BEYOND SOFTWARE PRIVACY POLICY
Draft prepared for attorney review. Drafted 09/09/2026 against POPIA. Risk rating R2. This policy covers Beyond's software products only. Beyond's separate privacy policy at beyondic.co.za covers its marketing and agency business, and the two must not contradict each other — see the note at the end.
Version 1.0 · Effective 9 September 2026
THE THING MOST PRIVACY POLICIES LEAVE OUT
Beyond wears two different hats in its software, and which one it is wearing decides who you complain to, who answers a request, and who must notify a breach. Nearly every complaint that goes to the wrong place goes there because a policy never said this plainly.
| Beyond is the Responsible Party | Beyond is the Operator | |
|---|---|---|
| Whose information | The people who run a customer account — the person who signs up, who pays the invoice, who writes to support. And visitors to our website. | The customer's own employees, contractors and clients, whose details the customer puts into the software. |
| Who decides why it is held | Beyond | The customer |
| Who you ask about it | Beyond — details in section 9 | Your employer, or whichever business gave you your account. Beyond cannot answer for them, and would be acting unlawfully if it did. |
| Governed by | This policy | The Beyond Operator Agreement, and the customer's own privacy policy |
If you are an employee whose time is recorded in Beyond Pulse: your employer is the Responsible Party, not Beyond. Your rights are real and are set out in section 8 — but you exercise them against your employer, who holds the information and decides what happens to it. Beyond holds it on their instruction and must not act on it without them.
1. WHO WE ARE
Beyond Imagination Consulting (Pty) Ltd, trading as Beyond Imagination Registration number 2023/885807/07 Waterford Court Office Park, 236 Glover Ave, Die Hoewes, Centurion, 0163, Gauteng, South Africa Info@beyondic.co.za · +27 12 111 9164
Information Officer: Antonie Holtzhausen, contactable at the address above.
2. WHERE BEYOND IS THE RESPONSIBLE PARTY
This section covers information Beyond holds for its own purposes.
2.1 What we collect
| Category | What | Why |
|---|---|---|
| Account administration | Name, work email, telephone, job role, business name and address | To provide and administer the service, and to reach the right person |
| Applications | Business name, contact name and email, country, team size, what you use today, and the IP address the form was submitted from | To assess an application, and as an abuse signal on a public form |
| Billing | Invoices, amounts, payment records, bank reference | To be paid, and to keep the records tax law requires |
| Support | Correspondence, and what was done to resolve it | To help, and to know what was done to your account |
| Security | Sign-in events, access records, audit entries | To keep accounts secure and to be able to answer "who did that" |
2.2 The lawful bases we rely on
- Performance of a contract — POPIA section 11(1)(b) — for account administration, billing and support.
- Legal obligation — section 11(1)(c) — for tax and company records.
- Legitimate interest — section 11(1)(f) — for security records and fraud prevention, balanced against the individual's privacy by keeping the least data that answers the question.
- Consent — section 11(1)(a) — for direct marketing, which you may withdraw at any time.
2.3 How long we keep it
| Account and contract records | 5 years after the relationship ends |
| Tax and accounting records | 5 years per financial year, per the Tax Administration Act 28 of 2011 |
| Support correspondence | 3 years |
| Security and sign-in records | 12 months |
| Applications that never became customers | 12 months, then deleted |
3. WHERE BEYOND IS THE OPERATOR
3.1 When a business uses Beyond software, the information it puts in about its own people and its own clients is that business's information. Beyond holds it on their instruction.
3.2 Beyond does not decide what goes in, why, or for how long. The customer sets the retention period within the limits the product allows, and the product deletes data past it automatically.
3.3 Beyond does not use that information for its own purposes. Specifically:
- we do not sell it;
- we do not use it for our own marketing;
- we do not use it to train any machine-learning model;
- we do not combine it with another customer's data.
3.4 Beyond staff enter a customer's workspace only to provide support, investigate a fault, or comply with the law. Every such entry is recorded in that customer's own audit trail, where they can read it, naming the individual and the time. Beyond cannot remove that record.
3.5 The full terms are in the Beyond Operator Agreement, which every customer accepts.
4. WHAT BEYOND SOFTWARE DELIBERATELY DOES NOT COLLECT
This is a product decision, enforced in code, and not a preference we could quietly change.
Where a Beyond product records workstation activity, it never collects:
- window titles, document names or URLs — the field exists in the underlying data and is discarded at the boundary; there is no setting that turns it on;
- screenshots — none, ever;
- keystrokes — not in any form;
- individual application names — the machine works out that a program is an "editor" and sends only the category.
