Skip to content
GeoLayers
GeoLayers StudioThe complete browser-based spatial workspaceFeaturesGIS, planning, analysis and publishingGeoAIGoverned AI for spatial workEarth ObservationRaster and satellite intelligenceGeoMLPredictive spatial analyticsMobility & LogisticsRouting, accessibility and logistics3D & Digital Twins3D scenes and operational simulationDesign & PublishingCartography, layouts and storiesApps & DashboardsNo-code spatial experiencesSpatial AutomationWorkflow orchestration and integrations
SolutionsSpatial workflows by sectorGovernmentPublic-sector spatial intelligenceTown PlanningEvidence-led planning workflowsEnvironmentMonitoring, screening and sustainabilityInfrastructureAssets, capacity and resilienceLogisticsNetworks, routing and accessibilityAgricultureEarth observation and spatial planningReal EstateSite intelligence and development planningResearch & EducationTeaching, research and reproducible GIS
DataSpatial data ecosystemDatasetsCurated GIS data resourcesMarketplaceMaps and spatial products
Developer PlatformAPIs, SDKs and OGC servicesDocumentationDeveloper and platform documentationEnterpriseAdministration, governance and reliabilityTrust CentreSecurity, privacy and platform controls
ResourcesGuides, learning and product knowledgeBlogGIS and spatial intelligence articlesCase StudiesApplied GeoLayers workflowsLearning CentreStep-by-step GeoLayers tutorialsReleasesProduct release historyFAQsCommon platform questionsSupportHelp and platform support
Pricing
GeoLayers Studio →
Home›Legal Centre›POPIA & Data Protection Notice
LEGAL & POLICY

POPIA & Data Protection Notice

This notice explains how GeoLayers approaches the Protection of Personal Information Act 4 of 2013 (POPIA) and should be read with the Privacy Policy and PAIA Manual.

Effective: 21 September 2026Last updated: 21 September 2026
GeoLayers Legal Centre
Legal CentrePrivacy PolicyPOPIA NoticePAIA ManualTerms of ServiceCookie PolicyAcceptable UseSubscription TermsRefund & CancellationMarketplace TermsDeveloper & API TermsData LicensingResponsible GeoAICopyright & IPDisclaimerAccessibility Statement
On this page1. Purpose2. POPIA conditions for lawful processing3. Categories of personal information4. Responsible-party and operator roles5. Lawful grounds and purpose limitation6. Special personal information and children's information7. Security safeguards8. Security compromises9. Data-subject participation10. Direct marketing11. Automated decision-making and GeoAI12. Cross-border transfers13. Information Officer and complaints14. Relationship with other documents

1. Purpose

POPIA establishes conditions for the lawful processing of personal information by public and private bodies in South Africa. This notice summarizes how GeoLayers applies those principles across website, account, project, subscription, API, support and administrative activities.

Supplier and operator information

Service / trading nameGeoLayers.co.za
Legal operatorGlory Mulopo
Physical business addressRoodepoort, Johannesburg
Websitehttps://geolayers.co.za/
Emailinfo@geolayers.co.za
Telephone+27 74 379 6476

2. POPIA conditions for lawful processing

GeoLayers' data-protection programme is organized around the eight POPIA conditions:

  1. Accountability — the responsible party remains accountable for compliance and for appropriate oversight of operators.
  2. Processing limitation — processing should be lawful, reasonable, proportionate and based on an appropriate ground.
  3. Purpose specification — personal information should be collected for specific, defined purposes and retained only as long as justified.
  4. Further processing limitation — later use should remain compatible with the original purpose or otherwise be lawfully justified.
  5. Information quality — reasonable steps should be taken to keep personal information complete, accurate, not misleading and updated where necessary.
  6. Openness — processing should be transparent and data subjects should receive the information required by law.
  7. Security safeguards — appropriate technical and organizational measures should protect personal information against loss, damage and unauthorized access or processing.
  8. Data-subject participation — data subjects should be able to exercise applicable access, correction, deletion and objection rights.

3. Categories of personal information

GeoLayers may process account identifiers, contact details, organization membership, billing and subscription metadata, project/collaboration metadata, support communications, service logs, IP/device information, API/developer metadata, analytics information and any personal information intentionally contained in user-uploaded project data.

