Privacy Policy & POPIA Notice
Protection of Personal Information Act (Act No. 4 of 2013) • Promotion of Access to Information Act (Act No. 2 of 2000) • Companies Act 71 of 2008
Statutory Responsible Party Particulars (Section 18 POPIA)
Official corporate registration & statutory domicile under the Companies Act 71 of 2008
01. Legislative Scope & Definitions
This statutory Privacy Policy and POPIA Compliance Manual constitutes the formal regulatory disclosure of VAULTCORE SOLUTIONS (PTY) LTD ("VaultCore", "the Company", "the Responsible Party", "we", "us", or "our") pursuant to:
- Section 14 of the Constitution of the Republic of South Africa, 1996 (the fundamental constitutional right to personal privacy);
- The Protection of Personal Information Act No. 4 of 2013 ("POPIA");
- The Promotion of Access to Information Act No. 2 of 2000 ("PAIA");
- The Electronic Communications and Transactions Act No. 25 of 2002 ("ECTA");
- The Cybercrimes Act No. 19 of 2020; and
- The Companies Act No. 71 of 2008.
"Data Subject" means the natural or juristic person to whom personal information relates, including institutional partners, licensees, enterprise researchers, and website visitors.
"Personal Information" has the meaning assigned to it in Section 1 of POPIA.
"Processing" means any operation or activity concerning personal information, whether automated or not.
"Operator" means a person or entity that processes personal information on behalf of a responsible party in terms of a formal contract or mandate.
02. Pure IP Entity Positioning & Ecosystem Boundaries
VaultCore Solutions (Pty) Ltd operates strictly as a deep-technology research, development, and intellectual property holding entity. Our activities encompass the architectural design, security hardening, and source-code licensing of applied cryptographic software, zero-knowledge proof engines, and the LifeLink emergency response platform.
Important Jurisdictional & Operational Demarcation:
1. No Consumer Retail Operations: VaultCore Solutions does not operate consumer-facing emergency dispatch rooms, nor do we provide direct retail consumer subscriptions or public call centers. All end-user operational relationships, consumer onboarding, field emergency networks, and direct regulatory subscriber reporting sit exclusively with qualified operating licensees, such as Mind Haven Innovations (Pty) Ltd.
2. Parent Governance: VaultCore Solutions is a subsidiary of Horizon Strategic Group (Pty) Ltd, which provides capital allocation, risk governance, and group fiduciary oversight.
03. Lawful Grounds for Processing (Section 11 POPIA)
In accordance with Section 11(1) of POPIA, VaultCore processes personal information only where one or more of the following statutory grounds apply:
- Contractual Performance (Section 11(1)(b)): Processing is necessary to conclude or execute software licensing agreements, evaluation NDAs, developer master agreements, or maintenance contracts with licensees.
- Statutory & Legal Obligation (Section 11(1)(c)): Compliance with statutory duties under the Companies Act 71 of 2008, the Tax Administration Act 28 of 2011 (statutory retention of invoices and corporate ledgers for 5 years), and reporting under the Cybercrimes Act 19 of 2020.
- Legitimate Interests of the Responsible Party (Section 11(1)(f)): Protecting proprietary intellectual property, preventing unauthorized software decompilation or breach of cryptographic covenants, and maintaining network and infrastructure security.
- Explicit Consent (Section 11(1)(a)): Where an institutional partner has explicitly requested technical whitepapers, architectural advisories, or product demonstrations.
04. Categories of Personal Information Processed
Subject to the Principle of Minimality (Section 10 of POPIA), we collect and process only the minimum information necessary for technology licensing and enterprise operations:
A. Enterprise & Licensee Identity
Full names, corporate designation, corporate email address, business telephone number, corporate registration documentation (CIPC CoR 14.3 / CoR 15.2), and authorized signatory credentials.
B. Developer & Technical Telemetry
Public cryptographic keys, SSH deployment credentials, API authentication tokens, source IP addresses, client HTTP user agents, and cryptographic checksums generated during reproducible build audits.
C. Inquiries & Legal Correspondence
Information transmitted through contact forms or direct engineering correspondence regarding licensing evaluation, cryptographic audit inquiries, and technical advisory requests.
05. Special Personal Information: On-Device Biometric Invariant (Sections 26 & 32 POPIA)
Section 26 of POPIA strictly restricts the processing of special personal information, including biometric data, unless authorized by law or subject to specific statutory exemptions.
The proprietary LifeLink emergency software platform developed by VaultCore incorporates 6-modality neural biometric authentication (face, fingerprint, iris, ear, foot, and hand).
Under VaultCore's strict architectural mandate:
- Zero Central Storage: Raw biometric image files, acoustic samples, and raw feature vectors NEVER leave the user's local mobile device.
- Local Neural Inference: All biometric feature extraction and quality gate evaluations (≥ 0.60 threshold) run strictly inside isolated on-device machine learning environments via TFLite.
