POPIA Data-Handling Statement
AccredIQ processes personal information — including special personal information such as South African ID numbers — belonging to learners, staff and administrators of the skills development providers on this platform, under the Protection of Personal Information Act (POPIA).
Where data is stored
All data is stored in a single Supabase project hosted in the EU (Stockholm, eu-north-1), a deliberate cross-border processing decision made under POPIA §72. AccredIQ does not use a secondary storage provider — one database is the single system of record for both structured data and uploaded documents.
How entities are separated
Four independently registered providers share one application and one database schema. Isolation between them is enforced at the database level by row-level security, not by filtering in application code — a provider cannot read another provider's records even if the application itself were bypassed.
Audit trail
Changes to compliance-relevant records are written to an append-only audit log capturing who made the change and when, so that access to and changes made to personal information can be reviewed after the fact.
Accessing, correcting or deleting your data
A formal data-subject-request (DSAR) process — including erasure — is architecturally planned for but not yet built or staffed with a contact channel. Until it exists, there is no working route on this site to submit one.