Table of Contents
Privacy Policy
Protection of Personal Information Act (POPIA) Compliance
Last Updated: 14 May 2026This privacy policy complies with the Protection of Personal Information Act 4 of 2013 (POPIA) of South Africa. We are committed to protecting your personal information and respecting your privacy rights.
- Parliament assented to POPIA on 19 November 2013
- Section 1, Part A of Chapter 5, Sections 112 & 113 commenced on 11 April 2014
- All other sections commenced on 1 July 2020 (proclaimed by the President of South Africa)
- One-year grace period to comply ended on 30 June 2021
1. Introduction
Welcome to the Hostel Management System ("we", "us", "our"). We are committed to protecting your personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA") of South Africa.
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our hostel management website. Please note: This system is a web-based application only and does not include any mobile applications.
By using our services, you consent to the collection and use of information in accordance with this policy. If you do not agree with any part of this policy, please do not use our services.
2. Responsible Party
In terms of POPIA, the "Responsible Party" for your personal information is:
Organization: Not yet configured
Information Officer: Not yet designated
3. Information We Collect
We collect the following categories of personal information:
Student Information
- Full name and student number
- Email address and phone number
- Gender (for room allocation purposes)
- Room allocation and building information
- Emergency contact information
Visitor Information
- Visitor name and contact details
- ID number and relationship to student
- Vehicle registration (where applicable)
- Check-in and check-out times
Parcel Information
- Sender information and tracking details
- Parcel collection records
Maintenance Records
- Maintenance requests and issue descriptions
- Digital signatures for service confirmation
Technical Information
- IP addresses and browser information
- Login timestamps and session data
- Cookies and usage analytics
4. Legal Basis for Processing
We process your personal information based on the following lawful grounds under POPIA Section 11:
Consent
You have given us explicit consent to process your information for specific purposes.
Contractual Necessity
Processing is necessary for the performance of our accommodation contract with you.
Legal Obligation
Processing is required to comply with legal requirements (e.g., safety regulations).
Legitimate Interest
Processing is necessary for our legitimate interests (e.g., security, fraud prevention).
The 8 Conditions for Lawful Processing (POPIA Chapter 3)
We adhere to all eight conditions for lawful processing as prescribed by POPIA:
5. How We Use Your Data
We use your personal information for the following purposes:
Room allocation, check-in/out processes, and residence administration
Building access, visitor management, and emergency procedures
Processing and tracking maintenance requests
Receiving, storing, and distributing parcels
Important notices, announcements, and emergency alerts
6. Data Sharing & Third Parties
We may share your personal information with:
- Emergency Services: In case of emergencies affecting your health or safety (ambulance, fire, police)
- Legal Authorities: When required by law, court order, or legal process
6b. Direct Marketing (POPIA Section 69)
In terms of POPIA Section 69, we may only conduct direct marketing if:
- You are an existing resident/customer and we market similar services
- We have obtained your explicit consent (opt-in) for marketing communications
- You have been given a reasonable opportunity to object at no cost
Your Right to Opt-Out
You can opt-out of direct marketing at any time by:
- Clicking "unsubscribe" in any marketing email
- Visiting your Data Privacy settings in your account
- Contacting our Information Officer
6c. Data Breach Notification (POPIA Sections 21-22)
In the event of a security compromise where your personal information may have been accessed by unauthorized persons, we will:
- Notify the Information Regulator as soon as reasonably possible
- Notify you (the data subject) in writing as soon as reasonably possible, unless:
- A public body or the Information Regulator determines notification would impede a criminal investigation
- We have implemented sufficient security safeguards rendering the information unintelligible
7. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
Encryption
Data encrypted in transit and at restAccess Control
Role-based access restrictionsAudit Logs
Comprehensive activity trackingSecure Hosting
Enterprise-grade infrastructureRegular Backups
Automated backup systemsStaff Training
POPIA awareness training8. Your Rights Under POPIA (Chapter 5)
Under POPIA, you have the following rights regarding your personal information:
Exercise Your Rights
To exercise any of these rights, please:
- Log into your account and visit the Data Privacy section
- Contact the designated Information Officer
- Submit a written request to our Information Officer
9. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by law:
| Data Category | Retention Period | Action After Period |
|---|---|---|
| Student Records | 5 years after departure | Anonymized or Deleted |
| Visitor Logs | 2 years | Deleted |
| Parcel Records | 1 year after collection | Deleted |
| Maintenance Records | 3 years | Archived |
| Audit Logs | 7 years | Archived |
| Login History | 90 days | Deleted |
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes:
- We will notify you via email or prominent notice on our website
- The "Last Updated" date at the top of this policy will be revised
- Where required by law, we will obtain your consent to material changes
We encourage you to review this policy periodically to stay informed about how we protect your information.
12. Contact Us
Information Officer
Our Privacy Officer is available to assist you with any privacy-related inquiries, including data access requests, correction requests, or any questions about how we handle your personal information.
Use the form below to contact us
Information Regulator
If you are not satisfied with our response, you may lodge a complaint with:
The Information Regulator (South Africa)
Woodmead North Office Park, 54 Maxwell Dr, Woodmead, Johannesburg, 2191
Phone: 010 023 5200 | Toll Free: 0800 017 160
Email: enquiries@inforegulator.org.za
Website: inforegulator.org.za
Contact Privacy Officer
By continuing to use our services, you acknowledge that you have read and understood this Privacy Policy.
Version 1.0 | Effective Date: 14 May 2026