Privacy Policy
Stratida (Pty) Ltd
Effective date: 24 July 2026 · Last updated: 24 July 2026
1. Introduction
Stratida (“Stratida”, “we”, “us”, “our”) is a software engineering and digital transformation company based in South Africa. We build and operate websites, web platforms, mobile applications and connected products for ourselves and for our clients.
This Privacy Policy explains how we collect, use, share, store and protect personal information when you:
- visit or use www.stratida.com;
- download, install or use any mobile application published by Stratida on the Apple App Store, Google Play Store, Huawei AppGallery or any other distribution channel;
- use any web platform, portal, API or connected device operated by Stratida; or
- contact us, apply for work with us, or engage us as a client, supplier or partner.
Together, these are referred to as the “Services”.
We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), the Electronic Communications and Transactions Act 25 of 2002 (“ECTA”), the Consumer Protection Act 68 of 2008 where applicable, and — where our Services reach users outside South Africa — comparable data protection laws such as the EU and UK GDPR.
Please read this Policy carefully. By using our Services you acknowledge that you have read and understood it. Where the law requires your consent, we will ask for it separately and clearly.
2. Who is responsible for your information
Stratida (Pty) Ltd is the Responsible Party for the personal information described in this Policy, except where we act as an Operator for a client as explained below.
Stratida (Pty) Ltd
Attention: The Information Officer
Email: hello@stratida.com
Website: www.stratida.com
South Africa
Our Information Officer is registered with the Information Regulator of South Africa and is responsible for ensuring our compliance with POPIA. All privacy queries, requests and complaints should be directed to hello@stratida.com.
Where Stratida acts as an Operator, not a Responsible Party
A large part of our work involves building and maintaining applications on behalf of our clients. In those cases:
- our client is the Responsible Party and decides why and how your personal information is processed;
- Stratida is an Operator acting only on that client’s documented instructions, under a written agreement as required by sections 20 and 21 of POPIA;
- our client’s own privacy policy governs that processing, and you should direct your requests to them.
Each application identifies who the Responsible Party is. If you are unsure, email us at hello@stratida.com and we will tell you who controls your information and how to reach them.
3. The personal information we collect
We only collect information that is adequate, relevant and not excessive for the purpose it is needed. Not every category below applies to every app or service — what we actually collect depends on which Service you use and which features you enable.
3.1 Information you give us
- Identity and contact details: name, surname, email address, mobile number, physical or delivery address, company name, job title.
- Account credentials: username, password (stored only as a salted cryptographic hash), security questions, multi-factor authentication settings.
- Profile information: profile photo, display name, language and communication preferences, biography, skills or interests where the app offers this.
- Content you submit: messages, comments, support tickets, form submissions, documents, images, audio, video, code, survey responses and any other content you upload or create in our Services.
- Transaction information: records of purchases, subscriptions, invoices, orders and billing address. We do not store full card numbers. Card payments are processed by PCI-DSS compliant third-party payment providers.
- Recruitment information: CV, qualifications, references and work history if you apply for a role with us.
- Verification information where a specific service legally requires it, such as an identity number or company registration documents (for example FICA or RICA-type verification, KYC for financial features, or age verification).
3.2 Information collected automatically
- Device information: device make and model, operating system and version, screen resolution, language and region settings, mobile network operator, and an app instance identifier or advertising identifier (Google Advertising ID or Apple IDFA).
- Usage and diagnostic information: screens viewed, features used, buttons tapped, session duration, timestamps, app version, referral source, crash logs, stack traces and performance metrics.
- Log and connection information: IP address, approximate location derived from IP, browser type, and pages or endpoints requested.
- Cookies and similar technologies on our website and web platforms (see section 9).
