Legal

Terms and Conditions
and Privacy Policy

IDToday Secure Data Solutions South Africa (Pty) Ltd · Reg no 2026/233950/07

Part 1 — Terms and Conditions

Last updated: 3 August 2026

1. Who We Are and Who These Terms Apply To

IDToday, we, us or our means:

2. Acknowledgement

These Terms govern your use of the Service and form a binding agreement between you and IDToday. Access to and use of the Service is conditional on your acceptance of and compliance with these Terms.

Where you are an End User, the Client that requested your information, not IDToday, decides why and how your personal information is processed for KYC purposes. IDToday processes that information on the Client’s written instructions. Section 3 of Part 2 (Privacy Policy) details your rights and the appropriate primary contact.

Age Requirement: The Service is intended for individuals aged 18 and over. Where a Client is legally required to verify the identity of a minor (e.g., a minor account holder or beneficial owner), such information must be submitted by a parent, legal guardian, or authorized competent person, and will be processed under Clause 8 of the Privacy Policy.

3. Submission of Information

You as an End User warrant that information submitted or uploaded via the Service:

3A. Indemnity

You indemnify and hold IDToday harmless against any claims, costs, damages, expenses, and liabilities (including reasonable legal costs) arising out of or in connection with: (a) your breach of these Terms; (b) your unlawful use of the Service; (c) information submitted or uploaded by you, or on your behalf, in breach of Clause 3 above; or (d) your use of the Service or the Website, or any content or information made available through the Service or the Website.

4. Intellectual Property

IDToday and/or its licensors retain all intellectual property rights in and to the Service (including technology, software, visual interfaces, and branding, but excluding data submitted by you or a Client).

5. Third-Party Services

The Service may link to or integrate with third-party systems. We assume no control over, and accept no liability for, the content, privacy policies, or practices of any third-party software, data provider, or website.

6. Termination

We reserve the right to suspend or terminate access to the Service immediately, without prior notice, in the event of a breach of these Terms or system misuse. Obligations regarding personal information collected prior to termination remain governed by Part 2 (Privacy Policy) and the applicable SaaS agreement.

6A. Effect of Breach

Without limiting Clause 6, where we reasonably suspect a breach of these Terms, we may, at our discretion and depending on the severity of the breach, take one or more of the following steps:

You may not take any action to circumvent a suspension, restriction, or block imposed under this Clause, including by submitting or using different credentials or information to regain access.

7. Limitation of Liability

7.1 Subject to Clause 7.3, IDToday shall not be liable for indirect, incidental, special, or consequential loss arising from your use of or reliance on the Service or Website, whether arising in delict, contract, or otherwise.

7.2A Subject to Clause 7.3, and without limiting the generality of the exclusion of liability above, IDToday will not be liable for any loss of profit, contracts, business, goodwill, data, income, revenue or anticipated savings arising under these Terms or in connection with the Service or the Website, whether direct or indirect, nor will IDToday be liable for any loss or damage arising out of any event that is beyond its reasonable control.

7.3 Statutory Carve-outs: Nothing in these Terms limits, excludes, or purports to contract out of:

7.4 Nothing in these Terms deprives a data subject of the right to lodge a complaint with the South African Information Regulator or to pursue statutory remedies under applicable law.

8. Disclaimer of Warranties

The Service is provided on an “as is” and “as available” basis. Except as expressly stated, IDToday disclaims all implied warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the operation of the platform will be uninterrupted or error-free. This disclaimer does not diminish our statutory security duties under Section 19 of POPIA or Clause 10 of the Privacy Policy.

9. Screening Results

Sanctions, watchlists, adverse media, and Politically Exposed Person (PEP) screening results returned by the Service represent potential data matches against external databases. They do not constitute a definitive determination about an individual or an automated decision to decline a customer. Final business determinations are made exclusively by the relevant Client.

10. Governing Law

10.1 These Terms are governed by the laws of the Republic of South Africa.

10.2 Clause 10.1 does not restrict the extraterritorial application of POPIA under Section 3 where processing activities occur within South Africa or involve South African data subjects.

10A. Jurisdiction

You consent to the non-exclusive jurisdiction of the courts of the Republic of South Africa in respect of any dispute arising from or relating to these Terms, without prejudice to IDToday’s right to bring proceedings in any other court of competent jurisdiction. Nothing in this Clause limits a data subject’s right to approach the South African Information Regulator, or a competent court, in respect of matters arising under POPIA.

10B. Force Majeure

Neither party shall be liable for any failure or delay in performing its obligations under these Terms (other than payment obligations) to the extent such failure or delay is caused by circumstances reasonably beyond that party’s control, including load-shedding or power interruptions, internet or telecommunications outages, failure of third-party data providers or cloud infrastructure, natural disaster, pandemic, civil unrest, or governmental action. The affected party will use reasonable efforts to notify the other party and to resume performance as soon as reasonably possible.

