RIZO PROVIDER APP

PRIVACY POLICY

Last updated: 29 August 2026

1. Introduction

RIZO respects the privacy of professionals and service businesses that use the RIZO Provider Platform.

This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you:

·       create or use a RIZO Provider account;

·       create or manage a Provider profile;

·       offer Services through RIZO;

·       receive and manage Service Requests;

·       communicate with Clients;

·       use the HandyMan functionality;

·       receive ratings and reviews;

·       seek Gigducation credit through the Gig Skills Quality Council;

·       communicate with RIZO support; or

·       otherwise interact with the RIZO Platform.

RIZO is operated by:

Legal entity: Helping Everyone Rise Pty Ltd
Registration number:
2024/491226/07
Trading name: RIZO
Registered address: Baillie Park, Potchefstroom, 2526
Physical address: Baillie Park, Potchefstroom, 2526
Email: geraldine@helpingrise.co.za
Telephone: 083 798 1785
Website: www.helpingrise.co.za

 

In this Privacy Policy, “RIZO”, “we”, “our” and “us” refer to the legal entity identified above.

We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”) and other applicable South African law.

This Privacy Policy should be read together with the RIZO Provider Terms and Conditions.

2. Who This Privacy Policy Applies To

This Privacy Policy applies primarily to:

·       individual Providers;

·       professionals;

·       sole proprietors;

·       representatives of service businesses;

·       persons administering Provider accounts;

·       persons whose information is submitted as part of Provider verification; and

·       Providers using the HandyMan functionality.

Separate privacy information may apply to Clients using the MyRIZO Client application.

Where a HandyMan creates or uses a separate RIZO-related account, additional privacy information may be provided to that person where appropriate.

3. Our Role Under POPIA

Where RIZO determines why and how personal information is processed for purposes of operating the Platform, RIZO acts as a Responsible Party under POPIA.

We may appoint technology companies and other service providers to process information on our behalf.

Where those organisations process personal information according to RIZO’s instructions, they act as operators or service providers and are required to apply appropriate privacy and security protections.

A Provider may separately act as a Responsible Party in relation to personal information that the Provider independently collects or processes for the Provider’s own business activities.

For example, a Provider may independently process information concerning:

·       its own Clients;

·       employees;

·       Handymen;

·       contractors;

·       invoices;

·       customer records; or

·       statutory business records.

4. Personal Information We May Collect

The information we collect depends on how you use RIZO and the type of Provider account you operate.

We aim to collect only information reasonably necessary for legitimate Platform, verification, security and operational purposes.

5. Account and Contact Information

When you register or manage a RIZO Provider account, we may collect:

·       first name;

·       surname;

·       mobile telephone number;

·       email address;

·       username or Provider profile name;

·       password or authentication credentials in protected form;

·       profile photograph;

·       account identifier;

·       preferred language;

·       communication preferences;

·       account creation date;

·       account status; and

·       authentication and security information.

Your mobile number or email address may be used for account verification, login and one-time-password authentication.

6. Identity and Provider Verification Information

RIZO may require Providers to complete verification procedures.

Depending on the Provider category and verification procedures in use, we may collect or process information such as:

·       full legal name;

·       identity number or other identifying information;

·       identity-document information;

·       date of birth;

·       photograph;

·       proof of address;

·       mobile number;

·       email address;

·       business registration information;

·       business ownership or representative information;

·       professional registrations;

·       licences;

·       permits;

·       qualifications or certificates;

·       verification status;

·       dates on which documents were submitted or verified; and

·       other information reasonably required to verify information represented on a Provider profile.

RIZO verification confirms only the matters included within the applicable verification procedure.

It does not constitute a determination or guarantee by RIZO of a Provider’s skill level, workmanship, character, reliability or trustworthiness.

Where additional verification requiring special personal information is introduced, RIZO will process that information only where permitted by applicable law and will provide additional notice or obtain consent where required.

7. Business and Professional Profile Information

To enable Clients to discover and assess Providers, we may collect and display Provider information including:

·       Provider or business name;

·       profile photograph or business logo;

·       Service categories;

·       description of Services;

·       professional experience;

·       areas of operation;

·       availability;

·       qualifications or professional information that the Provider chooses or is required to display;

·       business registration information where relevant;

·       photographs of previous work;

·       pricing or quotation information;

·       Provider ratings;

·       Client reviews; and

·       other information included on the Provider profile.