3.3 Device permissions on mobile applications
Our apps only request the permissions they need, and each permission is requested at the point of use with an explanation. You may decline any permission, and you can withdraw it at any time in your device settings, although some features may then not work.
| Permission | Why an app may need it |
|---|---|
| Location (precise or approximate) | Nearby search, delivery or routing, geofenced features, asset or field-service tracking, fraud prevention. Background location is only ever used where the app’s core function requires it and is disclosed to you separately. |
| Camera | Taking photos, scanning QR or barcodes, document capture, video calls. |
| Microphone | Voice notes, voice input, calls, audio recording features. |
| Photos, media and files | Uploading and saving images and documents. |
| Contacts | Only where you choose to invite or select a contact. We do not upload your full contact list unless you explicitly consent. |
| Notifications | Sending you push notifications (see section 8). |
| Bluetooth and nearby devices | Connecting to IoT hardware, sensors, printers or payment terminals. |
| Calendar | Creating or reading events where the app offers scheduling. |
| Biometrics (fingerprint or face) | Unlocking the app. Biometric data never leaves your device and is never transmitted to us. We only receive a yes or no result from the operating system. |
3.4 Special personal information and children
We do not deliberately collect special personal information (as defined in section 26 of POPIA, including race, health, biometrics, religious or philosophical beliefs, trade union membership, political persuasion, sexual orientation, or criminal behaviour) unless:
- you have given your express written consent;
- it is necessary to establish, exercise or defend a right or obligation in law; or
- another exemption in section 27 of POPIA applies.
Where an app is health-related, we make its handling of health information clear in that app’s in-product notice.
Children. Our Services are not directed at children under 18 unless an app is expressly designed for educational or youth use. Where an app is intended for children, we process their personal information only with the prior consent of a competent person (a parent, guardian or person legally competent to consent on the child’s behalf, as required by section 35 of POPIA), and we limit collection to what the educational purpose requires. If we learn that we have collected a child’s information without the required consent, we will delete it promptly. A parent or guardian may contact hello@stratida.com to review, correct or delete a child’s information.
4. Why we process your personal information and on what legal basis
We process personal information only where POPIA permits it. The lawful bases we rely on are:
| Purpose | Lawful basis under POPIA |
|---|---|
| Creating and managing your account, authenticating you | Performance of a contract (s11(1)(b)) |
| Delivering the features and content of the app or platform | Performance of a contract (s11(1)(b)) |
| Processing payments, subscriptions and refunds | Performance of a contract; legal obligation |
| Providing customer and technical support | Performance of a contract; legitimate interests |
| Diagnosing crashes, fixing bugs, monitoring performance | Legitimate interests (s11(1)(f)) |
| Improving and developing our products, analytics and product research | Legitimate interests, using aggregated or de-identified data wherever possible |
| Security, fraud detection, abuse prevention and access control | Legitimate interests; legal obligation |
| Sending service and transactional messages | Performance of a contract |
| Direct marketing to existing customers about similar products | Legitimate interests, subject to section 69 of POPIA and an opt-out in every message |
| Direct marketing to anyone else, including electronic marketing | Your consent (s69) |
| Personalised content, advertising and cross-app tracking | Your consent |
| Complying with tax, accounting, regulatory and court obligations | Legal obligation (s11(1)(c)) |
| Recruitment | Steps prior to entering a contract; consent |
We will not use your personal information for a new purpose that is incompatible with the purpose it was collected for without first informing you and, where required, obtaining your consent.
Automated decision-making
Some of our Services use algorithms, machine learning or AI models for features such as recommendations, content ranking, risk scoring, fraud screening or automated categorisation. In line with section 71 of POPIA, we do not make decisions that have a legal effect on you, or that substantially affect you, based solely on automated processing without human involvement, unless it is necessary for a contract with you and appropriate safeguards are in place. You may ask us to explain such a decision and to have it reviewed by a person. Contact hello@stratida.com.
5. When we share personal information
We do not sell your personal information. We share it only as set out below.
- Our clients, where we build and run an application on their behalf and they are the Responsible Party.
- Operators (service providers) who process information on our documented instructions under written contracts requiring confidentiality and appropriate security. These typically include:
- cloud hosting and infrastructure providers;
- authentication, database and backend platforms;
- analytics and crash reporting providers;
- push notification services;
- email, SMS and WhatsApp messaging providers;
- payment gateways and financial institutions;
- customer support and ticketing tools;
- mapping and location services;
- identity verification providers, where legally required.
