Part 1 — Terms and Conditions
Last updated: 3 August 2026
1. Who We Are and Who These Terms Apply To
IDToday, we, us or our means:
- IDToday Secure Data Solutions South Africa (Pty) Ltd, registration number 2026/233950/07, a company incorporated in the Republic of South Africa, with its registered address at 15 Sterling Grove, Buh-Rein Estate, Kraaifontein, Cape Town, Western Cape, 7570 (“IDToday South Africa”).
- Client means an entity that has signed a Software as a Service (SaaS) agreement with IDToday to make use of our services.
- End User means an individual or entity (or a representative or beneficial owner of a juristic person) who submits information via the Service at the request of, or for the purposes of, a Client’s Know Your Customer (KYC), customer due diligence, or anti-money-laundering obligations.
- Service and Website mean the website https://idtodaykyc.com/, the IDToday software application, and all related services.
- Terms means these Terms and Conditions as updated from time to time.
- You and Your mean the individual accessing or using the Service, or the entity on behalf of which such individual accesses the Service.
2. Acknowledgement
These Terms govern your use of the Service and form a binding agreement between you and IDToday. Access to and use of the Service is conditional on your acceptance of and compliance with these Terms.
Where you are an End User, the Client that requested your information, not IDToday, decides why and how your personal information is processed for KYC purposes. IDToday processes that information on the Client’s written instructions. Section 3 of Part 2 (Privacy Policy) details your rights and the appropriate primary contact.
Age Requirement: The Service is intended for individuals aged 18 and over. Where a Client is legally required to verify the identity of a minor (e.g., a minor account holder or beneficial owner), such information must be submitted by a parent, legal guardian, or authorized competent person, and will be processed under Clause 8 of the Privacy Policy.
3. Submission of Information
You as an End User warrant that information submitted or uploaded via the Service:
- Does not infringe any third party’s intellectual property, privacy, or statutory rights;
- Is submitted with lawful authority where it relates to a person other than yourself;
- Does not violate any applicable law, regulation, or binding code;
- Is accurate, current, and complete to the best of your knowledge; and
- Does not contain software viruses, Trojan horses, worms, or any code designed to disrupt, intercept, or expropriate any system or data.
3A. Indemnity
You indemnify and hold IDToday harmless against any claims, costs, damages, expenses, and liabilities (including reasonable legal costs) arising out of or in connection with: (a) your breach of these Terms; (b) your unlawful use of the Service; (c) information submitted or uploaded by you, or on your behalf, in breach of Clause 3 above; or (d) your use of the Service or the Website, or any content or information made available through the Service or the Website.
4. Intellectual Property
IDToday and/or its licensors retain all intellectual property rights in and to the Service (including technology, software, visual interfaces, and branding, but excluding data submitted by you or a Client).
5. Third-Party Services
The Service may link to or integrate with third-party systems. We assume no control over, and accept no liability for, the content, privacy policies, or practices of any third-party software, data provider, or website.
6. Termination
We reserve the right to suspend or terminate access to the Service immediately, without prior notice, in the event of a breach of these Terms or system misuse. Obligations regarding personal information collected prior to termination remain governed by Part 2 (Privacy Policy) and the applicable SaaS agreement.
6A. Effect of Breach
Without limiting Clause 6, where we reasonably suspect a breach of these Terms, we may, at our discretion and depending on the severity of the breach, take one or more of the following steps:
- issue you with a formal written warning;
- suspend your access to the Service pending investigation;
- restrict or block specific accounts, credentials, or IP addresses associated with the suspected breach;
- permanently terminate your access to the Service; and/or
- institute legal proceedings for breach of contract or otherwise.
You may not take any action to circumvent a suspension, restriction, or block imposed under this Clause, including by submitting or using different credentials or information to regain access.
7. Limitation of Liability
7.1 Subject to Clause 7.3, IDToday shall not be liable for indirect, incidental, special, or consequential loss arising from your use of or reliance on the Service or Website, whether arising in delict, contract, or otherwise.