You are responsible for ensuring that the information you submit is accurate and that you have the lawful right to provide it.

8. Location Information

Location information is important to RIZO because the Platform helps connect Providers with Clients requiring Services in relevant geographic areas.

Depending on the features you use and the permissions you grant, RIZO may process:

·       approximate location;

·       precise device location;

·       Provider areas of operation;

·       town or city;

·       suburb;

·       province;

·       geographic coordinates;

·       location associated with Service Requests;

·       Service addresses provided by Clients; and

·       location information needed for mapping or Service delivery.

Device location permissions can generally be managed through your Android or iOS device settings.

Disabling location access may limit some Platform functionality.

9. Service Request and Job Information

When you receive, accept, manage or complete Service Requests, we may process:

·       Service category;

·       Service description;

·       Client selected;

·       Provider selected;

·       Service address;

·       requested date and time;

·       accepted date and time;

·       Booking status;

·       Service status;

·       cancellation information;

·       quotation or agreed pricing information recorded through the Platform;

·       assignment to a HandyMan;

·       completion status;

·       Client confirmation;

·       Provider notes;

·       photographs or attachments submitted in relation to the job;

·       complaint or dispute status; and

·       other information reasonably necessary to operate the Service Request.

These records may form part of the electronic history of a Service arranged through RIZO.

10. Client Information Received by Providers

RIZO may make certain Client information available to a Provider where necessary for a Service Request.

Depending on the Service and stage of the transaction, this may include:

·       Client name or profile name;

·       Client contact details;

·       Service description;

·       Service address;

·       location information;

·       preferred date and time;

·       photographs or attachments supplied by the Client;

·       communications; and

·       other information reasonably necessary to assess or perform the Service.

Providers must process Client personal information lawfully and in accordance with the RIZO Provider Terms and applicable data-protection legislation.

Access to Client information through RIZO does not give a Provider unrestricted rights to use that information for unrelated purposes.

11. Communications

Where RIZO provides communication functionality between Providers, Clients and Handymen, we may process:

·       messages;

·       communication participants;

·       date and time information;

·       attachments;

·       delivery or read status where supported;

·       job-related communications;

·       reports of inappropriate communications; and

·       technical records relating to Platform communications.

Communications may be retained where reasonably necessary for:

·       facilitating Service Agreements;

·       resolving disputes;

·       Client and Provider support;

·       safety investigations;

·       preventing fraud;

·       enforcing Platform rules;

·       maintaining transaction records; or

·       complying with law.

Providers should not unnecessarily transmit sensitive information such as passwords, banking PINs or one-time passwords through Platform communications.

12. Ratings and Reviews

Clients may rate and review Providers after Services.

RIZO may process:

·       individual rating scores;

·       written reviews;

·       average rating;

·       number of ratings received;

·       Service associated with a rating;

·       date of a rating or review;

·       Provider responses;

·       complaints concerning reviews;

·       information relating to suspected review manipulation; and

·       aggregated rating information.

Ratings and reviews may become part of the Provider’s Platform service history and may be visible to other Users.

RIZO does not treat a rating as an independent RIZO certification of the Provider’s skill or trustworthiness.

13. Service History and Platform Reputation

RIZO may maintain information about a Provider’s activity and service history, including:

·       Services accepted;

·       Services completed;

·       cancellations;

·       response behaviour;

·       Service categories;

·       rating history;

·       review history;

·       complaints;

·       Platform-rule violations;

·       Provider status; and

·       other legitimate Platform activity.

This information may be used to:

·       operate Provider profiles;

·       support Client decision-making;

·       prevent fraud;

·       investigate Platform misuse;

·       administer Provider accounts;

·       improve the marketplace; and

·       support Provider-requested recognition processes where applicable.

14. Gig Skills Quality Council and Gigducation Information

RIZO may provide functionality enabling a Provider to use relevant Platform evidence when seeking Gigducation credit or other recognition through the Gig Skills Quality Council (“GSQC”).

Participation is voluntary.

RIZO will not share an identifiable Provider’s ratings or relevant Provider service-history information with the GSQC for this purpose unless the Provider has expressly consented to the proposed disclosure.

Where the Provider chooses to seek Gigducation credit, RIZO may request consent to share information such as:

·       Provider name or Provider identifier;

·       relevant Service category;

·       number of relevant completed Services;

·       Client rating scores relevant to the application;

·       average or aggregated rating information;

·       the period over which ratings were obtained;

·       relevant Provider service-history information; and

·       other information expressly disclosed to and authorised by the Provider.

