LegalPrivacy

Privacy Policy

How we collect, use, share, retain and protect personal information under POPIA - and the rights you can exercise over it.

Contents
Effective date
Last updated

Riskscape (Pty) Ltd, registration number 2012/131998/07 (Riskscape, we, us, or our), respects privacy and processes personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable law.

This Policy explains how we collect, use, share, retain, and protect personal information when you visit our website, create or use a Riskscape Console account, use our APIs or data services, buy a subscription or digital product, contact us, or otherwise interact with us.

1. Our role

Riskscape is the responsible party for personal information used to operate accounts, provide and secure the Services, manage billing, communicate with customers, and run our business.

Where a customer submits personal information for us to process only on its instructions, Riskscape generally acts as the customer's operator and the customer remains the responsible party. In that situation, the customer's privacy notice and any data-processing agreement also apply.

2. Personal information we collect

Depending on how you use the Services, we may collect:

Account and contact information

  • name, job title, organisation, email address, telephone number, and business address;
  • account identifiers, authentication records, password hashes, roles, permissions, and security settings; and
  • communications, support requests, demo enquiries, preferences, and feedback.

Billing and transaction information

  • billing contact, billing address, tax information, plan, order, invoice, payment status, currency, amount, and transaction reference;
  • limited payment-method details returned by Paystack, such as card type, masked digits, authorisation reference, or payment channel; and
  • refund, cancellation, failed-payment, fraud-screening, and dispute information.

Paystack processes the payment credentials needed to complete a transaction. Riskscape does not receive or store your full card number, CVV, online-banking password, EFT PIN, or one-time password through the standard hosted payment flow.

Service and usage information

  • API requests and response metadata, usage units, plan consumption, download history, feature activity, timestamps, and service events;
  • device, browser, operating system, IP address, approximate location derived from IP, session, cookie, referral, and diagnostic information; and
  • security, authentication, audit, error, performance, and incident logs.

Customer-submitted data

  • addresses, coordinates, property references, files, datasets, queries, and other information submitted to an API, upload, secure transfer channel, or support request; and
  • information needed to perform a custom project or produce a requested output.

Customer-submitted data may contain personal information depending on the customer's use. Customers must not submit restricted or highly sensitive personal information unless the relevant Service and a written agreement expressly permit it.

Information from other sources

We may receive information from:

  • your organisation or another authorised account administrator;
  • payment providers, fraud-prevention providers, data suppliers, business partners, or service providers;
  • public records, licensed datasets, open-data repositories, and lawful commercial sources; and
  • referrals, events, or professional networks.

Riskscape also works with source datasets to create aggregated or de-identified data products. We apply controls intended to remove or reduce identifying information before broader distribution.

3. Why we process personal information

We process personal information to:

  • create accounts, authenticate users, manage permissions, and provide the Services;
  • process orders, measure usage, issue invoices, collect payment, and administer credits, cancellations, and refunds;
  • deliver API access, downloads, reports, data processing, support, and customer communications;
  • understand requirements, respond to enquiries, and manage our customer relationship;
  • maintain, troubleshoot, monitor, secure, test, and improve the Services;
  • prevent, detect, investigate, and respond to fraud, abuse, unlawful use, security incidents, and policy violations;
  • maintain audit, transaction, tax, accounting, and legal records;
  • conduct service analytics, research, and product development using proportionate safeguards;
  • send service notices and, where lawful, relevant marketing communications that can be opted out of;
  • establish, exercise, or defend legal claims and protect our rights, users, systems, and the public; and
  • comply with law, lawful requests, court orders, regulatory duties, and contractual obligations.

Under POPIA, our lawful justification may include your consent, performance of a contract, compliance with law, protection of your legitimate interests, or pursuit of our or a third party's legitimate interests where the law permits.

4. Mandatory information and consequences

Fields marked as required are needed to create an account, contract with you, secure the Services, process payment, or comply with law. If you do not provide required information, we may be unable to open the account, process the order, or provide the relevant Service. Optional fields are identified where practicable.

5. Payment processing

Paystack processes payments for Riskscape. When you pay, relevant personal and transaction information is provided directly to Paystack and shared with payment networks, banks, acquirers, fraud-prevention services, and authorities as needed to process and protect the transaction.

Paystack acts under its own terms and privacy notices for payment-processing activities. Payment and personal information may be processed in South Africa and other countries in accordance with applicable data-protection law. Review Paystack's South African privacy information at https://paystack.com/za/terms.

6. Sharing of personal information

We do not sell personal information. We may disclose it only as reasonably necessary to:

  • service providers who host, store, secure, and support our systems (e.g. Amazon Web Services, Microsoft), bound by contract to protect your information and use it only as we authorise;
  • payment processors and related parties (e.g. Paystack, banks, fraud-prevention providers, tax authorities), to process transactions;
  • your organisation's authorised users, if you share an account;
  • regulators, courts, or law enforcement, where required or permitted by law;
  • a buyer or successor, in a merger, sale, or reorganisation; and
  • other parties with your instruction or consent.

We require operators processing personal information for us to protect it and use it only for authorised purposes. Providers and locations may change as our systems evolve.

