1. Purpose
POPIA establishes conditions for the lawful processing of personal information by public and private bodies in South Africa. This notice summarizes how GeoLayers applies those principles across website, account, project, subscription, API, support and administrative activities.
Supplier and operator information
| Service / trading name | GeoLayers.co.za |
|---|---|
| Legal operator | Glory Mulopo |
| Physical business address | Roodepoort, Johannesburg |
| Website | https://geolayers.co.za/ |
| info@geolayers.co.za | |
| Telephone | +27 74 379 6476 |
2. POPIA conditions for lawful processing
GeoLayers' data-protection programme is organized around the eight POPIA conditions:
- Accountability — the responsible party remains accountable for compliance and for appropriate oversight of operators.
- Processing limitation — processing should be lawful, reasonable, proportionate and based on an appropriate ground.
- Purpose specification — personal information should be collected for specific, defined purposes and retained only as long as justified.
- Further processing limitation — later use should remain compatible with the original purpose or otherwise be lawfully justified.
- Information quality — reasonable steps should be taken to keep personal information complete, accurate, not misleading and updated where necessary.
- Openness — processing should be transparent and data subjects should receive the information required by law.
- Security safeguards — appropriate technical and organizational measures should protect personal information against loss, damage and unauthorized access or processing.
- Data-subject participation — data subjects should be able to exercise applicable access, correction, deletion and objection rights.
3. Categories of personal information
GeoLayers may process account identifiers, contact details, organization membership, billing and subscription metadata, project/collaboration metadata, support communications, service logs, IP/device information, API/developer metadata, analytics information and any personal information intentionally contained in user-uploaded project data.
The detailed categories and purposes are described in the Privacy Policy.
4. Responsible-party and operator roles
For GeoLayers' own account, subscription, security, marketing and platform-administration data, the GeoLayers operator is generally the responsible party. For customer-controlled project content, an organization customer may determine the purpose and means of processing and GeoLayers may act as an operator.
Where GeoLayers appoints operators, it seeks to use contractual and security measures appropriate to POPIA, including confidentiality and security obligations where required.
5. Lawful grounds and purpose limitation
GeoLayers processes personal information only where there is an appropriate legal basis under POPIA, such as consent, contractual necessity, legal obligation, protection of legitimate interests of the data subject, or legitimate interests of GeoLayers or a third party as permitted by law.
GeoLayers does not intentionally repurpose private project data for unrelated public use. A user must deliberately activate publishing, sharing, public API or marketplace functions before project content is made public through those features.
6. Special personal information and children's information
Users should not upload special personal information or children's personal information unless they have lawful authority and the relevant project controls, agreements and safeguards are appropriate. Where prior authorization or another regulatory step is required, the responsible party for that processing remains responsible for completing it.
7. Security safeguards
GeoLayers applies safeguards that may include HTTPS/TLS, authenticated access, role and project permissions, restricted secret handling, public/private data separation, audit evidence, security logging, rate limits, backups and recovery controls.
Users and organization administrators must configure sharing, collaborators, API publication and public links carefully and protect their credentials.
8. Security compromises
Where GeoLayers has reasonable grounds to believe personal information has been accessed or acquired by an unauthorized person, it will assess the incident and make notifications required by section 22 of POPIA, subject to any lawful delay requested by authorities. Customers acting as responsible parties may also have notification obligations and should promptly report suspected project-data incidents to GeoLayers.
9. Data-subject participation
A data subject may, subject to POPIA and verification requirements, request access to personal information, correction or deletion, object to qualifying processing and withdraw consent where applicable. Requests may be submitted to info@geolayers.co.za with the subject POPIA Request.
Formal access-to-record requests may also be made under the PAIA Manual.
10. Direct marketing
Unsolicited electronic marketing is handled in accordance with applicable POPIA requirements. Promotional communications should include a practical opt-out mechanism. GeoLayers may still send non-marketing communications required to operate an account, subscription, security process or support request.
11. Automated decision-making and GeoAI
GeoLayers provides AI-assisted and predictive tools for decision support. GeoLayers does not position those outputs as a substitute for human review, authoritative source verification or statutory decision-making. Customers using GeoLayers to make decisions about individuals are responsible for assessing whether POPIA section 71 or other sector-specific rules apply to their use case.
See the Responsible GeoAI Notice.
12. Cross-border transfers
Where personal information is transferred outside South Africa, GeoLayers seeks to rely on a mechanism permitted by section 72 of POPIA, such as adequate protection under law or binding agreement, consent, contractual necessity or another permitted basis.
13. Information Officer and complaints
The Information Officer for the GeoLayers operator is identified in the Supplier and Operator Information table above. Privacy and POPIA correspondence can be sent to info@geolayers.co.za.
A data subject may also complain to the Information Regulator (South Africa). Current contact channels are published at inforegulator.org.za, including enquiries@inforegulator.org.za and 010 023 5200.
14. Relationship with other documents
This notice should be read with the Privacy Policy, Cookie Policy, PAIA Manual, Terms of Service and any organization-specific Data Processing Addendum or enterprise agreement.