Before the Provider confirms the request, RIZO will endeavour to identify the information proposed to be shared and the purpose of the transfer.

15. Client Information Will Not Ordinarily Be Shared With GSQC

A Provider’s consent to share the Provider’s rating or service-history information with GSQC does not automatically authorise disclosure of Client personal information.

Unless separately authorised or otherwise lawfully required, RIZO will not disclose to GSQC for Gigducation-credit assessment:

·       Client names;

·       Client telephone numbers;

·       Client email addresses;

·       Client Service addresses;

·       private Client–Provider messages; or

·       other unnecessary Client personal information.

Where evidence can reasonably be provided in aggregated or de-identified form, RIZO may use that approach.

16. GSQC Assessment Is Independent

RIZO’s role is to provide Provider-authorised Platform evidence where applicable.

The GSQC is responsible for applying its own assessment criteria to determine whether Gigducation credit or other recognition should be awarded.

Consent to share information does not guarantee:

·       Gigducation credit;

·       certification;

·       recognition;

·       a particular competency finding; or

·       any other outcome.

RIZO may confirm that particular information originates from RIZO Platform records without declaring that the data independently proves a Provider’s skill level.

17. Withdrawing GSQC Consent

Where disclosure to GSQC is based on Provider consent, the Provider may withdraw that consent before RIZO transmits the relevant information.

Withdrawal of consent after information has already been lawfully transferred does not automatically invalidate the earlier transfer.

Information already received by the GSQC may remain subject to GSQC’s own lawful retention obligations and privacy responsibilities.

18. HandyMan Information

Where a Provider uses the RIZO HandyMan functionality, the Provider may submit or manage information relating to Handymen.

Depending on the functionality available, this may include:

·       name;

·       surname;

·       mobile number;

·       photograph;

·       identification information;

·       Provider association;

·       assigned Service;

·       Service location;

·       job status;

·       Service category;

·       job history;

·       access permissions; and

·       other information reasonably necessary for the HandyMan functionality.

RIZO will process this information for legitimate Platform purposes and in accordance with applicable law.

19. Provider Responsibility When Supplying HandyMan Information

Where you submit personal information about a HandyMan, employee, contractor or other person to RIZO, you confirm that you have a lawful basis to provide the information.

You are responsible for appropriately informing those persons where required by law that their information will be processed through RIZO.

You must not submit unnecessary or unlawfully obtained information about another person.

Where a Provider independently controls information concerning its employees, contractors or Handymen, the Provider remains responsible for its own POPIA obligations.

20. Customer Support and Complaint Information

If you contact RIZO support or are involved in a complaint, we may process:

·       Provider identity;

·       contact information;

·       account information;

·       Client information relevant to the complaint;

·       Service Request information;

·       messages;

·       photographs;

·       documents;

·       allegations or responses;

·       investigation records;

·       safety information;

·       action taken by RIZO; and

·       correspondence relating to the matter.

We may use this information to investigate complaints, enforce Platform rules, protect Users and respond to legal requirements.

21. Safety and Fraud Information

RIZO may process information where reasonably necessary to detect, prevent or investigate:

·       identity fraud;

·       fake accounts;

·       false verification documents;

·       fabricated Service Requests;

·       rating manipulation;

·       theft;

·       harassment;

·       threats;

·       unsafe behaviour;

·       illegal Services;

·       cybersecurity incidents;

·       abuse of Client information; or

·       other suspected Platform misuse.

Where serious misconduct is alleged, relevant information may be retained for investigation and legal purposes.

22. Device and Technical Information

When you use RIZO, technical information may be generated automatically by RIZO and the technology services supporting the Platform.

This may include:

·       IP address;

·       device type;

·       device operating system;

·       application version;

·       browser information;

·       device or application identifiers;

·       app-instance identifiers;

·       language and region;

·       login records;

·       session information;

·       screens or features used;

·       search and interaction activity;

·       approximate geographic location;

·       location information where permission has been granted;

·       error logs;

·       diagnostic information;

·       security information; and

·       technical events generated through Platform use.

We use this information to operate, secure, maintain and improve RIZO.

23. App Permissions

Depending on the features available, the RIZO Provider application may request permission to use certain device functions.

These may include:

Location

To identify Service Requests in relevant areas, display Service locations or provide mapping functionality.

