Privacy Policy
TEMPLATE — FOR REVIEW BY LEGAL COUNSEL BEFORE PUBLICATION This document has not been reviewed by a qualified attorney and must not be relied upon as legal advice or published in its current form. It is provided as a starting-point template only.
Last updated: June 2026 Effective date: June 2026
Cognizance Processing (Pty) Ltd (“KeyOne”, “we”, “our”, or “us”), registration number [REG NUMBER], a company incorporated in South Africa, operates the KeyOne platform accessible at keyone.sh.
This Privacy Policy explains how we collect, use, share, and protect personal information in connection with our services. It must be read together with our Terms of Service and POPIA Compliance Statement.
1. Who This Policy Applies To
This policy applies to:
- Visitors to keyone.sh and our documentation
- Account holders — individuals who register for a KeyOne account
- End users — employees and contractors of our corporate customers who access the platform under a customer’s tenant
2. Information We Collect
2.1 Information You Provide Directly
| Category | Examples |
|---|---|
| Identity information | Full name, job title, company name |
| Contact information | Email address, phone number |
| Authentication credentials | Password (stored as a one-way argon2id hash — we never store plaintext passwords) |
| Profile information | Profile photo, team membership |
| Support communications | Messages sent to our support team |
2.2 Information Collected Automatically
When you use the KeyOne platform, we automatically collect:
- Usage data: pages visited, features used, actions taken, time spent
- Device and browser data: browser type and version, operating system, screen resolution
- Network data: IP address, approximate geographic location (country/province level only)
- Session data: login timestamps, session duration, authentication events
- Error and diagnostic data: crash reports, performance metrics (no personal data payload)
2.3 Information From Third Parties
- OAuth providers: When you sign in with Google or Microsoft, we receive your name, email address, and profile photo from that provider in accordance with their privacy policies
- Customer data: If your employer uses KeyOne, your employer controls what data about you is shared with us
2.4 Business and Operational Data
If you are a KeyOne customer (a principal/brand owner):
- Retailer POS and scan data you upload
- SAP/ERP data you provide
- Configuration, metric definitions, and analytical outputs
This data is yours. We process it only to deliver the service. See Section 6 for customer data handling.
3. How We Use Your Information
We use personal information for the following purposes:
| Purpose | Legal basis (POPIA) |
|---|---|
| Creating and managing your account | Contract performance |
| Delivering the KeyOne platform and its features | Contract performance |
| Authenticating your identity on login | Contract performance / Legitimate interest |
| Sending transactional emails (password reset, verification) | Contract performance |
| Responding to support requests | Contract performance |
| Maintaining platform security and preventing fraud | Legitimate interest |
| Diagnosing technical issues and improving reliability | Legitimate interest |
| Sending product updates and new feature announcements | Legitimate interest (you may opt out) |
| Complying with legal obligations | Legal obligation |
We do not use your information for automated profiling that produces legal or similarly significant effects without explicit consent.
4. How We Share Your Information
We do not sell personal information to third parties.
We share personal information only in these circumstances:
4.1 Service Providers (Operators under POPIA)
We use third-party providers to operate the platform. Each is bound by a data processing agreement:
| Provider | Purpose | Location |
|---|---|---|
| Cloud infrastructure provider | Hosting, compute, storage | South Africa (africa-south1) |
| ClickHouse Cloud / self-hosted | Analytical data warehouse | South Africa |
| Email delivery provider | Transactional email | [To be confirmed] |
4.2 Your Employer
If you access KeyOne under a corporate tenant, your employer (the customer) may have access to your activity logs within that tenant’s administrative panel.
4.3 Legal Requirements
We may disclose personal information when required by South African law, court order, or to protect the rights and safety of our users or the public.
4.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, personal information may be transferred. We will notify affected users in advance.
5. Data Retention
| Data type | Retention period |
|---|---|
| Account information | For the lifetime of the account, plus 12 months after closure |
| Authentication logs | 12 months |
| Support communications | 3 years |
| Usage analytics | 24 months (aggregated beyond 12 months) |
| Backups | 90 days rolling |
After the retention period, data is deleted or anonymised.
6. Customer Data (Tenant Data)
Data uploaded by customers (retailer feeds, ERP data, analytical outputs) is treated as follows:
- It is stored in a physically isolated tenant database (
ks_{tenant}) on infrastructure located in South Africa - We access it only to provide the contracted service
- We do not use it to train models, analyse competitors, or share with other customers
- The customer retains all rights to their data
- On account termination, we delete tenant data within 30 days, with confirmation to the customer
7. Security
We implement the following controls to protect personal information:
- Encryption in transit: TLS 1.2+ for all connections
- Encryption at rest: AES-256 for all stored data
- Authentication: Argon2id password hashing; JWT with rotating refresh tokens; OAuth 2.0 with established providers
- Access controls: Role-based access; principle of least privilege; administrative access requires MFA
- Audit logging: All authentication events, administrative actions, and data access are logged
- Penetration testing: Scheduled annually
Despite these measures, no system is completely secure. We will notify affected users and the Information Regulator of any breach as required under POPIA.
8. Your Rights Under POPIA
As a data subject under the Protection of Personal Information Act, 4 of 2013, you have the right to:
- Access: request a copy of the personal information we hold about you
- Correction: request correction of inaccurate or incomplete information
- Deletion: request erasure of your personal information (subject to legal retention requirements)
- Objection: object to our processing of your information for direct marketing
- Restriction: request restriction of processing in certain circumstances
- Portability: receive your personal information in a structured, commonly used format
- Complaint: lodge a complaint with the Information Regulator of South Africa
To exercise these rights, contact our Information Officer at: privacy@keyone.sh
We will respond within 30 days of receiving a request.
9. Information Officer
Our designated Information Officer as required by POPIA is:
[Name TBC] Cognizance Processing (Pty) Ltd Email: privacy@keyone.sh Address: [Physical address TBC]
10. Children
KeyOne is a business-to-business service. We do not knowingly collect personal information from individuals under 18 years of age. If we become aware that we have collected information from a minor, we will delete it promptly.
11. Changes to This Policy
We will notify you of material changes to this policy by email and by displaying a notice on the platform at least 30 days before the change takes effect.
12. Contact Us
For privacy-related questions:
Cognizance Processing (Pty) Ltd Email: privacy@keyone.sh Website: keyone.sh
Template only — must be reviewed and approved by qualified South African legal counsel before publication.