Privacy Policy

Exequtech Products & Services

Effective Date: 2 March 2026  |  Last Updated: 2 March 2026

1. Introduction

This Privacy Policy explains how Exequtech (“we”, “us”, or “our”) collects, uses, stores, shares, and protects your personal information when you use any of our products and services (collectively, “the Services”). The Services currently include:

We are committed to protecting your privacy and processing your personal information in accordance with the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) (“POPIA”), the Electronic Communications and Transactions Act, 2002 (Act No. 25 of 2002) (“ECTA”), and all other applicable South African legislation.

By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please discontinue use of the Services and contact your employer or our support team.

↑ Back to top

2. Responsible Party & Information Officer

In terms of Section 18(b) of POPIA, the responsible party for the processing of your personal information is:

Responsible Party: Exequtech

Email: support@exequtech.com

All requests, enquiries, or complaints regarding the processing of your personal information may be directed to the contact details above. Our Information Officer is responsible for ensuring compliance with POPIA and for addressing any data subject requests.

↑ Back to top

3. Definitions & Glossary

3.1 Legal Definitions

The following terms, as used in this Policy, bear the meanings assigned to them under POPIA unless the context indicates otherwise:

3.2 Data Categories

Throughout this Policy, we refer to the following broad categories of personal information. These categories are used to describe what we collect, why, and how long we retain it:

CategoryDescription
Identity DataName, username, unique user identifiers
Contact DataEmail addresses, phone numbers, physical addresses, site access instructions
Authentication DataCredentials (email/password), PINs, access and refresh tokens, session identifiers, lockout information
Financial DataBanking details, tax numbers, purchase records, invoices, quotations, billing records
Content DataJob cards, work records, notes, photos, receipts, digital signatures, checklists, customer feedback, documents
Asset DataInventory items, SKUs, serial numbers, quantities, unit prices, categories
Device DataDevice model, operating system version, browser type and version, app version
Usage DataLogin timestamps, session activity, feature usage patterns
Location DataGPS coordinates captured at specific events (e.g., job status changes); not continuous tracking
Profile DataRoles, permissions, team assignments, user preferences
Technical DataServer logs, IP addresses, API request metadata, error reports
↑ Back to top

4. Scope & Application

This Privacy Policy applies to all personal information processed through our Services, including data:

This Policy applies to all users of our Services, including field technicians, office administrators, managers, and any other persons authorised by their employer to access the Services. Where the Services display customer contact information as part of job card or business data, this Policy also covers the processing of that customer data within the Services.

Our Services are typically provided to users through their employer. Your employer may have separate privacy policies and data processing agreements with Exequtech that govern additional aspects of data processing. This Policy covers Exequtech’s responsibilities as the developer and operator of the Services.

4.1 Platform-Specific Notes

↑ Back to top

5. Information We Collect

In compliance with Section 18(a) of POPIA, the following describes the personal information we collect and process through our Services. The specific data collected depends on which Service you use and which features you access.

5.1 Data Categories by Service

Data CategoryMobile AppWeb App
Identity DataYesYes
Contact DataYes (synced from cloud)Yes (managed directly)
Authentication DataYes (email/password, PIN, tokens)Yes (email/password, session cookies, tokens)
Financial DataPurchases onlyYes (invoices, quotations, banking, tax)
Content DataYes (job cards, photos, signatures, checklists)Yes (job cards, documents, reports)
Asset DataYesYes
Device DataYes (device model, OS, app version)Yes (browser type and version)
Usage DataYesYes
Location DataYes (GPS on job status changes)No
Profile DataYesYes
Technical DataYes (API metadata, error reports)Yes (server logs, IP addresses)

5.2 Conditional Collection

Not all data categories apply to every user. Where a feature requires additional personal information beyond what is described above, you will be informed at the point of collection and, where required by law, asked to provide your consent before that information is processed.