11. Dispute Resolution

In the event of a dispute, parties agree to attempt informal resolution by contacting the Information Officer. Data subjects maintain the right to lodge a complaint directly with the Information Regulator (South Africa) at any time.

12. Changes to Terms

Material changes to these Terms will be published on the Website with 30 days’ advance notice where feasible. Continued use of the platform after effective dates constitutes acceptance.

12A. Severability

If any provision of these Terms is found by a court, tribunal, or the Information Regulator to be invalid, unlawful, or unenforceable, that provision shall be severed and enforced to the maximum extent permissible, and the remaining provisions shall continue in full force and effect.

12B. Non-Waiver

No failure or delay by IDToday in exercising any right under these Terms shall operate as a waiver of that right, nor shall any single or partial exercise of a right preclude any other or further exercise of that right or any other right. Any waiver is only effective if given in writing and signed by an authorised representative of IDToday, and applies only to the specific instance for which it is given.

12C. Disclosures under the Electronic Communications and Transactions Act 25 of 2002

In compliance with Section 43(1) of the Electronic Communications and Transactions Act 25 of 2002, the following particulars are provided in respect of IDToday South Africa:

13. POPIA Operator Agreement (Data Processing Terms)

13.1 Legal Roles: Where a Client uses the Service to process personal information of End Users or third parties, the Client is the Responsible Party and IDToday is the Operator, as defined in POPIA.

13.2 Authorisation & Confidentiality: In terms of Section 20 and Section 21(1) of POPIA, IDToday shall process such personal information solely on the documented, written instructions of the Client, and shall treat all such personal information as strictly confidential.

13.3 Security Safeguards: IDToday shall establish and maintain appropriate technical and organisational security measures to safeguard personal information in accordance with Section 19 of POPIA, as detailed in Clause 8 of Part 2 (Privacy Policy).

13.4 Security Compromises: In compliance with Section 21(2) of POPIA, IDToday shall notify the Client immediately (and in any event within 48 hours of confirmation) upon becoming aware of any confirmed or reasonably suspected security compromise involving Client personal information.

13.5 Sub-Operators: The Client grants IDToday general authorisation to engage sub-operators to assist in delivering the Service, as listed in Annex A to Part 2 (Privacy Policy). IDToday shall ensure that all sub-operators are bound by data protection obligations substantially similar to those set out herein.

Part 2 — Privacy Policy

Last updated: July 2026

1. Scope and Approach

IDToday is committed to processing personal information lawfully, transparently, and securely. This Privacy Policy details our processing activities under the Protection of Personal Information Act 4 of 2013 (“POPIA”). In addition, IDToday’s processing of personal information relating to Clients, End Users and suppliers in South Africa is carried out pursuant to, and where required by, the Financial Intelligence Centre Act 38 of 2001 (“FICA”), the Income Tax Act 58 of 1962, the Value-Added Tax Act 89 of 1991, and the Promotion of Access to Information Act 2 of 2000 (“PAIA”), in each case to the extent applicable.

In this policy, “personal information” bears the statutory definition established in Section 1 of POPIA.

2. Responsible Entity and Information Officer Contact Details

South African Responsible Party / Operator:
IDToday Secure Data Solutions South Africa (Pty) Ltd
Registration Number: 2026/233950/07
15 Sterling Grove, Buh-Rein Estate, Kraaifontein, Cape Town, Western Cape, 7570, South Africa

South African Information Regulator:
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
E-mail: complaints.IR@inforegulator.org.za / enquiries@inforegulator.org.za
Website: inforegulator.org.za

3. Legal Roles: Responsible Party vs. Operator

3.1 IDToday as an OPERATOR

For End User identity documents, proof of address, biometrics, and screening checks submitted by or on behalf of a Client for KYC/FICA compliance, the Client is the Responsible Party and IDToday is the Operator. We process this information strictly on the documented written instructions of the Client.

If an End User seeks to exercise rights of access, correction, or deletion regarding KYC data, the request should be directed to the relevant Client. Requests sent directly to IDToday will be forwarded to the Client’s Information Officer within 3 (three) business days. IDToday will notify you that your request has been redirected in this manner.

3.2 IDToday as a RESPONSIBLE PARTY

IDToday acts as a Responsible Party for:

Where personal information is submitted via a shared digital intake tool such as Cognito Forms, the applicable role depends on whose information is collected and for what purpose: End User identity documents collected on a Client’s behalf for KYC/FICA purposes are processed under Clause 3.1 (IDToday as Operator, Client as Responsible Party); a Client’s own onboarding and identification information, collected so that IDToday may onboard that Client onto the Service, is processed under this Clause 3.2 (IDToday as Responsible Party).

