Operated by Beantech (Pty) Ltd | Reg. No: 2010/008997/07
Information Regulator Registration No: 2025-006973
Effective Date: 19 October 2025
1. Introduction
This Privacy Notice explains how Beantech (Pty) Ltd, operating Oaths.co.za, manages personal information under the Protection of Personal Information Act (POPIA, Act 4 of 2013) and the Promotion of Access to Information Act (PAIA, Act 2 of 2000). The platform provides secure, compliant digital certification of identity and address documents by duly appointed Commissioners of Oaths in South Africa.
2. Information We Collect
We may collect: Identity Data (full name, ID number, facial biometrics, Smart ID/Passport details); Contact Data (email, mobile number, physical address); Document Data (live-captured images or scans of supported documents); Technical Data (device type, browser, IP address, operating system, session logs); Guardian Data (name, ID number, contact details, digital consent record); and Verification Data (Home Affairs records, PEP/AML/sanctions screening results).
3. How We Collect Information
Directly from you during registration or document submission; automatically through secure system logging and analytics; and from verified third parties (e.g., Department of Home Affairs, FIC databases).
4. Purpose of Collection
Information is processed to facilitate digital document certification by a Commissioner of Oaths; verify identity and prevent fraud; comply with FICA, AML, and RICA obligations; maintain a tamper-proof blockchain audit trail; record and validate guardian consent for minor users; improve platform security and user experience; and fulfil legal and regulatory requirements under South African law.
5. Legal Grounds for Processing
Processing relies on consent (from the data subject or guardian for minors); contractual necessity (to deliver services); legal obligation (to comply with FICA, AML, POPIA); and legitimate interest (preventing fraud and protecting public trust).
6. Sharing of Information
Information is shared only where lawful and necessary with Commissioners of Oaths for certification purposes; trusted service providers for secure hosting, biometric verification, and AML screening; and regulators or law enforcement when required by statute or warrant. We do not sell, lease, or trade personal information. All third parties are POPIA-compliant and bound by confidentiality agreements.
7. Security of Your Data
Enterprise-grade security controls include encryption at rest and in transit (AES-256); role-based access control and multi-factor authentication; biometric and liveness verification systems; blockchain-linked QR certification records; and continuous integrity monitoring and auditing. The platform is hosted entirely on Microsoft Azure South Africa (North and South Regions). All personal data, backups, processing operations, and application code are stored and executed within South Africa's geographic borders. No personal information is transferred outside South Africa unless required by law or with explicit user consent, ensuring compliance with POPIA Section 72 (cross-border transfer restrictions).
8. Minors and Guardian Consent
Oaths.co.za permits minors aged 16–17 with a valid Smart ID Card to use the platform for educational and early-career purposes, provided that a parent or legal guardian provides verifiable consent before registration; guardian information is recorded and stored in the encrypted ledger; and use is strictly limited to lawful personal certification activities. Guardians may withdraw consent or request erasure of minor data at any time.
9. Minor Data Ring-Fencing and Encryption
To protect children's information under Section 19 of POPIA and Sections 129–133 of the Children's Act 38 of 2005, all minor personal data (16–17) is ring-fenced in a dedicated, access-restricted encrypted ledger separate from adult data; the ledger uses Microsoft Azure Confidential Ledger with AES-256 encryption and key-rotation policies; access is restricted to authorised compliance officers under dual-control procedures; every access event is recorded in an immutable blockchain audit trail; and ledger records are cryptographically shredded once consent is withdrawn or retention expires.
10. Your Rights Under POPIA
You and, where applicable, your guardian have the right to access personal information held about you; request correction or deletion of inaccurate data; object to certain forms of processing; withdraw consent (where applicable); and lodge a complaint with the Information Regulator (www.inforegulator.org.za). Guardians may exercise these rights on behalf of minors.
11. Retention and Deletion
Personal data is retained only as long as necessary to meet legal and regulatory requirements (e.g., the FICA five-year rule). Upon subscription termination, users have a 60-day grace period to access or download their certified documents. After this period, data is permanently and irreversibly deleted, unless retention is mandated by law. To request access to, or deletion of, your personal data, contact the Information Officer at compliance@oaths.co.za.
12. Cookies and Analytics
The platform uses cookies to enhance functionality and security. Analytics data is aggregated and anonymised; no behavioural profiling is performed. Users can manage cookies via their browser settings.
13. Information Officer and Contact
Information Officer: Mr J.M. van der Westhuizen, Professional Accountant (SA) and Commissioner of Oaths (Ex Officio).
Email: compliance@oaths.co.za.
Address: Regus Cradlestone Mall, Entrance 5, L2, 17 Hendrik Potgieter Road, Krugersdorp, Gauteng 1739.