Camera and photographs

To allow you to upload profile images, verification documents, photographs of previous work or job-related evidence.

Notifications

To send information about:

·       Service Requests;

·       Client communications;

·       accepted jobs;

·       changes to Bookings;

·       safety information;

·       account security; and

·       other relevant Platform activity.

Storage or file access

Where required to upload documents, photographs or attachments selected by you.

You can generally manage application permissions through your device settings.

Disabling a permission may prevent the associated feature from functioning.

24. Information We Receive From Other People

Not all Provider information is necessarily collected directly from the Provider.

We may receive information from:

·       Clients;

·       Handymen;

·       persons authorised by a Provider;

·       verification services;

·       regulators or professional bodies;

·       customer-support reports;

·       fraud and safety reports;

·       law-enforcement authorities;

·       technology providers; and

·       publicly available sources where lawful and appropriate.

For example, Clients may provide ratings, complaints or safety reports concerning a Provider.

Where required by POPIA, RIZO will take appropriate steps to inform data subjects about information obtained from another source.

25. Information We Do Not Process for Client-to-Provider Service Payments

RIZO does not currently process Client payments for Provider Services.

Payments for Services are made directly between the Client and Provider according to their agreed payment arrangement, including cash on delivery/completion or another lawful direct-payment method.

Accordingly, RIZO does not ordinarily require:

·       Provider bank-account credentials;

·       Client card information;

·       banking passwords;

·       card PINs;

·       card security codes; or

·       banking one-time passwords

for purposes of paying for a Provider Service.

Where payment information is voluntarily included in Platform communications or submitted as evidence in a dispute, it may form part of the relevant record.

Users should avoid disclosing secret banking or authentication credentials.

If RIZO introduces Platform payment processing in future, this Privacy Policy and relevant Terms will be updated where required before such functionality is implemented.

26. Why We Process Provider Personal Information

RIZO may process Provider personal information for purposes including:

26.1 Creating and administering Provider accounts

Including:

·       registration;

·       authentication;

·       account recovery;

·       account security;

·       Provider profile administration; and

·       account communications.

26.2 Provider verification

Including:

·       verifying identity;

·       confirming supplied information;

·       detecting fraudulent registrations;

·       maintaining verification records; and

·       administering Provider verification indicators.

26.3 Operating the marketplace

Including:

·       displaying Provider profiles;

·       matching Providers with relevant Service Requests;

·       facilitating Service Requests;

·       enabling Client–Provider communications;

·       managing job status; and

·       maintaining Platform service histories.

26.4 Providing location-based functionality

Including:

·       identifying Service Requests within relevant geographic areas;

·       mapping Service locations; and

·       helping Providers reach Clients.

26.5 Operating HandyMan functionality

Including:

·       associating Handymen with Providers;

·       facilitating job allocation;

·       sharing information necessary to perform Services; and

·       managing job status.

26.6 Managing ratings and reviews

Including:

·       displaying Client feedback;

·       calculating Provider ratings;

·       detecting rating manipulation; and

·       maintaining Provider reputation information.

26.7 Supporting Provider-requested Gigducation recognition

Where a Provider expressly requests and consents to it, relevant Provider ratings or service-history information may be transferred to GSQC for Gigducation-credit assessment.

26.8 Providing support and resolving complaints

Including:

·       responding to Provider enquiries;

·       investigating disputes;

·       responding to Client complaints; and

·       investigating serious incidents.

26.9 Protecting RIZO and its Users

Including:

·       fraud prevention;

·       cybersecurity;

·       account protection;

·       safety investigations;

·       enforcing Platform rules; and

·       establishing or defending legal claims.

26.10 Improving the Platform

Including:

·       analysing Platform usage;

·       identifying technical problems;

·       improving Provider matching;

·       understanding Provider engagement;

·       developing new features; and

·       improving Platform performance.

26.11 Complying with law

Including responding to lawful obligations, regulatory requirements and valid legal process.

27. Lawful Grounds for Processing

Depending on the processing activity, RIZO may process personal information because:

·       you have consented;

·       processing is necessary to conclude or perform an agreement with you;

·       processing is required to comply with law;

·       processing protects your legitimate interests;

·       processing protects another person’s legitimate interests; or

·       processing is necessary for legitimate interests pursued by RIZO or another person, provided those interests do not unjustifiably prejudice your rights.

