Privacy Policy
This policy explains, in plain terms, what personal information Seven Twenty Degrees (Pty) Ltd collects, why, where it is processed, who it is shared with, and the rights you have — in line with the Protection of Personal Information Act 4 of 2013 (POPIA). We build data protection into how the product works, and we would rather state a limitation honestly than overstate a safeguard.
On this page
- Who we are
- Our two roles: responsible party and operator
- Whose information we process
- What we collect, and why
- Special personal information
- Website analytics — cookieless by design
- AI features (7Assistant) — where your data is processed
- Automated decision-making
- Who we share information with
- Cross-border transfers
- How we protect information
- How long we keep information
- Your rights, and how to use them
- Children
- Changes to this policy
1. Who we are
Seven Twenty Degrees (Pty) Ltd (registration number 2023/212025/07), incorporated in South Africa and based in Pietermaritzburg, is the maker of 7Maintain. For the information described in this policy, we are the "responsible party" under POPIA (except where we act as an operator — see section 2).
Information Officer: Terence Grenfell.
Postal address: 52 Wilkes Road, Prestbury, Pietermaritzburg, South Africa.
Email: admin@720degree.co.za.
2. Our two roles: responsible party and operator
We handle personal information in two different capacities, and it matters which one applies:
- As the responsible party — for information about our own account holders, our website visitors, and people who enquire with us. We decide why and how that information is processed, and this policy governs it.
- As an operator (processor) — for the information a customer puts into 7Maintain about their own business, in particular their employees. Here the customer is the responsible party and we process that data on the customer's instructions, to provide the service. The customer is responsible for having the right to load their employees' personal information and for informing those employees as their law requires. If you are an employee of a company that uses 7Maintain and want to exercise a right over your data, please contact your employer; we will assist them as their operator.
3. Whose information we process
- Account users / customers — the people who sign up for and administer a 7Maintain account.
- Customer employees — people whose details a customer records in 7Maintain (we are the operator here).
- Website visitors — people who browse our sites.
- Leads and enquiries — people who fill in a form or contact us.
4. What we collect, and why
(a) Account users / customers — we are the responsible party
Name, work email, company name, phone number, and a password (which we store only as a secure bcrypt hash — never in plain text). To keep accounts secure we also record sign-in activity such as session and login records, which include the IP address and browser/device used, and two-factor authentication details. We use this to provide the service, to bill you, to support you, and to protect the account. Lawful basis: performance of our contract with you (POPIA s 11(1)(b)) and our legitimate interest in security (s 11(1)(f)).
(b) Customer employees — we are the operator
On the customer's instruction, 7Maintain stores the employee information the customer chooses to record, which can include: name, employee number, work email, phone number, a profile photo, job title/role, department or trade, shift pattern, a work PIN (stored as a secure hash), an RFID/NFC badge identifier, and skills, competencies and certifications. It also records operational activity tied to a person: work-order assignments, comments and photos, electronic sign-offs, clock-in/attendance times (including the site Wi-Fi network name and a resolved on-site "zone"), voice-note transcripts (text only — see below), and leave/unavailability records.
What we do NOT collect about employees: we have no fields for national ID or passport numbers, date of birth, home address, next-of-kin, bank account, salary, or race/gender. Voice notes are transcribed to text on the device — we do not store audio. Presence tracking stores only a resolved zone label and site Wi-Fi identifiers — we do not store a person's GPS coordinates. Lawful basis for this category rests with the customer as responsible party (typically the employment relationship and their own legal duties); we process it under their instruction.
(c) Website visitors
Privacy-first, cookieless analytics (see section 6) and standard web-server logs (IP address, timestamp, browser, page requested, referrer, response code), which we keep for security and abuse handling. Lawful basis: our legitimate interest in running and securing the site (s 11(1)(f)).
(d) Leads and enquiries
When you submit an enquiry or request (for example the "apply" or compliance-pack forms) we collect the name, work email, company, phone number and any equipment details you enter, your consent tick, and — to prevent abuse — the IP address and browser of the submission. Lawful basis: your consent (s 11(1)(a)) and taking steps at your request towards a contract (s 11(1)(b)).
5. Special personal information
Two things deserve a plain, honest note:
- Face recognition (biometric) is available but OFF by default. 7Maintain includes an optional face-recognition clock-in. It does nothing unless a customer explicitly switches it on and enrols employees, with consent recorded in a consent ledger. When enabled, we store a mathematical face template (encrypted at rest) — not a usable photograph — solely to confirm attendance. A face template is "special personal information" under POPIA sections 26–27, so enabling this feature triggers additional obligations and requires the employee's consent. If the feature is off (the default), no face data is collected or processed.
- Health-adjacent leave reasons. Leave records may carry a reason such as "sick", which can imply health information. We hold this only so the customer can manage scheduling; it is entered by the customer's managers.
6. Website analytics — cookieless by design
Our site analytics are deliberately privacy-preserving, and we want to be precise about it:
- No cookies, no third-party analytics, no advertising or tracking pixels.
- We do not store your IP address. Your IP is used only momentarily, in memory, to (a) look up a coarse city/country from a local database on our own server — there is no third-party geolocation lookup — and (b) compute a one-way daily visitor hash. It is then discarded.
- The visitor hash is salted with a random value that changes every day, so the same visitor cannot be linked across days, and the hash cannot be reversed.
- What we keep: page path, referring domain (not the full URL), device type, coarse country/region/city, campaign (UTM) tags, and a timestamp.
