1. Introduction
Prosum Solutions ("Prosum", "we", "us" or "our") is committed to protecting the privacy and security of personal information entrusted to us.
This Privacy Policy explains how personal information may be collected, processed, stored, accessed, protected, transferred and disclosed when using Prosum products and services, including Prosum EMS (Education Management Solution), Prosum POS, our websites, applications and related services.
This Privacy Policy has been prepared in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and other applicable South African privacy and information-protection laws.
We recognise that our customers entrust important information to systems provided by Prosum. We therefore aim to process that information only for legitimate and authorised purposes and to maintain appropriate safeguards against loss, unauthorised access, misuse, alteration or disclosure.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal information processed in connection with:
- Prosum EMS – Education Management Solution;
- Prosum POS;
- Prosum websites and online portals;
- Prosum mobile and web applications;
- customer support and technical services;
- customer account and subscription administration;
- sales and business enquiries; and
- other products or services supplied by Prosum which refer to this Privacy Policy.
Certain functionality within our products may involve services supplied by third parties, including cloud infrastructure, banking, payment, messaging, communications and other technology services. Those third parties may also be subject to their own legal obligations, privacy policies and terms of service.
3. Prosum's Role Under POPIA
3.1 Prosum as Responsible Party
Prosum will generally be the Responsible Party when Prosum determines why and how personal information is processed.
This may include information relating to our own customers, prospective customers, users, suppliers, service providers and business contacts. Examples include information used for customer registration, quotations, contracts, billing, account administration, technical support, enquiries and communications with Prosum.
3.2 Prosum as Operator
Where a customer uses Prosum EMS, Prosum POS or another Prosum service to collect, record, manage, store or process personal information for that customer's own purposes, the customer will generally be the Responsible Party and Prosum will generally act as an Operator.
For example, a school using Prosum EMS determines which learner, parent, employee, financial and educational information it requires. Similarly, a business using Prosum POS determines which customer, supplier, product, transaction or other business information it wishes to maintain within the system.
In these circumstances, the customer determines the purpose for which the personal information is collected and processed. Prosum provides the software and associated services through which that information is processed.
Prosum will process Customer Data for the purposes of providing, operating, maintaining, securing and supporting the relevant service, in accordance with the customer's authorised use of the service, applicable contractual arrangements and applicable law.
4. Customer Responsibility for Information Entered into Prosum Systems
Our customers remain responsible for determining what information they collect and store within Prosum EMS, Prosum POS or another Prosum service.
Customers are responsible for ensuring that their collection and processing of personal information complies with POPIA and other applicable laws.
This includes determining the lawful purpose for collecting information, providing appropriate notices to data subjects, obtaining consent where consent is legally required, ensuring that information collected is appropriate for the intended purpose, determining who may access the information and determining appropriate retention periods.
Prosum does not determine what personal information a school, retailer, business or other customer is required to collect for its own operational purposes.
5. Personal Information
For purposes of this Privacy Policy, "personal information" has the meaning provided in POPIA.
Depending on the circumstances and the particular Prosum service being used, personal information may include names, contact information, identification information, educational information, employment information, customer or supplier information, financial information, transaction information, account information, user information, online identifiers, IP addresses and other information relating to an identifiable person or juristic person.
The nature of information stored within a Prosum system will differ according to the requirements of the customer using that system.
6. Information Collected Directly by Prosum
Where Prosum deals directly with customers, prospective customers, users or other persons, we may collect information when a person contacts us, requests a quotation or demonstration, enters into an agreement with us, registers for a service, creates an account, communicates with our support personnel, makes a payment, submits an enquiry or otherwise interacts with Prosum.
The information collected will ordinarily be limited to information reasonably required for the relevant purpose. This may include a person's name, organisation, telephone number, email address, billing information, account details and communications with Prosum.
7. Information Collected Through Our Systems
Our websites, applications, servers and infrastructure may automatically generate or record certain technical information relating to the use of our services.