4. Personal Information Collected

CategoryDescription
Identification DataFull name, national identity number, passport details, date of birth, nationality, identity document copies.
Contact DataResidential/business address, postal address, email address, phone numbers.
Proof of ResidenceUtility statements, bank letters, lease agreements or official municipal declarations.
Financial / Risk DataSource of wealth/funds declarations, sanctions screening flags, PEP statuses.
Biometric DataFacial image captures and liveness verification metrics (where enabled by Client).
Technical DataIP addresses, browser specs, device identifiers, system access logs.

4A. Personal Information of Clients (Commercial and Contracting Relationship)

In addition to the personal information described above, IDToday also collects and processes personal information relating to Clients that are juristic persons, in connection with the SaaS agreement and commercial relationship, which information includes, for example:

4B. Personal Information of Juristic Persons Submitted for KYC/Onboarding Purposes

Where a Client uses the Service to onboard or verify a customer that is a juristic person, IDToday processes personal information relating to that juristic person and its representatives on the Client’s documented written instructions (see Section 3.1 above), which may include, for example:

5. Lawful Bases for Processing (POPIA Section 11 Alignment)

Core KYC and customer due diligence processing is not grounded in revocable consent, as it is mandated by financial regulatory statutes.

Processing PurposeLawful Basis under POPIA
End User KYC Collection & VerificationSection 11(1)(c) (Compliance with legal obligation under FICA / Financial Intelligence Act) & Section 11(1)(f) (Legitimate interests of Client and IDToday).
Sanctions & PEP ScreeningSection 11(1)(c) & Section 11(1)(f).
SaaS Service ProvisioningSection 11(1)(b) (Performance of contract with Client) & Section 11(1)(f).
Platform Security & Audit LoggingSection 11(1)(f) (Legitimate operational security interest).
Website Analytics / MarketingSection 11(1)(a) (Voluntary, specific consent via Cookie Banner / Opt-in forms).

5A. Additional Purposes for Processing (Juristic Persons)

The purposes for which IDToday processes the personal information of Clients that are juristic persons (described in Section 4A above) include, among others:

6. Special Personal Information & Biometrics

Special personal information (including criminal background details resulting from sanctions checks and biometric facial data) is processed in strict compliance with POPIA requirements:

7. Cross-Border Transfers (POPIA Section 72 Compliance)

Because Namibia has not finalized an enforceable comprehensive data protection statute, transfers of South African personal information to IDToday Namibia or external sub-operators are executed under Section 72(1)(a) of POPIA using binding intra-group data transfer agreements and robust Data Processing Agreements (DPAs).

The recipients to which such information may be transferred, the countries or locations in which they are established, and the transfer mechanism relied on in each case, are set out in the single consolidated table at Annex A (Reconciled Sub-Operator & Recipient List) to this Privacy Policy, which IDToday maintains as the single source of truth for all sub-processor and cross-border recipient arrangements, rather than duplicating that detail here.

Each of the agreements referred to in Annex A is structured to satisfy both limbs of Section 72(1)(a): (i) the recipient is bound by provisions upholding principles for reasonable processing that are substantially similar to POPIA’s conditions for lawful processing; and (ii) the agreement restricts the recipient from transferring the personal information onward to any further third party in another foreign country, save on terms imposing equivalent safeguards. Each agreement also confers on affected data subjects (or on IDToday acting on their behalf) an enforceable right to invoke the relevant safeguards directly against the recipient.

Because the Namibian data protection framework has not yet been finalised, the Binding Intra-Group Data Transfer Agreement between IDToday South Africa and IDToday Namibia specifically incorporates, on a clause-by-clause basis, the eight conditions for lawful processing set out in Chapter 3 of POPIA, and remains binding on IDToday Namibia notwithstanding termination of the underlying SaaS relationship or of the intra-group relationship between the two entities.

New Sub-Processors: Before engaging any new sub-processor or cross-border recipient, IDToday will assess the proposed transfer against the requirements of Section 72(1)(a), update Annex A accordingly, and, where the new recipient will process KYC data for which a Client is the Responsible Party, notify the affected Client(s) in advance.

7B. AI/ML Sub-Processors and Automated Verification Tools

Where any sub-processor listed in Annex A uses artificial intelligence or machine learning technologies to process personal information on IDToday’s behalf — including for biometric facial matching, liveness detection, or sanctions, PEP, or adverse media screening — IDToday requires that such personal information is processed solely to deliver the relevant service to IDToday and its Clients, and is not used by the sub-processor for any other or independent purpose, including the training or improvement of the sub-processor’s own AI/ML models, unless IDToday has given prior written authorisation. Each relevant Data Processing Agreement imposes confidentiality and security obligations on the sub-processor consistent with Section 19 of POPIA, and any output generated by such tools (including biometric match scores) remains subject to the mandatory human review requirements set out in Section 10 below.