7.2A Subject to Clause 7.3, and without limiting the generality of the exclusion of liability above, IDToday will not be liable for any loss of profit, contracts, business, goodwill, data, income, revenue or anticipated savings arising under these Terms or in connection with the Service or the Website, whether direct or indirect, nor will IDToday be liable for any loss or damage arising out of any event that is beyond its reasonable control.
7.3 Statutory Carve-outs: Nothing in these Terms limits, excludes, or purports to contract out of:
- Liability for fraud, gross negligence, or intentional misconduct;
- Any civil liability of a responsible party or operator to a data subject under Section 99 of the Protection of Personal Information Act 4 of 2013 (“POPIA”); or
- Any non-excludable statutory rights under applicable consumer protection legislation.
7.4 Nothing in these Terms deprives a data subject of the right to lodge a complaint with the South African Information Regulator or to pursue statutory remedies under applicable law.
8. Disclaimer of Warranties
The Service is provided on an “as is” and “as available” basis. Except as expressly stated, IDToday disclaims all implied warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the operation of the platform will be uninterrupted or error-free. This disclaimer does not diminish our statutory security duties under Section 19 of POPIA or Clause 10 of the Privacy Policy.
9. Screening Results
Sanctions, watchlists, adverse media, and Politically Exposed Person (PEP) screening results returned by the Service represent potential data matches against external databases. They do not constitute a definitive determination about an individual or an automated decision to decline a customer. Final business determinations are made exclusively by the relevant Client.
10. Governing Law
10.1 These Terms are governed by the laws of the Republic of South Africa.
10.2 Clause 10.1 does not restrict the extraterritorial application of POPIA under Section 3 where processing activities occur within South Africa or involve South African data subjects.
10A. Jurisdiction
You consent to the non-exclusive jurisdiction of the courts of the Republic of South Africa in respect of any dispute arising from or relating to these Terms, without prejudice to IDToday’s right to bring proceedings in any other court of competent jurisdiction. Nothing in this Clause limits a data subject’s right to approach the South African Information Regulator, or a competent court, in respect of matters arising under POPIA.
10B. Force Majeure
Neither party shall be liable for any failure or delay in performing its obligations under these Terms (other than payment obligations) to the extent such failure or delay is caused by circumstances reasonably beyond that party’s control, including load-shedding or power interruptions, internet or telecommunications outages, failure of third-party data providers or cloud infrastructure, natural disaster, pandemic, civil unrest, or governmental action. The affected party will use reasonable efforts to notify the other party and to resume performance as soon as reasonably possible.
11. Dispute Resolution
In the event of a dispute, parties agree to attempt informal resolution by contacting the Information Officer. Data subjects maintain the right to lodge a complaint directly with the Information Regulator (South Africa) at any time.
12. Changes to Terms
Material changes to these Terms will be published on the Website with 30 days’ advance notice where feasible. Continued use of the platform after effective dates constitutes acceptance.
12A. Severability
If any provision of these Terms is found by a court, tribunal, or the Information Regulator to be invalid, unlawful, or unenforceable, that provision shall be severed and enforced to the maximum extent permissible, and the remaining provisions shall continue in full force and effect.
12B. Non-Waiver
No failure or delay by IDToday in exercising any right under these Terms shall operate as a waiver of that right, nor shall any single or partial exercise of a right preclude any other or further exercise of that right or any other right. Any waiver is only effective if given in writing and signed by an authorised representative of IDToday, and applies only to the specific instance for which it is given.
12C. Disclosures under the Electronic Communications and Transactions Act 25 of 2002
In compliance with Section 43(1) of the Electronic Communications and Transactions Act 25 of 2002, the following particulars are provided in respect of IDToday South Africa:
- Full name: IDToday Secure Data Solutions South Africa (Pty) Ltd;
- Registration number: 2026/233950/07;
- Physical address: 15 Sterling Grove, Buh-Rein Estate, Kraaifontein, Cape Town, Western Cape, 7570, South Africa;
- Website: www.idtodaykyc.com; E-mail: gerhard@idtodaykyc.com;
- Telephone number: +27 79 692 4985;
- Alternative dispute resolution: the parties may agree to refer a dispute to expedited arbitration, in accordance with the rules of the Arbitration Foundation of Southern Africa, prior to instituting court proceedings, without prejudice to a data subject’s statutory right to approach the Information Regulator at any time.
