Privacy Policy
PROTECTION OF PERSONAL INFORMATION (POPIA) POLICY
Breaze Delivery (Pty) Ltd | Registration No. 2019/410905/07
1. PURPOSE
The purpose of this Policy is to ensure that Breaze Delivery (Pty) Ltd protects the personal information of its individual clients, corporate representatives, outsourced service providers (drivers), and employees. In the logistics sector, the lawful processing of delivery addresses, contact details, and tracking data is critical to maintaining operational integrity and regulatory compliance.
This Policy gives effect to the rights and obligations contained in the Protection of Personal Information Act 4 of 2013 (POPIA) and demonstrates Breaze’s commitment to responsible, transparent, and lawful data processing.
2. SCOPE
2.1 Who This Policy Applies To
This Policy applies to:
- Clients: Individual and corporate customers whose delivery details and contact information are processed by Breaze.
- Outsourced Drivers / Service Providers: Independent contractors or third-party agencies providing delivery services on behalf of Breaze.
- Operations Staff: Employees managing dispatch, customer service, and fleet logistics.
- Third-Party Operators: IT hosting providers, GPS tracking providers, and payment gateways.
2.2 What Information Is Covered
This Policy applies to all personal information processed by Breaze, regardless of medium or form, including:
- Digital Data: Information stored on company servers, dispatch software, GPS tracking systems, mobile delivery applications, and email communications.
- Physical Data: Hard-copy delivery manifests, paper waybills, driver logbooks, signed proof-of-delivery (POD) notes, and printed employee files.
Sensitive data categories include:
- Customer / Client Data: Names, delivery addresses, contact numbers, and delivery instructions.
- Driver / Provider Data: ID numbers, driver’s licences, vehicle registration details, GPS coordinates, and banking details for payment.
- Employee Data: Biometric data (if applicable), health information (sick notes), disciplinary history, and payroll records.
2.3 Data Lifecycle
This Policy covers the entire data lifecycle: from initial collection from clients, transmission of manifests to drivers, storage of records for SARS compliance, through to the final secure destruction of documents.
3. DEFINITIONS
| Responsible Party | Breaze Delivery (Pty) Ltd, which determines the purpose and means for processing personal information. |
| Data Subject | The person or legal entity receiving or sending goods (the customer), or the outsourced driver whose personal information is processed. |
| Operator | An outsourced delivery driver or third-party agency that processes personal information (e.g., delivery addresses) on behalf of Breaze. |
| Personal Information | Names, physical addresses, GPS coordinates, ID numbers of drivers, and contact numbers, as defined in POPIA. |
| Processing | The collection, receipt, recording, organisation, storage, and transmission of delivery manifests, waybills, and associated records. |
| Information Regulator | The statutory body established under POPIA to monitor compliance and receive breach notifications in South Africa. |
4. POLICY STATEMENT — THE 8 CONDITIONS OF POPIA
Breaze Delivery commits to processing all personal information in strict accordance with the 8 lawful processing conditions of POPIA:
| 1 | AccountabilityBreaze accepts full responsibility for the personal information it holds. All staff and outsourced drivers (Operators) are trained on these conditions, and technical and organisational measures are in place to prevent unauthorised access. |
| 2 | Processing LimitationData is processed lawfully and minimally. Breaze only collects the specific details required for delivery and billing (e.g., name, address, and contact number). Information that is not necessary for logistics operations is not collected. |
| 3 | Purpose SpecificationPersonal information is collected for a specific, defined purpose: the successful fulfilment of a delivery mandate and subsequent invoicing. Records are retained only for the period required by the Companies Act and SARS, after which they are securely destroyed. |
| 4 | Further Processing LimitationInformation collected for a delivery will not be used for any other purpose (such as marketing or sharing with third-party lead generators) without the explicit opt-in consent of the data subject. |
| 5 | Information QualityBreaze takes reasonable steps to ensure that delivery manifests and waybills are accurate and kept up to date. Dispatchers are required to verify addresses and contact details to prevent data errors and delivery failures. |
| 6 | OpennessBreaze maintains transparency regarding the data it holds. This Policy and the Breaze Privacy Notice (available on waybills and the Breaze website) clearly inform clients and drivers who we are, what we collect, and why. |
| 7 | Security SafeguardsBreaze implements layered security measures across physical, technical, and operational controls to protect personal information against loss, damage, or unauthorised access. See Section 5 for detail. |
| 8 | Data Subject ParticipationData subjects (clients or drivers) have the right to request access to their personal information, request corrections, or request deletion of their information, subject to lawful retention requirements. Requests must be directed to the Information Officer. |
5. SECURITY SAFEGUARDS
Breaze recognises that in the logistics chain, data breaches frequently occur via physical documentation (waybills) or mobile device theft. The following safeguards are in place:
5.1 Physical Security
- Locked shredding bins for old waybills and delivery manifests.