8. Security Safeguards (POPIA Section 19)

IDToday enforces comprehensive technical and organizational safeguards:

9. Security Compromise Notification (POPIA Section 22)

In the event of a confirmed or reasonably suspected data breach:

10. Automated Decision-Making & Human Oversight

The platform utilizes automated screening algorithms to flag potential watchlist matches. No legal or binding decision is made solely by an automated algorithm. Every match flag is subject to mandatory manual review by qualified personnel prior to client reporting, ensuring full compliance with Section 71 of POPIA.

11. Rights of Data Subjects

Data subjects possess the following statutory rights under POPIA:

Should you wish to exercise any of the above rights, you are required to submit your request in writing to the Information Officer at the contact details set out in Section 2 above. IDToday will acknowledge receipt of your request within 5 (five) business days and will use reasonable efforts to respond substantively within 30 (thirty) days, in line with applicable PAIA timeframes (subject to Clause 3.1 above, where your request relates to KYC data for which a Client is the Responsible Party). Depending on the nature of your request, you may be required to complete the applicable form prescribed under the POPIA Regulations.

12. Retention Limits

Personal information is retained only for periods prescribed by statute or operational necessity:

13. Cookie Policy

IDToday uses cookies and similar tracking technologies on the Website to distinguish you from other visitors, remember your preferences, and understand how the Website is used. Cookies fall into the following categories:

You may withdraw or adjust your cookie consent at any time via the cookie preference tool on the Website, save for Strictly Necessary Cookies. Declining non-essential cookies will not affect your ability to access the core Service.

14. Revisions to this Privacy Policy

IDToday may update or amend this Privacy Policy from time to time to reflect changes in our processing activities, legal or regulatory requirements, or the functionality of the Service. Where a change is material — for example, a change to the purposes for which we process personal information, the categories of recipients with whom we share it, or your rights as a data subject — we will provide advance notice by e-mail (where we hold a valid address for you) and/or by posting a prominent notice on the Website prior to the change taking effect. Non-material changes may be made by updating the “Last updated” date at the top of this Privacy Policy. We encourage you to review this Privacy Policy periodically. Continued use of the Service after a revised Privacy Policy takes effect constitutes acknowledgement of the changes, without prejudice to any statutory rights you may have under POPIA.

Annex A — Reconciled Sub-Operator & Recipient List

This is the single, consolidated recipient table referred to in Section 7 (Cross-Border Transfers) above: it lists every sub-processor and external recipient authorised to process personal information within the IDToday infrastructure, whether the transfer is domestic or cross-border, together with the transfer mechanism relied on in each case. IDToday updates this table — and this table alone — whenever a new sub-processor or cross-border recipient is engaged.

Factiva Limited (Dow Jones) is listed below as a data recipient for cross-border transfer purposes only. Unlike the other entities in this table, Factiva does not process data as IDToday’s sub-processor or on IDToday’s instructions: under the Data Processing Terms Schedule to the Dow Jones Partner Agreement, Dow Jones is an independent third-party controller of its own Watchlist database, and IDToday is a separate controller of the Service Results it receives.

Recipient Legal Entity Service Function Country / Data Location Transfer Mechanism / Basis (POPIA Section 72)
Factiva Limited (a Dow Jones company) — independent controller, not a sub-processor Risk, PEP, RCA, and Sanctions screening API data feeds United States Section 72(1)(a) — DPA incorporating Standard Contractual Clause-equivalent safeguards, and confirming Factiva’s role as an independent controller — not IDToday’s sub-processor — of the Dow Jones Watchlist database, with IDToday acting as a separate controller of the screening results it receives, in each case pursuant to the Data Processing Terms Schedule to the Dow Jones Partner Agreement.
Cognito Forms Cloud form collection interface United States Section 72(1)(a) — DPA does not itself reference POPIA. Transfer is supported on a risk basis by (i) the DPA’s general security, confidentiality, breach-notification and sub-processor accountability obligations, and (ii) IDToday’s operational controls, under which submissions are transferred automatically to IDToday’s secure GCP host and deleted from Cognito Forms near-instantly, with deletion logged for audit. See IDToday’s Section 72 Transfer Risk Memorandum (3 August 2026), retained on file, which can be provided upon request.
Google Cloud Platform (Firestore) Core database compute and cloud storage Belgium (European Union) Section 72(1)(a) — Recipient bound by the Google Cloud DPA, which imposes safeguards substantially similar to POPIA’s conditions for lawful processing.
Amazon Web Services (Pty) Ltd Secondary cloud data backups Johannesburg, South Africa Local Storage — No cross-border transfer; primary database back-up hosted locally.
IDToday Secure Data Solutions (Pty) Ltd Intra-group operational support & platform management Namibia Binding Intra-Group Data Transfer Agreement establishing standard protection clauses equivalent to POPIA.