5.3 Data We Do Not Collect

For clarity, our Services do not collect, access, or transmit the following:

↑ Back to top

6. How and Why We Use Your Data

In compliance with POPIA Section 13 (purpose specification), Section 11 (lawfulness of processing), and Section 18(c) and (f), the following table describes the purposes for which we process each data category and the legal basis on which we rely:

Data CategoryPurposeLegal Basis
Identity Data To identify you within the system, display your name to colleagues, and associate records with your account Performance of a contract (s11(1)(b))
Contact Data To enable communication, navigation to job sites, and delivery of service-related notifications Performance of a contract (s11(1)(b))
Authentication Data To verify your identity, secure your account, prevent unauthorised access, and manage sessions Performance of a contract (s11(1)(b)); Legitimate interest (s11(1)(f)) for security measures
Financial Data To process invoices and quotations, record purchases, manage billing, and support financial reporting Performance of a contract (s11(1)(b)); Legal obligation (s11(1)(c)) for tax records
Content Data To manage job assignments, document work performed, capture customer feedback and sign-off, and maintain service records Performance of a contract (s11(1)(b))
Asset Data To track materials and parts used or reserved for jobs, manage inventory, and reconcile stock Performance of a contract (s11(1)(b))
Device Data To diagnose platform-specific issues, monitor compatibility, and support debugging Legitimate interest (s11(1)(f))
Usage Data To enforce idle timeouts and account lockout policies, and to monitor system health Legitimate interest (s11(1)(f))
Location Data To record where job status changes occur for service verification, proof of attendance, and operational reporting Consent (s11(1)(a)) via device permission; Legitimate interest (s11(1)(f))
Profile Data To manage roles and permissions, assign team members, and personalise the user experience Performance of a contract (s11(1)(b))
Technical Data To maintain system security, debug errors, and monitor platform performance Legitimate interest (s11(1)(f))

We process your personal information only for the purposes described above or for compatible purposes permitted by law. We do not sell your personal information to third parties. We may send you service-related communications; where these constitute direct marketing, we will provide an easy way to opt out.

You may withdraw consent at any time where processing is based on consent. For mobile device permissions (camera, location, gallery, notifications), you can withdraw consent by revoking the relevant permission in your device’s system settings. Withdrawal of consent does not affect the lawfulness of processing conducted prior to the withdrawal. See Section 13 for full details on exercising your rights.

↑ Back to top

7. Cookies & Browser Storage

7.1 Web Application

The Exequtech web application uses a limited number of cookies and browser storage mechanisms that are strictly necessary for the operation and security of the Service:

TechnologyPurposeDuration
CSRF cookieCross-site request forgery protection — prevents malicious third-party sites from performing actions on your behalfSession (cleared when you close your browser)
Refresh token cookieMaintains your authenticated session so you do not need to re-enter your password on every requestUntil logout or token expiry
Browser local storageStores UI preferences (e.g., sidebar state, theme settings) for a consistent user experienceUntil cleared by you or the application

Our web application currently uses only strictly necessary cookies for security and authentication, as described above. We do not use advertising cookies. If we introduce analytics cookies in the future, we will update this policy and obtain your consent where required by applicable law.

7.2 Mobile Application

The ExequJobs mobile application does not use cookies or web-based tracking technologies. Authentication tokens are stored in encrypted device storage and are not cookies.

↑ Back to top

8. Voluntary vs Mandatory Information

In terms of POPIA Section 18(d) and (e), we disclose which information is mandatory and which is voluntary, along with the consequences of not providing it:

8.1 Mandatory Information

The following information is required for the Services to function:

8.2 Voluntary Information

The following information is optional. You may choose not to provide it, with the noted consequences:

↑ Back to top

9. Data Sharing & Third Parties

In terms of POPIA Section 18(h)(i), we disclose the categories of recipients of your personal information:

RecipientPurposeData SharedRelationship
Exequtech Cloud Platform Central infrastructure for processing and synchronising all service data All data categories as applicable to your use of the Services Responsible Party’s own infrastructure
Cloud storage provider Storage of uploaded files (photos, receipts, documents) File content only, transferred via time-limited secure links Operator (data processor)
Mapping services (e.g., Google Maps or device default) Navigation to job site addresses Address or coordinates (only when you choose to navigate) Third-party service invoked at your request
Device services (location, camera, biometrics) Provides on-device functionality Data accessed on-device only — not sent to third parties by our Services On-device system services
Google / Firebase (Crashlytics, Analytics) Crash reporting, app stability monitoring, and usage analytics to improve the mobile application Device Data (device model, OS version, app version), crash logs, and aggregated usage patterns Operator (data processor) under Google’s Data Processing Agreement
Google ML Kit (Barcode Scanning) On-device barcode scanning within the mobile application Camera input processed locally on the device — no image data is sent to Google servers On-device processing library

We do not:

Where we engage third-party service providers, they process your data on our behalf under contractual obligations to protect your information.

