Unified Global Privacy Policy (Privacy Notice)
1 Introduction
FlowCentric (Pty) Ltd (“FlowCentric”, “we”, “our”, “us”) is committed to protecting personal information in accordance with the Protection of Personal Information Act (POPIA) (South Africa), the General Data Protection Regulation (GDPR) (EU/UK), the Australian Privacy Act 1988, and other applicable international privacy frameworks.
FlowCentric (Pty) Ltd acts as the data controller / responsible party for the personal information described in this Privacy Policy. In some cases, FlowCentric (Pty) Ltd may send personal information to FlowCentric Professional Services (Pty) Ltd, FlowCentric Technologies (Pty) Ltd and/or FlowCentric Resourcing (Pty) Ltd to help deliver services and support; these entities process personal information on our behalf or, where appropriate, as joint controllers.
This Policy applies to our websites, cloud platforms (including Processware and DSO) and related professional services. Employees and contractors receive a separate internal privacy notice.
This Privacy Policy explains how we handle personal information when you engage with us, access our systems (Processware, DSO), visit our website, or use our services.
2 What personal information we collect
We may collect the following categories of personal information:
2.1 General personal information
- Names, titles, and organisational details.
- Contact information (email, phone, physical address).
- Communications and engagement details.
2.2 Technical and operational information
- Usernames, authentication credentials, and access logs for our platforms.
- IP addresses, device identifiers, and audit trails.
- System usage information within Processware or DSO.
2.3 Sensitive / special personal information
Where necessary and authorised by law (for example, for our DSO product or HR purposes), we may collect:
- Biometric information (for access control or identity verification).
- Identity verification details.
- Background screening information.
We only collect sensitive information with explicit consent or as legally required.
2.4 Website, cookies, and analytics
- Browsing behaviour.
- Cookie data and similar tracking technologies.
2.5 Employment and recruitment data
- CVs, qualifications, and employment history.
- References and background check information.
- Payroll information (bank, tax).
3 How we collect personal information
We may collect information through:
- Direct interactions (email, phone, meetings, forms).
- Access to our systems, platforms, or cloud services.
- Recruitment, onboarding, and HR processes.
- Website interactions.
- Third-party providers (for example, LinkedIn, PNET).
4 Why we collect and use personal information
We collect, hold, and use personal information to:
4.1 Service delivery
- Provide our software platforms (Processware) and professional services.
- Support digital transformation and process automation.
4.2 Compliance and governance
- Meet regulatory (POPIA, SARS, labour law) and contractual obligations.
- Maintain cybersecurity and operational integrity.
4.3 Business operations
- Manage client relationships, contracts, and finance.
- Conduct marketing (only with consent where required).
4.4 Human resources
- Recruitment, onboarding, payroll, and performance management.
If you become an employee, additional HR processing is described in our internal employee policies, which we will provide during onboarding.
5 Lawful basis for processing (GDPR / POPIA)
We process personal information under the following lawful bases:
- Performance of a contract: To deliver the services you have engaged us for.
- Legitimate interests: For security, analytics, and business continuity.
- Compliance with legal obligations: To meet tax, labour, and reporting laws.
- Consent: Where explicitly required (for example, for marketing or biometric processing).
6 International transfers of personal information
FlowCentric is a global organisation. We may transfer personal information to locations outside your home country, including:
- FlowCentric entities in the United Kingdom and Australia.
- Global cloud hosting regions (for example, Microsoft Azure data centres).
Where required, we implement:
- Standard Contractual Clauses (SCCs).
- Data Processing Agreements (DPAs).
- Encryption and strict access controls.
You can contact us for more information about these safeguards.
7 Disclosure of personal information
We may disclose personal information to:
- FlowCentric Group entities for technical support.
- Cloud hosting (Microsoft Azure) and cybersecurity (Darktrace) providers.
- Legal, financial, and audit advisers.
- Regulatory bodies (for example, the Information Regulator, SARS) as required by law.
8 Data security
We apply multi-layered security controls, aligned with ISO/IEC 27001, including:
- Industry-standard encryption at rest and in transit (for example AES and TLS).
- Strict Identity and Access Management (MFA, RBAC).
- Continuous monitoring and intrusion detection.
- Secure development practices.
9 Your rights
9.1 South Africa (POPIA)
Under POPIA, you have the right to:
- Notification: Know when your personal information is being collected.
- Access: Request a record of the personal information we hold about you.
- Correction: Request the correction or deletion of inaccurate, irrelevant, or outdated information.
- Objection: Object to the processing of your personal information on reasonable grounds.
- Complaint: Submit a complaint to the Information Regulator (South Africa) if you believe your rights have been infringed.
9.2 Australian APP rights
You may request access to your personal information and corrections to inaccurate information.
9.3 EU / UK GDPR rights
You have the right to:
- Access
- Rectification
- Erasure (“right to be forgotten”)
- Restriction
- Objection
- Data portability
- Withdraw consent
10 Cookies and tracking technologies
We use cookies for website functionality, analytics, and security. You may adjust your browser settings to reject cookies, though some features may be limited.
11 Data retention
We retain personal information only as long as necessary to meet legal, contractual, or operational requirements. Once the retention period expires, data is securely deleted or de-identified.
12 Children’s data
We do not knowingly collect personal information from individuals under 18 years of age without parental consent.
13 Automated decision-making
We do not use automated decision-making that produces legal or significant effects on individuals.
14 Contact us
For privacy enquiries, rights requests (DSAR), or complaints, please contact our Information Officer / Data Protection Officer:
Information Officer: Denis Bensch (CIO)
Email: [email protected]
Phone: +27 12 020 4488
Physical Address: 146 Boeing Street East, Monument Park, Pretoria, 0181, South Africa
14.1 Supervisory authorities
- South Africa: Information Regulator (inforegulator.org.za)
- Australia: Office of the Australian Information Commissioner (OAIC)
- UK: Information Commissioner’s Office (ICO)
15 Changes to this Policy
We may update this Policy periodically. The latest version will always be available on our website.
Download a PDF version of our Unified Global Privacy Policy (Privacy Notice).
To request access for a record, complete and send this form to the company at [email protected]
Read PAIA Manual GCR.pdf
FlowCentric: Information Officer’s Details
FlowCentric Professional Services: Information Officer’s Details


