Privacy Policy
How Supa Cloud Base processes and protects Personal Data across our website, cloud software, subdomains, portals, and mobile applications.
Data Protection
A global privacy policy built around lead integrity, transparent data roles, and responsible cross-border processing.
Global Privacy Policy
Scope, Dual Roles, and Lead Integrity Guarantee
Supa Cloud Base (Pty) Ltd
Version 3.1 | Effective Date: September 2026
1.1. Scope. This Global Privacy Policy governs the processing of Personal Data by Supa Cloud Base (Pty) Ltd ("Supa Cloud Base", "we", "us", "our") across www.supacloudbase.com, our cloud software, subdomains, portals, and mobile applications (collectively, the "Platform").
1.2. Dual Legal Roles:
- Supa Cloud Base as Data Controller / Responsible Party: We act as a Controller for Personal Data collected directly from website visitors, prospects requesting product demonstrations, account administrators, and representatives of our business Customers.
- Supa Cloud Base as Data Processor / Operator: When our Customers (property developers, agencies, and brokerages) use the Platform to manage their buyer networks, leads, or client records ("Customer Data"), the Customer is the Data Controller. We process that information strictly on the Customer’s documented instructions under our Data Processing Addendum (DPA).
1.3. Lead Integrity & Non-Monetization Guarantee. We recognize that property lead data and commercial developer relationships are highly confidential. We do not sell, rent, scrape, cross-profile, or monetize demo inquiry details or Customer lead databases. Information submitted to request a product demonstration or manage property sales will never be shared with competing property developers or unauthorized third parties.
Information We Collect
We strictly separate data collected for inquiries from contracted business data to ensure complete operational transparency.
2.1 Demo Inquiries & Website Leads
When you request a product demonstration or submit a contact form, we collect only the business contact details necessary to fulfill your request:
- Full name and business email address;
- Company name, job title, and country of operation;
- Phone number or WhatsApp contact details (used solely for scheduling and sending the requested demo connection link); and
- Specific business requirements or messages you voluntarily submit.
2.2 Account Administration & Contracted Billing Data (Paying Customers Only)
For contracted business Customers using our Platform, we process operational details separately from initial inquiries:
- Corporate registration details and billing addresses;
- Designated user credentials and access permissions; and
- Payment status, invoicing records, and transaction histories (all card and bank processing is securely handled directly by PCI-DSS compliant payment infrastructure; Supa Cloud Base never stores full payment card numbers).
2.3 Technical Usage & Analytics Data
When you navigate our Platform, we automatically collect basic technical data using standard, secure web analytics and enterprise customer relationship management (CRM) infrastructure to optimize system performance:
- IP address, browser type, and operating system;
- Referral URLs, pages visited, and feature interactions; and
- Approximate geographic location derived at the city/country level.
Lawful Bases for Processing
We process Personal Data strictly in accordance with applicable global data protection laws (including the EU GDPR, UK GDPR, POPIA, and CCPA/CPRA):
| Processing Purpose | Data Categories | Lawful Basis |
|---|---|---|
| Fulfilling Demo Requests & Inquiries | Demo Inquiry Data | Pre-contractual steps taken at your request |
| Delivering SaaS Services & Support | Account & Technical Data | Performance of a Contract |
| Invoicing & Commercial Accounting | Billing & Transaction Data | Contractual Necessity / Legal Obligation |
| Platform Security & Abuse Prevention | Technical Usage & IP Data | Legitimate Interest (System Security) |
| Optional Marketing Communications | Business Contact Details | Explicit Opt-In Consent Only |
Demo Request & Marketing Communication Boundaries
4.1. Demo Request Isolation. Submitting a request for a product demonstration does not automatically register you for general marketing sequences or third-party email lists. We use your inquiry details exclusively to schedule, conduct, and follow up on your requested demonstration.
4.2. Opt-In Direct Marketing. We will send promotional updates or newsletters regarding new Platform features only where you have explicitly opted in. You may revoke consent at any time by clicking the "Unsubscribe" link in any communication or emailing support@supacloudbase.com. Opting out of promotional messages does not affect transactional or service-related communications regarding your active account.
