South African data protection

Our practical POPIA approach

POPIA compliance is a shared operational responsibility. WorkOrderPro provides controls and processes that help customers manage work-order information responsibly; each customer remains responsible for how it collects and uses information in its own business.

Defined roles

The customer is generally the responsible party for people and job data it enters. WorkOrderPro generally acts as an operator for that workspace data.

Purpose-limited processing

Workspace information is processed to provide, secure, support, and maintain the field-service workflow and related communications.

Access and security

Tenant separation, authenticated access, configurable roles, audit records, encryption in transit, and operational safeguards reduce unauthorised access risk.

Requests and incident handling

Documented privacy and security paths support access or correction requests and the investigation of suspected information-security incidents.

What customers should configure

  • Give each user an individual account and only the permissions needed for their role.
  • Tell employees and customers when location, photos, signatures, or other personal information will be collected.
  • Set lawful retention and deletion practices for job cards, invoices, equipment records, and employee evidence.
  • Review exports, integrations, shared links, and mobile-device access as part of the company’s own privacy and security programme.
  • Notify WorkOrderPro promptly if a suspected incident may involve the hosted service.

Privacy requests

For information held in a customer workspace, contact that organisation first. For WorkOrderPro account or website privacy questions, email privacy@workorderpro.co.za. We verify requests and respond subject to POPIA and applicable exceptions.