7. International transfers

Some providers, support teams, systems, or data recipients may be outside South Africa. Where personal information is transferred across borders, we use a lawful basis and safeguards appropriate under section 72 of POPIA, such as an adequate legal regime, a binding agreement providing an adequate level of protection, contractual necessity, or consent where applicable.

8. Retention

We keep personal information only as long as reasonably necessary for the purpose for which it was collected, a compatible lawful purpose, a contract, dispute, or applicable law.

In particular:

  • transaction, tax, accounting, and core business records may be retained for seven (7) years or a longer period required by law, contract, or a legitimate dispute;
  • Customer Data is retained for the period agreed with the customer or needed to provide the Service, unless law requires otherwise;
  • secure file-transfer locations are delivery channels and may be periodically purged;
  • security and usage records are retained for a proportionate period needed for billing, audit, abuse prevention, incident response, and service integrity; and
  • backups are removed through managed rotation cycles unless preservation is legally required.

When information is no longer required, we securely delete, destroy, de-identify, or restrict it in accordance with applicable obligations. Some information may remain in protected backups until rotation completes.

9. Security

We use appropriate, reasonable technical and organisational measures designed to protect the confidentiality, integrity, and availability of information. Depending on the system and risk, these include:

  • encryption in transit and encryption at rest;
  • access control, authentication, least-privilege permissions, and credential-management rules;
  • segregated processing environments and controlled secure file transfer;
  • logging, monitoring, vulnerability assessment, threat detection, backup, and recovery controls;
  • data classification, minimisation, anonymisation, and restricted handling procedures;
  • staff obligations, security awareness, and incident-response processes; and
  • contractual security and confidentiality requirements for operators.

No method of transmission or storage is completely secure. You must also protect your credentials, use supported security features, and notify us promptly of suspected compromise.

If a security compromise affects personal information, we will investigate, contain, and notify affected parties and the Information Regulator as required by POPIA and other applicable obligations.

10. Cookies and similar technologies

We may use cookies, local storage, pixels, and similar technologies to:

  • keep you signed in and maintain secure sessions;
  • remember preferences;
  • prevent fraud and protect the Services;
  • understand performance and usage; and
  • measure communications or marketing where lawful.

Strictly necessary technologies are required for the website and Console to function. Where required, we ask for consent before using non-essential analytics or advertising technologies. You can use the available cookie controls or browser settings, although blocking necessary cookies may prevent parts of the Services from working.

11. Marketing

We may send marketing only where consent has been provided. You can unsubscribe using the message link or by emailing info@riskscape.pro. We may still send non-marketing messages about accounts, security, billing, transactions, or requested Services.

12. Automated processing and customer decisions

Riskscape uses models and automated processing to generate risk, property, financial, geospatial, and other analytical output. That output generally supports a customer's own analysis and does not itself constitute a decision by Riskscape about an individual.

Customers are responsible for ensuring that their use of output complies with POPIA and other applicable laws concerning automated decisions, fairness, explanations, human review, discrimination, and data quality. The Services must not be used as the sole basis for a legally significant decision where additional safeguards are required.

13. Your rights

Subject to POPIA and other applicable law, you may have the right to:

  • ask whether we hold personal information about you;
  • request access to that information;
  • ask us to correct, update, delete, or destroy information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, unlawfully obtained, or no longer authorised to be retained;
  • object on reasonable grounds to certain processing;
  • withdraw consent where processing is based on consent;
  • object to direct marketing;
  • ask about relevant cross-border processing or recipients; and
  • complain to the Information Regulator.

To exercise a right, email info@riskscape.pro with enough information for us to identify the relevant records and right. We may need to verify your identity and authority. We will not require more identity information than reasonably necessary, and any fee will be limited to one permitted by law.

If your request concerns data controlled by a Riskscape customer, we may refer it to that customer and assist as required by law or contract.

14. Children

The website and Services are intended for adults and organisations and are not directed to children under 18. Do not submit children's personal information unless a written agreement expressly permits it and all required authorisation, lawful grounds, and safeguards are in place. If you believe a child provided information improperly, contact us.

Our website may link to third-party websites or services. Their privacy practices are governed by their own notices, and we are not responsible for services we do not control.

16. Changes to this Policy

We may update this Policy as our Services, providers, and legal obligations evolve. We will post the updated version and effective date. If a change materially affects how previously collected personal information is used or shared, we will give notice or obtain consent where required.

17. Contact us

For privacy questions, objections, access or correction requests, consent withdrawal, or complaints, contact:

Riskscape (Pty) Ltd
Registration number: 2012/131998/07

Physical address: Unit A-1002A, First Floor, Corobay, corner Aramist and Corobay Avenue, Menlyn, Pretoria, Gauteng, 0181, South Africa

Telephone: +27 76 626 0234

Email: info@riskscape.pro

Website: https://www.riskscape.pro

You have the right to complain to the Information Regulator (South Africa) if you believe your personal information has been processed unlawfully. You can lodge a complaint via the Regulator's website (https://inforegulator.org.za/) or eServices portal (https://eservices.inforegulator.org.za/). General enquiries: enquiries@inforegulator.org.za / +27 10 023 5200.

Questions about this policy?

Talk to us about data licensing, processing agreements, security reviews or anything else in this document.