Legal
Privacy Policy
How we collect, use and protect personal information, and the rights you have under the Protection of Personal Information Act (POPIA).
Last updated 10 September 2026
Are you an employee or a job applicant?
If you are using Xinnace because your employer (or a company you applied to) uses it to run their HR, payroll or recruitment, then that company, not Xinnace, decides how your information is used. In POPIA terms they are the Responsible Party and Xinnace is their Operator: we only store and process that information on their instructions, and we never use it for our own purposes.
So if you want to see, correct or delete your employee or application information, please contact that company directly, as they are the ones who can action it. If you are not sure who to ask, write to us at privacy@xinnace.com and we will point you to the right place.
1. Who we are
Xinnace (Pty) Ltd (“Xinnace”, “we”, “us”) provides a people platform for South African organisations, covering HR, attendance, recruitment and payroll-ready data. Registration number 2025/316516/07. Registered address: 22 Umhlanga Boulevard, Umhlanga, KwaZulu-Natal, 4321, South Africa.
This policy explains what we do with personal information where Xinnace itself is the Responsible Party: chiefly enquiries made through this website and the accounts of our customers. It does not describe what our customers do with their own people’s data (see the note above).
2. What we collect, and why
When you contact us through this website
Our contact form asks for your name, work email address, company name, company size and, optionally, your phone number and a message. We also automatically record your IP address and browser user-agent with the submission.
We use this to respond to your enquiry, to prepare for a conversation about your organisation’s needs, and to keep an internal record of the enquiry. Submitting the form triggers an automated acknowledgement email to you, and a notification to our team. Providing this information is voluntary, but without at least a name and email address we cannot reply to you.
When you become a customer
We hold the account details of the people who administer your workspace: name, work email address, a securely hashed password, and records of sign-ins and actions taken in the system (audit logs). We use these to provide the service, secure the account, support you, and bill you.
Data we process on our customers’ behalf
Our customers use Xinnace to process personal information about their own employees, job applicants and referred candidates, typically including:
- full name and surname, employee code or staff number;
- contact details;
- gender and race, collected for employment equity and transformation reporting;
- South African ID number (or equivalent identification number);
- disability status;
- education and qualification records;
- performance management records, ratings and coaching notes;
- absence records, and health-related information where the employer’s own process records it — for example a return-to-work file noting that a medical certificate was produced, who signed it and the days it books off, and, where the employer chooses to keep copies, the certificate itself;
- attendance and shift records: clock-in and clock-out times, break and status changes, and the roster the employee is scheduled against;
- where the employer switches on the Xinnace Time Tracker browser extension, the activity signals described under the browser extension below;
- payment and remuneration information, including banking details where processed for payroll.
We process that data only as an Operator, on their instructions and under a written agreement, and we do not use it for our own purposes.
The Xinnace Time Tracker browser extension
Some of our customers ask their employees to install the Xinnace Time Tracker, a browser extension that lets a person clock in, change status, take a break and clock out without going back to the Xinnace tab. Because it runs in the browser rather than on a page of ours, it is worth setting out separately what it does and does not do.
While an employee is signed in to it, the extension sends the following to their employer’s Xinnace workspace:
- Clock-in, clock-out, break and status events — the actions the employee takes in the widget itself.
- A presence signal roughly every 30 seconds, so the employer’s floor view can show who is currently working. The IP address the signal arrives from is recorded with it.
- Screen lock and idle transitions, reported by the browser, used to measure adherence. The extension is told only that the screen locked or went idle; it cannot see what is on it.
- Counts of clicks and keystrokes, batched about once a minute. These are numbers only: how many, never which. The extension does not record which keys were pressed, and does not capture what an employee types, their passwords, their messages or the contents of any page.
- Page addresses and titles, only if the employer has switched that on. See the next paragraph.
Whether page addresses are collected at all is a setting the employer chooses, and it has three positions. On off, no address or page title is ever stored, only the counts. On workspace only, addresses are kept only for pages on that employer’s own Xinnace workspace, and anything else is discarded. On all sites, addresses and page titles are kept for other websites too. The choice is enforced on our servers, not in the extension, so it cannot be overridden by altering the software on an employee’s machine.
What the published extension actually sends today. The release currently on the browser stores attaches a page address and title only on the employer’s own Xinnace workspace pages, whatever the workspace has been set to. All sites is a server-side position that a later release of the extension would send for; while the present release is the one installed, choosing it collects nothing beyond the workspace addresses. If that changes, this policy will say so before the release goes out, and an employer choosing all sites should tell its employees what it means before it takes effect.
The extension does not read, alter or transmit the content of the web pages an employee visits. It has no access to passwords, form contents, banking sessions, private messages or anything else on the page. It does not sell or share any of this data with third parties, and it is never used for advertising, profiling for advertising purposes, or for any purpose other than the attendance and adherence reporting the employer uses Xinnace for.
All of the above is processed by us as an Operator on the employer’s instructions. The employer decides whether to require the extension at all, which of these settings apply, and how long the records are kept. An employee who wants to know what is being collected about them, or who objects to it, should raise it with their employer, who is the Responsible Party; we will help them find the right contact if they are not sure. The extension can be removed from the browser by the employee at any time, though we would expect that to be a conversation with their employer first, since attendance may be recorded through it.
