Privacy NoticePOPIA-compliant.
Last updated: 11 July 2026
1. Responsible Party and Information Officer
EstateAgently (Pty) Ltd (“EstateAgently,” “we,” “us”) is the Responsible Party for the processing of personal information in accordance with the Protection of Personal Information Act, 4 of 2013 (POPIA). Our Information Officer can be reached at: privacy@estateagently.com
2. What We Collect
Agency Administration
- Agency name, registration details, PPRA registration number
- Principal/director identity (name, email, phone, ID number)
- Payment and billing information (name, address, banking details)
- FICA verification documents (where legally required)
Agents and Staff
- Full name, email, phone number, WhatsApp contact
- FFC number and validity dates
- Qualifications and CPD record
- Call recordings with explicit consent (stored separately, access controlled)
Leads and Contacts (data flowing through the Platform)
- Contact details (name, email, phone, WhatsApp)
- Property preferences and communication history
- Viewing history and engagement data
- FICA and identity information (where collected for transactional purposes)
Platform Usage
- Log data (IP address, browser type, device type, pages viewed, timestamps)
- Feature usage and engagement metrics
- AI feature usage (for billing and compliance purposes)
3. Why We Collect It
EstateAgently processes personal information on the basis of:
- Your consent — for optional features such as call recording and AI analysis
- Contractual necessity — to provide the Platform and fulfil our SaaS agreement with your agency
- Legal obligation — to comply with PPRA, FICA, POPIA, and other South African laws
- Legitimate interests — to improve the Platform, detect fraud, and maintain security (balanced against your rights)
4. Who We Share It With
EstateAgently does not sell, rent, or trade personal information. We may share data with:
- Service providers — cloud infrastructure (Supabase, Vercel), payment processors, email delivery services, and AI providers (e.g., Anthropic for AI features). All service providers are bound by confidentiality and data protection agreements.
- Legal and regulatory authorities — when required by law or court order (e.g., PPRA investigations, FICA compliance checks).
- Your agency team — only data relating to your own agency and agents is visible to your team members.
We never share data between agencies. Row-level security at the database level ensures complete isolation.
5. Data Retention
- Transaction and financial records: retained for at least 5 years from completion, in line with the Financial Intelligence Centre Act
- Call recordings: retained for 5 years unless deleted earlier by the agency; recordings are encrypted and access is audit-logged
- FICA and compliance data: retained for the period required by law (typically 5+ years)
- Contact and lead data: retained as long as the agency is active; deleted within 30 days of account termination
- Platform usage logs: retained for 90 days for security purposes, then deleted
6. Your Rights Under POPIA
You have the right to:
- Access: request a copy of the personal information EstateAgently holds about you. Requests will be processed within 20 business days.
- Correction: request that we update inaccurate or incomplete data
- Deletion: request erasure of your data, subject to legal retention obligations (e.g., FICA, PPRA)
- Object: object to direct marketing, automated decision-making, or processing based on legitimate interest. We will stop processing within 20 business days unless we have a compelling reason to continue.
- Lodge a complaint with the Information Regulator of South Africa (justice.gov.za/inforeg) if you believe your rights have been violated.
To exercise any of these rights, contact our Information Officer (details below).
7. Cross-Border Data Transfers
Some of EstateAgently's service providers (e.g., cloud infrastructure) may process data outside South Africa. Where transfers occur, we ensure equivalent levels of data protection through:
- Standard contractual clauses (where applicable)
- Data Processing Agreements with service providers
- Encryption at rest and in transit
- Access controls and audit logging
8. Data Security
EstateAgently implements industry-standard security measures, including:
- Encryption of personal information at rest (AES-256) and in transit (TLS 1.2+)
- Row-level security at the database level to ensure tenant isolation
- Regular security audits and penetration testing
- Access controls based on role and agency
- Audit logging of all data access and modifications
However, no security system is impenetrable. EstateAgently cannot guarantee absolute security against all threats.
9. AI and Automated Processing
EstateAgently uses AI features (e.g., property descriptions, valuations, call analysis) to provide value to agencies. When you use these features:
- Your data is processed by AI service providers (e.g., Anthropic)
- EstateAgently does not train on your data or use it for model improvement
- You retain full control over when and how AI features are used
- Results are stored only on the Platform within your isolated tenant
- You can disable AI features at any time
10. Children's Privacy
The Platform is not intended for users under 18. EstateAgently does not knowingly collect personal information from minors. If we become aware that a minor has provided personal information, we will delete it immediately.
11. Contact and Complaints
For any privacy enquiry, to exercise your POPIA rights, or to report a suspected data breach:
- Email: privacy@estateagently.com
- Postal: EstateAgently (Pty) Ltd, address to be confirmed
For complaints to the Information Regulator:
- Website: justice.gov.za/inforeg
12. Changes to This Notice
EstateAgently may update this Privacy Notice at any time. Material changes will be notified to you via email. Your continued use of the Platform after such notification constitutes acceptance of the updated notice.
