1. Introduction
This Privacy Policy ("Policy") describes how Zuri Client Lync (Proprietary) Limited, trading as Zuri Client Lync ("Zuri", "we", "us", "our") collects, uses, discloses, stores, and protects personal information when you:
- visit our websites, landing pages, or marketing properties;
- create or use a business account on the Zuri platform ("Platform");
- communicate with us as a prospective customer, subscriber, or support contact; or
- interact with us in any other way relating to the Platform.
This Policy applies to business account holders, authorised users (employees, contractors, and agents invited to a business workspace), and website visitors. It does not replace your obligations to your own clients, patients, or customers. Where you upload or process personal information about your clients through the Platform, you remain the responsible party (data controller) for that information, and Zuri generally acts as an operator (processor) on your documented instructions — see our Data Processing Agreement.
By accessing or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree, you must not use the Platform.
Important: This Policy is intended to comply with the Protection of Personal Information Act, 4 of 2013 (POPIA) and other applicable South African law. Nothing in this Policy limits any rights you may have under POPIA that cannot be limited by contract.
2. Definitions
In this Policy:
- "Personal information" has the meaning given in POPIA and includes information relating to an identifiable, living natural person and, where applicable, an identifiable juristic person to the extent POPIA applies.
- "Processing" means any operation performed on personal information, including collection, storage, use, disclosure, deletion, or destruction.
- "Responsible party" means the entity that determines the purpose and means of processing personal information.
- "Operator" means a person who processes personal information on behalf of a responsible party.
- "Special personal information" includes information relating to religious or philosophical beliefs, race, ethnic origin, trade union membership, political persuasion, health, sex life, biometric information, and criminal behaviour, as defined in POPIA.
Capitalised terms not defined here have the meaning given in our Terms of Service.
3. Our role and your role
| Data subject | Typical responsible party | Zuri's role |
|---|---|---|
| Business owners, admins, and staff using the Platform | Zuri | Responsible party |
| End-clients, patients, or customers whose data you store in Zuri | Your business | Operator (on your instructions) |
| Website visitors and waitlist sign-ups | Zuri | Responsible party |
You represent and warrant that:
- you have a lawful basis to collect and upload personal information about your clients and staff into the Platform;
- you have provided all required notices and obtained all required consents;
- your use of the Platform complies with POPIA, sector-specific rules (including healthcare, cannabis/dispensary, financial, or professional conduct rules where applicable), and your own privacy commitments.
Zuri is not responsible for the content, accuracy, lawfulness, or appropriateness of personal information you or your users submit to the Platform.
4. Information we collect
We may collect the categories of personal information below, depending on how you interact with us.
4.1 Account and identity information
- Full name, username, email address, telephone number, profile photo
- Job title, role, permissions, and organisation membership
- Authentication identifiers, session tokens, and multi-factor authentication metadata
- Government or professional identifiers you choose to provide (e.g. for verification workflows)
4.2 Business and billing information
- Business or branch name, trading name, address, category, and business type
- Billing contact details, subscription tier, invoice history, and tax-related information you provide
- Payment status and transaction references (payment card numbers are processed by our payment partners; we do not store full card numbers)
4.3 Platform usage and technical information
- IP address, browser type, device identifiers, operating system, and approximate location derived from IP
- Log files, audit trails, access timestamps, feature usage, and performance diagnostics
- Error reports, crash data, and security event logs
- Cookies, local storage, and similar technologies (see Section 9)
4.4 Communications and support
- Messages you send to us (email, in-app chat, support tickets, demo requests)
- Call recordings or notes where you consent or where permitted by law
- Feedback, survey responses, and beta-programme communications
4.5 Information you or your users submit about third parties
When you use Platform features, you may submit personal information about your clients, staff, or other third parties, including:
- Contact details, appointment history, notes, and preferences
- Loyalty, wallet, and transaction records
- Inventory, sales, and dispensary compliance records where enabled
- Messaging content (SMS, email, WhatsApp, or in-app notifications you configure)
- Files, images, and documents you upload
- Consent records and marketing preferences you maintain for your clients
You control what is submitted. We process this information solely to provide the Platform as configured by you.
4.6 Information from third parties
We may receive information from:
- Authentication providers (e.g. identity and organisation membership data)
- Payment processors (e.g. payment confirmation, billing events, fraud signals)
- Integration partners you enable (calendars, messaging gateways, POS, or other connected services)
- Public sources where lawful (e.g. company registry information you authorise us to retrieve)
- Other users in your organisation who invite or reference you
We do not knowingly collect special personal information unless you submit it through the Platform or we are required by law to process it. You should not upload special personal information unless you have a lawful basis and appropriate safeguards.
