Privacy statement
Statement & consent
Daala is committed to protecting your privacy and managing your Personal Information transparently and securely. This Privacy Notice explains how we collect, use, process, share, and safeguard your personal data in strict compliance with the Protection of Personal Information Act, No. 4 of 2013 (POPIA) and the Promotion of Access to Information Act, No. 2 of 2000 (PAIA) of South Africa.
By accessing, downloading, registering for, or using the Daala application or associated web services, you acknowledge that you have read and understood this Privacy Notice and explicitly consent to the processing of your Personal Information as set out herein.
What information we collect
- Identification
- Contact
- Financial
- Visual & media
- Technical
What we hold on you
To operate our two-sided gig marketplace and fulfil our legal and operational obligations, we collect the following categories of Personal Information.
1.1Personal Identifiable Information (PII) & identity data
- User identity: Full legal name(s), South African National Identity Number or formal Business Registration number.
- Verification media: Photographic evidence, live biometric selfies, or official ID document copies for account authentication and verification.
- Contact details: Mobile phone number, verified email address, and physical address/location details.
1.2Financial & transactional data
- Settlement details: Valid bank account details used for processing digital wallet withdrawals and payouts.
- Transaction records: Historical records of escrow deposits, job completion releases, service commission deductions, subscription fees, and payment channel surcharges.
Note: Payment card details (Visa, Ozow, EFT) are processed directly by our regulated third-party payment partner and are never stored on our local application servers.
1.3User content & media data
- Media portfolios: Photos, before-and-after work evidence, short video tutorials, portfolio clips, and service descriptions uploaded to user profiles or gig listings.
- Dispute proof: Photographic or documentary proof submitted to support claims during formal escrow arbitration.
- In-app messaging: Text, image, and timestamp data generated through our built-in real-time chat interface.
- Feedback & reviews: Anonymous public reviews, 5-star ratings, and written comments left post-transaction.
1.4Geolocation & technical data
- Precise geolocation: Real-time spatial and GPS coordinate data collected to power interactive map discovery, localised gig matching, and transit calculations.
- Device & diagnostic data: IP addresses, operating system version, mobile device model, performance logs, and error/crash reports logged via crash analytics software.
Purpose of data processing
We process your Personal Information strictly for specified, explicit, and lawful purposes in accordance with POPIA Condition 3 (Purpose Specification):
- Service delivery & gig allocation: To enable account registration, manage Gig Requests and Gig Posts, render interactive location maps, and facilitate communication between Buyers and Merchants.
- Financial execution & escrow management: To transmit transactional data to our regulated partner for operating secure escrow holding accounts and payouts.
- Identity verification & compliance (KYC/FICA): To perform automated real-time identity verification checks, combat financial crime, fraud, money laundering, and comply with legal mandates.
- Platform security & dispute resolution: To arbitrate escrow disputes, review uploaded job completion evidence, enforce our Terms of Use, and detect suspicious or fraudulent activity.
- App stability & performance: To monitor software crashes, optimise data usage for low-bandwidth devices, and debug platform errors.
Third-party operators & recipients of data
| Operator | What they do | What we send them |
|---|---|---|
| TradeSafe | Authorised Third-Party Payment Provider (TPAP) managing escrow balances, payouts, and financial compliance. | We send:Full legal name, SA ID/registration number, mobile number, email, bank settlement details, transaction amounts. |
| VerifyNow | Automated Know-Your-Customer (KYC) identity verification engine. | We send:Full legal name, SA ID number, live biometric/photo verification data. |
| Google Maps Platform | Geolocation rendering, address validation, and distance routing. | We send:Physical address queries, device coordinates (anonymised/aggregated). |
| Google Firebase / Sentry | Serverless backend database infrastructure, cloud storage, and real-time crash monitoring. | We send:Encrypted application data, profile media, telemetry, and crash debugging logs. |
In order to run the platform without operating as an unlicensed bank or accountable institution, Daala securely shares data with specialised, regulated third-party operators under strict data-processing agreements, as set out in the table above.
Data protection & security measures
We implement robust administrative, technical, and physical safeguards to protect Personal Information from loss, misuse, unauthorised access, disclosure, alteration, or destruction, as required by Section 19 of POPIA:
- In-transit encryption: All communications between the mobile application frontend, cloud databases, and third-party API endpoints are encrypted using industry-standard SSL/TLS protocols.
- At-rest encryption: Personal identifiers, chat messages, and account details stored within database environments are protected with server-side encryption key management.
- Device storage policy: No sensitive financial credentials or official South African ID documents are stored locally on your mobile device.
- Access control: Personnel access to user data is restricted on a strict need-to-know basis and protected by multi-factor authentication.
Cross-border data transfers
Because Daala uses serverless cloud computing infrastructure (such as Google Firebase), your encrypted Personal Information may be transferred to, processed, and stored on cloud servers located outside the Republic of South Africa.
Where cross-border data transfer occurs, Daala ensures compliance with Section 72 of POPIA by confirming that:
- The recipient foreign cloud host is subject to data privacy laws, corporate rules, or binding agreements that provide an adequate level of protection equivalent to POPIA; and
- The transfer is necessary for the performance of the contract between you and Daala.
Data retention & cryptographic erasure
6.1Retention timelines
We retain your Personal Information only for as long as is necessary to fulfil the operational purposes for which it was collected, or as mandated by applicable South African laws (e.g. retaining financial transaction records for a minimum of 5 years pursuant to tax and anti-money laundering legislation).
6.2Account deletion & cryptographic wipe
You may request the deletion of your Daala account at any time via the in-app account settings menu or by contacting our Information Officer. Upon confirmed account deletion:
- Your profile and publicly visible listings are immediately deactivated.
- An automated cryptographic wipe is initiated across active cloud instances to erase all non-statutory Personal Information.
- Transactional records requiring statutory retention are archived securely and isolated from active operational environments until the statutory retention window expires.
Your data subject rights under POPIA
As a data subject under South African law, you hold the following explicit rights regarding your Personal Information:
- Right to access (Section 23): You have the right to request confirmation of whether we hold Personal Information about you and receive a copy of that record.
- Right to correction/deletion (Section 24): You have the right to request the correction, updating, or deletion of inaccurate, irrelevant, out-of-date, incomplete, or unlawfully obtained data.
- Right to object (Section 11(3)): You may object on reasonable grounds to the processing of your Personal Information, subject to applicable contractual or statutory obligations.
- Right to object to direct marketing (Section 69): You may opt out of receiving direct electronic marketing communications at any time by using the “unsubscribe” link or toggling notifications in the app settings.
- Right to lodge a complaint: You have the right to lodge a complaint with the South African Information Regulator if you believe your data privacy rights have been infringed.
Contact details & regulatory recourse
8.1 — Ask us first
Daala Privacy Team
Information Officer
Pretoria Central, Gauteng, South Africa
Email help@daala.co.za
8.2 — If we get it wrong
The Information Regulator (South Africa)
JD House, 27 Stiemans Street
Braamfontein, Johannesburg, 2001
P.O. Box 31533, Braamfontein, Johannesburg, 2017
Complaints complaints.IR@inforegulator.org.za
General enquiries enquiries@inforegulator.org.za
8.1Daala Information Officer
For any questions regarding this Privacy Notice, requests to exercise your data subject rights, or privacy concerns, please contact our internal Information Officer.
8.2The Information Regulator (South Africa)
If you are unsatisfied with our response or believe your data processing is non-compliant with POPIA, you may contact the Information Regulator directly.