Sub-Processors and Service Providers
We engage a limited number of vetted enterprise service providers to maintain system security, host cloud infrastructure, and deliver transactional communications. All service providers are bound by strict contractual obligations ensuring data confidentiality, security, and prohibition against using your data for any independent purpose.
Categories of service providers include:
- Tier-three cloud hosting and database infrastructure providers;
- Encrypted transactional email and system notifications gateways;
- Secure customer support ticketing platforms; and
- PCI-DSS certified payment processing gateways.
International Cross-Border Data Transfers
6.1. Global Infrastructure. To maintain high platform availability for cross-border property sales, Personal Data may be hosted or processed across secure cloud nodes located in the European Union, the United Kingdom, the United States, and South Africa.
6.2. International Transfer Safeguards. Transfers of Personal Data outside the jurisdiction of origin are executed in full compliance with applicable cross-border transfer requirements:
- EU and UK Data Subjects: Cross-border transfers to non-adequate jurisdictions are protected under the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum.
- South African Data Subjects: International transfers adhere strictly to Section 72 of POPIA, ensuring third-party recipients maintain privacy protections equivalent to South African statutory standards.
Data Security and Protection
We maintain technical, administrative, and physical security measures designed to prevent unauthorized access, loss, or disclosure of Personal Data, including:
- AES-256 bit encryption for data at rest and TLS 1.3 encryption for data in transit;
- Multi-factor authentication (MFA) and strict role-based access controls; and
- Continuous vulnerability monitoring and automated incident response protocols.
In the event of a confirmed security incident impacting Personal Data, we will notify affected parties and regulatory authorities within statutory timelines (and no later than 48 hours post-confirmation for enterprise accounts).
Data Retention and Deletion
We retain Personal Data only for as long as necessary to fulfill the specific purpose for which it was collected:
- Demo Inquiries: Retained for up to 12 months following your request to facilitate ongoing commercial discussions, or until you request erasure.
- Active Account Data: Retained for the duration of the commercial agreement plus 3 years following account closure.
- Financial & Invoicing Records: Retained for 5 to 7 years in compliance with applicable statutory tax and legal requirements.
- Customer Lead Databases (Processor Role): Deleted or permanently anonymized within 60 calendar days of contract termination.
Your Global Privacy Rights
Depending on your jurisdiction, you enjoy the following statutory rights regarding your Personal Data:
- Right to Access & Portability: Request a copy of your Personal Data in a structured, machine-readable format.
- Right to Rectification: Request correction of inaccurate or incomplete information.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your Personal Data where processing is no longer required by law.
- Right to Restrict or Object: Object to processing based on legitimate interests or opt out of direct marketing.
- Right to Withdraw Consent: Revoke consent at any time without affecting the lawfulness of prior processing.
To exercise your rights, submit a written request to support@supacloudbase.com. We respond to all verified requests within 30 days. (Note: If your data was uploaded to our system by a property developer using our software, please direct your request directly to that developer, as they act as the Data Controller).
Multi-Jurisdictional Governing Law and Contacts
10.1. Global Compliance Baseline. This Policy provides a unified global privacy standard. It is governed by applicable regional privacy frameworks, including the EU GDPR, UK GDPR, South African POPIA, and CCPA/CPRA, ensuring that no mandatory local consumer protections are restricted.
10.2. Contacting Us & Regulatory Complaints. For questions, privacy requests, or regulatory queries, please contact our Data Protection Officer:
| Role / Authority | Contact Details |
|---|---|
| Data Protection Officer / Information Officer | support@supacloudbase.com |
| General Support & Inquiries | support@supacloudbase.com |
| Information Regulator (South Africa) | inforeg@justice.gov.za |
| UK Information Commissioner’s Office (ICO) | ico.org.uk |
| EU Data Protection Authorities | Contact details via European Data Protection Board (EDPB) |
Supa Cloud Base (Pty) Ltd
Registration No: 2026/352825/07
Cape Town, Western Cape, South Africa
Questions about your data?
Speak to Supa Cloud Base
For privacy questions, rights requests, regulatory queries, or general support, contact our team.
Contact Support