OrgSpace logoOrgSpaceby Pixels
PRIVACY & POPIA

Privacy Policy

How OrgSpace handles personal and organisation information.

Effective 18 September 2026

1. Who is responsible for your information

OrgSpace is a South African workplace operations service operated under the Pixels trading name. This Privacy Policy applies to the OrgSpace mobile app, secure web portals and public website.

When an organisation uses OrgSpace for its own workplace records, that organisation is normally the responsible party under the Protection of Personal Information Act 4 of 2013 (POPIA), and Pixels acts as its operator. The organisation decides why those records are used, who should have access and how long legitimate organisation records must be kept.

Pixels is separately responsible for personal information used for OrgSpace account administration, service security, subscription and billing administration, support, legal compliance and its own business communications. The contracting entity and commercial details for a customer are also recorded in the applicable order, subscription record or data-processing agreement.

2. Information OrgSpace may process

The information involved depends on the features an organisation enables and the way its users work in OrgSpace.

3. Where the information comes from

Information may come directly from the user, from an organisation administrator or manager, from another authorised person taking part in a workflow, from the user's device, from Firebase authentication and service infrastructure, from Paystack or another disclosed payment provider, and from security or audit events generated by OrgSpace.

4. What is required and what is optional

Fields needed to create an account, join an organisation or complete a particular workflow are required for that action. If required information is not supplied, OrgSpace may not be able to create the account, complete the workflow or provide the relevant feature. Optional fields can be left blank unless the customer organisation has a separate lawful reason for requiring them.

A customer organisation may have its own legal, employment, financial or governance reasons for collecting workplace information. The organisation is responsible for explaining those requirements to its staff and identifying any law that makes a particular collection compulsory.

5. Why the information is used

Depending on the context, processing may be necessary to provide the OrgSpace service, comply with law, carry out the customer organisation's authorised workplace processes, protect legitimate interests such as security and reliable recordkeeping, or act on consent where consent is the appropriate lawful basis.

6. Who can see organisation information

Access inside an organisation follows the roles, groups and assignments configured for that workspace. Staff, managers, administrators, approvers, group owners and finance users may therefore see different information. Organisation administrators are responsible for giving people appropriate access and removing that access when it is no longer needed.

OrgSpace personnel and service providers may access information only where that access is reasonably needed to operate, support, secure or lawfully administer the service.

7. Service providers and other disclosures

OrgSpace uses service providers that may act as operators or sub-processors. These include Google Firebase and Google Cloud for authentication, databases, storage, functions and monitoring; Expo for mobile build, update and push-notification infrastructure; Paystack where subscription payments are enabled; and the configured transactional-email provider for service and support email.

Information may also be disclosed to the customer organisation, authorised users, professional advisers, regulators, law-enforcement bodies or another party where the disclosure is required by law, reasonably necessary to protect rights or security, or authorised by the responsible party. OrgSpace does not sell personal information.

8. International processing and transfers outside South Africa

OrgSpace uses Google Cloud and Firebase infrastructure. Many application functions are deployed in Google Cloud's South Africa region. Certain web-portal and scheduled workloads use a Google Cloud Europe region because of Firebase platform constraints. Google, Expo, Paystack and other providers may also process information in other countries under their own service arrangements.

Where personal information is transferred outside South Africa, OrgSpace and the responsible customer organisation must rely on a ground permitted by POPIA section 72 and use reasonable contractual, organisational and technical safeguards. Current sub-processor and processing-region information can be requested through the Support & Privacy page.

9. Security and security incidents

OrgSpace uses measures such as Firebase authentication, role- and organisation-based access, server-side checks for sensitive workflows, protected private-file paths, short-lived authorised file access, audit records, encrypted provider transport, monitoring and device security features. No online service can promise absolute security.

A suspected security compromise or security incident can be reported through the Support & Privacy page. OrgSpace will investigate, contain and document material incidents and will notify the responsible customer, affected people and the South African Information Regulator where POPIA or another applicable law requires notification.

10. How long information is kept

Personal information is kept only for as long as it is reasonably needed for the stated purpose, the customer's lawful recordkeeping, security and fraud prevention, dispute resolution, contractual duties or applicable law.

Operational notification records are scheduled for deletion after 12 months. Public-form rate-limit records are scheduled for deletion within 7 days (seven days). Completed support and privacy request records are scheduled for deletion after 3 years (three years). Account-deletion audit records retain only a hashed subject reference and the completion result for as long as reasonably needed to show that the deletion process was completed.

OrgSpace does not keep a device-side queue of business changes for later sending. Operational changes require a live connection. Temporary local files used during an upload, ordinary application cache and a small user-scoped session envelope may remain on a device as part of normal app operation, but they are not a store of unsent business records.

Approved requisitions, finance approvals, leave history, fleet and fuel records, meeting records and audit trails may remain as legitimate organisation records even after a user leaves. Where appropriate, personal details can be anonymised without rewriting the organisation's underlying audit history.

Backup copies may remain until the configured backup or soft-delete cycle expires and are used only for security, continuity and recovery.

11. Your privacy rights

Subject to POPIA, PAIA and any lawful need to preserve organisation records, a person may ask whether personal information is held, request access, ask for inaccurate information to be corrected, request deletion where there is no lawful reason to keep the information, object to processing in appropriate circumstances, or withdraw consent where processing depends on consent. Identity may need to be verified before a request is completed.

Where the customer organisation controls the relevant workplace record, OrgSpace may refer the request to that organisation or assist the organisation in responding.

12. Account deletion

An authenticated in-app deletion request starts the account-deletion process. It revokes the login, removes unnecessary private account information and protected personal licence files, and anonymises the membership profile while preserving legitimate organisation records. Failed automated steps are retried and escalated for manual review. The target completion period is 30 days.

A public web request must be verified before account data can be deleted. If the requester is the sole owner of an organisation, ownership must first be transferred or the organisation must be formally closed.

13. Service messages and direct marketing

OrgSpace may send service messages that are necessary for account security, approvals, workflow activity, support or subscription administration. These are different from marketing messages.

Electronic direct marketing is sent only where permitted by applicable law. Where a marketing message includes an unsubscribe or opt-out option, using it will stop that type of marketing but will not stop operational messages needed to provide or secure the service.

14. Automated rules

OrgSpace applies configured workflow rules, access rules, reminders and plan limits, but it is not intended to make solely automated decisions that have legal or similarly significant effects on a person. Approval, employment, finance, leave and fleet decisions remain the responsibility of authorised people in the customer organisation.

15. Special personal information and children

Workplace records can sometimes contain special personal information, for example where a leave reason or supporting document reveals health information. Customer organisations must only ask users to enter that information when there is a lawful basis and appropriate safeguards.

OrgSpace is intended for authorised workplace use and is not designed as a consumer service for children. An organisation must not create an account for a child unless it has a lawful basis and has put in place all safeguards required by applicable law.

16. Changes to this policy

This policy may change when OrgSpace features, providers, processing locations or legal requirements change. The current version and effective date will remain available on the public Privacy Policy page. Material changes will be communicated through an appropriate service channel.

17. Contact and complaints

For privacy, access, correction, objection or security requests, use orgspace.co.za/support. For deletion requests, use orgspace.co.za/account-deletion. The OrgSpace privacy and Information Officer contact channel is hello@orgspace.co.za.

You may also complain to the Information Regulator (South Africa). The Regulator publishes its current contact details at inforegulator.org.za. Its general contact number is 010 023 5200, its general email is enquiries@inforegulator.org.za and POPIA complaints may be sent to POPIAComplaints@inforegulator.org.za.