Privacy Notice
This notice is issued in terms of the Protection of Personal Information Act 4 of 2013 (POPIA) and explains how Yaba Net collects, uses, stores and protects your personal information. Please read this notice carefully before submitting any personal information to us.
Last reviewed: May 2026
1. Who We Are
Yaba Net, operated by YellowChicken, is the Responsible Party as defined in POPIA. We are responsible for the lawful and transparent processing of your personal information.
| Information Officer | Chris Lemmer |
| privacy@yabanet.co.za | |
| Postal Address | South Africa |
2. Personal Information We Collect
We collect only the personal information necessary to deliver the Yaba Net service. This includes:
Identity Information
Full name, email address, and contact number — collected when you register for access or submit a request to use the platform.
Employment Information
Organisation name, department, and job role — used to assign appropriate access permissions and to scope your data within your organisation.
Operational Data
Budget entries, expense submissions, and purchase approvals that you create or modify while using the platform. This data belongs to your organisation.
Technical Information
Log entries and session data generated automatically during your use of the platform, used for security monitoring and troubleshooting.
We do not collect sensitive personal information such as race, gender, health data, financial account numbers, biometric data, or criminal records.
3. Why We Collect Your Information (Lawful Basis)
Your personal information is collected and processed for the following specific purposes:
Account Creation & Authentication
To verify your identity, create your platform account, and authenticate your login.
Basis: Necessary for the performance of a contract (your access agreement).
Service Delivery
To provide the budgeting, expense tracking, and purchase approval features of the platform.
Basis: Necessary for the performance of a contract.
Notifications & Alerts
To send you workflow notifications such as approval requests, status updates, and account notices.
Basis: Legitimate interest and/or consent.
Security & Compliance
To protect the platform, detect fraud or unauthorised access, and comply with legal obligations.
Basis: Legal obligation and legitimate interest.
We will not use your personal information for any purpose other than those listed above without your prior consent, unless we are required to do so by law.
4. Who We Share Your Information With
We do not sell, rent, or trade your personal information. Your information may be shared only in the following limited circumstances:
Within Your Organisation
Your name, role, and activity within Yaba Net is visible to authorised administrators and managers within your own organisation, as required by the service.
Service Providers
We may use third-party providers for infrastructure (hosting, email delivery) who process personal information on our behalf under binding data processing agreements.
Legal Requirement
We may disclose your information if required by law, court order, or a request by a competent regulatory authority.
5. Retention of Personal Information
Active Accounts
Your personal information is retained for as long as you hold an active account on the platform and your organisation remains a subscriber.
After Account Closure
Following account closure, personal information is retained for a maximum of 5 years to comply with financial record-keeping legal requirements, and then securely deleted.
Audit Logs
System audit and access logs are retained for 3 years for security and compliance purposes, then permanently deleted.
6. Security of Your Information
We implement reasonable technical and organisational measures to protect your personal information against loss, theft, unauthorised access, and unlawful processing, including:
Encryption in Transit
All communication between your browser and our servers is encrypted using TLS (HTTPS).
Encrypted Storage
Passwords are hashed using industry-standard algorithms. Sensitive tokens are encrypted at rest.
Access Controls
Access to personal information is restricted to authorised personnel on a strict need-to-know basis.
Regular Backups
Data is backed up regularly to prevent loss. Backups are stored securely and access-controlled.
No system is completely secure. If you become aware of any security vulnerability, please contact us immediately at privacy@yabanet.co.za.
7. Your Rights as a Data Subject
POPIA grants you the following rights regarding your personal information. To exercise any of these rights, contact our Information Officer at privacy@yabanet.co.za.
Right of Access
You have the right to request a record or description of the personal information we hold about you, free of charge (subject to reasonable limitations).
Right to Correction
You may request that we correct inaccurate, incomplete, or outdated personal information held about you.
Right to Deletion
You may request that we destroy or delete your personal information where we are no longer legally required to retain it.
Right to Object
You may object to the processing of your personal information on reasonable grounds, including for direct marketing purposes.
Right to Complain
If you believe we have not handled your personal information in accordance with POPIA, you have the right to lodge a complaint with the Information Regulator of South Africa (IRSA).
Withdraw Consent
Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
8. Information Regulator of South Africa
The Information Regulator (South Africa) is the independent body established under POPIA to enforce compliance. If you believe your rights under POPIA have been violated, you may contact the Regulator:
| Website | inforegulator.org.za |
| Complaints Email | POPIAComplaints@inforegulator.org.za |
| General Enquiries | inforeg@justice.gov.za |
| Physical Address | JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 |
9. Changes to This Notice
We may update this Privacy Notice from time to time. The revised version will be published at yabanet.co.za/privacy-notice and the "Last reviewed" date at the top of this page will be updated. We encourage you to review this notice periodically. Material changes will be communicated to registered users by email.
Contact Our Information Officer
For any queries about this Privacy Notice, to exercise your POPIA rights, or to report a privacy concern, please contact:
Email: privacy@yabanet.co.za
Subject line: POPIA Enquiry – [your name]
We aim to respond to all POPIA-related requests within 30 days as required by law.



