POPIA Compliance

Last updated: 24 June 2026

This document describes how Comunicore complies with the Protection of Personal Information Act (POPIA) in the processing of personal information within our platform.

1. Overview

Comunicore is committed to full compliance with the Protection of Personal Information Act, 2013 (POPIA). This document outlines how we process personal information in accordance with POPIA and the rights of data subjects whose personal information we process.

2. Personal Information We Process

We process personal information of estate residents, management staff, trustees, contractors, and visitors. This includes names, contact details, identity numbers, biometric data (facial recognition and fingerprints), vehicle registration numbers, access logs, and financial information relevant to levy billing and payments.

3. Lawful Basis for Processing

We process personal information only where we have a lawful basis under POPIA, including: the consent of the data subject; performance of a contract; compliance with a legal obligation; protection of legitimate interests; or performance of a public law duty. Where consent is the basis, data subjects may withdraw consent at any time.

4. Data Subject Rights

Under POPIA, data subjects have the right to: be informed about the processing of their personal information; access and obtain a copy of their personal information; request correction or deletion of inaccurate information; object to the processing of their information; and withdraw consent where applicable. Requests should be directed to our Information Officer.

5. Information Security Measures

We implement appropriate technical and organisational security measures to safeguard personal information against loss, unauthorised access, alteration, or disclosure. These measures include data encryption, role-based access controls, audit logging, regular security assessments, and staff training on POPIA compliance.

6. Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including compliance with legal, accounting, or reporting requirements. Access logs are retained for a minimum of three years as required by applicable security regulations. Biometric data is deleted upon a resident or worker leaving the estate.

7. Cross-Border Transfers

Where personal information is transferred to a third party in another country, we ensure that the recipient is subject to a law, binding corporate rules, or binding agreement that provides an adequate level of protection consistent with POPIA requirements.

8. Information Officer

Our Information Officer is responsible for ensuring compliance with POPIA and for handling data subject requests. You may contact our Information Officer at popia@comunicore.co.za or by mail at Comunicore, 1st Floor, Block C, Fourways, Sandton, Johannesburg, 2191, South Africa.

9. Complaints

If you believe we have processed your personal information in a manner inconsistent with POPIA, you may lodge a complaint with the Information Regulator at P.O. Box 31533, Braamfontein, Johannesburg, 2017, or via complaints@inforegulator.org.za. We encourage you to contact us first so we can address your concerns directly.