Effective from Needs an effective date — set effectiveDate in src/lib/legal.ts
Privacy policy
This policy explains what SureWork stores about you and the company you work for, why, and who it’s shared with. It’s a plain description of what the product actually does, not a legal template — where a fact only SureWork’s owner can supply, it’s marked in yellow below until it’s filled in.
Who this policy covers
SureWork is used by South African companies (“customers”) to run their HR, time, payroll, documents, hiring and accounting. Three relationships sit inside this policy, and South Africa’s data protection law (POPIA) treats them differently:
- Your company’s records about its people. Your employer is the responsible party for its employees’ personal information. SureWork acts as an operator, processing that information only on your employer’s instructions, to provide the service.
- Job applicants and candidates. If you apply for a job through a company’s careers page on SureWork, or a company’s recruiters add you to SureWork as a candidate, that company is the responsible party for your information, and SureWork is its operator.
- Your own SureWork account, and your company’s subscription. For the account, sign-in and billing data described below, SureWork (Needs SureWork’s registered legal name — set
entityinsrc/lib/legal.ts) is the responsible party.
What we store
SureWork stores the information a company needs for the modules it uses. Which of the categories below apply depends on your company’s plan and on what it chooses to record.
- Company details — your company’s name and the details in its Company Profile, including its tax, UIF and SDL references, VAT number and the bank account it pays salaries from.
- Employee records — the details your company keeps on each employee, which can include a South African ID or passport number, contact details, banking details, Employment Equity information (such as race, gender and disability status) used for statutory reporting, and an emergency contact’s name, phone number and relationship to the employee. If your company sends you an onboarding link, it also keeps what you submit through it (such as a copy of your ID and a bank confirmation letter) and your acknowledgement of its employee privacy notice: when, which version, your IP address and browser.
- Leave records — leave requests, balances, and, where a request needs one, a medical certificate. A medical certificate is special personal information under POPIA because it reveals health information, and it’s only visible to the people your company has given permission to verify it.
- Payroll records — salary and pay rates, tax number and any tax directive, bank account details for salary payments, medical aid membership (scheme, membership number, contributions and number of dependants), retirement fund membership and contributions, including Two-Pot savings withdrawals, deductions such as loans and garnishee orders, taxable fringe benefits, payslips and IRP5/IT3(a) tax certificates. SureWork prepares payroll files (such as the bank payment file, EMP201, EMP501 and the e@syFile export) for your company to download and submit itself; SureWork doesn’t send them to SARS or to a bank.
- Time and attendance — clock-in and clock-out times, breaks, rosters, shifts and timesheets, the IP address and device a clock-in came from, and a hashed kiosk PIN if your company uses a shared kiosk. Your location (geolocation) is recorded when you clock in or out only if your company has switched on location checks and your browser allows it.
- Documents and e-signatures — the files your company stores, such as contracts, policies and certificates; a record of each time someone views or downloads a document, and of each policy acknowledgement, with the time, the IP address and the browser used; and, when you sign a document in SureWork, the evidence of that signature: your typed or drawn signature, the time, your IP address, your browser’s user agent and a fingerprint (SHA-256 hash) of the exact version you signed. People without a SureWork login, such as candidates, can be asked to sign through a secure link.
- Calendars — events, invitations and your responses to them, meeting rooms, and reminders. When an event includes guests from outside the company, their names and email addresses are stored so they can be sent the invitation and reply to it.
- Job applicants and candidates — when you apply through a company’s careers page: your name, email address, phone number, CV, cover letter, LinkedIn and portfolio links, and any expected salary, notice period, referral and answers you give, with the record of your POPIA consent (when, the version of the wording, your IP address and browser). A company’s recruiters can also add you as a candidate themselves, noting how you gave consent (verbally, by email or in writing), and may record identity and contact details (such as an ID number, date of birth, gender, nationality and home address), your work history, qualifications and skills. The company’s own records can include interview notes, feedback, ratings and any offer; whether it has marked you as not to be considered again (blacklisted), and why; and, if you agree to a background check, your consent and the check’s outcome. A background check’s outcome can reveal criminal-record information, which is special personal information under POPIA. Your details are kept for 12 months from your consent. About 30 days before that ends, you’re emailed a link to keep them for longer; if you don’t, they’re erased, unless you were hired or an application of yours is still open.
- SureWork Jobs accounts — if you save your details after applying, or sign in on the careers pages, SureWork keeps a free candidate account for you, separate from any company: your email address, name, phone number, town, province, right to work in South Africa (not your ID number), an optional headline, up to five CVs, answers you chose to save, jobs you bookmarked, and your sign-ins (when, and the browser used). SureWork is the responsible party for this account. A company only receives what you send it with an application, including its own copy of the CV you chose; it can’t see the rest of your account. The account is kept until you delete it, or until 24 months after your last sign-in, when we delete it after warning you by email 30 days before; details from an application that you never confirmed with the emailed code are deleted after 30 days. Under Account you can download everything it holds or delete it at once; applications you already sent stay with each company under its retention.
