← BackUpdated August 2026

Privacy Notice & Security

This page is maintained by Ozwa one (trading as OZWA ONE) to explain how we collect, use and protect personal information of our customers, their guards and their clients. It describes the controls we have enabled today — it is not an independent audit or compliance certification.

Who we are and our role

Ozwa one (trading as OZWA ONE) is the data controller for account and billing-related personal information we collect about our own customers and their users. Where our customers upload records about their own employees, guards and clients, the customer is the controller of that information and we act as processor on their instructions.

Contact for data protection matters: privacy@ozwaone.app.

What we collect

To run payroll, scheduling, and compliance for our security operations, we store:

  • Guard details — name, ID number, PSIRA number, grade, phone, email, banking details.
  • Client site details — name, address, contact person, rates.
  • Operational records — daily postings, schedules, incidents, invoices, payslips.
  • User account details — email, role, page-access permissions, sign-in history.
  • Subscription details — plan, status and billing period. Card and bank details are collected and held by our payment provider, never by us.

Why we process it, and our legal basis

  • Providing the service and your account — necessary for performance of our contract with you.
  • Billing and subscription management — performance of contract and compliance with tax and accounting obligations.
  • Security, fraud prevention and audit logging — our legitimate interest in keeping the platform and your data safe.
  • Customer support — performance of contract and our legitimate interest in resolving your queries.
  • Product improvement and service emails — legitimate interests; marketing emails are sent only with your consent, which you can withdraw at any time.
  • Legal and regulatory retention — compliance with a legal obligation.

Who we share it with

  • Paddle.com — our online reseller and Merchant of Record for all orders. Paddle receives the personal information needed to process payments, manage subscriptions, handle refunds and customer billing enquiries, issue invoices and meet tax obligations. Paddle acts as an independent controller for that payment data.
  • Service providers / subprocessors — cloud hosting and database providers, email delivery and support tooling, acting on our instructions.
  • Professional advisers — legal and accounting advisers where needed.
  • Authorities — where we are required to disclose information by law.

We do not sell personal information. Where data is transferred outside South Africa or the EEA/UK, we rely on appropriate safeguards such as standard contractual clauses.

Who can see what

Access is role-based and enforced on the server, not just the sidebar. A user only sees pages they have been explicitly granted:

  • Company Owner: full access, including sensitive PII and audit logs.
  • Administrator: operational data and financials; sensitive PII on a need-to-know basis.
  • Manager & Supervisor: scheduling, incidents, and postings only.
  • Bravo 1 (Guards / limited users): only their own records and assignments.

Bank details, ID numbers, and other sensitive fields are masked for users who do not need them (e.g. •••• 1234).

How we protect it

  • Encryption in transit: all traffic uses HTTPS/TLS.
  • Encryption at rest: our managed cloud database encrypts stored data on disk.
  • Row-level security: the database itself enforces who can read or change each row, not just the app.
  • Server-side authorisation: every protected page and every server function re-checks the user's role and page access.
  • Audit logging: every change to a guard record is written to a tamper-resistant log visible to the CEO.
  • Automated backups: daily backups with point-in-time restore.

Account security

  • Passwords are hashed by our authentication provider — we never see them in plain text.
  • Failed sign-in attempts are rate-limited to slow down brute-force attacks.
  • Every successful sign-in is logged with IP and device; new devices trigger an alert.
  • Two-factor authentication is recommended for all Company Owner and Administrator accounts.
  • Access can be revoked instantly by an Company Owner from the Users page.

How long we keep it (retention schedule)

Each customer company has a documented retention period per data type, visible and adjustable in Settings → Security → Retention & privacy. Our defaults are:

  • Employee records — 3 years after an employee leaves, then anonymised (BCEA record keeping).
  • Payroll, payslips and timesheets — 5 years (SARS and labour law).
  • Applicant details — 6 months after an unsuccessful application (consent based).
  • Uploaded documents (ID copies, PSIRA certificates, contracts) — 3 years.
  • Incident and inspection reports, including photos — 5 years.
  • Chats, discussions and announcements — 12 months.
  • Audit trail and change history — 7 years; sign-in and security logs 30–365 days depending on type.

Deletion and anonymisation

When a person asks for their data to be deleted, a company owner or administrator can run an erasure on that employee record. Their name, ID number, phone, email, banking details, PSIRA number, custom fields and uploaded documents are permanently removed, and the record is replaced by an anonymous reference. Payroll totals, invoices and audit entries that we are legally required to keep remain linked to that anonymous reference, so financial and compliance history stays intact without holding personal information.

Every erasure is written to an append-only erasure log recording who requested it, why, which fields were cleared and when. Closing a company account deletes all of that company's records — sites, employees, postings, payroll, invoices, incidents, documents and members — and that closure is itself logged.

Requests are actioned within 30 days. Where a legal retention duty applies, we will tell you which records we must keep and for how long.

Your rights (POPIA / GDPR)

You have the right to know what personal information we hold about you, to request a correction, to object to processing, and to request deletion where the law allows. Requests are handled by the CEO within 30 days.

If something goes wrong

If we discover a data breach that affects your personal information, we will notify affected users and the Information Regulator without unreasonable delay, in line with POPIA obligations.

To report a suspected security issue, please email privacy@ozwaone.app. Please do not publicly disclose the issue until we have had a reasonable chance to investigate.

Contact

Data protection queries: privacy@ozwaone.app

See also our Terms & Conditions and Refund Policy.

© 2026 Ozwa one. This page describes controls in effect at the time of the last update and does not constitute a legal contract or certification.