The detailed categories and purposes are described in the Privacy Policy.

4. Responsible-party and operator roles

For GeoLayers' own account, subscription, security, marketing and platform-administration data, the GeoLayers operator is generally the responsible party. For customer-controlled project content, an organization customer may determine the purpose and means of processing and GeoLayers may act as an operator.

Where GeoLayers appoints operators, it seeks to use contractual and security measures appropriate to POPIA, including confidentiality and security obligations where required.

5. Lawful grounds and purpose limitation

GeoLayers processes personal information only where there is an appropriate legal basis under POPIA, such as consent, contractual necessity, legal obligation, protection of legitimate interests of the data subject, or legitimate interests of GeoLayers or a third party as permitted by law.

GeoLayers does not intentionally repurpose private project data for unrelated public use. A user must deliberately activate publishing, sharing, public API or marketplace functions before project content is made public through those features.

6. Special personal information and children's information

Users should not upload special personal information or children's personal information unless they have lawful authority and the relevant project controls, agreements and safeguards are appropriate. Where prior authorization or another regulatory step is required, the responsible party for that processing remains responsible for completing it.

7. Security safeguards

GeoLayers applies safeguards that may include HTTPS/TLS, authenticated access, role and project permissions, restricted secret handling, public/private data separation, audit evidence, security logging, rate limits, backups and recovery controls.

Users and organization administrators must configure sharing, collaborators, API publication and public links carefully and protect their credentials.

8. Security compromises

Where GeoLayers has reasonable grounds to believe personal information has been accessed or acquired by an unauthorized person, it will assess the incident and make notifications required by section 22 of POPIA, subject to any lawful delay requested by authorities. Customers acting as responsible parties may also have notification obligations and should promptly report suspected project-data incidents to GeoLayers.

9. Data-subject participation

A data subject may, subject to POPIA and verification requirements, request access to personal information, correction or deletion, object to qualifying processing and withdraw consent where applicable. Requests may be submitted to info@geolayers.co.za with the subject POPIA Request.

Formal access-to-record requests may also be made under the PAIA Manual.

10. Direct marketing

Unsolicited electronic marketing is handled in accordance with applicable POPIA requirements. Promotional communications should include a practical opt-out mechanism. GeoLayers may still send non-marketing communications required to operate an account, subscription, security process or support request.

11. Automated decision-making and GeoAI

GeoLayers provides AI-assisted and predictive tools for decision support. GeoLayers does not position those outputs as a substitute for human review, authoritative source verification or statutory decision-making. Customers using GeoLayers to make decisions about individuals are responsible for assessing whether POPIA section 71 or other sector-specific rules apply to their use case.

See the Responsible GeoAI Notice.

12. Cross-border transfers

Where personal information is transferred outside South Africa, GeoLayers seeks to rely on a mechanism permitted by section 72 of POPIA, such as adequate protection under law or binding agreement, consent, contractual necessity or another permitted basis.

13. Information Officer and complaints

The Information Officer for the GeoLayers operator is identified in the Supplier and Operator Information table above. Privacy and POPIA correspondence can be sent to info@geolayers.co.za.

A data subject may also complain to the Information Regulator (South Africa). Current contact channels are published at inforegulator.org.za, including enquiries@inforegulator.org.za and 010 023 5200.

14. Relationship with other documents

This notice should be read with the Privacy Policy, Cookie Policy, PAIA Manual, Terms of Service and any organization-specific Data Processing Addendum or enterprise agreement.

Questions? Contact info@geolayers.co.za.

Return to Legal Centre →
GeoLayers

Professional browser-based GIS, planning, GeoAI and spatial intelligence for data-driven decisions.

info@geolayers.co.za
ProductGeoLayers StudioFeaturesGeoAIDigital TwinsAutomation
SolutionsGovernmentTown PlanningEnvironmentInfrastructureLogistics
ResourcesResourcesBlogCase StudiesLearning CentreDocumentationSupport
Company & LegalAboutContactTrust CentrePrivacyTermsCookiesPOPIALegal CentrePAIA Manual
© GeoLayers. All rights reserved. Built by Glory MulopoGeospatial tools for better decisions.