- Within Stratida group companies and affiliates, where necessary for the purposes above.
- Professional advisers such as auditors, lawyers, insurers and accountants, under duties of confidentiality.
- Law enforcement, regulators and courts, where we are legally compelled or where disclosure is necessary to protect our rights, your safety or the safety of others.
- Acquirers, in the event of a merger, acquisition, restructuring or sale of assets. You will be notified of any change in the Responsible Party.
We may also publish aggregated or de-identified statistics that cannot reasonably be linked back to you. This is not personal information under POPIA.
6. Transfers of personal information outside South Africa
Some of our infrastructure and service providers are located outside South Africa, including in the European Union, the United Kingdom, the United States, and in jurisdictions where we do business such as China and Hong Kong. Your personal information may therefore be transferred, stored and processed outside South Africa.
In line with section 72 of POPIA, we only transfer personal information across borders where at least one of the following applies:
- the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection substantially similar to POPIA, including onward-transfer restrictions;
- you have consented to the transfer;
- the transfer is necessary to perform a contract with you, or to implement pre-contractual measures taken in response to your request;
- the transfer is for your benefit and it is not reasonably practicable to obtain your consent, but you would likely have given it.
Where we rely on contractual protection, we use data processing agreements incorporating recognised safeguards such as Standard Contractual Clauses. You may request further detail from hello@stratida.com.
7. How long we keep your information
We keep personal information only for as long as it is needed for the purpose it was collected, unless a longer period is required or permitted by law.
| Category | Typical retention |
|---|---|
| Active account information | For as long as your account is active |
| Account information after closure | Up to 12 months, then deleted or de-identified |
| Financial and tax records | 5 years from the end of the relevant tax period (Tax Administration Act) |
| Company and transaction records | 7 years (Companies Act) |
| Support correspondence | 3 years |
| Crash logs and diagnostic data | Up to 12 months |
| Marketing consents and opt-out records | Until withdrawn, plus a record of the withdrawal |
| Unsuccessful job applications | 12 months, unless you ask us to keep them longer |
Where we act as an Operator for a client, retention is determined by that client’s instructions and their agreement with us.
After the retention period we securely delete, destroy or permanently de-identify the information.
8. Marketing and communications
Service messages. We will always send you messages necessary to operate your account, such as password resets, security alerts, transaction confirmations, service outages and material changes to terms. You cannot opt out of these while you hold an account.
Direct marketing. In line with section 69 of POPIA:
- If you are not an existing customer, we will only send you electronic direct marketing if you have consented. We may approach you once to request that consent.
- If you are an existing customer, we may market our own similar products and services to you, and every message will give you a simple, free way to opt out.
- Every marketing message identifies Stratida and gives a valid reply address.
Push notifications. Our apps may send push notifications. You can disable them at any time in your device settings or in the app’s own settings. Marketing push notifications are sent only with your consent and can be switched off separately from service notifications.
To unsubscribe from all marketing at any time, use the link in any message or email hello@stratida.com.
9. Cookies and similar technologies
Our website and web platforms use cookies and similar technologies such as local storage, pixels and SDKs, for the following purposes:
- Strictly necessary — session management, authentication, load balancing, security. These cannot be switched off.
- Functional — remembering your preferences, language and region.
- Analytics — understanding how the site and apps are used so we can improve them.
- Marketing and advertising — measuring campaign performance and, where you consent, showing you relevant advertising.
Non-essential cookies are set only where you consent through our cookie banner. You may change or withdraw your choice at any time via the cookie settings link on our website, and you can block or delete cookies in your browser settings.
Mobile apps use SDKs rather than cookies. Where an app uses advertising identifiers, we request your permission through the operating system (App Tracking Transparency on iOS, or the equivalent Android control), and you can reset or limit the identifier in your device settings.