RIZO will not rely on consent where another lawful basis is more appropriate merely to create the appearance that all processing is optional.

Where consent is the lawful basis, you may withdraw that consent subject to applicable law.

Some information is necessary to operate a Provider account. Failure to provide required information may mean that RIZO cannot register, verify or provide particular Platform functionality to you.

28. Who We May Share Provider Information With

RIZO may disclose Provider information only where reasonably necessary and lawful.

Recipients may include the categories below.

29. Clients

Information displayed or disclosed to Clients may include:

·       Provider profile name;

·       photograph;

·       business name;

·       Service categories;

·       experience;

·       Service areas;

·       professional information;

·       availability;

·       ratings;

·       reviews;

·       verification indicators;

·       information necessary for an accepted Service Request; and

·       Provider contact details where appropriate.

The purpose is to enable Clients to discover, assess, contact and engage Providers.

30. Handymen

Where a Provider assigns a Service to a HandyMan, RIZO may share information reasonably required to perform the job, including:

·       Provider information;

·       Service information;

·       Service address;

·       Client information necessary for Service delivery;

·       scheduled date and time; and

·       other job instructions.

Information should be limited to what is reasonably required for the relevant Service.

31. Gig Skills Quality Council

Where a Provider expressly chooses to seek Gigducation credit or another GSQC recognition and gives the required consent, RIZO may provide the GSQC with the Provider information identified during that application process.

RIZO will endeavour to limit the transfer to information reasonably relevant to the assessment.

RIZO will not treat general acceptance of the RIZO Provider Terms as blanket consent to share Provider ratings with GSQC.

A separate Provider action or consent mechanism will be used for this purpose.

32. Hostinger

The main RIZO website and related web infrastructure are hosted using Hostinger services.

Depending on the technical configuration, information processed through Hostinger-hosted infrastructure may include:

·       Provider account information;

·       web submissions;

·       database information;

·       IP addresses;

·       server logs;

·       support or administrative data; and

·       other information stored through RIZO’s hosted systems.

RIZO remains responsible for determining the purposes for which personal information under its control is processed.

Hostinger may use infrastructure and subprocessors located in different jurisdictions.

33. Google Firebase Authentication and OTP Services

RIZO uses Google Firebase Authentication for authentication and account-security functionality.

Depending on the authentication method used, Firebase Authentication may process information including:

·       telephone numbers;

·       email addresses;

·       passwords or authentication information;

·       user-agent information;

·       IP addresses; and

·       authentication identifiers.

Where OTP authentication is used, your telephone number may be processed to:

·       send or verify an OTP;

·       authenticate your Provider account;

·       prevent fraudulent access; and

·       protect account security.

You must not provide an authentication OTP to another person.

RIZO representatives, Clients and Handymen should not require your account-authentication OTP.

34. Google Maps Platform

RIZO uses Google Maps Platform for mapping and geographic functionality.

Google Maps functionality may be used to:

·       display maps;

·       identify Service locations;

·       show locations relevant to a Service Request;

·       support address entry;

·       support Provider geographic search;

·       provide navigation-related functionality; and

·       identify Services within relevant operating areas.

Information processed in connection with Google Maps may include:

·       IP address;

·       application or device information;

·       coordinates;

·       addresses;

·       location queries; and

·       other technical request information.

Precise device location will be accessed only where enabled by the relevant feature and device permissions.

35. Google Analytics and Firebase Analytics

RIZO uses Google Analytics, including analytics functionality associated with Firebase, to understand how Providers interact with the Platform.

Depending on configuration, analytics information may include:

·       app-instance identifiers;

·       sessions;

·       application events;

·       screens viewed;

·       features used;

·       approximate location;

·       browser information;

·       device information;

·       operating system; and

·       application-performance information.

RIZO may use this information to:

·       understand Platform usage;

·       improve Provider functionality;

·       troubleshoot problems;

·       identify commonly used features;

·       measure Platform performance; and

·       guide product development.

Where reasonably practicable, analytics information is reviewed in aggregated or statistical form.

RIZO does not currently use Google Analytics information to determine whether a Provider is skilled or trustworthy.

36. Google Platform Services

The Android version of RIZO may use Google platform and developer services and may be distributed through Google Play.

Google may separately process certain information when providing:

·       Google Play;

·       Android;

·       device security;

·       operating-system functionality; and

·       Google account services.

Information Google independently processes as part of its own relationship with a Google user is governed by Google’s applicable privacy policies and terms.