- Consultants, contractors and clients — if your company places consultants with clients: each placement (the client, role, dates, and the rates charged and paid), the hours captured in SureWork or imported from a client’s timesheet file, and the invoices raised from them. For an independent contractor’s business: its registered and trading names, registration, VAT and income tax numbers, the owner’s name and ID or passport number where the business is a sole proprietorship, contact and address details, its bank account with a bank confirmation letter, and the invoices it sends. For each client: its company details and its contact people’s names, job titles, email addresses and phone numbers.
- Accounting records — your company’s chart of accounts, journals and financial statements, including the journals posted from its pay runs; its customers and suppliers, with their contact details, VAT numbers and, for suppliers, the bank account it pays; and its quotes, invoices, bills, imported bank statements and VAT201 figures.
- Expense claims — the claims people submit to their company: category, amount, date, merchant and notes; the receipts they photograph or upload, which can show what was bought and where (a medical receipt is special personal information); mileage trips with their dates, distances, places and vehicle; and what was approved and how it was paid. Receipts are kept for as long as tax law requires your company to keep them (at least five years from the end of the tax year) and are then deleted automatically; an unfinished draft that nobody touches for a year, and the receipts of a claim that was declined, are deleted sooner.
- Performance, goals and feedback — review ratings and comments, goals and their updates, notes from one-to-one meetings, feedback people give each other and, where a company runs one, an improvement plan with a record of what was agreed and how it went. Reviews, ratings and goals are visible to the person, to the managers above them in the reporting line, to your company’s HR and to the Owner. An improvement plan is limited to the person, the plan’s manager and HR, and a private note stays with whoever wrote it.
- Surveys, kudos and announcements — your answers to a survey your company runs (in an anonymous survey, SureWork records that you answered, but not which answers are yours, and shows results only for groups large enough that nobody can be picked out); anonymous feedback you send, which you follow up with a code only you hold; kudos you give or receive; and which announcements you have read.
- Onboarding, offboarding and exit interviews — the task checklists your company runs for people joining and leaving and, if it uses an exit interview, your answers to it.
- Training and skills — courses, certificates, required training, skills ratings, study leave and training costs; and, where your company reports to its SETA or measures its B-BBEE skills development, the race, gender and disability details it already holds for Employment Equity. Screens show them only as group totals, and the Training module doesn’t store them. The files your company prepares for its SETA and for its B-BBEE verification agency do list these details for each person, because those bodies require it. SureWork reads them from the employee record when the file is made, and only people your company has given Training management rights can make those files (never an accountant working in your company, and never SureWork support).
- Single sign-on, API keys and webhooks — if your company connects its own identity provider, SureWork stores the connection details (for an OpenID Connect connection that includes its client secret, which is kept as it is in the database, never shown again and never included in exports; a SAML connection has no secret) and the identifier your provider sends for you; and for the API keys and webhook endpoints your company creates, the key’s name and a fingerprint (never the key itself), the endpoint address, a log of what was delivered (kept 30 days) and of requests made with the key (kept 90 days).
- Connected accounting packages — if your company connects Xero or QuickBooks, SureWork stores the connection (the access tokens are encrypted) and the record of what it sent: the journal for each approved pay run (the amounts by account, not payslips). Invoices and bills are not sent.
- An accountant or bookkeeper working in your company — if your company gives an accounting practice access, that practice’s people can see and do what the company allowed, nothing else, and only for as long as the company allows. They act for your company as its operator; everything they do is written to your company’s audit trail, and your company can stop their access at any time.
- Support tickets — the tickets and messages you write, and any files you attach. Tickets to your company’s own help desk are handled by your company; tickets to SureWork support are read by SureWork’s support staff.
- Billing — your company’s plan, invoices and payments, and its billing contact email, address and VAT number. Card payments are made on Stitch’s secure payment page, so SureWork never receives or stores a full card number; for a saved card it keeps only the card type, the last four digits, the expiry month and year, and Stitch’s reference for the card.
- Login and account data — your name, work email address, a securely hashed password, two-factor authentication settings, and records of your sign-ins and sessions, including the IP address and browser used. If you connect another app to your account, SureWork records the connection and a log of each action that app takes on your behalf.
Why we use it
- To provide the modules your company has signed up for: records, leave, time, payroll, documents, calendars, hiring, expense claims, performance, training, engagement, consultants and client billing, accounting and reports.
- To calculate pay and tax on SARS’s published tables, and prepare the statutory files your company submits.
