1. Identity of the Responsible Party
TimeWorks Data Solutions (Pty) Ltd is the Responsible Party for the purposes of POPIA. We determine the purpose and means of processing your personal information.
Company Name: TimeWorks Data Solutions (Pty) Ltd
Registration Number: 2016/209939/07
VAT Number: 4230305817
Physical Address: 13A Geelhout Crescent, Plattekloof, Western Cape, 7500
Telephone: 0861 736 767
Email: Contact us
Privacy Email: privacy@timeworksdata.co.za
Information Officer: Tauhier Sylvester
2. What Personal Information We Collect
2.1 As Responsible Party - Website Visitors and Leads
When you interact with our website or enquire about our products and services, we may collect:
- Full name and contact details (phone number, email address)
- Business name, trading name and physical address
- Information submitted through contact forms, demo booking requests and support tickets
- Website usage data collected via cookies (see our Cookie Policy)
- IP address and browser information for security and analytics purposes
- Communication records including emails and support correspondence
2.2 As Operator - POS Client Data
When we provide POS software and support services to our clients (who are themselves Responsible Parties), we act as an Operator. In this capacity we may process:
- Employee names and usernames required to set up and operate the POS system
- Customer transaction records within the POS database
- Loyalty programme data if the client has enabled that feature
- Business financial and sales data stored within the POS system
Where we act as Operator, we process this data solely on the instruction of the client and in accordance with a written Operator agreement.
3. Purpose of Processing
We process personal information only for the following specific and lawful purposes:
- Responding to enquiries: To answer questions submitted through our website or by phone or email
- Demo bookings: To schedule and conduct product demonstrations
- Providing POS services: To install, configure, maintain and support POS software and hardware under contract
- Invoicing and billing: To generate invoices, process payments and maintain financial records
- Technical support: To diagnose and resolve issues with hardware or software
- Direct marketing: To send product updates, promotions and relevant communications, only where you have given explicit consent
- Legal compliance: To meet obligations under South African law including SARS requirements, the Companies Act and PAIA
- Website security and improvement: To monitor for security threats and improve our website
4. Legal Basis for Processing
We rely on one or more of the following conditions when processing personal information:
- Consent: You have given us clear consent to process your data for a specific purpose, such as receiving marketing communications
- Contractual necessity: Processing is necessary to perform a contract with you, or to take steps at your request before entering into a contract
- Legal obligation: Processing is required for us to comply with a legal obligation, such as maintaining tax records
- Legitimate interest: Processing is necessary for our legitimate business interests, provided these interests do not override your rights. This includes fraud prevention, website security and product improvement
5. Third Parties and Operators
We may share personal information with trusted third parties who assist in delivering our services. All such third parties are bound by written agreements that require them to protect personal information in line with POPIA Section 21.
- Payment gateways: We use PCI-DSS compliant third-party payment processors. Card data is never stored on TimeWorks systems or servers.
- Cloud hosting providers: Our systems and backups may be hosted on cloud infrastructure. These providers are subject to data processing agreements.
- Accounting integrations: Where clients use integrations with accounting software, data sharing is limited to what is necessary for the integration to function.
- Technical support contractors: We may use vetted contractors who access client systems only for authorised support purposes.
We do not sell personal information to third parties. We do not share personal information for any purpose other than those listed above.
6. Cross-Border Transfers
Some of the cloud services we use may store or process data on servers located outside South Africa. Where this occurs, we take steps to ensure that the receiving country or organisation provides an adequate level of protection, or we put appropriate safeguards in place such as data processing agreements that include standard contractual clauses.
You may request details of the specific third-party services that may involve cross-border transfers by contacting us at privacy@timeworksdata.co.za.
7. Data Retention
We retain personal information only for as long as necessary for the purpose for which it was collected, or as required by law:
- Client and contract records: 5 years from the end of the contract, in line with SARS requirements
- Support tickets and correspondence: 3 years from the date of resolution
- Marketing consent records: For the duration of the marketing relationship plus 3 years
- Website enquiries not converted to clients: 12 months from the date of last contact
- Invoices and financial records: 5 years from the date of issue
When records are no longer required, we securely delete or anonymise them.
8. Security Measures
We implement reasonable technical and organisational measures to protect personal information against loss, unauthorised access, disclosure, alteration and destruction. These measures include:
- Encryption of data in transit using TLS/HTTPS
- Access controls that limit who can view personal information to authorised staff only
- Regular staff training on data protection obligations
- A documented incident response procedure
- Secure disposal of physical documents containing personal information
- Regular review of our security practices
No method of electronic storage or transmission is 100% secure. If you believe your personal information may have been compromised, please contact us immediately.
9. Your Rights as a Data Subject
Under POPIA, you have the following rights in relation to your personal information:
- Right of access: You may request a description of the personal information we hold about you and details of how it is used
- Right to correction: You may request that we correct inaccurate, incomplete or outdated personal information
- Right to deletion: You may request that we delete your personal information where it is no longer necessary for the purpose it was collected, subject to any legal retention obligations
- Right to object: You may object to the processing of your personal information, including for direct marketing purposes
- Right to complain: You may lodge a complaint with the Information Regulator if you believe we have not handled your personal information lawfully
To exercise any of these rights, contact our Information Officer at privacy@timeworksdata.co.za. We will respond within 30 days.
10. Breach Notification
In the event of a security compromise that is likely to affect your personal information, we will notify you and the Information Regulator as soon as we are reasonably certain that a breach has occurred, in accordance with POPIA Section 22 and the 2025 notification amendments. Notifications will be sent to the contact details you have provided to us.
11. Cookies and Tracking
Our website uses cookies and similar tracking technologies. Please read our Cookie Policy for full details on what cookies we use, why we use them, and how you can manage them.
12. Direct Marketing
We will only send you marketing communications if you have given us explicit consent to do so. Each marketing communication will include a clear and easy way to opt out. If you opt out, we will remove you from our marketing list promptly and will not send further marketing communications unless you provide consent again.
To opt out of marketing communications at any time, contact us at privacy@timeworksdata.co.za or use the unsubscribe link in any marketing email.
13. Contact and Complaints
For any questions, requests or concerns about this Privacy Policy or about how we handle your personal information, contact our Information Officer:
Information Officer: Tauhier Sylvester
Email: privacy@timeworksdata.co.za
Phone: 0861 736 767
Address: 13A Geelhout Crescent, Plattekloof, Western Cape, 7500
If you are not satisfied with our response, you may lodge a complaint with the Information Regulator of South Africa:
Information Regulator (South Africa)
Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: complaints.IR@inforegulator.org.za
Website: www.inforegulator.org.za
This Privacy Policy was last updated on 3 April 2026. We may update this policy from time to time. The current version will always be available on this page.