5. How we use personal information
We process personal information for the following purposes:
5.1 Providing the Platform
- Creating and administering accounts, organisations, and user roles
- Enabling appointments, clients, services, inventory, sales, loyalty, messaging, reporting, and related features
- Processing subscriptions, renewals, trials, and payment-related events
- Delivering notifications you or your business configure
5.2 Security, integrity, and abuse prevention
- Authenticating users and preventing unauthorised access
- Detecting, investigating, and responding to fraud, abuse, policy violations, and security incidents
- Enforcing our Terms, protecting our rights, and complying with legal obligations
5.3 Improvement and analytics
- Monitoring performance, diagnosing errors, and improving reliability
- Understanding aggregate usage patterns to develop features (preferably using de-identified or aggregated data where practicable)
- Conducting internal research and quality assurance
5.4 Communications
- Sending service-related notices (security alerts, billing, material policy changes, downtime)
- Responding to support requests and onboarding enquiries
- Sending marketing communications only where permitted — see our Marketing Communications Policy
5.5 Legal and regulatory
- Complying with court orders, subpoenas, and lawful requests from authorities
- Establishing, exercising, or defending legal claims
- Meeting accounting, tax, and record-keeping requirements
We will not use personal information for purposes incompatible with those described above without notice and, where required, consent.
6. Legal bases for processing (POPIA)
We process personal information only where a lawful ground exists under POPIA, including:
| Ground | Typical use |
|---|---|
| Contract | Providing the Platform you subscribe to; account administration; billing |
| Legitimate interest | Security monitoring, fraud prevention, product improvement, B2B marketing to business contacts (balanced against your rights) |
| Legal obligation | Tax, regulatory, and law-enforcement compliance |
| Consent | Optional marketing; certain cookies; processing you explicitly authorise |
| Protection of data subject | Where necessary to protect vital interests in emergency situations |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. Withdrawing consent may limit Platform functionality.
7. Disclosure of personal information
We may disclose personal information to the categories of recipients below, subject to appropriate contractual and security safeguards:
7.1 Service providers and sub-processors
Including providers of:
- Cloud hosting and database infrastructure
- Identity, authentication, and organisation management
- Email, SMS, WhatsApp, and push notification delivery
- Payment processing and subscription billing
- Error monitoring, logging, and analytics
- Customer support and ticketing tools
- Professional advisers (lawyers, auditors, insurers) under confidentiality
A current list of material sub-processors is available on request at info@zuri-lync.com. We require operators to process personal information only on our instructions and to implement appropriate security measures.
7.2 Your organisation and authorised users
Information you submit may be visible to other users in your business workspace according to the roles and permissions you configure. You are responsible for configuring access appropriately.
7.3 Business transfers
If we are involved in a merger, acquisition, reorganisation, or sale of assets, personal information may be transferred as part of that transaction, subject to confidentiality and continued protection consistent with this Policy.
7.4 Legal and safety disclosures
We may disclose information where we believe in good faith that disclosure is necessary to:
- comply with applicable law, regulation, legal process, or enforceable governmental request;
- protect the rights, property, or safety of Zuri, our users, or the public;
- detect or prevent fraud or security issues.
7.5 Aggregated and de-identified information
We may use and disclose aggregated or de-identified information that cannot reasonably be used to identify you for analytics, benchmarking, and business purposes.
We do not sell personal information.
8. International transfers
Our service providers may process personal information in South Africa and other countries. Where personal information is transferred outside South Africa, we implement safeguards required by POPIA, which may include:
- transfers to countries with adequate protection recognised under POPIA;
- standard contractual clauses or equivalent binding agreements with recipients;
- your explicit consent where required.
By using the Platform, you acknowledge that cross-border transfers may occur for the purposes described in this Policy.
9. Cookies and similar technologies
We and our service providers use cookies, pixels, local storage, and similar technologies to:
- keep you signed in and maintain session security;
- remember preferences (e.g. theme, sidebar state);
- measure website and Platform performance; and
- protect against abuse.
Marketing website analytics. On www.zuri-lync.com we use:
- Vercel Analytics and Vercel Speed Insights — cookieless, privacy-preserving performance and traffic metrics that do not require consent under typical cookie rules.
- Google Analytics 4 (GA4) — loaded only after you accept analytics cookies via our consent banner. Until you accept, Consent Mode defaults keep advertising and analytics storage denied. You may reject GA4 and continue using the site; cookieless Vercel metrics may still run.
Consent choices are stored in your browser’s local storage so we can respect them on return visits. You can clear site data in your browser to reset the banner.
You can control cookies through your browser settings. Disabling certain cookies may impair Platform functionality. We do not currently respond to "Do Not Track" signals in a uniform way across all browsers.
For marketing-site analytics, we use data in aggregated form where possible.
10. Retention
We retain personal information only for as long as necessary to fulfil the purposes in this Policy, unless a longer period is required or permitted by law.
| Category | Typical retention |
|---|---|
| Active account data | Duration of subscription plus a reasonable wind-down period |
| Billing and tax records | As required by South African tax and commercial law (often 5 years or longer) |
| Security and audit logs | Up to 24 months, or longer if needed for investigations |
| Support communications | Up to 36 months after resolution, unless longer retention is needed |
| Backups | Deleted or overwritten according to backup rotation schedules (residual copies may persist for a limited period) |
| Client data you upload | Until you delete it, your account is terminated, or we delete it per your instructions and our DPA — subject to legal holds |
When retention ends, we delete, anonymise, or securely destroy personal information in accordance with our data retention procedures. You are responsible for exporting or deleting your business data before account closure where required.
