Privacy Policy
Effective from 1 September 2026
- Responsible Party
- Applying.co.za
- Information Officer
- The Information Officer
- Enquiries
- Contact form
1. Introduction and Statutory Framework
1.1This Privacy Policy governs the processing of Personal Information by Applying.co.za, in its capacity as a Responsible Party, in accordance with the Protection of Personal Information Act, 4 of 2013 (“POPIA”) and the Promotion of Access to Information Act, 2 of 2000 (“PAIA”).
1.2This Policy sets out the categories of Personal Information collected, the purposes for which it is processed, the periods for which it is retained, and the rights available to Data Subjects.
1.3Capitalised terms bear the meanings assigned to them in POPIA unless the context indicates otherwise.
2. Categories of Personal Information
2.1Job seekers. Account credentials comprising an email address and a cryptographically hashed password; search preferences including role categories and location filters; and technical telemetry including IP addresses, browser identifiers and timestamp logs.
2.2Employers. Identity data comprising the full name and business email address of the account holder; entity data comprising the company name and, where provided, registration and value-added tax particulars; and billing details where a paid service is procured.
2.3Aggregated vacancies. The Platform indexes job announcements published on publicly accessible career portals and applicant tracking systems. The Platform does not index, access or process applicant records or non-public employer databases.
3. Purpose and Lawful Basis of Processing
3.1Personal Information is processed only for the specified, explicitly defined and lawful purposes set out below, as contemplated in section 11 of POPIA.
| Purpose | Categories of data | Lawful basis |
|---|---|---|
| Account creation and authentication | Email address, hashed password | Consent; performance of a contract |
| Delivery of vacancy alerts | Email address, search preferences | Consent (express opt-in) |
| Employer registration and service delivery | Business contact and entity data | Performance of a contract |
| Platform security, auditing and abuse prevention | IP addresses, access and audit logs | Legitimate interests of the Responsible Party |
| Invoicing, accounting and tax compliance | Employer billing records | Legal obligation (Tax Administration Act, 28 of 2011) |
3.2Personal Information is not processed for any further purpose incompatible with those listed above without the prior consent of the Data Subject.
4. Retention and Destruction of Records
4.1Records of Personal Information are not retained for longer than is necessary to achieve the purpose for which they were collected, save where a longer period is required or permitted by law, as contemplated in section 14 of POPIA.
| Category of record | Retention period | Method of destruction |
|---|---|---|
| Inactive job seeker accounts | 24 months from date of last sign-in | Permanent deletion or irreversible anonymisation |
| Vacancy alert subscriptions | Until withdrawal of consent | Removal from distribution lists upon unsubscribe |
| Aggregated public vacancies | 90 days following expiry, for labour market analysis | Deletion, or removal of identifying metadata |
| Employer financial records | 5 years from the end of the relevant financial year | Secure archival until statutory period lapses, then deletion |
| Server, security and audit logs | 90 days | Automated rolling truncation |
5. Transborder Flows of Personal Information
5.1The Platform is hosted on cloud infrastructure operated by third-party processors. Personal Information may accordingly be transmitted to and stored on servers situated outside the Republic of South Africa.
5.2Such transfers are effected only in accordance with section 72 of POPIA, and only to recipients situated in jurisdictions subject to a law or binding agreement that upholds principles for the lawful processing of Personal Information substantially similar to those contained in POPIA.
5.3Each processor is engaged under a written agreement obliging it to process Personal Information only on documented instruction and to maintain appropriate security measures.
6. Cookies, Advertising and Analytics
6.1Strictly necessary cookies. The Platform sets a session cookie upon authentication in order to maintain a signed-in session. This cookie is essential to the provision of the service, is not used for advertising or profiling, and expires when the browser session ends.
6.2Advertising. The Platform displays advertising supplied by Google AdSense, a service operated by Google LLC. Where advertising is served, Google may process the Internet Protocol address, device and browser characteristics, and pages viewed on the Platform, and may set cookies or comparable identifiers on the device.
6.3Consent. No advertising request is made until the data subject has responded to the preference prompt displayed on first visit. Where consent is refused, advertising continues to be displayed but is selected on the basis of the content of the page rather than on any profile of the data subject.
6.4Withdrawal of consent. In accordance with section 11(2)(b) of POPIA, a data subject may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal. Advertising preferences may be revisited at any time by means of the “Advertising preferences” control in the footer of every page.
6.5Google LLC processes such information as an independent responsible party under its own privacy terms. Information regarding that processing, and controls over the advertising Google serves, are published by Google at policies.google.com/technologies/partner-sites.
6.6The Platform does not sell Personal Information, and does not disclose Personal Information to advertisers for the purpose of enabling them to identify a data subject.
7. Security Safeguards
7.1The Platform maintains appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unauthorised destruction of Personal Information, and unlawful access to or processing of Personal Information, as required by section 19 of POPIA.
7.2These measures include encryption of data in transit by means of Transport Layer Security; encryption of data at rest; one-way cryptographic hashing of authentication credentials; rate limiting and account lockout on authentication endpoints; audit logging of security-relevant events; and role-based access control.
7.3Where there are reasonable grounds to believe that Personal Information has been accessed or acquired by an unauthorised person, the Information Regulator and the affected Data Subjects will be notified in accordance with section 22 of POPIA.
8. Rights of Data Subjects
8.1Access. A Data Subject may request confirmation of whether the Platform holds Personal Information concerning them, and may request the record or a description of that information, as contemplated in section 23 of POPIA.
8.2Correction and deletion. A Data Subject may request the correction or deletion of Personal Information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, as contemplated in section 24 of POPIA.
8.3Objection. A Data Subject may object, on reasonable grounds relating to their particular situation, to the processing of their Personal Information, as contemplated in section 11(3) of POPIA.
8.4Withdrawal of consent. Where processing is based on consent, that consent may be withdrawn at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
8.5Requests under this clause must be submitted through the contact form, selecting the data request category. The Platform may require verification of identity before giving effect to a request.
9. Complaints to the Information Regulator
9.1A Data Subject who is of the view that their Personal Information has been processed in contravention of POPIA may lodge a complaint with the Information Regulator of South Africa at the following particulars:
- Address
- JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
- POPIAComplaints@inforegulator.org.za
- Website
- inforegulator.org.za
10. Amendment of this Policy
10.1This Policy may be amended from time to time. The version in force is the version published on the Platform, and the effective date appears at the head of this document.
10.2Where an amendment materially affects the manner in which Personal Information is processed, registered users will be notified before the amendment takes effect.