Automated checks fail Beyond's build if any of that changes. The server is built so that it cannot accept a window title, a URL or an application name even if something tried to send one. It is the strongest form of a privacy promise available: one the software cannot break without the build stopping.
5. WHO ELSE SEES IT
5.1 We do not sell, rent or trade personal information. Ever.
5.2 We share it only with:
- operators we engage to run the service — hosting, email delivery — each under a written contract meeting POPIA section 21, and each listed in Annexure B of the Operator Agreement;
- professional advisers — accountants, attorneys — under professional confidentiality;
- an authority, where the law requires it, and where lawful we will tell the affected party first.
5.3 Where a customer connects a third-party integration, information flows to that third party on the customer's instruction, and that third party's own policy applies to what they then do with it.
6. WHERE IT IS KEPT
6.1 Beyond's software runs in the Republic of South Africa and customer data is stored here.
6.2 We will not transfer personal information outside the Republic except where section 72 of POPIA permits it, and any operator outside the Republic is named in Annexure B of the Operator Agreement with the section 72 basis stated beside it.
7. HOW IT IS PROTECTED
As POPIA section 19 requires, Beyond takes appropriate, reasonable technical and organisational measures. In practice:
- each customer's data is confined to its own workspace, enforced in the software and verified by an automated test that fails the build if that boundary ever stops holding;
- confidential figures are withheld by the interface that produces them, based on role, rather than merely hidden from view;
- encryption in transit, and encryption at rest for stored third-party credentials;
- password minimums, rate limiting on sign-in, and one-time links rather than passwords chosen for people by somebody else;
- an append-only audit trail that cannot be edited or deleted from within the software;
- backups verified when made, with restoration rehearsed rather than assumed;
- automatic deletion of data past its retention period, running daily.
No system is perfectly secure, and a policy that claimed otherwise would be worth less than one that says this.
8. YOUR RIGHTS
Under POPIA you may:
| Right | Section |
|---|---|
| Ask what personal information is held about you | s23 |
| Have it corrected or deleted where it is inaccurate, irrelevant, excessive or unlawfully obtained | s24 |
| Object to processing based on legitimate interest | s11(3) |
| Object to direct marketing | s69 |
| Not be subject to a decision based solely on automated processing | s71 |
| Complain to the Information Regulator | s74 |
8.1 How to exercise them
If Beyond is the Responsible Party (section 2 above), write to Info@beyondic.co.za with the subject "POPIA Data Request". We acknowledge within 3 Business Days and respond substantively within 30 days. One request per twelve months is free; we may charge a reasonable fee for repeated requests.
If your information is in a customer's workspace (section 3 above), ask that business. They are the Responsible Party. If they ask us to assist, we will.
8.2 A gap we are naming rather than hiding
Beyond Pulse currently has no self-service deletion request. Where an individual asks for their activity data to be erased before the retention period expires, it is done by hand by the customer's administrator with our assistance. It gets done — but it is a manual operation today, not a button, and saying otherwise would be a claim the software does not support.
8.3 The Information Regulator
You may complain directly, at any time:
Information Regulator (South Africa) JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 complaints.IR@justice.gov.za · inforeg@justice.gov.za · www.inforegulator.org.za
9. CONTACT
Anything about personal information: the Information Officer, Antonie Holtzhausen, at Info@beyondic.co.za, or by post to the registered address in section 1.
10. CHANGES
This policy may change. Each version carries a version number, an effective date and a content hash, so the version that applied at any date can always be produced. Where a change is material we tell customers before it takes effect.
For the attorney reviewing this
- The two-hats table at the top. This is the substantive difference between this policy and the one published at beyondic.co.za, which addresses Beyond only as a Responsible Party. Please confirm the split is stated accurately and that section 3 does not overstate what an Operator may say about processing it does not control.
- Section 8.2. The absence of a self-service deletion mechanism is disclosed rather than omitted. Please advise whether disclosure is sufficient or whether section 24 requires the capability itself.
- Reconciliation with the published policy. The live policy at beyondic.co.za carries an unfilled `[NAME OF INFORMATION OFFICER]` placeholder and does not contemplate Beyond acting as an Operator. Both need fixing there, and this policy should be cross-referenced from it so a reader is not left thinking one covers the other.
- Section 4. The negative list is stated as strongly as it is because it is enforced in code. Please confirm that stating it in a privacy policy creates the representation we intend and no more.
privacy · v1.0 · sha256 6c69c5f3f6e020126e266e22b8174c06b3638880bac11036d99a4fa6c77c0945