11. Security
We implement technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration, or destruction, including:
- encryption in transit (TLS) for data transmitted over public networks;
- access controls, role-based permissions, and authentication requirements;
- logging and monitoring of administrative access;
- secure development practices and vulnerability management; and
- incident response procedures.
No method of transmission or storage is completely secure. We cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials, configuring user permissions appropriately, and promptly notifying us at info@zuri-lync.com if you suspect unauthorised access to your account.
12. Your rights under POPIA
Subject to POPIA and applicable exceptions, you may have the right to:
- Request access to personal information we hold about you;
- Request correction of inaccurate, incomplete, or misleading information;
- Request deletion of personal information where retention is no longer necessary or lawful;
- Object to processing based on legitimate interests or for direct marketing;
- Withdraw consent where processing is consent-based;
- Request restriction of processing in certain circumstances;
- Lodge a complaint with the Information Regulator (South Africa).
Requests relating to client data you uploaded: We will direct data subjects to your business where you are the responsible party. We will assist you in responding to such requests as described in our DPA.
We may request proof of identity before fulfilling a request. We may decline requests that are manifestly unfounded, repetitive, or excessive, or where we are permitted or required by law to retain information. We will respond within timeframes required by POPIA.
To exercise your rights, contact info@zuri-lync.com with the subject line "POPIA Request".
13. Direct marketing
We may send marketing communications about Zuri products and services to business contacts where permitted by law. You may opt out at any time via unsubscribe links or by emailing info@zuri-lync.com. Opting out of marketing does not affect essential service communications.
Marketing messages you send to your own clients through the Platform are your responsibility. See our Marketing Communications Policy.
14. Children
The Platform is intended for use by businesses and adults aged 18 and over. We do not knowingly collect personal information from children under 18 without appropriate parental or guardian consent. If you believe we have collected information from a child improperly, contact us and we will take appropriate steps to delete it.
15. Third-party services and links
The Platform integrates with and links to third-party services (including payment gateways, authentication providers, messaging platforms, and calendar tools). Those services have their own privacy policies and practices. We are not responsible for the privacy practices of third parties you choose to connect or link to.
Your use of third-party integrations is at your own risk and subject to their terms.
16. Automated processing
We may use automated systems for fraud detection, security monitoring, usage analytics, and feature recommendations. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals without human review where required by law.
17. Data breaches
If we become aware of a compromise of personal information that triggers notification obligations under POPIA, we will:
- take reasonable steps to contain and remediate the incident;
- assess the scope and risk to data subjects;
- notify affected businesses and, where required, the Information Regulator and affected individuals without undue delay; and
- cooperate with you in fulfilling your own notification obligations regarding client data you control.
18. Limitation of liability and disclaimers
To the maximum extent permitted by applicable law:
- The Platform and our privacy practices are provided on an "as is" and "as available" basis.
- We disclaim all warranties, express or implied, regarding uninterrupted or error-free operation or absolute data security.
- Zuri shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or for loss of profits, revenue, data, or goodwill, arising from or related to this Policy or our processing of personal information, except where liability cannot be excluded under POPIA or other applicable law.
- Our aggregate liability for claims arising from privacy-related processing shall not exceed the greater of (a) amounts paid by your business to Zuri in the 12 months preceding the claim, or (b) ZAR 5,000, except where a higher minimum is mandated by law.
Nothing in this Policy excludes or limits liability for fraud, wilful misconduct, or any liability that cannot be limited under South African law.
You agree to indemnify and hold Zuri harmless against claims, losses, and expenses (including reasonable legal fees) arising from your unlawful processing of personal information, your failure to obtain required consents, or your breach of this Policy or applicable data-protection law in respect of client data you control — to the extent permitted by law.
19. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will:
- update the effective date and version number;
- notify business account owners via email or in-app notice; and
- require renewed acceptance where our Terms or onboarding process provides for it.
Continued use of the Platform after the effective date of an updated Policy constitutes acceptance of the changes, except where POPIA or our contract with you requires explicit consent.
20. Governing law and jurisdiction
This Policy is governed by the laws of the Republic of South Africa. Subject to mandatory provisions of POPIA and consumer protection law, the courts of South Africa shall have jurisdiction over disputes relating to this Policy.
21. Contact and Information Officer
For privacy enquiries, POPIA requests, or complaints:
Email: info@zuri-lync.com
Subject line: Privacy / POPIA Request
Entity: Zuri Client Lync (Proprietary) Limited
We will acknowledge requests within a reasonable time and respond in accordance with POPIA.
Information Regulator (South Africa):
Website: https://www.inforegulator.org.za
22. Relationship with other documents
This Policy should be read together with:
If there is a conflict regarding client data you control, the DPA prevails. If there is a conflict regarding your account or billing data, this Policy and the Terms govern.
