Privacy Policy

Version 1.0 · Effective 20 May 2026

In short. We collect only what we need to verify you as a driver, store it securely in South African accessible servers, never sell it, and let you see, correct or delete it from your dashboard at any time. This policy is issued under the Protection of Personal Information Act, 4 of 2013 (POPIA).

1.Who is responsible for your data

My Symbiosis Pty Ltd is the Responsible Party (data controller) for the personal information described below.

Information Officer: popia@mysymbiosis.co.za. You can write to this address for any access, correction, or deletion request, or to lodge a complaint.

2.What personal information we collect

Through the My Symbiosis driver portal we collect:

Identity document
Front-side photograph of your South African National Identity Card and the fields our AI extracts from it: surname, first names, ID number, date of birth, sex, nationality, citizen status, country of birth.
Driving credentials
Front-side photograph of your driving licence (and PrDP card if applicable), and the fields extracted: licence number, code, issue and expiry dates, first-issue date, country of issue, restrictions, card number, PrDP codes and PrDP expiry.
Contact information
Phone number, email address, residential address, province.
Work-experience information
Most recent employer, role, period, years of driving experience, optional reason for leaving.
Account credentials
The email address you sign up with and a one-way bcrypt hash of your password (we never store your plain-text password).
Technical and analytics data
IP address, browser user-agent, marketing UTM parameters used when you reached the site, timestamps of key actions (application submitted, status changed).

Your South African ID number is classified as a unique identifier under POPIA. We process it only for the lawful purposes set out below.

3.Why we process your data (lawful purposes)

We process your personal information only for:

  • Onboarding and verification — to confirm you are who you say you are and that your driving credentials are valid. Lawful ground: performance of the contract you enter into with us when applying (section 11(1)(b) POPIA).
  • Matching with Client Companies — to share your verified profile with prospective employers / fleet operators. Lawful ground: your consent (section 11(1)(a) POPIA), withdrawable at any time.
  • Compliance with law — to comply with the National Road Traffic Act, tax law, anti-money-laundering, and other obligations applicable to fleet operators. Lawful ground: legal obligation (section 11(1)(c) POPIA).
  • Service improvement — anonymised analytics on how drivers use the platform. Lawful ground: our legitimate interest (section 11(1)(f) POPIA).

4.AI-based document extraction

To save you typing, we send your uploaded ID and licence images to a generative AI service (currently Google Gemini 2.5 Flash, processed via Google's AI Studio API) which returns the structured fields for our app to display.

  • Images are sent only at the moment of upload, are not used by the AI provider to train their models, and are not retained by them beyond the API call.
  • You always see and confirm the extracted fields before submission.
  • Our underlying decision to approve or reject you is taken by a human operator, never solely by automated processing.

5.Who we share your data with

We share personal information only with:

  • Client Companies you are matched with, and only with your explicit consent for each match.
  • Our infrastructure provider, Supabase (operated by Supabase Inc., with data hosted in compliant regions). They process data on our instructions only and are bound by a written Data Processing Agreement.
  • Verification partners (e.g. the Department of Home Affairs, eNaTIS, accredited criminal-record verifiers) only as strictly required for the verifications listed above.
  • Law-enforcement and regulators, where compelled by law (e.g. a court order, a SAPS subpoena under section 205 of the Criminal Procedure Act).

We do not sell your data, share it with advertising networks, or use it for cross-context behavioural targeting.

6.Cross-border transfers

Where infrastructure providers store data outside of South Africa, we rely on the conditions in section 72 of POPIA — namely that the recipient is subject to a law, binding corporate rules or contract that provides an adequate level of protection. Supabase's standard contractual terms include EU SCCs and equivalent protections.

7.How long we keep your data

Active driver profile
While your account exists.
Rejected or withdrawn application
12 months from the date of decision, then anonymised.
Approved profile after deactivation
3 years from deactivation, for audit and dispute resolution.
Audit log entries (status changes by admins)
5 years, as required for compliance and dispute resolution.
Marketing analytics
Anonymised after 90 days.

8.How we keep your data secure

  • Documents are stored in a private Supabase Storage bucket, isolated per user, and accessible only via short-lived (≤5 minute) signed URLs.
  • All database tables enforce Row-Level Security: a driver can only read or modify their own row; admins are gated by a role-based policy.
  • Passwords are stored as bcrypt hashes; we never see or store the plain-text password.
  • Connections to and from the platform use TLS 1.2 or higher.
  • Internal admin access is restricted to named individuals subject to confidentiality agreements.

9.Your rights under POPIA

You have the right to:

  • Access a copy of the personal information we hold on you — the driver dashboard shows it all, or email us for a machine-readable export.
  • Correct or update any of your information at any time from your dashboard.
  • Object to processing for direct marketing or any other purpose based on legitimate interest.
  • Withdraw your consent at any time, with effect for the future.
  • Request deletion of your data, subject to the retention periods set out in section 7.
  • Lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za or POPIAComplaints@inforegulator.org.za.

10.Children

The platform is intended for adults aged 21 and over (the minimum age for a Professional Driving Permit). We do not knowingly collect information from minors. If you believe a minor has registered, contact us and we will delete the account.

11.Cookies and similar technologies

We use cookies for two purposes only:

  • Strictly necessary — the Supabase authentication session cookies. Without these, you cannot stay logged in.
  • Attribution — short-lived UTM-source cookies used to understand which campaign brought you to the site (cookie life: 30 days). These contain no personal identifiers.

12.Changes to this policy

We may update this policy when our practices or applicable law change. The version number and effective date above will always reflect the current version. Material changes will be notified by email.

13.Contact us

Information Officer: popia@mysymbiosis.co.za
General queries: hello@mysymbiosis.co.za

See also our POPIA notice and Driver Agreement.

This document is a working draft template. My Symbiosis reserves the right to revise it on advice of legal counsel before final commercial launch.