Legal

Privacy & POPIA Notice

Version 1.0 Effective 30 November 2025 Last updated 20 August 2026

1. About this notice

The Big Data Showroom (Pty) Ltd (registration number 2025/921835/07) — "TBDS", "we", "us" — provides contact tracing, identity verification and screening services to vetted South African businesses for purpose-built use cases.

This notice explains what personal information we process, why, who we share it with, how long we keep it and how we protect it. It also sets out your rights under the Protection of Personal Information Act 4 of 2013 ("POPIA") and how to exercise them. It is issued in terms of section 18 of POPIA.

It applies to everyone whose personal information we hold — including people who have never been our customer, because our services involve processing information about individuals who are the subject of a search. If you are such a person, section 12 tells you what you can ask us to do.

Our physical and postal addresses are available on request from the Information Officer, whose details are in section 14.

2. The roles we play

Under POPIA our role depends on what we are doing:

  • As a responsible party. When we decide why and how to collect, match and hold the data behind our services, and when we handle our own client and website-visitor information, we determine the purpose and means of that processing ourselves. The obligations in this notice are ours.
  • As an operator. Where we process information purely on a client's instruction and under their mandate, the client is the responsible party for that processing and carries the duty to notify data subjects. We process under a written agreement as section 21 of POPIA requires.

Our clients are separately responsible for what they do with results after we deliver them. Their obligations are set out in our Terms of Use.

3. Whose information we process

Category of data subjectWhy we hold their information
Search subjects Individuals who are the subject of a search run by a vetted client — for example a debtor, a client of an attorney, or a party to a transaction.
Client users The individuals at our client businesses who hold accounts and run searches.
Applicants People and businesses who apply for access, including those we decline.
Website visitors People who visit our website or contact us.
Suppliers and contacts Individuals at our data suppliers and service providers.

4. What we process, and where it comes from

POPIA requires us to tell you what we collect and, where we did not collect it from you directly, the source it came from.

4.1 Information about search subjects

We process the following categories of personal information about individuals who are searched:

  • names and surnames;
  • identity numbers;
  • contact telephone numbers.

We do not collect this information from the data subject. It is supplied to us by:

  • credit bureaux registered with the National Credit Regulator in terms of the National Credit Act 34 of 2005;
  • commercial data providers under contract with us; and
  • sources where the data subject consented to the collection and onward supply of their information.

We query those sources at the time of a search. We do not build or hold our own matched database of contact information; what we retain is a record of the searches our clients run, described in section 9.

4.2 Information about client users and applicants

  • name, job title, work email address and telephone number;
  • company name, registration number and trading address;
  • professional registration details and any proof supplied during vetting;
  • the lawful purpose recorded for the account;
  • account credentials and authentication records;
  • a log of every search run — the user, the timestamp and the stated purpose;
  • billing and payment records.

We collect this directly from you when you apply, and generate it as you use the service.

4.3 Special personal information

We do not currently process special personal information as defined in section 26 of POPIA. Two services in development — Liveness Verification, which involves biometric information, and Compliance Screening, which involves criminal-behaviour and politically-exposed-person data — will fall into that category. Neither is live, and this notice will be updated to describe how each is handled before either is made available.

5. Why we process it, and our lawful basis

PurposeLawful basis (POPIA s11)
Providing search, verification and screening results to vetted clients for their recorded lawful purpose s11(1)(f) — the legitimate interests of the client to whom the information is supplied, as declared by that client for each search
Vetting applicants and confirming eligibility s11(1)(b) — necessary to conclude or perform the contract
Operating accounts, authentication and billing s11(1)(b) — performance of the contract
Logging searches, auditing use and investigating misuse s11(1)(c) and s11(1)(f) — legal obligation and our legitimate interest in preventing unlawful use
Keeping records the law requires us to keep s11(1)(c) — compliance with a legal obligation

No legislation specifically authorises or requires our collection of this information.

6. Voluntary or mandatory

If you apply for an account, supplying the information we ask for is voluntary, but we cannot vet or activate an account without it. If you decline to provide it, or provide information that is inaccurate, we will decline the application or close the account.

Search subjects do not supply information to us, so nothing is required of them.

7. Who we share it with

We share personal information with:

  • The vetted client who ran the search, and only that client. Results are delivered to the account that requested them, for the purpose recorded against it.
  • Our data sources — registered credit bureaux and commercial data providers — to the extent a search must be passed to them to be answered.
  • Service providers who host, secure, support or bill for the service, under written operator agreements. Our infrastructure runs on Google Cloud Platform and Firebase, on servers we configure and control.
  • Regulators, courts and law enforcement, where the law requires it or to establish, exercise or defend a legal claim.
  • Professional advisers — our attorneys, auditors and insurers — under a duty of confidence.

We do not sell personal information, and we do not supply it in bulk. Access is per search, vetted, logged and bound to a recorded purpose. Bulk requests are declined.

8. Cross-border transfers

We may transfer or store personal information on secure data servers located in the European Union. Such transfers are made in accordance with section 72 of POPIA: the recipients are subject to laws providing a level of protection for personal information that is substantially similar to, and in material respects not less than, that afforded by POPIA — namely the General Data Protection Regulation.

