Legal
Privacy Policy
How we collect, use and protect personal information, and the rights you have under the Protection of Personal Information Act (POPIA).
Last updated 21 September 2026
Are you an employee or a job applicant?
If you are using Xinnace because your employer (or a company you applied to) uses it to run their HR, payroll or recruitment, then that company, not Xinnace, decides how your information is used. In POPIA terms they are the Responsible Party and Xinnace is their Operator: we only store and process that information on their instructions, and we never use it for our own purposes.
So if you want to see, correct or delete your employee or application information, please contact that company directly, as they are the ones who can action it. If you are not sure who to ask, write to us at privacy@xinnace.com and we will point you to the right place.
1. Who we are
Xinnace (Pty) Ltd (“Xinnace”, “we”, “us”) provides a people platform for South African organisations, covering HR, attendance, recruitment and payroll-ready data. Registration number 2025/316516/07. Registered address: 22 Umhlanga Boulevard, Umhlanga, KwaZulu-Natal, 4321, South Africa.
This policy explains what we do with personal information where Xinnace itself is the Responsible Party: chiefly enquiries made through this website and the accounts of our customers. It does not describe what our customers do with their own people’s data (see the note above).
2. What we collect, and why
When you contact us through this website
Our contact form asks for your name, work email address, company name, company size, three preferred times for us to call you back and, optionally, your phone number and a message. We also automatically record your IP address and browser user-agent with the submission.
We use this to respond to your enquiry, to prepare for a conversation about your organisation’s needs, and to keep an internal record of the enquiry. Submitting the form triggers an automated acknowledgement email to you, and a notification to our team. Providing this information is voluntary, but without at least a name and email address we cannot reply to you. We keep enquiries for up to 12 months.
When you become a customer
We hold the account details of the people who administer your workspace: name, work email address and a securely hashed password. When a customer accepts our terms, we record the time and the IP address the acceptance came from. We use this information to provide the service, secure the account, support you, and bill you.
When you sign in to the platform
For everyone who signs in to the Xinnace platform, administrators and employees alike, we keep:
- sign-in records: when you signed in, your IP address, your browser’s user-agent, and a device type (mobile, tablet or desktop) worked out from that user-agent;
- usage records: which pages of the platform you open, with your IP address and user-agent, used for security, support and reporting on how the platform is used;
- an audit log of changes made in the system, including who made them, with the IP address and user-agent they were made from;
- failed sign-in attempts, including the email address that was typed, and requests our security controls blocked;
- rate-limiting records on public forms, which store only a one-way hash of the IP address, never the address itself.
We do not work out your location from your IP address, and we do not fingerprint your device. How long each of these is kept is set out under how long we keep it.
Data we process on our customers’ behalf
Our customers use Xinnace to process personal information about their own employees, job applicants and referred candidates, typically including:
- full name and surname, employee code or staff number;
- contact details and residential address;
- date of birth, nationality and citizenship;
- profile photographs;
- gender and race, collected for employment equity and transformation reporting;
- South African ID number (or equivalent identification number);
- disability status;
- education and qualification records;
- CVs and application documents, including previous employers and roles;
- the contact details of candidates referred by employees;
- performance management records, ratings and coaching notes;
- disciplinary records, such as warnings and CCMA matters, and grievance records;
- absence records, and health-related information where the employer’s own process records it — for example a return-to-work file noting that a medical certificate was produced, who signed it and the days it books off, and, where the employer chooses to keep copies, the certificate itself;
- attendance and shift records: clock-in and clock-out times, break and status changes, and the roster the employee is scheduled against;
- where the employer switches on the Xinnace Time Tracker browser extension, the activity signals described under the browser extension below;
- payment and remuneration information, including banking details where processed for payroll.
When an employee acknowledges a warning or signs a performance review on the platform, the IP address and browser user-agent the signature came from are stored with it, as evidence of the signature, and are kept with that record.
We process that data only as an Operator, on their instructions and under a written agreement, and we do not use it for our own purposes.
The Xinnace Time Tracker browser extension
Some of our customers ask their employees to install the Xinnace Time Tracker, a browser extension that lets a person clock in, change status, take a break and clock out without going back to the Xinnace tab. Because it runs in the browser rather than on a page of ours, it is worth setting out separately what it does and does not do.
While an employee is signed in to it, the extension sends the following to their employer’s Xinnace workspace:
- Clock-in, clock-out, break and status events — the actions the employee takes in the widget itself.
- A presence signal roughly every 30 seconds, so the employer’s floor view can show who is currently working. The IP address the signal arrives from is kept as the employee’s last-seen address.
- Screen lock and idle transitions, reported by the browser, used to measure adherence. The extension is told only that the screen locked or went idle; it cannot see what is on it.
- Counts of clicks and keystrokes, batched about once a minute. These are numbers only: how many, never which. The extension does not record which keys were pressed, and does not capture what an employee types, their passwords, their messages or the contents of any page.
- Page addresses and titles, depending on the employer’s setting. See the next paragraph.
The IP address is stored with each clock and activity event, and kept for as long as the employer’s account is active (see section 6).