13. POPIA Operator Agreement (Data Processing Terms)
13.1 Legal Roles: Where a Client uses the Service to process personal information of End Users or third parties, the Client is the Responsible Party and IDToday is the Operator, as defined in POPIA.
13.2 Authorisation & Confidentiality: In terms of Section 20 and Section 21(1) of POPIA, IDToday shall process such personal information solely on the documented, written instructions of the Client, and shall treat all such personal information as strictly confidential.
13.3 Security Safeguards: IDToday shall establish and maintain appropriate technical and organisational security measures to safeguard personal information in accordance with Section 19 of POPIA, as detailed in Clause 8 of Part 2 (Privacy Policy).
13.4 Security Compromises: In compliance with Section 21(2) of POPIA, IDToday shall notify the Client immediately (and in any event within 48 hours of confirmation) upon becoming aware of any confirmed or reasonably suspected security compromise involving Client personal information.
13.5 Sub-Operators: The Client grants IDToday general authorisation to engage sub-operators to assist in delivering the Service, as listed in Annex A to Part 2 (Privacy Policy). IDToday shall ensure that all sub-operators are bound by data protection obligations substantially similar to those set out herein.
Part 2 — Privacy Policy
Last updated: July 2026
1. Scope and Approach
IDToday is committed to processing personal information lawfully, transparently, and securely. This Privacy Policy details our processing activities under the Protection of Personal Information Act 4 of 2013 (“POPIA”). In addition, IDToday’s processing of personal information relating to Clients, End Users and suppliers in South Africa is carried out pursuant to, and where required by, the Financial Intelligence Centre Act 38 of 2001 (“FICA”), the Income Tax Act 58 of 1962, the Value-Added Tax Act 89 of 1991, and the Promotion of Access to Information Act 2 of 2000 (“PAIA”), in each case to the extent applicable.
In this policy, “personal information” bears the statutory definition established in Section 1 of POPIA.
2. Responsible Entity and Information Officer Contact Details
South African Responsible Party / Operator:
IDToday Secure Data Solutions South Africa (Pty) Ltd
Registration Number: 2026/233950/07
15 Sterling Grove, Buh-Rein Estate, Kraaifontein, Cape Town, Western Cape, 7570, South Africa
- Registered Information Officer: Gerhardus Jacobus le Roux
- E-mail: gerhard@idtodaykyc.com
- Telephone: +27 79 692 4985
- Information Regulator Registration: The Information Officer is registered with the Information Regulator in terms of Section 55 of POPIA. Information Regulator registration number is: 2026-024122.
- PAIA Manual: available at idtodaykyc.com/paia.html.
South African Information Regulator:
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
E-mail: complaints.IR@inforegulator.org.za / enquiries@inforegulator.org.za
Website: inforegulator.org.za
3. Legal Roles: Responsible Party vs. Operator
3.1 IDToday as an OPERATOR
For End User identity documents, proof of address, biometrics, and screening checks submitted by or on behalf of a Client for KYC/FICA compliance, the Client is the Responsible Party and IDToday is the Operator. We process this information strictly on the documented written instructions of the Client.
If an End User seeks to exercise rights of access, correction, or deletion regarding KYC data, the request should be directed to the relevant Client. Requests sent directly to IDToday will be forwarded to the Client’s Information Officer within 3 (three) business days. IDToday will notify you that your request has been redirected in this manner.
3.2 IDToday as a RESPONSIBLE PARTY
IDToday acts as a Responsible Party for:
- Visitor data captured directly on our Website (enquiry forms, direct contact, cookie preferences);
- Client onboarding and account data, including identification documents and KYC information of a Client’s (e.g., a legal practitioner’s) representatives and administrative personnel, collected when we onboard that Client onto the Service (including via digital intake tools such as Cognito Forms), together with their account credentials;
- Platform audit logs, security records, and billing infrastructure; and
- Independent compliance screening performed directly to meet IDToday’s statutory obligations under FICA.
