1. Who we are
Responsible Party: MAP Food Safety Solutions.
Information Officer: support@mapfoodsafetysolutions.co.za.
We process personal information from the Republic of South Africa.
2. What we collect
- Account data: name, email, password hash, profile info you provide.
- Consultation & quote data: name, company, mobile, email, sourcing requirements, message content.
- Calendar booking data: attendee email, selected slot, Google Meet link.
- Usage data: IP address, browser/device, pages viewed, Sentinel actions, error logs.
- Payment data: handled directly by our payment partner; we receive transaction metadata only (amount, status, last four digits, customer ID).
- Communications: messages you send via chat or email.
3. Why we collect it
- Provide, secure and improve the Services.
- Authenticate users and prevent fraud or abuse.
- Process bookings, quotes and payments.
- Send service announcements and, with your opt-in, marketing updates.
- Comply with legal obligations and resolve disputes.
4. Lawful basis (POPIA s.11)
We rely on one or more of:
- Consent — for marketing communications and optional cookies.
- Contractual necessity — to deliver the Services you request.
- Legal obligation — tax, accounting, regulatory.
- Legitimate interest — security, fraud prevention, product analytics (balanced against your rights).
5. Who we share it with
We share personal information only with:
- Hosting & database: our managed cloud backend (Lovable Cloud).
- Calendar integration: Google (Google Calendar / Google Meet) for consultations.
- Payment processor: our regulated payment partner for once-off and recurring payments.
- Email delivery: transactional email providers for confirmations and notices.
- Professional advisors: auditors, lawyers, accountants under duty of confidence.
- Authorities: when required by law or a valid court order.
We do not sell your personal information.
6. Cross-border transfers
Some processors store data outside South Africa (e.g. United States, European Union). We rely on POPIA section 72 by ensuring the recipient is subject to binding rules or law providing an adequate level of protection, or by obtaining your consent where required.
7. Retention
We keep personal information only as long as necessary for the purposes set out above and to satisfy legal, accounting and reporting obligations. Account data is deleted within 90 days of account closure unless retention is required by law (e.g. tax records — 5 years).
8. Your rights
Under POPIA you have the right to:
- Access the personal information we hold about you.
- Request correction or deletion.
- Object to processing on legitimate-interest grounds.
- Withdraw consent at any time (without affecting prior lawful processing).
- Lodge a complaint with the Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001; complaints.IR@justice.gov.za; inforegulator.org.za.
To exercise these rights email support@mapfoodsafetysolutions.co.za. We will respond within 30 days.
9. Security
We use industry-standard safeguards including TLS in transit, encryption at rest, role-based access, row-level security on the database, password hashing, and least-privilege service accounts. No system is perfectly secure; you must also protect your own credentials. We will notify affected data subjects and the Information Regulator of a security compromise as required by POPIA section 22.
10. Children
The Services are not directed at persons under 18. We do not knowingly process personal information of children. If you believe a child has provided information, contact us and we will delete it.
11. Changes
We may update this policy. The version and effective date appear at the top. Material changes will be notified in-app and may require re-acceptance.
12. Contact & complaints
Email support@mapfoodsafetysolutions.co.za with any privacy question or to exercise your POPIA rights.
Questions about this policy? Email support@mapfoodsafetysolutions.co.za. This document is provided for transparency and does not constitute legal advice.