Excellent CRM — Privacy Notice (POPIA)
| Responsible party | Excellent Meat Corp (Pty) Ltd |
| Registration number | «TO BE CONFIRMED» |
| Physical address | «TO BE CONFIRMED», Cape Town, Western Cape, South Africa |
| Information Officer | «TO BE CONFIRMED» |
| Contact for privacy matters | «TO BE CONFIRMED» |
| Version | 1.0 |
| Effective | «TO BE CONFIRMED» |
| Review cycle | Annually |
Before go-live: every «TO BE CONFIRMED» above and below must be filled in from the company's CIPC registration and internal appointments, and this notice must be signed off by the Information Officer. Excellent Meat Corp's Information Officer must also be registered with the Information Regulator (South Africa) — registration is a POPIA section 55 obligation, not an optional step, and it is not something this application can do for you. This document is an operational privacy notice written to fit how Excellent CRM actually processes data. It is not legal advice; have it reviewed by your attorneys before publication.
1. What this notice covers
Excellent CRM is the in-house customer relationship management system of Excellent Meat Corp (Pty) Ltd ("Excellent Meat Corp", "we"). It is used only by Excellent Meat Corp staff, from our Cape Town operation. It is not offered to, sold to, or operated on behalf of any other party.
This notice explains how we process personal information in Excellent CRM, in terms of the Protection of Personal Information Act 4 of 2013 ("POPIA"). It covers two groups of people:
- Customer contacts — the people at our customers, suppliers and prospects whose details we record so we can trade with them.
- Staff users — Excellent Meat Corp employees who log in to Excellent CRM.
Where this notice and any signed contract with a customer differ, the contract governs the commercial relationship; this notice still governs how we handle personal information.
2. Who is responsible
Excellent Meat Corp (Pty) Ltd is the responsible party for all personal information in Excellent CRM. We determine why and how it is processed.
Our Information Officer is «TO BE CONFIRMED». Under POPIA, the Information Officer of a private body is by default the head of that body, and the appointment must be registered with the Information Regulator. Queries, objections and data subject requests go to «TO BE CONFIRMED».
3. What personal information we process
3.1 Customer contacts
| Category | Examples | Where it comes from |
|---|---|---|
| Identity | First name, surname | The contact, their employer, or public business listings |
| Business contact details | Work email, work phone, job title, employer | The contact or their employer |
| Relationship records | Calls, emails, meetings, site visits, notes, outcomes, follow-up dates | Recorded by our traders |
| Visit reports | Structured after-visit reports (CVRs) about the customer's operation | Recorded by our traders |
| Survey responses | Quarterly customer health survey answers, including NPS score and free-text comments | Submitted by the contact |
| Commercial context | Territory, tags, trade direction, custom fields, health score | Derived by us |
We deliberately do not use Excellent CRM for special personal information as defined in POPIA section 26 (religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, or criminal behaviour), nor for the personal information of children. Do not record such information in notes or visit reports.
3.2 Staff users
| Category | Examples | Purpose |
|---|---|---|
| Account details | Username, full name, email, role, hashed password | Access control |
| Security records | Login attempts, IP addresses, active sessions, audit log entries | Securing the system, investigating incidents |
| Activity | Which records a user created, changed, exported or erased | Accountability |
Passwords are stored only as salted hashes (Werkzeug). We never store them in plain text and cannot retrieve them.
4. Why we process it, and on what lawful basis
POPIA requires a justification under section 11 for each processing purpose.
| Purpose | Lawful basis (POPIA s11) |
|---|---|
| Managing the trading relationship with a customer, including contacting the right person | s11(1)(b) — necessary to conclude or perform a contract to which the data subject is a party, and s11(1)(f) — our legitimate interests |
| Scheduling contact, tracking follow-ups, recording visits | s11(1)(f) — legitimate interests of Excellent Meat Corp in running its trade |
| Customer health scoring and internal analytics | s11(1)(f) — legitimate interests |
| Customer health surveys | s11(1)(a) — consent, given by responding to the survey |
| Audit logging, access control, session and login records | s11(1)(c) — compliance with a legal obligation, and s11(1)(f) |
| Retaining records after a relationship ends | s11(1)(c) — tax, company and commercial record-keeping obligations |
We do not use Excellent CRM for direct marketing by electronic communication to people who are not existing customers. If that ever changes, POPIA section 69 applies and we must obtain consent first.
5. How we obtained your information
Most contact details are given to us directly by the contact or by their employer in the ordinary course of trade. Some are drawn from publicly available business listings. Interaction history, visit reports and health scores are created by our own staff as a record of our dealings.
6. Who we share it with
We do not sell personal information, and we do not share it for anyone else's marketing.
Personal information in Excellent CRM may be handled by:
| Recipient | What they receive | Why |
|---|---|---|
| Excellent Meat Corp staff | Only what their role and territory allow — traders see their own accounts, managers see more | Doing their jobs |
| Our hosting provider | Whatever is stored in the application database | Running the system |
| Groq Inc. (optional AI assistant) | Only pseudonymised statistics — opaque IDs, never names, emails or phone numbers — and only when a user explicitly ticks "include my customers" | Answering questions about the customer book |
| Red Meat Producers' Organisation | Nothing. We only read their published carcass prices | Market pricing |
| Professional advisers, auditors, regulators | On request or where legally required | Legal and audit obligations |
Cross-border transfers. Some of these providers process data outside South Africa. POPIA section 72 permits this where the recipient is subject to a law, binding rules or an agreement that upholds principles substantially similar to POPIA, or where the transfer is necessary to perform a contract with the data subject. The current list of processors, what each one receives and where they are located, is maintained internally in the processor register (Excellent CRM operations runbook, section 9). Each processor must be under a written operator agreement as required by POPIA sections 20 and 21. A copy of the register is available on request to the Information Officer.