- Analytics records are automatically deleted after 400 days by a scheduled job.
7. AI features (7Assistant) — where your data is processed
7Assistant is the optional helper built into 7Maintain. It is off by default for each organisation, and every AI feature that touches customer data is architected to keep that data in South Africa:
- Customer-data AI runs on our own hardware in South Africa, reached over an encrypted private network, and it fails closed: if that system is unavailable, the feature switches off and tells you — it never falls back to a third-party AI service. No customer data is sent to any external AI provider.
- One narrow exception: a spare-parts research helper may send only public manufacturer, model and category text (for example "Bosch, model X") to a commercial AI provider outside South Africa to look up parts. It never sends customer names, personal data, serial numbers or any operational data. This helper is also off unless enabled.
8. Automated decision-making
POPIA section 71 gives you rights around decisions made only by automated means. Here is the honest position:
- Some work is assigned automatically. When a job is created, the system may assign it to a technician based on skills, who is on shift, current workload and area — without a manager confirming. One such rule (assigning a job when exactly one qualified technician is on shift in that area) is on by default; broader automatic assignment is off by default and switched on per organisation. Review work may similarly be routed to a checker automatically.
- The system produces individual performance summaries (for example jobs completed and first-time-fix rate) with coaching flags, shown to managers. This is profiling of individuals, but it drives no automatic action on its own.
- No automated decision takes an adverse action about a person. There is no automatic discipline, suspension, deactivation or dismissal — a human makes every such decision.
Your rights: if you are subject to an automatic assignment and want a human to look at it, you or your manager can reassign the work, and you may contact our Information Officer to object or ask for human review.
9. Who we share information with
We do not sell personal information. We use no SMS or WhatsApp integrations and no third-party analytics or advertising trackers. We share information only with the operators needed to run the service:
| Who | What they receive | Location |
|---|---|---|
| Paystack (payments) | Your account email and our internal reference IDs. Card details are entered directly on Paystack's secure page and never reach our servers. | Outside South Africa |
| Our email host (mail.720degree.co.za) | Transactional emails — verification, sign-in links, password resets, notifications (recipient name + email). | South Africa (managed host) |
| Push notification delivery — Google (Firebase) for Android/app, Apple for iOS | Delivers push notifications to your device. Note: notification text is transmitted to the delivery service, so we keep notification content free of sensitive personal detail. Web-push messages are encrypted in transit. | Outside South Africa |
| Commercial AI provider (parts research only) | Only public manufacturer/model/category text — no personal data — and only if the feature is enabled. | Outside South Africa |
We may also disclose information where the law requires it, or to protect the rights, property or safety of our users, the public or ourselves.
10. Cross-border transfers
Plainly: your operational data and all AI processing of your data stay in South Africa. The only personal information that leaves the country is:
- your account email and our reference IDs, sent to Paystack for payment;
- push-notification delivery via Google / Apple; and
- public, non-personal manufacturer/model text sent to the parts-research AI provider (if enabled).
Nothing else of your operational data leaves South Africa. These transfers rely on the protections POPIA Chapter 9 requires for cross-border processing (a recipient bound by comparable safeguards, your consent, or necessity for your contract).
11. How we protect information
- In transit: encrypted with TLS/HTTPS.
- At rest: the production database is stored on an encrypted disk volume (LUKS) in a South African data centre.
- Extra encryption (AES-256-GCM) at the application level for the most sensitive items — face templates, supplier banking details, and signing keys.
- Passwords are hashed with bcrypt; employee PINs use a stronger bcrypt setting with lockout after repeated failures.
- Role-based access — every request is checked against the user's role.
- Audit logging of security-relevant actions and access.
- AI traffic to our South African hardware runs over an encrypted WireGuard tunnel.
- Separation between customers: each organisation's records are separated by organisation-scoped filtering in our application over shared database tables. To be accurate, this is application-level filtering — not database row-level security, and not a separate database per customer.
- We take regular backups of the database. We are actively strengthening our backup and disaster-recovery posture and do not make claims about off-site backups here that we cannot yet stand behind.
12. How long we keep information
- Website analytics: deleted after 400 days (automated).
- Maintenance tool photos: deleted after about 6 months by default (automated; configurable per organisation).
- Certain short-lived operational logs: deleted after 30 days (automated).
- Account and operational data: kept while the account is active and until deletion is requested (see section 13).
- Records the law requires us to keep are retained even after a deletion request — in particular electronic work-order sign-off signatures, which are kept as evidentiary records under the Electronic Communications and Transactions Act, and financial/tax records.
13. Your rights, and how to use them
Under POPIA you may ask us to give you access to your personal information, correct it, delete it, or object to its processing (including any direct marketing), and you may complain to the Information Regulator.
How this actually works, honestly: these requests are handled manually by our team — there is no automated self-service export or one-click delete. Email admin@720degree.co.za; we verify your identity (to protect your data from fraudulent requests) and respond within 30 days. Deletion is request-based and actioned by our team — it is not automatic when an account is closed. Some records are retained where the law requires (see section 12).
If your information is held in 7Maintain by your employer, the employer is the responsible party — please direct your request to them; we assist them as their operator.
Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 — inforegulator.org.za. Please see their website for the current complaints channel.
14. Children
7Maintain is business software for workplaces. It is not directed at children, and we do not knowingly collect the personal information of anyone under 18.
15. Changes to this policy
We may update this policy from time to time. The current version, with its effective date, will always live at this URL, and we will notify account holders of material changes.