This may include IP addresses, login activity, browser or device information, dates and times of access, security events, error logs, diagnostic information and information relating to the use or performance of the service.
Such information may be processed for legitimate purposes including security, authentication, fraud prevention, technical support, troubleshooting, system administration, performance monitoring and maintaining the reliability of our services.
8. Prosum EMS – Education Management Solution
Prosum EMS is designed to assist educational institutions with the management of educational, administrative, financial and related information.
Depending on the functions selected and information entered by the educational institution, Prosum EMS may contain personal information relating to learners, parents or guardians, employees, educators, suppliers and other persons associated with the institution.
The educational institution using Prosum EMS generally determines what information is collected, why it is collected and how it is used. Prosum therefore generally processes this information as an Operator on behalf of the educational institution.
Children's Personal Information
Because Prosum EMS is used within the education environment, information processed through the system may include personal information relating to children.
The educational institution or other customer acting as Responsible Party is responsible for ensuring that children's personal information is collected and processed lawfully and that any consent, authority or other legal basis required for that processing is in place.
Prosum will process such information for purposes associated with providing and supporting the Prosum EMS service and in accordance with its role as Operator.
9. Prosum POS
Prosum POS is designed to assist businesses with point-of-sale, customer, product, supplier, transaction and related business-management functions.
The information contained within Prosum POS depends on the functionality used and the information the customer chooses to capture and retain.
Customers remain responsible for determining what customer, supplier, employee or other information they wish to maintain within their POS environment and for ensuring that such information is processed lawfully.
10. Banking and Payment Integrations
Prosum EMS and Prosum POS may integrate with banks, payment providers, payment gateways, payment devices or other financial-service providers.
These integrations may allow payment or transaction information to be transmitted between the relevant service provider and a Prosum system for purposes such as processing, recording, allocating, identifying, reconciling or confirming transactions.
Prosum EMS and Prosum POS are not designed to store sensitive payment authentication information such as card PINs, CVV security codes, online-banking passwords or similar banking authentication credentials.
Where such credentials are required to complete a payment, they are processed by the applicable bank, payment provider or financial-service provider rather than stored by Prosum as part of the customer's normal Prosum database.
Prosum systems may, however, store information relating to a transaction where this is necessary for the operation of the system or where the customer chooses to retain that information.
This may include transaction references, payment status, amounts, dates, customer records, account information and other information that the customer legitimately requires for its accounting, administration or business purposes.
A customer may also choose to record or retain customer information within Prosum EMS or Prosum POS. The customer remains responsible for ensuring that it is legally entitled to collect and retain that information.
The applicable bank or payment-service provider may process information independently and may have its own privacy policy and legal obligations.
11. How Prosum Uses Personal Information
Where Prosum acts as Responsible Party, we may process personal information where reasonably necessary to provide products and services, administer customer accounts, process subscriptions and payments, issue invoices, provide technical support, respond to enquiries, communicate with customers, maintain our business records, maintain and improve our systems, prevent misuse or fraud, investigate security incidents, comply with contractual obligations and comply with applicable legal or regulatory requirements.
Where Prosum acts as Operator, Customer Data will primarily be processed for purposes necessary to provide, maintain, support, secure and operate the service used by the customer.
Prosum does not sell Customer Data or personal information entrusted to us as part of providing our software services.
12. Access to Customer Data by Prosum
Prosum personnel do not access Customer Data for unrelated purposes.
Authorised Prosum personnel or authorised service providers may access Customer Data where reasonably necessary to provide technical support, investigate an error, diagnose a software problem, perform maintenance or an upgrade, maintain the security or integrity of the service, investigate suspected misuse or a security incident, restore or recover systems, implement an authorised customer request or comply with a lawful requirement.
Access is restricted to persons who reasonably require access for the applicable purpose.
Prosum employees, contractors and service providers who may have access to personal information are required to maintain appropriate confidentiality.