Whether page addresses are collected at all is a setting the employer chooses, and it has three positions. The default is workspace only: addresses are kept only for pages on that employer’s own Xinnace workspace, and anything else is discarded. On off, no address or page title is ever stored, though activity counts and status are still recorded. On all sites, addresses and page titles are kept for other websites too. The employer can also set a different position for an individual employee. The choice is enforced on our servers, not in the extension, so it cannot be overridden by altering the software on an employee’s machine.
What the published extension actually sends today. The release currently on the browser stores attaches a page address and title only on the employer’s own Xinnace workspace pages, whatever the workspace has been set to. All sites is a server-side position that a later release of the extension would send for; while the present release is the one installed, choosing it collects nothing beyond the workspace addresses. If that changes, this policy will say so before the release goes out, and an employer choosing all sites should tell its employees what it means before it takes effect.
Tracker integrity checks. The activity signals above (idle and lock transitions, click counts and keystroke counts) are combined into an automated “tracker integrity” check. It flags patterns that are unlikely from a person at a keyboard, such as no idle time at all, or keystrokes without any clicks, in order to detect tools that fake activity. Employers see these flags. They are indicators for a person to review, not decisions: the check makes no decision about an employee, and a flag is not a finding against anyone until a person has looked at it, in keeping with section 71 of POPIA on decisions based solely on automated processing. An employee who thinks a flag is wrong, or who wants to know how it was reached, can raise it with their employer.
The extension does not read, alter or transmit the content of the web pages an employee visits. It has no access to passwords, form contents, banking sessions, private messages or anything else on the page. It does not sell or share any of this data with third parties, and it is never used for advertising, profiling for advertising purposes, or for any purpose other than the attendance and adherence reporting the employer uses Xinnace for.
All of the above is processed by us as an Operator on the employer’s instructions. The employer decides whether to require the extension at all, which of these settings apply, and how long the records are kept. An employee who wants to know what is being collected about them, or who objects to it, should raise it with their employer, who is the Responsible Party; we will help them find the right contact if they are not sure. The extension can be removed from the browser by the employee at any time, though we would expect that to be a conversation with their employer first, since attendance may be recorded through it.
Technical information
Our servers and load balancers keep standard access logs (IP address, request time, page requested and browser details) for security and troubleshooting, and keep them for 90 days. This website sets a single, strictly necessary session cookie, on the contact page only, used to protect the form against cross-site request forgery. We do not currently run third-party advertising or analytics trackers on this site.
This website does load its two typefaces from Google Fonts. That is a request your browser makes to Google when the page opens, so Google receives your IP address and basic browser details in order to serve the font files. Google states that it does not use these requests to build advertising profiles, and no cookie is set by them for this. It is the only third-party request this site makes, and we set no cookie and run no script on the strength of it.
Third-party services used by the platform
The Xinnace platform itself (as distinct from this website) loads a small number of outside services in your browser, each of which receives your IP address and basic browser details when it does:
- Google Fonts, for the platform’s typefaces;
- jsDelivr and cdnjs, content delivery networks that serve open-source interface code and icons;
- YouTube, in its privacy-enhanced mode (youtube-nocookie.com), and only on the tutorials page;
- Giphy, for the GIF picker. The search terms you type into it are sent to Giphy’s API from our server, and the GIFs themselves load in your browser from Giphy;
- Google Sign-In, only if you choose to sign in with a Google account.
3. Special personal information
Race, disability status, health information and, in some contexts, ID numbers are treated as special personal information under POPIA, which may only be processed where a specific justification applies. Grievance records can also contain special personal information that an employee chooses to include, such as details of their health, sexual orientation or religion. For data we process on a customer’s behalf, that justification is generally:
- compliance with the Employment Equity Act and the reporting obligations it places on employers;
- reasonable accommodation and workplace support relating to disability;
- the data subject’s consent, obtained by the employer; or
- establishing, exercising or defending a right in law.
We process this information strictly as instructed by the relevant customer, and never for a purpose of our own.
Health information and medical certificates
Sick absence is health information, and a medical certificate is the most sensitive form it takes. The platform is built so that an employer need never store one. A return-to-work file can record that a certificate was produced and checked — who signed it, their registration number, and the days it books off — without a copy of the certificate being uploaded at all. Certificate uploads on return-to-work files and on leave applications each have their own workspace setting that switches them off, after which the platform refuses them.
Where a customer does keep copies, they are held in private storage that the web server refuses to serve directly, are never served inline, and are released only through a permission-checked download, to a signed-in user who holds the specific permission and whose access to that employee has been checked on the request. Whether to hold certificates at all, and for how long, is the customer’s decision as responsible party; our role is to make “not at all” a workable one.
4. On what basis we process it
We process personal information to provide and maintain the platform, help customers meet their statutory HR, payroll, employment equity and skills development reporting obligations, administer accounts and access, communicate about the service, keep it secure and auditable, respond to enquiries, and meet our own legal obligations.
Depending on the situation, we rely on your consent (for example, when you submit our contact form, having been told on the form what the information is for), on the performance of a contract with you or your employer, on compliance with a legal obligation, or on our legitimate interests in operating, securing and improving our business, balanced against your rights. Throughout, we follow POPIA’s eight conditions for lawful processing: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation.