Where personal information is submitted via a shared digital intake tool such as Cognito Forms, the applicable role depends on whose information is collected and for what purpose: End User identity documents collected on a Client’s behalf for KYC/FICA purposes are processed under Clause 3.1 (IDToday as Operator, Client as Responsible Party); a Client’s own onboarding and identification information, collected so that IDToday may onboard that Client onto the Service, is processed under this Clause 3.2 (IDToday as Responsible Party).
4. Personal Information Collected
| Category | Description |
|---|---|
| Identification Data | Full name, national identity number, passport details, date of birth, nationality, identity document copies. |
| Contact Data | Residential/business address, postal address, email address, phone numbers. |
| Proof of Residence | Utility statements, bank letters, lease agreements or official municipal declarations. |
| Financial / Risk Data | Source of wealth/funds declarations, sanctions screening flags, PEP statuses. |
| Biometric Data | Facial image captures and liveness verification metrics (where enabled by Client). |
| Technical Data | IP addresses, browser specs, device identifiers, system access logs. |
4A. Personal Information of Clients (Commercial and Contracting Relationship)
In addition to the personal information described above, IDToday also collects and processes personal information relating to Clients that are juristic persons, in connection with the SaaS agreement and commercial relationship, which information includes, for example:
- the Client’s name and registration number;
- the Client’s telephone number, email address, physical address and postal address;
- the Client’s VAT number and other tax-related information, where applicable;
- the Client’s contact persons, and their personal information (including, where applicable, their name, email address and telephone number); and
- the Client’s authorised signatories.
4B. Personal Information of Juristic Persons Submitted for KYC/Onboarding Purposes
Where a Client uses the Service to onboard or verify a customer that is a juristic person, IDToday processes personal information relating to that juristic person and its representatives on the Client’s documented written instructions (see Section 3.1 above), which may include, for example:
- the juristic person’s name, registration number, and registered address;
- the juristic person’s nature of business and industry classification;
- proof of incorporation or registration documents;
- the juristic person’s directors, shareholders, and beneficial owners, and their personal information (including, where applicable, identification data, contact details, and proof of address);
- the juristic person’s authorised representatives who interact with the Service on its behalf, and their personal information;
- sanctions, watchlist, adverse media and PEP screening results relating to the juristic person and its representatives; and
- any other Know-Your-Customer information reasonably required by the Client for FICA/AML compliance purposes.
5. Lawful Bases for Processing (POPIA Section 11 Alignment)
Core KYC and customer due diligence processing is not grounded in revocable consent, as it is mandated by financial regulatory statutes.
| Processing Purpose | Lawful Basis under POPIA |
|---|---|
| End User KYC Collection & Verification | Section 11(1)(c) (Compliance with legal obligation under FICA / Financial Intelligence Act) & Section 11(1)(f) (Legitimate interests of Client and IDToday). |
| Sanctions & PEP Screening | Section 11(1)(c) & Section 11(1)(f). |
| SaaS Service Provisioning | Section 11(1)(b) (Performance of contract with Client) & Section 11(1)(f). |
| Platform Security & Audit Logging | Section 11(1)(f) (Legitimate operational security interest). |
| Website Analytics / Marketing | Section 11(1)(a) (Voluntary, specific consent via Cookie Banner / Opt-in forms). |
5A. Additional Purposes for Processing (Juristic Persons)
The purposes for which IDToday processes the personal information of Clients that are juristic persons (described in Section 4A above) include, among others:
- to conclude and perform SaaS agreements and other contracts with Clients;
- to provide the Service to Clients;
- to comply with applicable statutory obligations, including under FICA, tax and companies legislation;
- to respond to queries received from Clients;
- to carry out and manage IDToday’s business operations;
- for historical and statistical purposes, including to analyse trends and make projections;
- for corporate security, disaster recovery and legal reporting obligations;
- for direct marketing purposes, where applicable;
- to conduct statistical analysis, research or surveys;
- to meet Client obligations and for security purposes;
- in the event of a proposed transaction, merger or sale involving IDToday; and
- for any other legitimate business purpose.