13. User Access and Password Security
Access to Prosum EMS and Prosum POS is controlled through user accounts, authentication mechanisms and access permissions.
Customers are responsible for determining which users within their organisation are authorised to access their information and what level of access each user should receive.
Customers and users are responsible for maintaining appropriate control over passwords and login credentials and for promptly removing or disabling access when a user is no longer authorised to access the system.
Users should not share passwords or permit unauthorised persons to use their accounts. Any suspected unauthorised access should be reported to Prosum as soon as reasonably possible.
While Prosum maintains security controls intended to protect the services we provide, effective information security also depends on responsible management of users, permissions, passwords and devices by customers and their authorised users.
14. Hosting, Infrastructure and Service Providers
Prosum's cloud-based services are provided using reputable third-party hosting, infrastructure and technology-service providers.
Prosum may use third-party providers for infrastructure, hosting, backup, communications, messaging, banking integrations, payment processing, security, technical support and other services required to operate or support our products.
For security, confidentiality and commercial reasons, Prosum does not publicly disclose detailed information regarding its infrastructure architecture, individual hosting arrangements, security configuration or all service providers used in delivering its services.
This does not reduce Prosum's obligations to protect personal information.
Prosum takes reasonable steps to ensure that providers processing personal information on our behalf are subject to appropriate contractual, confidentiality and information-security requirements.
Prosum may appoint, replace or change technology and infrastructure providers in the normal course of operating and improving its services, subject to applicable legal and contractual obligations.
15. Information Security
Prosum takes reasonable technical and organisational measures to protect personal information against loss, damage, unauthorised destruction, unlawful access and unlawful processing.
These measures are reviewed and adapted according to the nature of the information processed, foreseeable risks, available technology and the services being provided.
No computer system, internet connection, cloud environment or electronic storage system can be guaranteed to be completely immune from every possible security threat.
Accordingly, Prosum does not make an absolute guarantee that a security incident can never occur. We undertake instead to maintain reasonable and appropriate safeguards as contemplated by applicable law.
16. International Processing and Storage
Prosum uses cloud-based technology and third-party infrastructure in providing its services.
As a result, personal information and Customer Data may be stored, backed up, accessed or processed in countries outside South Africa.
Prosum does not guarantee that all Customer Data will at all times be physically located within South Africa.
Where personal information is transferred outside South Africa, Prosum will take reasonable steps to ensure that the transfer is conducted in accordance with applicable requirements of POPIA, including section 72 where applicable.
17. Disclosure of Personal Information
Prosum will not sell personal information entrusted to us.
Personal information may be disclosed where reasonably necessary to provide the relevant service, to authorised technology or service providers involved in providing the service, to a bank or payment-service provider where required for an integration or transaction, on the lawful instructions of a customer acting as Responsible Party, where required by law, court order or regulatory authority, or where reasonably necessary to protect the security or integrity of Prosum's systems and services.
Where Prosum uses third-party service providers to process personal information on our behalf, appropriate measures will be taken having regard to Prosum's obligations under POPIA.
18. Data Retention
Prosum retains personal information for no longer than reasonably necessary for the purpose for which it is processed, subject to applicable legal, contractual, operational, accounting and regulatory requirements.
Where Prosum is the Responsible Party, retention periods may depend on the nature of the information and the purpose for which it is held.
Where Prosum acts as Operator, the customer as Responsible Party generally determines its own retention requirements for Customer Data.
Where functionality allows, customers may manage, update, archive or delete information using the applicable Prosum service.
19. Termination of Services and Deletion of Customer Data
When a customer's use of a Prosum service ends, Customer Data will be dealt with in accordance with the applicable agreement, the customer's lawful instructions, Prosum's data-retention procedures and any legal requirements applicable to the information.
Where reasonably practicable and provided for by the relevant service or agreement, a customer may be provided with an opportunity to retrieve or export its information before it is removed from active systems.