5. Who we share it with
We do not sell your personal information. We share it only with:
- your employer, who determines how your information on the platform is used;
- hosting: Amazon Web Services, which runs this website, our administration system and the Xinnace platform in its Cape Town region (af-south-1): the application servers, the databases (one for each customer), the session cache and file storage, all encrypted at rest;
- backups: Amazon Web Services, which stores off-site copies of our databases and uploaded files in its Cape Town region, encrypted at rest;
- email: Google Workspace, which carries both our own mailboxes and the platform’s system email;
- website fonts: Google Fonts, which receives the IP address and browser details of anyone loading a page on this website, in order to deliver the typefaces;
- platform service providers: Google Fonts, jsDelivr, cdnjs, YouTube (privacy-enhanced mode, tutorials page only), Giphy and, if you choose it, Google Sign-In, as described under Third-party services used by the platform above;
- professional advisors: our lawyers, auditors and accountants, where necessary, each bound to confidentiality;
- regulators or law enforcement, where the law requires it.
Each service provider is bound to protect your information and use it only for the purpose we have engaged them for. We may also disclose information to establish, exercise or defend a legal claim.
Information leaving South Africa
Some of these providers, notably Google and the content delivery, font and Giphy services the platform uses, may store or process information outside South Africa. Where that happens, we take reasonable steps to ensure the recipient is subject to laws, binding rules or contractual terms that provide an adequate level of protection, as POPIA requires.
6. How long we keep it
We keep information only for as long as it is needed for the purpose it was collected for, or for as long as the law requires us to. When it is no longer needed, we delete it or de-identify it.
While an organisation’s account is active
The records the platform keeps about how it is used — sign-in records, usage records, the audit log of changes, failed sign-in attempts and blocked requests, Time Tracker events, the log of system emails and application error logs — are kept for as long as the organisation’s account is active. They are what lets the organisation, and us, investigate a security incident, answer a dispute about who changed what, and show that its records are accurate, and those needs last as long as the account does. We do not delete them on a timer while the account is in use. The information an organisation holds about its own people follows that organisation’s instructions and its own retention policy, as described in section 2.
When an organisation’s account closes
When an account closes, the organisation can ask us for an export of its data. We then delete its workspace — the database holding its people’s information and all of the records listed above — and its uploaded documents within 90 days, sooner if it asks. Keeping the employment and tax records the law requires an employer to hold after that point, such as the three years the Basic Conditions of Employment Act sets and the five years the Tax Administration Act sets, is the organisation’s own responsibility, and the export is how it meets it.
After closure we keep only the minimum the law requires of us:
- Invoices and billing records: 5 years, as the Tax Administration Act requires.
- Evidence of the agreement (acceptance of our terms, including the IP address and time, the emailed receipt of it, and confirmation of the cancellation): 3 years after closure, the period within which most contractual claims can be brought under the Prescription Act.
- Backups: copies may persist in encrypted backups until those backups expire on their retention schedule, normally within 90 days of the deletion.
Not tied to an account
- Website enquiries: up to 12 months, unless the enquiry becomes an account.
- Server and load-balancer access logs: 90 days.
- Rate-limiting records on public forms (a one-way hash of the IP address): 24 hours.
Data we hold as an Operator is retained according to our customer’s instructions and their own retention policy.
7. How we protect it
We use encrypted connections (HTTPS/TLS), encryption at rest, hashed passwords, role-based access controls, audit logging, and access restrictions so that staff only reach information they need. No system is perfectly secure, but if a breach affects your personal information we will notify you and the Information Regulator as POPIA requires. Our Security page sets out the controls in more detail.
8. Your rights
Under POPIA you have the right to:
- be notified that your personal information is being collected;
- ask what personal information we hold about you, and request a copy;
- ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained;
- object to our processing of your information on reasonable grounds;
- withdraw consent you have given us (this does not affect processing already carried out);
- complain to the Information Regulator.
To exercise any of these, write to our Information Officer at privacy@xinnace.com. We may need to verify your identity before we act, and we will respond within a reasonable time. To support an access request, we can produce an export of the information the platform holds about a person. If you are an employee or job applicant, please make that request through your employer, as explained at the top of this page.
9. Complaining to the Regulator
If you are unhappy with how we have handled your information, you can lodge a complaint with:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
POPIA complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries.IR@justice.gov.za
inforegulator.org.za
10. Access to information (PAIA)
You also have rights of access to records under the Promotion of Access to Information Act. Requests can be sent to our Information Officer at the address below, and our PAIA Manual explains the procedure.
11. Changes to this policy
We may update this policy from time to time. The date at the top of this page shows when it was last changed, and material changes will be communicated to customers directly.
12. Contact us
Information Officer: Poobalan Soobramoney, Chief Executive Officer
Xinnace (Pty) Ltd
privacy@xinnace.com
22 Umhlanga Boulevard
Umhlanga, KwaZulu-Natal, 4321
South Africa
Questions about this document? Email privacy@xinnace.com.
Contact us