9. How long we keep it

We keep personal information only for as long as we need it for the purpose it was collected for, or for as long as the law requires, and then we delete or de-identify it.

RecordRetention period
Search logs — user, timestamp and stated purpose5 years from the date of the search
Search resultsNot retained. Results are returned to the client and are not stored by us.
Client account and vetting recordsFor the life of the account, then 5 years
Billing and tax records5 years, as required by the Tax Administration Act 28 of 2011
Declined applications12 months

10. How we secure it

Section 19 of POPIA requires us to secure the integrity and confidentiality of personal information with appropriate, reasonable technical and organisational measures. Ours include:

10.1 Where the data sits

Our systems run on Google Cloud Platform, with personal information held on servers located in the European Union. Data is encrypted in transit and at rest using the encryption Google Cloud applies as standard.

Google Cloud is independently certified against international information security standards. That certification covers Google's infrastructure rather than our application, so the controls we operate ourselves are set out separately below.

10.2 Getting into an account

  • Two-factor authentication is required on every account and cannot be disabled. A password on its own will not get anyone in.
  • Passwords are never stored in readable form.
  • Sessions expire and require re-authentication.
  • Access is granted by role, so a user reaches only what their role permits, and a principal controls who holds a seat.
  • Every account is vetted by a person before it is activated.

10.3 What we record

  • Every search is logged against a user, a timestamp and the purpose declared for it.
  • We monitor usage patterns for signs of misuse, and audit an account where we see them.
  • Operators who process personal information for us do so under written agreement.

If a security compromise occurs, we will notify the Information Regulator and the affected data subjects as soon as reasonably possible, as section 22 of POPIA requires.

11. Direct marketing

We do not use information obtained through our services for direct marketing, and our clients may not either. That prohibition is written into our Terms of Use.

Section 69 of POPIA prohibits direct marketing by electronic means — automated calls, SMS, email or fax — unless you have consented, or you are an existing customer being told about our own similar services, with an opt-out offered every time. Where we market to our own business contacts on that basis, every message identifies us and carries a way to opt out. You can opt out at any time by emailing admin@thebigdatashowroom.com.

12. Your rights

Under POPIA you have the right to:

  • Know whether we hold information about you, and get a copy. Ask us, or submit a PAIA request — see our PAIA manual. We may charge the prescribed fee and must verify your identity first.
  • Have it corrected or deleted where it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully. Use POPIA Form 2 (Request for Correction or Deletion).
  • Object to processing that we base on legitimate interest, on reasonable grounds relating to your situation. Use POPIA Form 1 (Objection to the Processing of Personal Information). If you object, we must stop processing your information on that basis.
  • Withdraw consent, where we relied on your consent.
  • Not be subject to a decision based solely on automated processing that has legal consequences for you, as section 71 provides.
  • Complain to the Information Regulator — see section 15.
  • Institute civil proceedings in a court of competent jurisdiction.

Send any request to our Information Officer using the details in section 14. We will respond within the period the law allows. Exercising these rights costs you nothing, except any prescribed fee for copies of records.

Note on form numbers. PAIA and POPIA each have their own numbered forms and they are not the same. A request for access to a record uses PAIA Form 02. Objection and correction use POPIA Form 1 and Form 2. Current versions of all of them are on the Information Regulator's website.

13. Cookies

We do not use cookies to follow you across other websites, and this site carries no advertising or marketing trackers.

  • Server logs. Our hosting provider keeps standard access logs, which include your IP address, for security and troubleshooting.
  • Fonts. This site loads its typeface from Google Fonts, so your browser requests those files from Google and Google receives your IP address as part of that request.
  • Signing in. The client portal sets a session cookie to keep you signed in. It is strictly necessary — the service cannot work without it — and it is not used for tracking.

You can block or delete cookies in your browser settings. Blocking the session cookie will prevent you from signing in.

14. Information Officer

Direct any privacy question, request or complaint to:

Information Officer
Ruan Petrus Greeff
Position
Director
Email
admin@thebigdatashowroom.com
Telephone
021 007 5899
Address
Available upon request
Regulator ref.
2026-001232, registered 29 January 2026

Full details are on our Information Officer page.

15. Complaints to the Information Regulator

If you are not satisfied with how we have handled your information or your request, you may complain to the Information Regulator (South Africa). You do not have to come to us first, though we would prefer the chance to put it right.

Address
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Telephone
010 023 5200
Toll-free
0800 017 160
General
enquiries@inforegulator.org.za
POPIA complaints
POPIAComplaints@inforegulator.org.za
PAIA complaints
PAIAComplaints@inforegulator.org.za
Website
inforegulator.org.za

A POPIA complaint uses POPIA Form 5, and complaints are generally lodged through the Regulator's eServices Portal.

16. Changes to this notice

We update this notice when our processing changes or the law does. The current version and its effective date are shown at the top of this page. Material changes affecting our clients are notified by email to the account's registered address.