Legal
POPIA Notice
This notice is provided in terms of the Protection of Personal Information Act, 2013 (POPIA) and explains how Zeroed processes personal information.
Last updated: 25 July 2026
1. Purpose of this notice
The Protection of Personal Information Act, 2013 (POPIA) gives data subjects rights over their personal information and sets duties on responsible parties and operators who process it.
This notice explains Zeroed's approach to POPIA. It should be read together with our Privacy Policy and Terms of Service.
2. Who is responsible for what
When you use Zeroed as a business customer
If you are a practice, school, or other business using Zeroed to work your overdue accounts, you are usually the responsible party for personal information about your debtors. You decide why that information is processed and you have the relationship with them.
Zeroed acts as an operator when we process that information on your documented instructions, for example to send reminders, log replies, create payment links to your PayFast account, or maintain compliance records.
When you are a Zeroed account holder or website visitor
For information about your own staff users, billing contacts, support enquiries, and account administration, Zeroed is typically the responsible party.
If you received a message about an overdue account
Contact the business named in the message first. They can explain the account, update your details, honour opt-outs, and handle most data-subject requests. Use the opt-out or preference link in the message where provided.
3. Categories of personal information
Depending on your relationship with us, we may process:
- Identity and contact details: names, phone numbers, email addresses, WhatsApp numbers, and preferred language or channel.
- Account and billing data: invoice references, amounts outstanding, due dates, payment history, promise-to-pay and plan records.
- Communications: message content, timestamps, delivery and read status, and inbound replies.
- Compliance records: consent basis, opt-outs, disputes, hardship submissions, prescription and credit-agreement flags where configured.
- User and administrative data: staff login details, roles, audit logs, and support correspondence.
- Technical data: IP address, device and browser information, and usage logs for security and service operation.
In medical, dental, or school contexts, information may relate to family or learner accounts. Businesses must apply additional care and lawful basis where minors are involved.
4. Purpose of processing
We process personal information to:
- Provide first-party accounts receivable and collections automation.
- Send reminders and service messages on authorised channels.
- Facilitate payment and payment-plan flows to your own PayFast account.
- Maintain immutable communication and event logs for operations and compliance.
- Enforce opt-outs, contact hours, fatigue limits, and tenant isolation.
- Bill, support, secure, and improve the Service.
- Comply with legal obligations.
5. Lawful basis
Processing may rely on:
- Consent where required, including debtor contact where your business has captured consent at import or onboarding.
- Contract to deliver the Service to business customers.
- Legitimate interest for security, fraud prevention, and limited service analytics, where balanced against data-subject rights.
- Legal obligation where retention or disclosure is required by law.
Businesses using Zeroed remain responsible for selecting and documenting the correct lawful basis for debtor data they upload.
6. Sources of information
- Directly from business customers and their authorised users.
- From CSV or spreadsheet imports and manual entry by customers.
- From debtors via replies, payment pages, and self-service flows.
- From channel and payment providers (for example delivery receipts or PayFast ITN confirmations).
- From website visitors who contact us or sign up.
7. Recipients and operators
Personal information may be shared with operators and service providers who assist us, including:
- WhatsApp / Meta and other messaging providers.
- SMS and email delivery providers.
- PayFast, for payments that settle to your business account.
- Cloud hosting, database, and storage providers.
- Analytics providers used in a privacy-appropriate way on our website.
We require operators to protect personal information and process it only for authorised purposes. We do not sell personal information.
8. Cross-border processing
Zeroed is designed for South Africa. Some infrastructure or channel providers may process data outside South Africa. Where cross-border transfers occur, we take steps required under POPIA, including ensuring appropriate safeguards through contracts or permitted mechanisms.
9. Security safeguards
We implement appropriate, reasonable technical and organisational measures, including:
- Encryption in transit and at rest.
- Role-based access and multi-tenant isolation enforced at the database layer.
- Server-side-only storage of sensitive credentials such as PayFast keys.
- Immutable logging of messages and material state changes.
- Contact-hour, fatigue-cap, and opt-out enforcement built into the product.
10. Retention
We retain personal information only for as long as necessary for the purposes described, unless a longer period is required by law. Retention limits can be configured for tenant data where the product provides that control. Cancelled accounts are retained for an export window, then deleted in line with our retention policy.
11. Your rights as a data subject
Subject to POPIA, you may have the right to:
- Be notified that your personal information is being collected.
- Request access to personal information held about you.
- Request correction or deletion of inaccurate or excessive information.
- Object to processing in certain circumstances.
- Withdraw consent where processing is based on consent, subject to legal or contractual restrictions.
- Lodge a complaint with the Information Regulator of South Africa.
To opt out of collection messages, use the STOP or preference mechanism in the message, or contact the business that sent it. Opt-outs are honoured immediately and permanently on the do-not-contact list.
12. How to exercise your rights
- Zeroed account holders and staff: email privacy@zeroed.co.za with your request and enough detail for us to verify your identity.
- Debtors: contact the business named in the communication. They are usually the responsible party.
- General enquiries: hello@zeroed.co.za
We will respond within a reasonable period and not later than required by POPIA. We may refuse requests where permitted by law, for example where disclosure would affect another person's rights or where we must retain records for legal reasons.
13. Information Officer
Zeroed has designated an Information Officer responsible for POPIA compliance. You can reach them at:
Information Officer
Zeroed
Email: privacy@zeroed.co.za
14. Complaints to the Information Regulator
If you are not satisfied with how we handle your personal information, you may complain to the Information Regulator (South Africa):
Website: www.inforegulator.org.za
Email: inforeg@justice.gov.za
15. Special processing notes
First-party collections only
Zeroed does not route debtor funds through Zeroed-controlled accounts. Payment links resolve to each business's own PayFast account. This first-party model is a core compliance and legal boundary.
Credit agreements and prescription
Accounts flagged as credit agreements may require National Credit Act section 129 processes. Trade debts may prescribe after three years from due date unless interrupted by acknowledgement, payment, or summons. Businesses remain responsible for legal classification and escalation decisions.
Schools
Public-school fee arrears may require an exemption process before enforcement. A learner may not be excluded or have reports withheld for a parent's debt. Extra POPIA care applies where minors' data is involved.
16. Changes
We may update this notice from time to time. The current version is always available on this page with the date of last update.