Your Employer

Your employer, who has contracted Exequtech for service management, has access to the data you enter through the Services via the Exequtech cloud platform. This includes job records, status changes, photos, signatures, location data, financial records, and other work-related information. Your employer’s access to this data is governed by their agreement with Exequtech and their own privacy and employment policies.

↑ Back to top

10. Cross-Border Data Transfers

In compliance with POPIA Section 72 and Section 18(g), we disclose that your personal information is transferred outside of the Republic of South Africa as follows:

Your personal information is primarily stored and processed within the EU/EEA via the Exequtech cloud platform. In the course of providing our Services, limited personal information may be transferred to other countries where our service providers operate. Where such transfers occur, we ensure appropriate safeguards under POPIA Section 72, including binding data processing agreements with contractual obligations substantially similar to POPIA’s conditions.

DestinationService ProviderLegal Basis (POPIA s72)
EU/EEA Exequtech Cloud Platform (central server and data storage) Adequate protection — GDPR (s72(1)(a)); performance of a contract (s72(1)(c))
United States Google / Firebase (analytics, crash reporting) Binding agreement — Data Processing Agreement + Standard Contractual Clauses (s72(1)(a))
↑ Back to top

11. Data Retention

In terms of POPIA Section 14 (retention limitation), we retain your personal information only for as long as is necessary for the purpose for which it was collected, or as required by law:

Data CategoryRetention PeriodDeletion Trigger
Authentication DataTokens: short-lived with automatic refresh or until logout; PINs: until changed or account removalAutomatic expiry, logout, or account deprovisioning
Identity & Profile DataDuration of account existenceAccount deprovisioning by employer
Content DataActive records: while in use; completed records: per employer retention policyEmployer-initiated deletion or data subject request
Financial DataAs required by South African tax and financial legislation (typically 5–7 years)Expiry of legal retention period
Location DataRetained as part of job event records; follows Content Data retentionSame as Content Data
Asset DataDuration of business use; follows employer retention policyEmployer-initiated deletion
Device, Usage & Technical DataServer logs retained for up to 90 days for debugging and security monitoringAutomatic rotation and deletion
Contact DataDuration of business relationshipAccount deprovisioning or data subject request

When data is no longer required, it is deleted or anonymised. On the mobile app, local data is removed when the app is uninstalled or when the local database is cleared. You or your employer may request deletion of cloud-stored data as described in Section 13.

11.1 Aggregated and Anonymised Data

We may retain anonymised or aggregated data — from which no individual can be identified — indefinitely for business analysis, service improvement, and reporting purposes. Such data is no longer personal information as defined by POPIA and is not subject to the retention limitations above.

↑ Back to top

12. Data Security

In compliance with POPIA Condition 7 (Security Safeguards), we implement appropriate technical and organisational measures to protect your personal information against loss, damage, unauthorised access, or unlawful processing:

12.1 Encryption

12.2 Access Controls

12.3 Infrastructure & Organisational Measures

12.4 Data Breach Notification

In the event of a security compromise involving your personal information, we will notify the Information Regulator and affected data subjects as required by POPIA Section 22, and take immediate steps to contain the breach and mitigate harm.

12.5 Your Responsibilities

You are responsible for keeping your login credentials, PIN, and any other authentication information confidential. You should not share your account credentials with any other person. If you believe your credentials have been compromised, you should change your password immediately and contact your employer or our support team at support@exequtech.com.

We regularly review and update our security practices to reflect current industry standards and evolving threats. Specific technical details regarding our security measures are available on request by contacting support@exequtech.com.

↑ Back to top

13. Your Rights as a Data Subject

Under POPIA Section 5 and Condition 8, and in compliance with Section 18(h)(iii)–(v), you have the following rights regarding your personal information:

13.1 Right of Access (POPIA s23)

You have the right to request confirmation of whether we hold personal information about you, and to request a copy of that information. We will respond to access requests within a reasonable time, and no later than the timeframes prescribed by POPIA.