The AI assistant is off by default and only works when an administrator sets a
GROQ_API_KEY. Even then, no customer names, emails or phone numbers are sent —
names typed by a user are replaced with opaque tokens before the request leaves
our server and translated back locally in the reply.
7. How long we keep it
| Record | Retention |
|---|---|
| Customer contacts and interaction history | For the duration of the trading relationship, then «TO BE CONFIRMED» years |
| Visit reports and survey responses | «TO BE CONFIRMED» years from creation |
| Audit log | Per the retention policy configured in Settings → Retention; default 730 days (two years) |
| Login attempts | Per the retention policy configured in Settings → Retention; default 30 days |
| Notifications | Per the retention policy configured in Settings → Retention; default 90 days |
| Encrypted erasure backups | Retained after an erasure so we can prove to the Information Regulator that the request was carried out |
| Staff accounts | Deactivated on exit; audit history retained for the audit log retention period |
Excellent CRM has configurable retention policies with delete, archive and anonymise actions. Records that must be kept for tax or company-law reasons are kept for those statutory periods even after a deletion request, as POPIA section 14 permits.
8. Your rights as a data subject
Under POPIA you may:
- Ask what we hold about you and get a copy (section 23). We can produce a complete JSON export of everything Excellent CRM holds on a contact.
- Ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date, misleading or unlawfully obtained (section 24).
- Object to processing based on legitimate interests, on reasonable grounds (section 11(3)).
- Withdraw consent where processing relies on consent, such as survey participation, without affecting what was lawful before withdrawal.
- Complain to the Information Regulator (section 74).
To exercise any of these, contact «TO BE CONFIRMED». We will acknowledge within «TO BE CONFIRMED» working days. We may ask you to verify your identity first — that check is itself a POPIA requirement and protects you, because handing your file to someone impersonating you would be a security compromise in its own right. We reply to the contact details we already hold for you.
Requests for access to records held by a private body are made under the Promotion of Access to Information Act 2 of 2000 (PAIA), which requires us to decide within 30 days of receiving the request, extendable once by a further 30 days in the circumstances PAIA allows. Those requests follow our PAIA manual, available at «TO BE CONFIRMED».
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
PO Box 31533, Braamfontein, Johannesburg, 2017
Complaints: POPIAComplaints@inforegulator.org.za
General: enquiries@inforegulator.org.za
9. How Excellent CRM protects the information
Technical and organisational measures required by POPIA section 19, as built into the application:
- Access control — role-based permissions on every route, with traders scoped to only the companies assigned to them.
- Authentication — hashed passwords, configurable password complexity, login rate limiting and brute-force protection, session management with remote revocation.
- Audit trail — every login, create, update, delete, export and erasure is logged with the actor, timestamp and IP address.
- Encryption — erasure backups are encrypted at rest with Fernet. In production the app is served over HTTPS with secure, HTTP-only, SameSite session cookies.
- Application hardening — CSRF protection on every form, open-redirect prevention on login, upload type and size restrictions, sort-column allow-listing, SSRF protection on webhook destinations, and a Content-Security-Policy that permits no third-party origin at all.
- No third-party resources — Excellent CRM loads no external scripts, styles, fonts or images. Nothing about your visit is disclosed to any other party simply by opening a page.
- Data minimisation in AI features — pseudonymisation before any external call, as described in section 6.
10. Security compromises
If personal information is accessed or acquired by an unauthorised person, POPIA section 22 requires us to notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovery. Our internal containment, investigation, escalation and notification procedure is maintained internally (Excellent CRM POPIA procedures, section 5) and is available on request to the Information Officer. The Excellent CRM audit log, login attempt records and session history are the primary evidence for investigating an incident.
11. Automated decision-making
Excellent CRM calculates a Red/Amber/Green customer health score from days-since-contact, visit report sentiment, survey scores and open follow-ups. This is an internal prioritisation aid for our traders. It does not by itself decide whether we trade with anyone, and no legal or similarly significant decision about a person is made solely by automated means, so POPIA section 71 is not engaged.
12. Staff obligations
If you use Excellent CRM, you are handling other people's personal information on behalf of Excellent Meat Corp. You must:
- Record only what is needed for the trade — no medical, financial, racial, political, religious or criminal information, and nothing about children.
- Keep notes factual and professional. Assume every note may one day be read by the person it describes, because a section 23 access request entitles them to it.
- Never share your login. Every action is attributed to your account.
- Use "POPIA Erase" rather than editing a record by hand when a deletion request comes in, so the audit trail is complete.
- Pass any request about a person's information to the Information Officer the same day, whatever form it arrives in. "Take me off your system" said to you on a site visit is a request; it does not have to mention POPIA or arrive on a form, and you must not act on it yourself.
- Report a suspected data breach to the Information Officer immediately.
The step-by-step procedure for each of these is in the internal Excellent CRM POPIA procedures document; the Information Officer will give you a copy.
13. Changes to this notice
We review this notice at least annually and whenever Excellent CRM's processing changes materially. The version and effective date are at the top.
This notice describes Excellent CRM, an internal application of Excellent Meat Corp (Pty) Ltd. It is not a public product and is not available to third parties.