This is distinct from information processed by Google on RIZO’s behalf through services such as Firebase.

37. Apple Developer and App Store Services

The iOS version of RIZO uses Apple developer and platform services and may be distributed through the Apple App Store.

Apple may independently process information when providing:

·       App Store distribution;

·       Apple ID services;

·       application installation and updates;

·       iOS functionality;

·       device security;

·       fraud-prevention functions; and

·       other Apple services.

Such information may include device information, identifiers, IP addresses and information associated with the User’s Apple services.

Information independently processed by Apple is subject to Apple’s own applicable privacy terms.

38. Other Technology Providers

RIZO may use additional service providers where reasonably necessary for:

·       cloud infrastructure;

·       communications;

·       customer support;

·       cybersecurity;

·       application development;

·       monitoring;

·       error reporting;

·       backup;

·       database services; and

·       other Platform functions.

Where these service providers process personal information on RIZO’s instructions, RIZO will take reasonable steps to require appropriate privacy, confidentiality and security protections.

39. We Do Not Sell Provider Personal Information

RIZO does not sell Provider personal information to unrelated third parties for their independent direct-marketing purposes.

RIZO also does not sell:

·       Provider identity documents;

·       private Client–Provider communications;

·       precise job-location history; or

·       Provider verification documents

to third parties for unrelated advertising purposes.

40. Direct Marketing to Providers

Where permitted by law, RIZO may communicate with Providers about:

·       Platform features;

·       Provider opportunities;

·       new Services;

·       Gigducation opportunities;

·       promotional initiatives;

·       Provider plans; or

·       other RIZO-related offerings.

Where consent is legally required for electronic direct marketing, RIZO will obtain that consent.

Providers may opt out of promotional communications through the available unsubscribe or preference mechanisms.

Opting out of marketing does not prevent RIZO from sending necessary operational communications such as:

·       Service Request notifications;

·       account-security notices;

·       changes to legal terms;

·       Provider verification notices;

·       Client messages;

·       safety information; or

·       important account communications.

41. Provider Search, Ranking and Recommendations

RIZO may use Provider and Platform information to determine how Providers are presented to Clients.

Relevant factors may include:

·       location;

·       Service category;

·       availability;

·       profile completeness;

·       rating information;

·       Service history;

·       response behaviour;

·       Platform activity; and

·       relevance to a Client’s Service Request.

Search positioning is a Platform-discovery mechanism and is not a certification of Provider competence or trustworthiness.

RIZO may review and modify ranking mechanisms as the Platform develops.

Where RIZO introduces solely automated decision-making that produces legal consequences or substantially affects a Provider in a manner regulated by POPIA, appropriate safeguards will be applied.

42. Cookies, SDKs and Similar Technologies

The RIZO website and applications may use:

·       cookies;

·       software development kits (“SDKs”);

·       application-instance identifiers;

·       device identifiers;

·       local storage;

·       analytics technologies; and

·       similar technical mechanisms.

These may support:

·       authentication;

·       security;

·       location services;

·       analytics;

·       preferences;

·       application performance;

·       session management; and

·       Platform improvement.

Providers may have certain controls through:

·       browser settings;

·       Android settings;

·       iOS settings; or

·       RIZO settings where available.

Where consent is legally required for a particular technology, an appropriate consent mechanism will be used.

43. International and Cross-Border Processing

Although RIZO operates in South Africa, some of the technology used to operate the Platform processes information internationally.

Current technology services include:

·       Hostinger;

·       Google Firebase;

·       Google Maps Platform;

·       Google Analytics;

·       Google developer/platform services; and

·       Apple developer/platform services.

In particular, Firebase Authentication processes authentication information in the United States.

Other Google, Apple and Hostinger services may process information in jurisdictions in which those organisations or their authorised service providers operate infrastructure.

Where personal information is transferred outside South Africa, RIZO will take reasonable steps to ensure that the transfer is permitted under section 72 of POPIA.

Depending on the circumstances, this may include ensuring that:

·       the recipient is subject to adequate legal protection;

·       an appropriate agreement or binding corporate rules apply;

·       the transfer is necessary for performance of an agreement;

·       another lawful basis under POPIA applies; or

·       appropriate consent is obtained where required.

Using international technology infrastructure does not remove RIZO’s POPIA responsibilities for information for which RIZO is the Responsible Party.