- To send the emails and notifications the product needs, such as approvals, payslips being ready, reminders and applicants’ acknowledgements.
- To keep evidence your company may need later: signatures, policy acknowledgements, applicants’ consent and the audit trail.
- To keep the service secure, such as checking sign-ins, two-factor codes and access permissions.
- To bill your company for its SureWork subscription.
SureWork doesn’t sell personal information, and doesn’t use it for advertising.
Who we share it with
A small number of service providers (“sub-processors”) process data on our behalf, strictly to run the product:
- Resend — delivers the emails SureWork sends, such as sign-in codes, leave and payroll notifications, document signing requests, invoices and emails to job applicants.
- Inngest — runs background work outside the request you made, such as leave accruals, reminders, scheduled reports and the retention rules above.
- Vercel Blob — stores uploaded and generated files in production, such as medical certificates, documents, CVs, payslips and reports.
- Stitch — processes card payments for SureWork subscriptions, when a company chooses to pay by card.
- Xero and Intuit QuickBooks — only when your company connects one of them: they receive the journal for each approved pay run (amounts by account). They are outside South Africa, so what is sent leaves the country, at your company’s choice and under its control.
- Your company’s own identity provider and accountant — when your company uses single sign-on, your sign-in goes through the identity provider your company chose; when it gives an accounting practice access, that practice sees what the company allowed. Both are your company’s own choices, under its own agreements with them.
- Hosting provider — Needs the hosting provider, once confirmed — set
hostingProviderinsrc/lib/legal.ts, including where the service and its database are physically hosted.
SureWork staff who run the service can see, depending on their role, each company’s profile, its users and their roles, its plan and billing, its account activity (such as sign-up, plan changes, suspensions and support sign-ins), the support requests it sends SureWork, and service records such as which emails SureWork sent, to whom and with what subject. They can’t see your company’s employee, leave, payroll or other records, or its audit trail of what its users have done.
To see anything else, an authorised member of SureWork support has to sign in as one of your company’s users, to see what they see and help with a problem. They must give a reason first. The reason is recorded, and each such session is written to your company’s audit trail.
Some information leaves SureWork because your company or you choose to send it: payroll files your company downloads for SARS or its bank; documents your company shares through a public link; scheduled reports it emails, including to addresses outside the company if its report settings allow that; and anything an app you connect to your account reads on your behalf, which that app’s provider handles under your own agreement with them.
How we keep it secure
Traffic to and from SureWork is encrypted in transit. Each company’s data is kept in its own workspace, and access within it is controlled by roles and permissions: ID, passport, tax and bank account numbers are masked unless a person’s role allows them. Two-factor sign-in is required for company owners, HR managers and SureWork staff, and SureWork keeps an audit trail of meaningful changes so your company can see who did what.
Your rights
You can ask to see, correct, or have deleted the personal information SureWork holds about you. If you’re an employee or a job applicant, start with the company concerned, since it controls your record; for questions about your own SureWork account, contact us directly. If you have a SureWork Jobs account, you can download or delete it yourself under Account on the careers pages. A SureWork login can be deleted by its owner under Settings → Security, and employees can file an access or deletion request with their company, and download the data they are given, under My privacy. For anything else, write to us and we’ll respond within a reasonable time. You also have the right to lodge a complaint with South Africa’s Information Regulator at inforegulator.org.za.
How long we keep it
We keep your company’s data for as long as your company’s SureWork account is active, and afterwards for as long as our agreement with your company requires. Within that, some records have their own rules: job applicants’ details follow the 12-month consent period described above; documents follow the retention rules your company sets, and are archived or deleted when their period ends; a signup whose email address was never verified is deleted after 30 days; and SureWork Jobs accounts follow the rules described above. A few short-lived working records are also deleted automatically when their period ends, whatever else your company has chosen: expense receipts once their tax retention period has passed, abandoned expense drafts, survey invitations after 12 months, named survey answers (de-identified after 24 months), survey comments (after 36 months) and anonymous feedback conversations (after 24 months), webhook delivery logs after 30 days and API request logs after 90 days. SureWork deletes or anonymises employee, leave, payroll and statutory records on a schedule only if your company’s Owner has switched retention enforcement on and confirmed it; it is off until then, and until then your company deletes those records itself.
Changes to this policy
If this policy changes in a way that matters, we’ll update the effective date above and let administrators know.
Contact us
For anything in this policy, including a request about your personal information, write to Needs a privacy contact email — set contactEmail in src/lib/legal.ts. Our POPIA Information Officer is Needs the Information Officer’s name — set informationOfficer in src/lib/legal.ts, and SureWork’s postal address is Needs a registered address — set address in src/lib/legal.ts. For general product questions in the meantime, you can reach us at support@surework.co.za.