Once information is deleted from active systems, residual copies may remain temporarily within system backups, archives, disaster-recovery systems or other protected storage until those copies are overwritten, rotated, expire or are securely deleted through normal data-management procedures.
Prosum does not undertake that every backup copy will be individually identified and immediately deleted when information is removed from an active production database.
Information retained within backups will remain subject to appropriate security safeguards and will not ordinarily be restored for operational use except where required for legitimate recovery, security, legal or continuity purposes.
20. Security Compromises
Prosum maintains procedures for responding to suspected or confirmed security incidents involving personal information.
Where Prosum acts as an Operator and becomes aware of reasonable grounds to believe that personal information processed on behalf of a customer has been accessed or acquired by an unauthorised person, Prosum will notify the applicable customer as Responsible Party in accordance with POPIA.
Where Prosum itself is the Responsible Party, Prosum will deal with notifications to affected data subjects and the Information Regulator as required by POPIA.
21. Data Subject Rights
Subject to POPIA and other applicable laws, a data subject may have the right to request confirmation of whether personal information is being held, request access to personal information, request correction of inaccurate information, request deletion or destruction where legally appropriate and object to certain processing.
Where the information concerned is Customer Data held by Prosum on behalf of a customer, the data subject should ordinarily direct the request to the organisation that collected the information.
For example, a learner or parent requesting information contained within a school's Prosum EMS database should generally submit the request to the relevant school because the school is the Responsible Party responsible for determining how that information is processed.
Prosum will reasonably assist customers with legitimate data-subject requests where this is required and reasonably possible.
22. Marketing Communications
Prosum may communicate with existing and prospective customers regarding our products and services where permitted by law.
Electronic direct marketing will be conducted in accordance with POPIA and other applicable requirements.
Where consent is legally required, Prosum will obtain the required consent before sending electronic direct marketing.
Where permitted by POPIA, Prosum may also communicate with existing customers regarding its own similar products or services, subject to the customer's right to object or opt out.
Recipients may request removal from Prosum marketing communications by using an unsubscribe facility where provided or by contacting info@prosumsolutions.co.za.
This does not prevent Prosum from sending necessary service, support, billing, security or administrative communications relating to a product or service used by the customer.
23. Third-Party Services
Prosum products may integrate with, connect to or make use of services supplied by independent third parties.
These services may include banks, payment providers, communications providers or other technology services.
Where a third party independently determines how personal information is processed, that third party may itself be a Responsible Party and its own terms and privacy policy may apply.
Prosum is not responsible for the independent privacy practices of third parties which are outside Prosum's control.
24. Confidentiality of Our Infrastructure and Security Arrangements
This Privacy Policy is intended to provide transparent information about how personal information is processed and protected.
It is not intended to disclose confidential information concerning Prosum's proprietary technology, software architecture, infrastructure configuration, security arrangements, commercial agreements or service providers.
Prosum may therefore provide information about its security and processing practices at an appropriate level without publicly identifying individual suppliers or disclosing information that could compromise security, intellectual property or legitimate commercial interests.
Nothing in this clause limits any disclosure that Prosum is legally required to make to a customer, regulator, court or other authorised party.
25. Changes to this Privacy Policy
Prosum may update this Privacy Policy from time to time to reflect changes in our products, services, technology, legal obligations or privacy and security practices.
The current version will be made available through the Prosum website or other appropriate location and will indicate the date on which it became effective.
Where reasonably appropriate, material changes may also be communicated directly to affected customers.
26. Contact Details
Questions, requests or complaints concerning this Privacy Policy or Prosum's processing of personal information may be addressed to:
Prosum Solutions
Information Officer: Prosum Solutions Information Officer
Email: info@prosumsolutions.co.za
Telephone: +27 82 498 4704
Location: Pinelands, Cape Town, South Africa
Where the request relates to information controlled by a Prosum customer, Prosum may refer the person to the relevant customer as Responsible Party.
A person who believes that their rights under POPIA have been infringed also has the right to submit a complaint to the Information Regulator of South Africa.