6. Special Personal Information & Biometrics
Special personal information (including criminal background details resulting from sanctions checks and biometric facial data) is processed in strict compliance with POPIA requirements:
- Biometrics: Processed under Section 27(1)(a) pursuant to explicit, unbundled End User opt-in consent captured during onboarding workflows, and, to the extent biometric verification is itself mandated by the Client’s FICA/AML obligations, under Section 33, read with Section 27(1)(f) (which authorises processing of biometric information by a responsible party that has obtained it in accordance with the law). Where consent is withdrawn but verification remains a precondition of the Client’s regulated onboarding process, the Client’s underlying statutory obligation continues to apply and access to the Service may be affected accordingly.
- Offence / Sanctions Data: Processed under Section 27(1)(b) (necessary for legal claims/statutory compliance under anti-money-laundering law) and Section 27(1)(c) (international public law compliance/UN Security Council listings).
7. Cross-Border Transfers (POPIA Section 72 Compliance)
Because Namibia has not finalized an enforceable comprehensive data protection statute, transfers of South African personal information to IDToday Namibia or external sub-operators are executed under Section 72(1)(a) of POPIA using binding intra-group data transfer agreements and robust Data Processing Agreements (DPAs).
The recipients to which such information may be transferred, the countries or locations in which they are established, and the transfer mechanism relied on in each case, are set out in the single consolidated table at Annex A (Reconciled Sub-Operator & Recipient List) to this Privacy Policy, which IDToday maintains as the single source of truth for all sub-processor and cross-border recipient arrangements, rather than duplicating that detail here.
Each of the agreements referred to in Annex A is structured to satisfy both limbs of Section 72(1)(a): (i) the recipient is bound by provisions upholding principles for reasonable processing that are substantially similar to POPIA’s conditions for lawful processing; and (ii) the agreement restricts the recipient from transferring the personal information onward to any further third party in another foreign country, save on terms imposing equivalent safeguards. Each agreement also confers on affected data subjects (or on IDToday acting on their behalf) an enforceable right to invoke the relevant safeguards directly against the recipient.
Because the Namibian data protection framework has not yet been finalised, the Binding Intra-Group Data Transfer Agreement between IDToday South Africa and IDToday Namibia specifically incorporates, on a clause-by-clause basis, the eight conditions for lawful processing set out in Chapter 3 of POPIA, and remains binding on IDToday Namibia notwithstanding termination of the underlying SaaS relationship or of the intra-group relationship between the two entities.
New Sub-Processors: Before engaging any new sub-processor or cross-border recipient, IDToday will assess the proposed transfer against the requirements of Section 72(1)(a), update Annex A accordingly, and, where the new recipient will process KYC data for which a Client is the Responsible Party, notify the affected Client(s) in advance.
7B. AI/ML Sub-Processors and Automated Verification Tools
Where any sub-processor listed in Annex A uses artificial intelligence or machine learning technologies to process personal information on IDToday’s behalf — including for biometric facial matching, liveness detection, or sanctions, PEP, or adverse media screening — IDToday requires that such personal information is processed solely to deliver the relevant service to IDToday and its Clients, and is not used by the sub-processor for any other or independent purpose, including the training or improvement of the sub-processor’s own AI/ML models, unless IDToday has given prior written authorisation. Each relevant Data Processing Agreement imposes confidentiality and security obligations on the sub-processor consistent with Section 19 of POPIA, and any output generated by such tools (including biometric match scores) remains subject to the mandatory human review requirements set out in Section 10 below.
8. Security Safeguards (POPIA Section 19)
IDToday enforces comprehensive technical and organizational safeguards:
- Encryption: Data encrypted in transit using TLS 1.3 and at rest using AES-256 standards.
- Access Management: Strict Role-Based Access Control (RBAC) enforcing least-privilege principles.
- Governance: Continuous oversight by Virtual CIO/CSO infrastructure (Marbeh Information Technology Advisory Services / Minc).
- Auditing & Testing: Mandatory annual independent external penetration testing and vulnerability assessments.