44. How Long We Keep Provider Information

RIZO retains personal information only for as long as reasonably necessary for the purpose for which it was collected or subsequently lawfully processed, unless longer retention is required or permitted by law.

Factors considered may include:

·       whether the Provider account remains active;

·       verification requirements;

·       ongoing Services;

·       disputes;

·       Client complaints;

·       safety incidents;

·       fraud-prevention requirements;

·       Provider ratings and service history;

·       GSQC/Gigducation applications;

·       legal claims;

·       statutory recordkeeping requirements;

·       regulatory obligations; and

·       legitimate Platform security needs.

Where personal information is no longer lawfully required, RIZO will take reasonable steps to delete, destroy or de-identify it.

Closing a Provider account does not necessarily require immediate deletion of all information where retention remains legally justified.

45. Verification Records After Account Closure

Certain Provider verification records may need to be retained after an account is closed where reasonably necessary for:

·       fraud prevention;

·       responding to legal claims;

·       regulatory requirements;

·       investigation of misconduct;

·       maintaining evidence of previous verification; or

·       preventing previously restricted Users from circumventing Platform controls.

RIZO will not retain verification information indefinitely without a lawful purpose.

46. Security of Personal Information

RIZO takes reasonable technical and organisational measures designed to protect personal information against:

·       loss;

·       unlawful access;

·       unauthorised disclosure;

·       destruction;

·       alteration;

·       misuse; and

·       unauthorised processing.

Depending on the relevant system, measures may include:

·       authentication;

·       access controls;

·       encryption where appropriate;

·       network safeguards;

·       secure software-development practices;

·       monitoring;

·       security updates;

·       backup procedures;

·       staff confidentiality requirements;

·       restricted administrative access;

·       incident-response processes; and

·       contractual safeguards for operators.

No online system can guarantee absolute security.

Providers must also protect their accounts by:

·       using strong credentials;

·       keeping passwords confidential;

·       protecting access to their devices;

·       never sharing OTPs;

·       limiting access by staff;

·       promptly removing access for persons who no longer require it; and

·       reporting suspected account compromise to RIZO.

47. Security Compromises

Where RIZO has reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, RIZO will investigate and respond in accordance with POPIA.

Where legally required, RIZO will notify:

·       the Information Regulator; and

·       affected data subjects

as soon as reasonably practicable, subject to lawful restrictions.

RIZO may also take steps to:

·       contain the incident;

·       secure affected systems;

·       reset credentials;

·       investigate the cause;

·       reduce potential harm; and

·       strengthen relevant safeguards.

48. Special Personal Information

RIZO is not designed to collect unnecessary special personal information.

Providers should avoid submitting information concerning matters such as:

·       health;

·       religious beliefs;

·       political persuasion;

·       race or ethnic origin;

·       trade union membership;

·       sexual life;

·       criminal behaviour; or

·       biometric information

unless it is genuinely required and lawfully processed for a specific purpose.

Where RIZO needs to process special personal information for a legitimate verification, legal or safety purpose, it will do so only where permitted under POPIA.

49. Provider Information About Children

Providers must not unnecessarily collect, upload or disclose children’s personal information through RIZO.

Where a Service legitimately concerns a child, Providers should process only the minimum information reasonably necessary for that Service.

Providers should not unnecessarily record or upload:

·       children’s identity information;

·       school details;

·       private photographs;

·       precise routine information;

·       health information; or

·       other sensitive information.

50. Your Rights Under POPIA

Subject to applicable law and appropriate identity verification, Providers may have the right to:

50.1 Be informed

To receive information about the collection and processing of their personal information.

50.2 Confirm whether information is held

To request confirmation that RIZO holds personal information about them.

50.3 Access information

To request access to personal information held by RIZO, subject to lawful limitations.

50.4 Correct information

To request correction of personal information that is inaccurate, incomplete, misleading or outdated.

50.5 Request deletion or destruction

To request deletion or destruction of information that RIZO is no longer authorised to retain.

50.6 Object to processing

To object to certain processing in circumstances permitted by POPIA.

50.7 Withdraw consent

Where processing relies on consent, to withdraw that consent.

50.8 Object to direct marketing

To object to personal information being used for direct marketing and to unsubscribe from electronic marketing communications.

50.9 Complain

To submit a privacy complaint to RIZO or, where applicable, the Information Regulator of South Africa.