Technical information
Our servers keep standard logs (IP address, request time, pages requested) for security and troubleshooting. This website sets a single, strictly necessary session cookie used to protect forms against cross-site request forgery. We do not currently run third-party advertising or analytics trackers on this site.
This website does load its two typefaces from Google Fonts. That is a request your browser makes to Google when the page opens, so Google receives your IP address and basic browser details in order to serve the font files. Google states that it does not use these requests to build advertising profiles, and no cookie is set by them for this. It is the only third-party request this site makes, and we set no cookie and run no script on the strength of it.
3. Special personal information
Race, disability status, health information and, in some contexts, ID numbers are treated as special personal information under POPIA, which may only be processed where a specific justification applies. For data we process on a customer’s behalf, that justification is generally:
- compliance with the Employment Equity Act and the reporting obligations it places on employers;
- reasonable accommodation and workplace support relating to disability;
- the data subject’s consent, obtained by the employer; or
- establishing, exercising or defending a right in law.
We process this information strictly as instructed by the relevant customer, and never for a purpose of our own.
Health information and medical certificates
Sick absence is health information, and a medical certificate is the most sensitive form it takes. The platform is built so that an employer need never store one. A return-to-work file can record that a certificate was produced and checked — who signed it, their registration number, and the days it books off — without a copy of the certificate being uploaded at all, and each workspace has a setting that switches certificate uploads off entirely, after which the platform refuses them.
Where a customer does keep copies, they are stored outside the web root, are never served inline, and are released only to a signed-in user who holds the specific permission and whose access to that employee has been checked on the request. Whether to hold certificates at all, and for how long, is the customer’s decision as responsible party; our role is to make “not at all” a workable one.
4. On what basis we process it
We process personal information to provide and maintain the platform, help customers meet their statutory HR, payroll, employment equity and skills development reporting obligations, administer accounts and access, communicate about the service, keep it secure and auditable, respond to enquiries, and meet our own legal obligations.
Depending on the situation, we rely on your consent (for example, when you tick the box on a form), on the performance of a contract with you or your employer, on compliance with a legal obligation, or on our legitimate interests in operating, securing and improving our business, balanced against your rights. Throughout, we follow POPIA’s eight conditions for lawful processing: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation.
5. Who we share it with
We do not sell your personal information. We share it only with:
- your employer, who determines how your information on the platform is used;
- hosting: Afrihost, which runs our application and databases on a dedicated server in a South African data centre;
- backups: Amazon Web Services, which stores encrypted off-site copies of our databases and uploaded files in its Cape Town region, encrypted before they reach it;
- email: Google Workspace, which carries both our own mailboxes and the platform’s outbound system email;
- website fonts: Google Fonts, which receives the IP address and browser details of anyone loading a page on this website, in order to deliver the typefaces;
- professional advisors: our lawyers, auditors and accountants, where necessary, each bound to confidentiality;
- regulators or law enforcement, where the law requires it.
Each service provider is bound to protect your information and use it only for the purpose we have engaged them for. We may also disclose information to establish, exercise or defend a legal claim.
Information leaving South Africa
Some of these providers, notably Google, may store or process information outside South Africa. Where that happens, we take reasonable steps to ensure the recipient is subject to laws, binding rules or contractual terms that provide an adequate level of protection, as POPIA requires.
6. How long we keep it
We keep enquiry and customer information only for as long as it is needed for the purpose it was collected for, or for as long as the law requires us to. When it is no longer needed, we delete it or de-identify it. Data we hold as an Operator is retained according to our customer’s instructions and their own retention policy. Where information is deleted, copies may persist in encrypted backups for up to 90 days before those backups expire on their retention schedule.
7. How we protect it
We use encrypted connections (HTTPS/TLS), hashed passwords, role-based access controls, audit logging, and access restrictions so that staff only reach information they need. No system is perfectly secure, but if a breach affects your personal information we will notify you and the Information Regulator as POPIA requires. Our Security page sets out the controls in more detail.
8. Your rights
Under POPIA you have the right to:
- be notified that your personal information is being collected;
- ask what personal information we hold about you, and request a copy;
- ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained;
- object to our processing of your information on reasonable grounds;
- withdraw consent you have given us (this does not affect processing already carried out);
- complain to the Information Regulator.
To exercise any of these, write to our Information Officer at privacy@xinnace.com. We may need to verify your identity before we act, and we will respond within a reasonable time.
9. Complaining to the Regulator
If you are unhappy with how we have handled your information, you can lodge a complaint with:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
POPIA complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries.IR@justice.gov.za
inforegulator.org.za
10. Access to information (PAIA)
You also have rights of access to records under the Promotion of Access to Information Act. Requests can be sent to our Information Officer at the address below, and our PAIA Manual explains the procedure.
11. Changes to this policy
We may update this policy from time to time. The date at the top of this page shows when it was last changed, and material changes will be communicated to customers directly.
12. Contact us
Information Officer: Poobalan Soobramoney, Chief Executive Officer
Xinnace (Pty) Ltd
privacy@xinnace.com
22 Umhlanga Boulevard
Umhlanga, KwaZulu-Natal, 4321
South Africa
Questions about this document? Email privacy@xinnace.com.
Contact us