- Restricted access to dispatch offices and hub operations areas.
- Mandatory daily returns of all paper manifests by drivers at end of shift.
5.2 Technical Security
- Encrypted GPS tracking systems.
- Password-protected mobile manifests and delivery applications.
- Role-based access controls on the Breaze Portal and backend systems.
5.3 Operator Controls
- All outsourced drivers and third-party service providers must sign an Operator Agreement containing mandatory POPIA confidentiality clauses.
- Drivers are strictly prohibited from using personal mobile devices to photograph delivery manifests, client IDs, or consignee information.
6. ROLES AND RESPONSIBILITIES
| Information Officer (CEO) | Responsible for registering Breaze with the Information Regulator and ensuring the PAIA Manual is publicly available. Oversees Breaze’s data privacy strategy and manages high-level breach responses. |
| Operations / Dispatch Manager | Ensures that drivers return or securely destroy paper waybills at the end of each shift. Ensures that digital manifests are cleared from mobile devices upon completion. |
| Human Resources | Manages employee personal information in accordance with this Policy. Ensures new staff complete POPIA induction training. |
| Outsourced Drivers / Operators | Must adhere to strict confidentiality regarding all client names, addresses, and consignee information encountered during the delivery process. |
7. PROCEDURES
7.1 Collection for Delivery
Personal information is collected only to facilitate the transit of goods. Corporate client data is treated with the same level of confidentiality as individual consumer data.
7.2 Outsourced Driver Compliance
All independent contractors must sign an Operator Agreement confirming they will not store or use client contact details for any purpose other than the specific delivery assigned. Photographing of delivery manifests or client identification on personal devices is strictly prohibited.
7.3 Data Retention
Delivery records, waybills, and associated documentation will be retained only for the period required by applicable tax law (SARS — currently 5 years) and the Companies Act, and thereafter securely destroyed in accordance with the Breaze Data Retention Schedule.
7.4 Real-Time Tracking Data
GPS data of drivers and delivery status updates provided to clients are encrypted and restricted to authorised users only. Tracking data is not retained beyond the operational period for which it was collected.
7.5 Further Processing
Data collected for delivery purposes will not be used for marketing, profiling, or any secondary purpose unless the data subject has provided explicit opt-in consent.
8. COMPLIANCE AND MONITORING
- Sub-Contractor Audits: Periodic checks will be conducted to ensure outsourced drivers are not retaining client lists, contact details, or delivery information beyond their assigned delivery.
- Breach Notification: If a delivery manifest is lost or stolen, or if any data breach is detected, the Information Officer will notify the Information Regulator and all affected data subjects as soon as reasonably possible, and in any event within 72 hours of becoming aware of the breach, in compliance with POPIA.
- Training: All staff and outsourced partners will undergo a POPIA induction focused on privacy in logistics prior to handling personal information.
- Retention: Records will be retained in accordance with the Breaze Data Retention Schedule.
9. DATA SUBJECT RIGHTS
In terms of POPIA, all data subjects have the following rights:
- Right of Access: To request confirmation of whether Breaze holds their personal information and to obtain a description of that information.
- Right to Correction: To request correction, deletion, or destruction of personal information that is inaccurate, irrelevant, excessive, or obtained unlawfully.
- Right to Object: To object to the processing of personal information on reasonable grounds.
- Right to Complain: To lodge a complaint with the Information Regulator (South Africa) where the data subject believes their rights have been infringed.
Requests must be submitted in writing to the Breaze Information Officer. Breaze will respond within a reasonable period and in accordance with the timelines prescribed by POPIA.
10. RELATED DOCUMENTS
| Operator / Driver Agreement | Contains mandatory POPIA confidentiality and non-disclosure clauses. |
| Standard Waybill Terms & Conditions | Includes reference to data processing and privacy notice. |
| Data Breach Incident Register | Internal register for recording, tracking, and reporting data breaches. |
| Privacy Notice (Website / Waybill) | Public-facing notice informing data subjects of their rights and Breaze’s processing activities. |
| Data Retention Schedule | Internal schedule specifying retention periods by data category. |
| PAIA Manual | Promotion of Access to Information Act manual, available on the Breaze website. |
| Employee Privacy Notice | Notice provided to all employees at commencement of employment. |
11. REVIEW AND REVISION
This Policy is subject to annual review or revision whenever there is a material change in Breaze’s outsourced delivery model, logistics technology stack, or applicable legislation. The Information Officer is responsible for ensuring this Policy remains current and effective.
12. APPROVAL AND VERSION CONTROL
| Version | Date | Approved By | Description |
| 1.0 | [Approval Date] | Braden Snyman, CEO | Initial publication of POPIA Policy. |
