Document

Privacy Notice

This notice is issued in terms of the Protection of Personal Information Act 4 of 2013 (POPIA) and explains how Yaba Net collects, uses, stores and protects your personal information. Please read this notice carefully before submitting any personal information to us.

Last reviewed: May 2026

1. Who We Are

Yaba Net, operated by YellowChicken, is the Responsible Party as defined in POPIA. We are responsible for the lawful and transparent processing of your personal information.

Information Officer Chris Lemmer
Email privacy@yabanet.co.za
Postal Address South Africa

2. Personal Information We Collect

We collect only the personal information necessary to deliver the Yaba Net service. This includes:

👤

Identity Information

Full name, email address, and contact number — collected when you register for access or submit a request to use the platform.

🏢

Employment Information

Organisation name, department, and job role — used to assign appropriate access permissions and to scope your data within your organisation.

📊

Operational Data

Budget entries, expense submissions, and purchase approvals that you create or modify while using the platform. This data belongs to your organisation.

🖥️

Technical Information

Log entries and session data generated automatically during your use of the platform, used for security monitoring and troubleshooting.

We do not collect sensitive personal information such as race, gender, health data, financial account numbers, biometric data, or criminal records.

3. Why We Collect Your Information (Lawful Basis)

Your personal information is collected and processed for the following specific purposes:

🔑

Account Creation & Authentication

To verify your identity, create your platform account, and authenticate your login.
Basis: Necessary for the performance of a contract (your access agreement).

⚙️

Service Delivery

To provide the budgeting, expense tracking, and purchase approval features of the platform.
Basis: Necessary for the performance of a contract.

📧

Notifications & Alerts

To send you workflow notifications such as approval requests, status updates, and account notices.
Basis: Legitimate interest and/or consent.

🛡️

Security & Compliance

To protect the platform, detect fraud or unauthorised access, and comply with legal obligations.
Basis: Legal obligation and legitimate interest.

We will not use your personal information for any purpose other than those listed above without your prior consent, unless we are required to do so by law.

4. Who We Share Your Information With

We do not sell, rent, or trade your personal information. Your information may be shared only in the following limited circumstances:

🏛️

Within Your Organisation

Your name, role, and activity within Yaba Net is visible to authorised administrators and managers within your own organisation, as required by the service.

🔧

Service Providers

We may use third-party providers for infrastructure (hosting, email delivery) who process personal information on our behalf under binding data processing agreements.

⚖️

Legal Requirement

We may disclose your information if required by law, court order, or a request by a competent regulatory authority.

5. Retention of Personal Information

📅

Active Accounts

Your personal information is retained for as long as you hold an active account on the platform and your organisation remains a subscriber.

🗂️

After Account Closure

Following account closure, personal information is retained for a maximum of 5 years to comply with financial record-keeping legal requirements, and then securely deleted.

📋

Audit Logs

System audit and access logs are retained for 3 years for security and compliance purposes, then permanently deleted.

6. Security of Your Information

We implement reasonable technical and organisational measures to protect your personal information against loss, theft, unauthorised access, and unlawful processing, including:

🔒

Encryption in Transit

All communication between your browser and our servers is encrypted using TLS (HTTPS).

🗄️

Encrypted Storage

Passwords are hashed using industry-standard algorithms. Sensitive tokens are encrypted at rest.

👁️

Access Controls

Access to personal information is restricted to authorised personnel on a strict need-to-know basis.

💾

Regular Backups

Data is backed up regularly to prevent loss. Backups are stored securely and access-controlled.

No system is completely secure. If you become aware of any security vulnerability, please contact us immediately at privacy@yabanet.co.za.

7. Your Rights as a Data Subject

POPIA grants you the following rights regarding your personal information. To exercise any of these rights, contact our Information Officer at privacy@yabanet.co.za.

📂

Right of Access

You have the right to request a record or description of the personal information we hold about you, free of charge (subject to reasonable limitations).

✏️

Right to Correction

You may request that we correct inaccurate, incomplete, or outdated personal information held about you.

🗑️

Right to Deletion

You may request that we destroy or delete your personal information where we are no longer legally required to retain it.

🚫

Right to Object

You may object to the processing of your personal information on reasonable grounds, including for direct marketing purposes.

📣

Right to Complain

If you believe we have not handled your personal information in accordance with POPIA, you have the right to lodge a complaint with the Information Regulator of South Africa (IRSA).

🔕

Withdraw Consent

Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

8. Information Regulator of South Africa

The Information Regulator (South Africa) is the independent body established under POPIA to enforce compliance. If you believe your rights under POPIA have been violated, you may contact the Regulator:

Website inforegulator.org.za
Complaints Email POPIAComplaints@inforegulator.org.za
General Enquiries inforeg@justice.gov.za
Physical Address JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

9. Changes to This Notice

We may update this Privacy Notice from time to time. The revised version will be published at yabanet.co.za/privacy-notice and the "Last reviewed" date at the top of this page will be updated. We encourage you to review this notice periodically. Material changes will be communicated to registered users by email.

Contact Our Information Officer

For any queries about this Privacy Notice, to exercise your POPIA rights, or to report a privacy concern, please contact:

Email: privacy@yabanet.co.za
Subject line: POPIA Enquiry – [your name]

We aim to respond to all POPIA-related requests within 30 days as required by law.

An unhandled error has occurred. Reload 🗙