Recruit 360
TermsPrivacySign in

Privacy policy

How we handle personal information under POPIA · Last revised 21 September 2026

1. Who we are

1.1 Recruit 360 is operated by Idealweb (Pty) Ltd, registration number 2015/054112/07, of 87 Marjoram Avenue, Sinoville, Pretoria, 0129.

1.2 Our Information Officer, appointed under section 55 of the Protection of Personal Information Act 4 of 2013 (POPIA), is Louis Coetzee, contactable at [email protected].

2. Two different roles, and which one applies

2.1 This is the point most software privacy policies blur, so we will be plain about it.

Whose informationWho decides how it is usedWhich document governs it
Your staff — the people who sign in to a workspace — and our billing contacts and website visitorsWe are the responsible partyThis policy
Candidates, client contacts and everyone else recorded inside a customer’s workspaceThe customer is the responsible party; we are its operatorThe data processing addendum, and the job-seeker privacy notice we publish
A person’s own Recruit 360 Jobs account, including one opened at a customer’s careers pageWe are the responsible partyThe Recruit 360 Jobs privacy notice, and clause 6A of the terms of service

2.2 We publish one job-seeker privacy notice and one set of job-seeker terms, and every application door shows those. A candidate accepts them at the point of application, whichever workspace’s advert brought them there. What the customer then does with its copy of the candidate’s information is the customer’s decision, not ours. Where the same person also holds a Recruit 360 Jobs account with us — which a registration at a customer’s door creates unless that customer has elected private mode — that account is ours to answer for, under the Recruit 360 Jobs privacy notice and clause 6A of the terms of service.

3. What we process about you

  • Account information — name, work email address, job title, profile photograph if you upload one, your role in the workspace, and your notification and display preferences.
  • Authentication information — a hashed password, second-factor enrolment, session and device records, and the record of your acceptance of our terms, which includes the version, time, IP address and browser user agent.
  • Usage and security records — sign-in events, the audit trail of significant actions taken in the workspace, IP addresses, and error and performance logs.
  • Billing information — the organisation’s billing contact, invoices, subscription history, and the last four digits and expiry of a card. We never see or store a full card number; it is tokenised by our payment gateway.
  • Support correspondence — what you tell us when you ask for help, and our replies.
  • Enquiries — where you ask for a demonstration, request a workspace or write to us before becoming a customer: your name, work email address, telephone number if you give us one, organisation, what you asked, and the network address the message came from.
  • Content you connect — where you connect a mailbox or calendar, metadata about those messages and events so that they can be shown in context. Message bodies and attachments are fetched from your provider when you open them and are stored only when you deliberately keep one.
  • A WhatsApp account you pair — where you link your own WhatsApp to the workspace: the account’s number and identity, and the conversations that mirror, including message text and attachments. Conversations mirror where the other person is already recorded in the workspace, or where you add them by hand, and unlinking the account deletes the mirror and the files with it.
  • Voice notes you dictate — where you speak to the assistant instead of typing, the recording is turned into text by a transcription service, which is bound not to keep it or train on it. The text is what we store.

4. Why we process it, and on what basis

PurposeLawful basis under POPIA
Providing the service you have subscribed toPerformance of a contract with you or with your employer (section 11(1)(b))
Billing, invoicing and collecting paymentContract, and our legitimate interests (section 11(1)(f))
Security, fraud prevention, audit trails and tenant isolationLegitimate interests, and section 19 security safeguards
Support and service noticesContract
Keeping records the law requires us to keepLegal obligation (section 11(1)(c))
Product announcements, which you can switch offYour consent, or — because you are a customer — section 69(1)(b) of POPIA, on the conditions in section 69(3): we use the address you gave us when you subscribed, we write only about this service, and every message carries a way to stop them

4.1 We do not sell personal information. We do not use your workspace data to train models, and we do not pool it with other customers’ data: no record in a customer’s workspace is searchable by, or copied to, another customer. Recruit 360 Jobs is different — a person who holds a Recruit 360 Jobs account holds it with us, under their own agreement with us, and clause 6A of the terms of service describes what that means for a registration taken through a customer’s doors. We do derive aggregated, de-identified statistics from use of the service to operate, improve and benchmark it; they cannot reasonably identify you, your organisation or a candidate.

4.2 Every product announcement we send carries a link that stops them. Service and billing notices are not marketing and continue while you hold an account.

5. Who we share it with

5.1 We use a small number of service providers. Most process only on our instructions; a few — those that receive no more than a fragment of text and no identifier, such as address suggestions and map look-ups — act for themselves under their own published terms. What each does for us, the country it processes in, and the basis it is engaged on is set out, for the providers that handle information inside a workspace, in Annexure A of the data processing addendum, which is the authoritative version and is updated on notice; the providers behind our own website are described in section 10. Providers are described there by function. A customer may ask the Information Officer in writing for the named list, which we give for that customer’s own data-protection compliance and which is confidential.

5.2 Beyond those providers, we share personal information only with professional advisers under duties of confidence, with an acquirer if our business is sold (on notice, and subject to this policy), and where a law, a court order or a regulator compels it.

