
Privacy Policy

ABOUT THIS PRIVACY POLICY
This website www.suresystems.co.za (the "Website") and our proprietary debit order processing system, SUREdebit (developed by SOFTSPLICE), are operated by SureSystems ("SureSystems").
This Privacy Policy sets out how SureSystems collects, uses, stores, and protects personal information when you visit our Website, make use of our payment solutions, or process transactions via SUREdebit, our DebiCheck platform, and speed point terminals.
Throughout this Privacy Policy:
-
References to “SureSystems”, “we”, “us”, “our”, and “ours” refer to SureSystems.
-
The terms “you”, “your”, and “yours” refer to any website visitor, merchant client, or individual whose personal information is processed through our systems.
-
“SUREdebit” refers to the debit order collection platform developed by SOFTSPLICE and utilized by SureSystems to manage DebiCheck and debit order processing.
PURPOSE OF THIS PRIVACY POLICY & OUR ROLE
We are committed to the privacy, confidentiality, and security of all personal information entrusted to us. SureSystems is a System Operator registered with the Payments Association of South Africa (PASA), compliant with Payment Card Industry Data Security Standards (PCI DSS), and our terminal devices are EMV certified (supported by Access Bank SA Pty Ltd).
Dual Role Under POPIA
Depending on how you interact with us, SureSystems operates in two capacities under the Protection of Personal Information Act (POPIA):
-
Responsible Party: When we collect personal information directly from our merchant clients, website visitors, or business partners to manage our contractual relationships, onboard businesses, or market our services.
-
Operator (Data Processor): When our merchant clients upload and process their customers' personal and banking information on SUREdebit to initiate and collect debit orders/DebiCheck transactions. In this role, we process consumer data strictly on behalf of and according to the instructions of our merchant clients, in compliance with financial clearing rules and applicable laws.
What is Personal Information?
Personal information means any information that identifies a natural person or legal entity, including names, identity numbers, contact details, bank account details, transaction records, DebiCheck mandates, and IP addresses.
NOTIFICATION OF CHANGES TO THIS PRIVACY POLICY
We continually improve our payment technologies, terminal hardware, and service offerings. Due to ongoing developments, technological updates, or changes in legal and regulatory requirements (such as PASA regulations or FICA), our data protection practices will evolve over time.
When changes are made, we will update this Privacy Policy on our Website. It is your responsibility to periodically review this Privacy Policy for updates.
COLLECTION OF PERSONAL INFORMATION
1. Information Provided by Merchant Clients & Website Visitors
When you inquire about our services, register as a merchant, or use our platforms, we may collect:
-
Contact & Business Details: Name, email address, telephone number, physical address, company registration numbers, and director/owner details.
-
Banking & Settlement Information: Bank account details required for merchant payouts and service billing.
-
Support Interactions: Communications, technical support requests, and preferences regarding our terminal hardware or SUREdebit setup.
2. Information Processed via SUREdebit (Consumer & Payer Data)
When our merchant clients utilize SUREdebit (developed by SOFTSPLICE) to schedule and execute debit order collections from their end-customers, the platform processes:
-
DebiCheck & Mandate Data: Customer names, account numbers, branch codes, identity numbers, debit collection amounts, transaction frequencies, and mandate approval histories.
-
Transaction Histories: Collection statuses, rejections, disputes, and payment tracking history.
Note for Consumers/Payers: If your bank account is debited via SUREdebit, your primary relationship is with the merchant/business collecting payment from you. SureSystems processes your payment data securely as a registered System Operator under instruction from that merchant and in alignment with PASA rules.
3. Identity Verification & Biometric Data
To comply with the Financial Intelligence Centre Act (FICA) and anti-money laundering regulations during merchant onboarding:
-
We may collect identity documentation, proof of address, and where required, verification photographs or facial biometric checks to confirm identities against official databases.
-
Facial biometrics are categorized as Special Personal Information under POPIA. This data is handled with maximum security via authorized verification partners solely for legal compliance and identity confirmation—never for behavioral tracking or marketing.
4. Automatically Collected Information & Cookies
When accessing our Website or merchant portals:
-
Our web servers automatically collect non-personal analytics, such as IP addresses, browser types, pages viewed, domain names, and session duration to improve functionality and performance.
-
Cookies: We may use cookies on our Website and login portals to manage user sessions and securely remember your settings. You can manage your cookie preferences in your browser settings.