- Zero-Knowledge Commitments: Only mathematical SHA-256 cryptographic commitments and zero-knowledge validity proofs are generated. VaultCore servers and licensee dispatch nodes never receive, process, or store raw biometric templates.
06. Compliance with the 8 Conditions for Lawful Processing
VaultCore's engineering and corporate procedures strictly enforce the eight statutory conditions of Chapter 3 of POPIA:
1. Accountability (Sec 8)
Continuous internal oversight, technical controls, and cryptographic audit trails to verify compliance.
2. Processing Limitation (Sec 9–12)
Processing is limited to lawful, minimal, and non-infringing operations obtained directly where possible.
3. Purpose Specification (Sec 13–14)
Data is gathered solely for clearly defined, explicit, and lawful software engineering and corporate purposes.
4. Further Processing Limitation (Sec 15)
Secondary processing is strictly prohibited unless compatible with the original collection purpose.
5. Information Quality (Sec 16)
Reasonable measures are maintained to verify that records remain accurate, complete, and up to date.
6. Openness (Sec 17–18)
Transparent disclosure through this statutory notice and explicit contract disclosures with licensees.
7. Security Safeguards (Sec 19–22)
State-of-the-art cryptography, zero-knowledge proofs, and automated breach alerting protocols.
8. Data Subject Participation (Sec 23–25)
Enforceable mechanisms for data subjects to inspect, rectify, or request deletion of their records.
07. Operators & Cross-Border Data Transfers (Section 72 POPIA)
We do not sell, rent, or trade personal data. We engage authorized third-party Operators strictly under binding Data Processing Agreements ensuring compliance with Section 72 of POPIA:
- Cloud Hosting & Server Infrastructure: Production backend nodes on VPS `213.199.52.198` and Truehost cPanel clusters (`das128.truehost.cloud`) operating with verified SSL/TLS endpoint security.
- Object Storage (MinIO): Encrypted asset and build artifact storage located at `storage.vaultcore.co.za`.
- Distributed Ledger Anchors: Immutable zero-knowledge verification commitments anchored to Hyperledger Fabric 2.5 and Polygon public ledger contracts.
08. Security Safeguards & Breach Protocol (Sections 19–22)
In compliance with Section 19 of POPIA, VaultCore employs institutional-grade technical security measures:
TLS 1.3 encryption in transit, AES-256-GCM encryption for storage, hardware-anchored key vaults, and SHA-256 integrity commitments.
Reproducible builds, software bill of materials (SBOM) generation, cryptographically signed release tags, and automated vulnerability audits.
Section 22 Breach Response Protocol: In the event of a suspected or confirmed compromise involving personal information, VaultCore will immediately notify the Information Regulator of South Africa and affected parties in writing, outlining the scope of the incident, probable consequences, and corrective remediation.
09. Retention & Destruction of Records (Section 14)
Personal data is retained only for the minimum period necessary to fulfill its statutory and contractual purposes:
- Corporate & Licensing Contracts: Retained for seven (7) years following agreement termination in terms of Section 24 of the Companies Act 71 of 2008.
- Financial & Invoicing Records: Retained for five (5) years in compliance with Section 29 of the Tax Administration Act 28 of 2011.
- System Diagnostics & Telemetry: Retained on rolling loops of 90 to 180 days before automated deletion or cryptographic aggregation.
- Secure Destruction: Expired digital records are sanitized via cryptographically irreversible overwrite routines; physical documents are cross-shredded.
10. Data Subject Rights & Access Procedures
Under Sections 23, 24, and 25 of POPIA and the provisions of PAIA, data subjects possess enforceable statutory rights:
- Right to Inquire & Access: Confirm whether we hold personal records and request copies thereof via formal PAIA Form 2.
- Right to Rectification: Request correction or update of inaccurate, outdated, or incomplete personal data.
- Right to Erasure: Request deletion or destruction of records where no statutory justification for retention persists.
- Right to Object: Formally object to processing on reasonable grounds (Form 1 of the POPIA Regulations).
Designated Information Officer Formal Contact Channel
All formal statutory requests, notices, or PAIA access applications must be directed in writing to:
11. Direct Marketing & Cookie Policy (Section 69 POPIA)
VaultCore Solutions enforces a strict zero-spam protocol. We do not engage in consumer electronic direct marketing. We correspond only with institutional representatives who have requested technical material or who maintain an ongoing licensing relationship with us.
Website Tracking & Cookies: Our website uses minimal, strictly essential operational cookies to preserve user interface preferences and maintain security sessions. We do not deploy third-party advertising tracking pixels or commercial ad retargeting networks.
12. Information Regulator of South Africa
While we encourage data subjects to direct any questions or grievances to our Information Officer first, you have the statutory right under Section 74 of POPIA to lodge a complaint with the South African Information Regulator:
The Information Regulator (South Africa)
Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Postal Address: P.O. Box 31533, Braamfontein, Johannesburg, 2017
General Inquiries: [email protected]
POPIA Complaints: [email protected]
PAIA Complaints: [email protected]
Official Portal: https://inforegulator.org.za/