5.3 The service links to systems the Customer connects and to job boards and websites we do not run. This policy does not cover them; their own notices do.

6. Sending information outside South Africa

6.1 Some of our providers operate outside South Africa. Where personal information leaves the country we engage the provider only on written terms that bind it not to use the information to train any model, not to keep it beyond serving the request, and not to use it for any purpose of its own — and, where the provider offers them, on data-processing terms of the standard section 72(1)(a) of POPIA describes. Only the text a task needs is sent, never a whole record.

6.2 The country in which each function is processed, and the terms each provider is engaged on, are listed in Annexure A of the data processing addendum. A customer may ask the Information Officer in writing for the named list, which we give for that customer’s own data-protection compliance and which is confidential.

7. How long we keep it

  • While you are a user — for as long as your account is active in a workspace.
  • After a workspace ends — the workspace stays read-only for 30 days and is then deleted — the records and the documents, CVs and other files stored with them. We keep only the organisation name, the billing contact, the subscription dates and the fact of deletion.
  • Billing and tax records — seven years, as required by the Companies Act 71 of 2008 (the Tax Administration Act 28 of 2011 requires five).
  • Terms acceptances — for as long as the agreement they evidence could be relied on, because a signature you can no longer produce is not evidence of anything.
  • Security logs — 12 months for the record of who viewed what, unless a specific incident requires longer.
  • The audit trail of changes made in a workspace — for as long as the workspace exists, because it is the record of what was done to a person’s information.
  • Enquiries that do not become a workspace — 12 months after our last contact, then deleted.
  • Backups — overwritten on an ordinary cycle not exceeding 35 days.

8. How we protect it

8.1 Row-level security applies to the tables that hold workspace data, so one workspace’s data is separated from another’s by the database itself and not by application code alone.

8.2 Traffic to and from the service is encrypted in transit. The credentials for a connected mailbox — which are also what gives the service access to that account’s calendar — are encrypted with a separate key held only by the server. Off-site backups are encrypted where they are stored. The service runs on a server of its own in a South African data centre with physical and network access controls. Access to production by our staff is limited, is granted for a limited time, and is logged.

8.3 If personal information we hold as responsible party is accessed or acquired by someone who should not have it, section 22 of POPIA requires us to notify the Information Regulator and the people affected. We will do so as soon as reasonably possible after we discover it, taking the time the Act allows to work out what happened and to secure the system, and we will say what was affected, what we are doing about it and what you can do. Where the information belongs to a customer’s workspace the customer is the responsible party, and section 21 requires us to tell the customer without delay so that it can notify.

9. Your rights

9.1 Under POPIA you may:

  • ask what personal information we hold about you and get a copy;
  • ask us to correct or delete information that is wrong, misleading, excessive or no longer needed;
  • object to processing based on legitimate interests;
  • withdraw consent where consent is the basis, without affecting what was done before;
  • complain to the Information Regulator (South Africa) at inforegulator.org.za.

9.2 Write to [email protected]. We will respond within 30 days. We may ask you to verify your identity, and we will say so if a request cannot be met in full and why.

9.3 If your request concerns a candidate record inside a customer’s workspace, we will refer you to that customer, who is the responsible party for it, and we will assist them to answer you.

10. Cookies and tracking

10.1 We set cookies to keep you signed in and to keep your session secure. They are necessary for the service to work and cannot be switched off while you use it.

10.2 In the application we do not use advertising cookies, third-party analytics trackers or cross-site tracking pixels.

10.3 On our public pages (recruit360.co.za and its landing pages) nothing from Google loads until you choose “Accept” in the cookie notice. If you do, we use Google Analytics to see how the pages are used and Google Ads conversion measurement to see which adverts bring people to us. Choosing “Only essential”, now or later, keeps or puts it off. We do not use these to show you advertising elsewhere.

10.4 If you reach us from a Google advert, the advert’s click identifier in the page address is kept with the enquiry you send us, and used to tell Google that the enquiry — and, later, whether it led to a demo — came from that advert. This does not use cookies and does not identify you to Google beyond that click. Where there is no click identifier we may report the outcome to Google as a hashed form of the email address you gave us, which Google can only match against an address it already holds. Both are deleted with the enquiry (section 7).

11. Children

11.1 The service is for workplace use by adults. We do not knowingly create accounts for children, and a customer must not record a child’s personal information in a workspace except where the law permits and its own notice covers it.

12. Changes

12.1 We may update this policy. Where a change materially affects how we use your personal information we will tell workspace owners in advance and, where required, ask for renewed acceptance on sign-in.

13. Contact

Information Officer
Louis Coetzee, Idealweb (Pty) Ltd
87 Marjoram Avenue, Sinoville, Pretoria, 0129
087 265 2153 / 072 617 4893
[email protected]
Related:Terms of servicePrivacy policyData processing addendum
© 2026 Recruit 360·Terms of service·Privacy policy·Data processing addendum·All legal documents·Sign in
Recruit 360 is a product of Idealweb (Pty) Ltd · reg 2015/054112/07 · 87 Marjoram Avenue, Sinoville, Pretoria, 0129 · 087 265 2153 / 072 617 4893 · [email protected]