13.2 Right to Correction (POPIA s24)

You have the right to request that we correct or update personal information about you that is inaccurate, misleading, or incomplete. Certain information (such as your user profile) may be managed by your employer through the cloud platform; corrections to employer-managed data should be directed to your employer.

13.3 Right to Deletion (POPIA s24)

You have the right to request the deletion or destruction of personal information that we are no longer authorised to retain, or that is no longer necessary for the purpose for which it was collected. Note that we may be required to retain certain records for legal or contractual compliance.

13.4 Right to Object (POPIA s11(3))

You have the right to object, on reasonable grounds relating to your particular situation, to the processing of your personal information. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.

13.5 Right to Withdraw Consent

Where processing is based on your consent, you may withdraw consent at any time. For mobile device permissions (camera, location, gallery, notifications), you can withdraw consent by revoking the relevant permission in your device’s system settings. Withdrawal of consent does not affect the lawfulness of processing conducted prior to the withdrawal.

13.6 Data Portability

Upon request, we can provide you or your employer with an export of your personal information in a commonly used, machine-readable format. To request a data export, please contact us at support@exequtech.com.

13.7 Right to Complain to the Information Regulator

You have the right to lodge a complaint with the Information Regulator if you believe that your personal information has been processed in violation of POPIA. See Section 21 for the Information Regulator’s contact details.

How to Exercise Your Rights

To exercise any of the rights described above, please contact us at support@exequtech.com. We may need to verify your identity before processing your request. We will respond within a reasonable period, and in any event within the timeframes required by POPIA.

↑ Back to top

14. Children’s Privacy

Our Services are workplace tools intended for use by employed or contracted personnel. They are not directed at, designed for, or intended for use by children under the age of 18. We do not knowingly collect personal information from children.

If we become aware that we have inadvertently collected personal information from a person under 18, we will take steps to delete such information promptly. If you believe a child has provided personal information through our Services, please contact us immediately at support@exequtech.com.

↑ Back to top

15. Automated Decision-Making

Our Services may use automated tools to assist with operational functions such as scheduling or workload management. All final decisions with legal or similarly significant effects are made by human operators—you, your employer, or your team.

↑ Back to top

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the functionality of our Services, or applicable law. When we make material changes:

We encourage you to review this Privacy Policy periodically. Your continued use of our Services after any changes constitutes your acceptance of the updated policy.

↑ Back to top

18. Business Transfers

In the event that Exequtech is involved in a merger, acquisition, reorganisation, sale of assets, or similar business transaction, your personal information may be transferred as part of that transaction. In such circumstances:

↑ Back to top

19. Limitation of Liability & Warranty Disclaimer

19.1 Warranty Disclaimer

Our Services are provided “as is” and “as available” without warranties of any kind, whether express or implied, to the fullest extent permitted by applicable South African law, including the Consumer Protection Act, 2008 (Act No. 68 of 2008) (“CPA”). We do not warrant that the Services will be uninterrupted, error-free, or free of harmful components.

19.2 Limitation of Liability

To the maximum extent permitted by law, Exequtech shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising out of or related to your use of the Services, including but not limited to loss of data, loss of profits, or business interruption.

Nothing in this section excludes or limits liability for:

19.3 Indemnification

You agree to indemnify and hold harmless Exequtech, its directors, employees, and agents from and against any claims, damages, losses, or expenses (including reasonable legal fees) arising from your misuse of the Services or violation of this Privacy Policy, to the extent permitted by applicable law.

↑ Back to top

20. Governing Law & Jurisdiction

This Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of South Africa, including POPIA, ECTA, and the CPA where applicable.

Any dispute arising out of or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of the Republic of South Africa.

↑ Back to top

21. Information Regulator

If you are dissatisfied with our handling of your personal information, you have the right to lodge a complaint with South Africa’s Information Regulator:

The Information Regulator (South Africa)

Physical Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg

Postal Address: P.O. Box 31533, Braamfontein, Johannesburg, 2017

Telephone: 010 023 5200

General Enquiries: enquiries@inforegulator.org.za

POPIA Complaints: POPIAComplaints@inforegulator.org.za

↑ Back to top

22. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our processing of your personal information, please contact us:

Exequtech

Email: support@exequtech.com

We will endeavour to respond to all enquiries within a reasonable timeframe.

↑ Back to top