Back to AccredIQ

POPIA Data-Handling Statement

This page is a placeholder. It has not yet been reviewed by AccredIQ's legal team and does not represent binding content — it exists so this link goes somewhere real instead of a broken page, and will be replaced before go-live.

AccredIQ processes personal information — including special personal information such as South African ID numbers — belonging to learners, staff and administrators of the skills development providers on this platform, under the Protection of Personal Information Act (POPIA).

Where data is stored

All data is stored in a single Supabase project hosted in the EU (Stockholm, eu-north-1), a deliberate cross-border processing decision made under POPIA §72. AccredIQ does not use a secondary storage provider — one database is the single system of record for both structured data and uploaded documents.

How entities are separated

Four independently registered providers share one application and one database schema. Isolation between them is enforced at the database level by row-level security, not by filtering in application code — a provider cannot read another provider's records even if the application itself were bypassed.

Audit trail

Changes to compliance-relevant records are written to an append-only audit log capturing who made the change and when, so that access to and changes made to personal information can be reviewed after the fact.

Accessing, correcting or deleting your data

A formal data-subject-request (DSAR) process — including erasure — is architecturally planned for but not yet built or staffed with a contact channel. Until it exists, there is no working route on this site to submit one.