51. Exercising Your Privacy Rights

To exercise a privacy right or submit a privacy enquiry, contact:

Information Officer: VFS Mudavanhu
Email: info@myrizo.app
Telephone: 083 798 1785
Physical address: Baillie Park, Potchefstroom, 22526

RIZO may require reasonable proof of identity before releasing, correcting or deleting Provider information.

This protects Provider information from unauthorised access.

Where RIZO cannot lawfully comply with a request in full, RIZO will provide an appropriate explanation where required by law.

52. Provider Account Deletion

A Provider may request closure or deletion of a Provider account through available Platform functionality or by contacting RIZO.

Following a valid request:

·       the Provider account may be deactivated;

·       personal information that is no longer required may be deleted, destroyed or de-identified;

·       information that RIZO must lawfully retain may continue to be retained;

·       completed Service records may be retained where necessary for Client records, disputes or legal purposes; and

·       ratings or reviews may be retained, de-identified or otherwise managed in accordance with legitimate Platform and legal requirements.

Account deletion does not require RIZO to destroy information that it remains legally entitled or required to retain.

53. Provider-Controlled Client Records

Providers may independently create business records relating to Clients, including:

·       quotations;

·       invoices;

·       receipts;

·       customer records;

·       Service notes;

·       photographs;

·       warranties; or

·       tax records.

Where the Provider independently determines why and how those records are processed, the Provider is responsible for complying with applicable privacy law.

A Client privacy request concerning information controlled independently by the Provider may need to be addressed directly by the Provider.

54. Provider-Controlled HandyMan and Employee Records

Similarly, RIZO does not assume responsibility for all personnel records independently maintained by a Provider concerning:

·       employees;

·       Handymen;

·       contractors; or

·       other workers.

The Provider remains responsible for its own employment, labour, tax and privacy obligations concerning such records.

55. Third-Party Websites and Services

RIZO may contain links or integrations involving third-party services.

Where a Provider independently uses a third-party website or service, that third party’s privacy practices may apply.

RIZO remains responsible for third-party operators to the extent required by applicable law where those organisations process personal information specifically on RIZO’s instructions.

56. Changes to Technology Providers

The technology used by RIZO may evolve.

RIZO may replace, add or remove providers of:

·       hosting;

·       authentication;

·       analytics;

·       mapping;

·       notifications;

·       communications;

·       cybersecurity; or

·       other technology.

Where a change materially affects how Provider personal information is processed, transferred or protected, RIZO will update this Privacy Policy and provide further notice where required.

57. Changes to This Privacy Policy

RIZO may update this Privacy Policy to reflect:

·       changes in Platform functionality;

·       changes in law;

·       new Provider functionality;

·       changes in verification processes;

·       changes in technology providers;

·       GSQC or Gigducation functionality;

·       security developments; or

·       legitimate operational requirements.

The current policy will display its latest update date.

Where a change materially affects how personal information is processed, RIZO will take reasonable steps to notify affected Providers and obtain additional consent where legally required.

A change to this Privacy Policy will not retrospectively legitimise unlawful processing.

58. Relationship With the RIZO Provider Terms

This Privacy Policy explains how Provider personal information is handled.

The RIZO Provider Terms and Conditions govern the Provider’s contractual use of the Platform.

The documents should be read together.

Nothing in either document overrides a mandatory requirement of POPIA or another applicable law.

59. Information Regulator

If you believe that RIZO has unlawfully processed your personal information or has failed to appropriately resolve a privacy complaint, you may lodge a complaint with the Information Regulator of South Africa.

Current contact details and complaint mechanisms are available through the Information Regulator’s official channels.

You are not required to waive your right to approach the Information Regulator in order to use RIZO.

60. Contact RIZO About Privacy

For privacy enquiries, objections, access requests, correction requests, deletion requests or complaints, contact:

RIZO Information Officer

Name: VFS Mudavanhu
Designation: Chief Technology Officer
Email: info@myrizo.app
Telephone: 083 798 1785
Physical address: Baillie Park

General Provider support:

Email: fred@webcommunities.co.za
Telephone: 083 798 1785

61. Provider Acknowledgement

By using RIZO, you acknowledge that this Privacy Policy has been made available to you and explains how Provider personal information may be processed in connection with the Platform.

Where a particular processing activity requires consent, RIZO will obtain consent where required. Personal information will be processed only on a lawful basis and for legitimate purposes consistent with POPIA and applicable law.

END OF RIZO PROVIDER APP PRIVACY POLICY