
Timeworks Logo

Trusted by 700+ South African businesses since 1999.

25+ YEARS IN BUSINESS

SECTORS

  • Hospitality POS
  • Retail POS
  • Services & Salons

SUPPORT

  • Contact Us
  • Log a Ticket
  • About Us
  • Rentals
  • Case Studies

CONTACT

location_on 13A Geelhout Crescent, Plattekloof

phone 0861 736 767

mail send us a message

© 2026 TIMEWORKS DATA SOLUTIONS (PTY) LTD. ALL RIGHTS RESERVED.

Reg: 2016/209939/07  |  VAT: 4230305817

Blog | FAQ | About