10. How we protect your information
In line with sections 19 to 22 of POPIA, we maintain appropriate, reasonable technical and organisational measures to protect personal information against loss, damage, unlawful access and unauthorised destruction. These include:
- encryption in transit (TLS 1.2 or higher) and encryption at rest for stored data;
- passwords stored only as salted hashes, never in plain text;
- role-based access control and least-privilege access;
- multi-factor authentication for administrative and production systems;
- network segmentation, firewalls, and secure API authentication;
- regular patching, dependency scanning and vulnerability management;
- secure development practices, code review and testing before release;
- logging, monitoring and alerting on our production environments;
- encrypted, access-controlled backups with tested restore procedures;
- confidentiality undertakings and privacy training for our personnel;
- written Operator agreements with all third parties who process information for us.
No system is completely secure. You are responsible for keeping your account credentials confidential and for the security of the device you use. Please notify us immediately at hello@stratida.com if you believe your account has been compromised.
Security compromises
If we have reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and you as soon as reasonably possible after discovering and containing the compromise, as required by section 22 of POPIA. The notification will describe the possible consequences, the measures we intend to take, what you can do to mitigate the harm, and the identity of the unauthorised person if known.
11. Your rights
Under POPIA, and subject to certain limits and exemptions, you have the right to:
- Be notified that we are collecting your personal information, and be told if it has been accessed by an unauthorised person.
- Access the personal information we hold about you, and be told who has had access to it (section 23). You may need to complete the prescribed Form 2 and a fee may apply for copies.
- Correct or update information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained (section 24, using the prescribed Form 2).
- Request deletion or destruction of information we are no longer authorised to keep.
- Object to processing on reasonable grounds, where we rely on legitimate interests or public interest (section 11(3), using the prescribed Form 1).
- Object to direct marketing at any time, free of charge.
- Withdraw consent at any time, where processing is based on consent. Withdrawal does not affect processing that already lawfully took place.
- Not be subject to a decision based solely on automated processing that significantly affects you (section 71).
- Data portability, where technically feasible, to receive a copy of information you provided to us in a structured, commonly used, machine-readable format.
- Complain to the Information Regulator (section 74).
Exercising your rights. Email hello@stratida.com with your request. We will verify your identity before acting, which is to protect you. We aim to respond within 30 days. If your request is complex we will tell you and explain the delay. Requests are free, except that a prescribed fee may apply to copies of records.
In-app controls. Most of our apps let you edit your profile, download your data and delete your account directly in the app’s settings. Deleting your account removes or de-identifies your information, except where we must keep records by law.
Refusals. If we refuse a request, we will tell you why and explain how to challenge the decision.
12. Complaints
If you are not satisfied with how we have handled your personal information, please contact us first at hello@stratida.com so that we can try to resolve it.
You also have the right to lodge a complaint directly with the regulator:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
P.O. Box 31533, Braamfontein, Johannesburg, 2017
Email: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Website: inforegulator.org.za
Complaints must be made in writing on the prescribed Form 5, or through the Regulator’s eServices portal.
13. App store and platform disclosures
When you download our apps, the app store (Apple App Store, Google Play, Huawei AppGallery) collects its own information about the download and any purchase, governed by that store’s privacy policy, not ours. Our app store listings contain a data safety or privacy nutrition label summarising what each app collects. Where a listing and this Policy differ for a specific app, the app’s own in-product privacy notice takes precedence for that app.
14. Third-party links and services
Our Services may link to or integrate with third-party websites, platforms, payment providers and social media services. We are not responsible for their privacy practices. Please read their privacy policies before providing them with personal information.
15. Access to information (PAIA)
Stratida has a Promotion of Access to Information Act 2 of 2000 (PAIA) manual, available on request from hello@stratida.com or for download at www.stratida.com. It explains how to request access to records held by us.
16. Changes to this Policy
We may update this Policy from time to time to reflect changes in our Services, technology or the law. The “Last updated” date at the top will change. Where the changes are material, we will notify you by email, by an in-app notice, or by a prominent notice on our website before they take effect. Continued use of the Services after the effective date means you accept the updated Policy.
17. Contact us
For any question, request or concern about this Policy or your personal information:
Stratida (Pty) Ltd
Attention: The Information Officer
Email: hello@stratida.com
Website: www.stratida.com
South Africa