Privacy Policy

Last updated: 27 June 2026

Voting App ("we", "us", or "our") operates the digital voting and meeting platform at votingapp.co.za. We are committed to protecting personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable South African laws.

This Privacy Policy explains what personal information we collect, how we use it, and your rights. By using the Service you consent to the processing described here.

1. Who we are and our role

We act as an operator (processor) under POPIA when we process personal information on behalf of a Body Corporate, Homeowners Association, or scheme management (the "Responsible Party" or controller). The trustees or management of each scheme remain responsible for ensuring their use of the Service complies with POPIA, the Sectional Titles Schemes Management Act, Prescribed Management Rules, and their own rules or MOI.

2. Personal information we collect

We collect and process the following categories of personal information:

  • Identity and contact details (full name, email address, phone number, unit number or erf number).
  • Ownership information (participation quota / PQ value, ownership percentage, primary owner status, chairman status).
  • Meeting-related data (attendance records, proxy appointments and instructions, voting choices, digital signatures or declarations).
  • Authentication data (OTP tokens, attendee session information).
  • Technical data (IP address, device information, login timestamps — limited and used only for security and audit).
  • Uploaded documents (Excel files containing owner/unit data, scheme governing documents such as conduct rules or MOI).

We do not collect special personal information (e.g. race, health, biometrics) unless it is voluntarily provided in a document you upload and is necessary for the Service.

3. How we collect personal information

  • Directly from you or scheme managers via registration, Excel imports, forms, proxy wizard, and meeting invitations.
  • Automatically through the platform (e.g. when you authenticate via OTP or cast a vote).
  • From scheme documents you upload for the AI document assistant (VoteBot).

4. Why we process personal information (purpose and legal basis)

We process personal information only for the following purposes:

  • To provide the core Service (creating and running meetings, weighted voting, quorum calculation, proxy management, live sessions, reports, and audit trails).
  • To authenticate attendees and prevent unauthorised access.
  • To enable scheme managers to comply with their legal obligations (e.g. maintaining records of resolutions and attendance).
  • To improve and secure the platform.
  • To operate and improve the AI document assistant (VoteBot): we log the questions asked and the answers given, together with technical metadata, in order to build helpful suggested questions, detect and prevent abuse, monitor performance, and — because VoteBot answers may be relied on in governance meetings — to audit answer quality and test improvements to the underlying model. The legal basis is our legitimate interest in providing a reliable, secure assistant, balanced against your rights. Where a question you type refers to a scheme’s owners, the managing agent processes that information under its existing mandate.
  • To respond to support requests or POPIA enquiries.

Legal bases under POPIA include consent (where you tick declarations), contractual necessity (to deliver the Service you requested), and legitimate interest (security, audit, and service improvement), balanced against your rights.

5. Sharing and disclosure

We do not sell or share personal information across different schemes. Information is isolated by scheme. We may share limited information with:

  • The trustees or authorised managers of your specific scheme (they are the Responsible Party).
  • Reputable third-party service providers who help us operate the platform — including secure cloud hosting and database, email delivery, and AI providers (used for VoteBot and Excel mapping). These providers are bound by confidentiality and data-processing agreements.
  • Law enforcement or regulators if legally required.

We never share data with other schemes or unrelated third parties.

6. Data security

We use industry-standard technical and organisational measures, including:

  • Row-level security and strict tenant isolation in the database so one scheme cannot access another scheme's data.
  • Encrypted connections (TLS).
  • Access controls and audit logging.
  • Secure OTP-based authentication for meeting attendees.
  • Immutable vote ledger (votes cannot be altered after casting, subject to the narrow POPIA erasure process below).

Despite these measures, no system is 100% secure. You should also take reasonable steps to protect your own access credentials.

7. Data retention and deletion

We retain personal information only for as long as it is needed for the purposes set out above, or for as long as the law requires. Different categories of information are kept for different periods:

  • Meeting and voting records (resolutions, attendance, proxy appointments, and voting outcomes) are retained for as long as the scheme's record-keeping obligations require under the STSMA and Prescribed Management Rules, and thereafter for any period reasonably needed to resolve disputes or to meet legal, audit, or tax obligations.
  • Vote records are stored in an append-only ledger and cannot be altered or ordinarily deleted, so that the integrity and auditability of a meeting's outcome is preserved. Each vote is keyed to an attendee session rather than to your raw identity details.
  • Authentication and technical data (OTP tokens, session and login information, IP addresses) are kept only for the short period needed for security and audit, and are then routinely purged.
  • Uploaded documents (owner/unit spreadsheets and scheme governing documents) are retained for as long as your scheme uses the Service, and are deleted on request or when the scheme is closed, subject to the limits below.
  • VoteBot conversation logs. The text of questions asked of VoteBot and the answers given are retained for up to 180 days, after which the free text is automatically and permanently removed, leaving only anonymous technical metrics (such as response time and whether an answer was found). They are also cleared earlier when you exercise an erasure request.

Correction and erasure requests. Under POPIA you may ask us to correct or delete your personal information. Because the vote ledger must remain immutable for legal and audit reasons, we satisfy a valid erasure request by de-identifying the personal details linked to your records — removing or anonymising identifying information such as your name, email address, and contact details — while leaving the anonymised voting record itself intact for the integrity of past meetings. This is a narrow, documented process:

  • it is carried out only by authorised administrators, through a single sanctioned erasure process;
  • every erasure is recorded in a tamper-evident audit log capturing who performed it, when, and what was de-identified;
  • the immutable vote ledger itself is never edited or deleted — only the personal information joined to it is removed.

You may also request deletion of your account or your scheme's data at any time. We will action this subject to the retention rules above and to any overriding legal obligation to keep certain records. To make a correction or erasure request, contact our Information Officer using the details in section 12.

8. Your rights under POPIA

You have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion or destruction of your personal information (subject to legal or contractual restrictions).
  • Object to processing in certain circumstances.
  • Lodge a complaint with the Information Regulator (South Africa).

To exercise these rights, email the address below with proof of identity. We will respond within the timeframes required by POPIA.

9. Cookies and similar technologies

We use essential cookies and local storage necessary for the Service to function (session management, security). We also use analytics and advertising cookies and similar technologies to understand how the Service is used and to measure our marketing:

Google Analytics 4 and Google Tag Manager (usage analytics), and Google Ads (conversion measurement and attribution, including a stored Google click identifier and campaign parameters). These set cookies and may share information with Google as a third-party processor. We do not sell your personal information. You can control or block cookies via your browser settings, opt out of Google Analytics with Google’s opt-out add-on, and manage Google ad personalisation in your Google account. See Google’s Privacy Policy for how Google processes this data.

10. International transfers

Some service providers may process data outside South Africa. Where this occurs we ensure appropriate safeguards are in place in accordance with POPIA.

11. Changes to this policy

We may update this Privacy Policy from time to time. The current version will always be available on this page with the last-updated date shown above. Material changes will be notified via the platform or email where appropriate.

12. Contact us

For any privacy or POPIA enquiries, including requests to exercise your rights, contact:

Information Officer
Voting App
Email: support@votingapp.co.za

The Voting App · votingapp.co.za