Our commitment
CRESA is committed to full compliance with the Protection of Personal Information Act 4 of 2013 (POPIA). This statement explains how we give effect to the eight conditions for lawful processing of personal information.
1. Accountability
CRESA takes responsibility for ensuring that all personal information processed through our platform is handled in compliance with POPIA. Our Information Officer is responsible for overseeing compliance and can be contacted at privacy@cresa.co.za.
2. Processing limitation
We collect only the personal information that is necessary for the specific purpose for which it is collected. We do not process personal information in ways that are incompatible with the purpose for which it was collected.
3. Purpose specification
Personal information is collected for clearly defined purposes: account registration and authentication, publication of consumer experiences with consent, generation of formal complaint letters, processing of EFT payments, operation of the expert directory and jobs board, and delivery of transactional and alert emails.
4. Further processing limitation
We do not use personal information collected for one purpose for any other incompatible purpose without your consent.
5. Information quality
We take reasonable steps to ensure that personal information is accurate, complete, and up to date. You can update your account information at any time through your dashboard.
6. Openness
We inform you at the point of collection what personal information we collect and why. Our Privacy Policy and this statement are publicly available on our website at all times.
7. Security safeguards
We implement appropriate technical and organisational measures to protect personal information. These include encrypted data storage, private storage buckets for sensitive documents, role-based access controls ensuring users can only access their own data, and password security measures including checking against known data breach databases.
8. Data subject participation
You have the right to request access to your personal information held by CRESA, request correction of inaccurate information, request deletion of your information, and object to the processing of your information. To exercise any of these rights contact privacy@cresa.co.za. We will respond within 30 days.
Complaints to the Information Regulator
If you believe we have processed your personal information in violation of POPIA you have the right to lodge a complaint with the Information Regulator of South Africa. Contact details: enquiries@inforegulator.org.za or visit www.justice.gov.za/inforeg.
Special categories of information
CRESA does not intentionally collect special categories of personal information including health information, financial account numbers, or identity numbers. If you include such information in a complaint submission you do so voluntarily. We recommend you do not include your ID number, bank account number, or full financial account details in any public submission.