5. Interception & Monitoring of Communications
Permissible under South African law (including RICA), SureSystems may intercept, monitor, and record phone calls or electronic correspondence with our support, sales, or operational teams for quality control, staff training, transaction verification, and fraud prevention.
HOW WE USE PERSONAL INFORMATION
We process personal information exclusively for lawful business and regulatory purposes, including:
-
Processing Collections via SUREdebit: Executing debit orders, routing DebiCheck mandate requests, tracking collection statuses, and settling funds.
-
POS & Card Services: Provisioning and maintaining certified EMV POS terminals and card transaction facilities.
-
FICA & Regulatory Compliance: Verifying merchant identities, conducting screening, and fulfilling reporting obligations required by PASA, Access Bank SA Pty Ltd, and financial regulators.
-
Security & Fraud Prevention: Detecting, preventing, and investigating unauthorized transactions, system abuse, or payment fraud.
-
Customer & Technical Support: Resolving platform issues, managing hardware updates, and providing continuous support to merchants and their technical staff.
-
Platform Maintenance: Enhancing the functionality, stability, and security of SUREdebit in collaboration with system developer SOFTSPLICE.
DISCLOSURE & SHARING OF PERSONAL INFORMATION
SureSystems will never sell personal information. We share personal data only on a confidential need-to-know basis under strict regulatory frameworks:
-
Sponsor Banks & Payment Clearing Bodies: Access Bank SA Pty Ltd, PASA, card schemes, and central clearing houses involved in routing DebiCheck and debit order instructions.
-
Technology Developers & Providers: Authorized system developers (such as SOFTSPLICE) and secure infrastructure hosters who assist in maintaining, updating, and securing the SUREdebit environment under strict non-disclosure and data processing agreements.
-
Verification & FICA Agencies: Credit bureaus and identity verification providers used for regulatory compliance checks.
-
Legal Authorities: Law enforcement agencies, regulators, or courts where required by law, subpoena, or official directive.
DATA SECURITY & COMPLIANCE
Because SUREdebit and our payment terminals handle sensitive financial data, security is embedded into our infrastructure:
-
PCI DSS Compliance: Our architecture meets Payment Card Industry Data Security Standards to ensure card and payment data protection.
-
EMV Certification: Physical POS hardware is EMV certified to guarantee secure processing.
-
Encryption & Access Control: Data transmitted through SUREdebit and stored within our database environment is encrypted in transit and at rest. Strict role-based access control ensures only authorized personnel handle operational data.
RETENTION OF PERSONAL INFORMATION
Personal information is kept only for as long as necessary to achieve the purpose for which it was collected or to satisfy statutory obligations:
-
Financial, Mandate & FICA Data: Under FICA, tax laws, and PASA clearing rules, client identity details, mandate logs, and debit order records processed via SUREdebit must be retained for a minimum of 5 years following the termination of the account or mandate.
-
System Logs & Web Queries: Retained for operational security and auditing purposes for as long as reasonably required.
After the mandatory retention period, personal information is securely destroyed, deleted, or de-identified in line with POPIA requirements.
YOUR RIGHTS UNDER POPIA
Subject to statutory limitations and financial record-keeping laws, you hold the following rights regarding your personal information:
-
Right to Access: Request confirmation of whether we hold your personal information and obtain a copy of such data.
-
Right to Correction/Deletion: Request that inaccurate, incomplete, or outdated information be updated or deleted.
-
Right to Object: Object on reasonable grounds to the processing of your personal information, or opt out of direct marketing communications.
-
Right to Lodge a Complaint: File a complaint with the South African Information Regulator if you believe your privacy rights have been infringed.
(Note: End-customers/payers wishing to exercise their rights regarding debit orders loaded on SUREdebit should contact the originating merchant directly, as the merchant acts as the primary Responsible Party for the commercial relationship).
CONTACT DETAILS
For questions about this Privacy Policy, updating your account details, or exercising data privacy rights, please contact us:
-
Company Name: SureSystems
-
Website: www.suresystems.co.za
-
Email: support@suresystems.co.za (or your dedicated Information Officer email)
-
Supporting Bank: Access Bank SA Pty Ltd
Information Regulator (South Africa)
If you are dissatisfied with our response to a privacy concern, you may contact the Information Regulator:
-
Website: inforegulator.org.za
-
Complaints Email: POPIAComplaints@inforegulator.org.za