Veza App Security Policy  

Effective Date: 01 August 2025 

 

  1. Introduction and Scope

This document outlines our commitment to protecting the integrity, confidentiality, and availability of all personal and sensitive company information. As a responsible party under the Protection of Personal Information Act 4 of 2013 (POPIA), we are legally required to implement appropriate and reasonable security measures. This policy serves as the cornerstone of our compliance. 

Our policy is guided by the principles of POPIA, the Electronic Communications and Transactions Act (ECTA), and the Cybercrimes Act. It applies to all our employees, contractors, and third parties who have access to our information systems and data, regardless of their location. This includes all data, whether in digital or physical format. 

  1. Core Principles and Technical Measures

To achieve our security objectives, we have implemented the following key measures: 

  • Data Minimization: We only collect and process personal information that is absolutely necessary for a specific, explicitly defined, and lawful purpose. We will not hold onto data longer than is required. 
  • Access Control: We operate on a strict “need-to-know” basis. Our systems enforce the Principle of Least Privilege, meaning each user is granted only the minimum level of access required to perform their job. We use strong passwords, multi-factor authentication (MFA) for critical systems, and regularly review user access rights. 
  • Data Encryption: To protect data both in transit and at rest, we employ encryption technologies. All sensitive data transmitted over public networks is encrypted, and we ensure that data stored on our servers, laptops, and mobile devices is also encrypted to prevent unauthorized access in the event of a physical loss. 
  • Network Security: Our network is protected by robust firewalls and regularly updated intrusion detection/prevention systems to monitor and block malicious traffic. We also conduct regular vulnerability scans and penetration tests to identify and remediate potential weaknesses. 
  • Physical Security: Access to our data storage facilities, including server rooms and physical archives, is strictly controlled. We use access control systems, surveillance, and detailed logbooks to monitor all entry and exit. 
  • Third-Party Oversight: When engaging third-party operators to process data on our behalf, we ensure a legally binding written agreement is in place. This agreement requires them to adhere to the same stringent security standards outlined in this policy and to notify us immediately of any security incidents. 
  1. Incident Management and Breach Notification

Despite our best efforts, we recognize that security incidents can occur. We have a clear and defined process for managing them: 

  • Incident Response Plan: We have a detailed plan for detecting, containing, investigating, and recovering from any data breach. Our dedicated response team is trained to act swiftly to mitigate harm and restore services. 
  • Breach Notification: In the event of a confirmed data breach involving personal information, we will legally notify both the Information Regulator and the affected data subjects as soon as reasonably possible, as mandated by POPIA. The notification will provide a clear description of the breach, its potential consequences, and the steps we have taken to address it. 
  1. Employee Responsibilities and Training

Our employees are our first line of defense against cyber threats. 

  • Mandatory Training: All employees and contractors undergo mandatory and regular training on data security and privacy best practices, including how to identify and report phishing attempts and other threats. 
  • Individual Accountability: Every individual with access to company data is responsible for adhering to this policy, protecting our assets, and immediately reporting any suspected security incidents. 
  • Consequences of Non-Compliance: Violations of this policy will be met with serious disciplinary action, which may include termination of employment, in accordance with our internal policies and South African labour law. 
  1. Policy Review and Oversight

This is a living document that we commit to reviewing and updating regularly to address new threats and legal requirements. 

  • Information Officer: Our designated Information Officer is responsible for overseeing our data protection compliance, managing the implementation of this policy, and serving as the primary point of contact for the Information Regulator. 
  • Regular Audits: We will conduct regular internal and external audits of our security measures to ensure their continued effectiveness and alignment with our legal obligations.