9. Security Compromise Notification (POPIA Section 22)
In the event of a confirmed or reasonably suspected data breach:
- Where IDToday is Operator: In line with Section 21(2) of POPIA, we will notify the affected Client(s) immediately upon becoming aware of the compromise, and in any event within 48 hours of confirmation, supplying technical details to enable their notification obligations to the Information Regulator. This 48-hour period is IDToday’s own operational commitment to Clients and is not itself a fixed statutory deadline under POPIA, which requires operator-to-responsible-party notification “immediately” under Section 21(2).
- Where IDToday is Responsible Party: We will notify the South African Information Regulator and affected data subjects as soon as reasonably possible in accordance with Section 22 requirements.
10. Automated Decision-Making & Human Oversight
The platform utilizes automated screening algorithms to flag potential watchlist matches. No legal or binding decision is made solely by an automated algorithm. Every match flag is subject to mandatory manual review by qualified personnel prior to client reporting, ensuring full compliance with Section 71 of POPIA.
11. Rights of Data Subjects
Data subjects possess the following statutory rights under POPIA:
- Right to establish whether IDToday holds personal information relating to you;
- Right to request access to held personal records (Section 23 via PAIA Form 2 procedures);
- Right to request correction, destruction, or deletion of inaccurate, excessive, or obsolete records (Section 24 via POPIA Form 2);
- Right to object to processing based on legitimate interests (Section 11(3) via POPIA Form 1);
- Right to withdraw consent for non-mandatory processing (e.g., marketing/cookies);
- Right to lodge a complaint with the Information Regulator; and
- Right to institute civil proceedings against a responsible party or operator for damages arising from alleged interference with the protection of personal information (Section 99 of POPIA).
Should you wish to exercise any of the above rights, you are required to submit your request in writing to the Information Officer at the contact details set out in Section 2 above. IDToday will acknowledge receipt of your request within 5 (five) business days and will use reasonable efforts to respond substantively within 30 (thirty) days, in line with applicable PAIA timeframes (subject to Clause 3.1 above, where your request relates to KYC data for which a Client is the Responsible Party). Depending on the nature of your request, you may be required to complete the applicable form prescribed under the POPIA Regulations.
12. Retention Limits
Personal information is retained only for periods prescribed by statute or operational necessity:
- KYC / FICA Documentation: Retained for a minimum of 5 (five) years following the formal termination of the business relationship, as mandated by anti-money-laundering statutes.
- System Audit Logs: Retained for 12 months for security verification purposes.
- Marketing Data: Retained until consent is withdrawn or 24 months post-inactivity.
- Third-Party Digital Intake Tools: Where personal information is submitted via a third-party form-collection tool during onboarding (e.g., Cognito Forms), that tool is used solely as a transient intake channel. Submissions are transferred automatically to IDToday’s secure hosting environment immediately upon receipt and are not separately retained by the third-party tool thereafter; deletion is logged for audit purposes (see IDToday’s Section 72 Transfer Risk Memorandum, retained on file).
13. Cookie Policy
IDToday uses cookies and similar tracking technologies on the Website to distinguish you from other visitors, remember your preferences, and understand how the Website is used. Cookies fall into the following categories:
- Strictly Necessary Cookies: required for the Website to function and cannot be disabled;
- Functional Cookies: remember your preferences and settings;
- Analytics / Performance Cookies: help us understand how visitors use the Website;
- Third-Party Cookies: set by third-party service providers (e.g., analytics providers) for the purposes described in their own privacy policies.
You may withdraw or adjust your cookie consent at any time via the cookie preference tool on the Website, save for Strictly Necessary Cookies. Declining non-essential cookies will not affect your ability to access the core Service.
14. Revisions to this Privacy Policy
IDToday may update or amend this Privacy Policy from time to time to reflect changes in our processing activities, legal or regulatory requirements, or the functionality of the Service. Where a change is material — for example, a change to the purposes for which we process personal information, the categories of recipients with whom we share it, or your rights as a data subject — we will provide advance notice by e-mail (where we hold a valid address for you) and/or by posting a prominent notice on the Website prior to the change taking effect. Non-material changes may be made by updating the “Last updated” date at the top of this Privacy Policy. We encourage you to review this Privacy Policy periodically. Continued use of the Service after a revised Privacy Policy takes effect constitutes acknowledgement of the changes, without prejudice to any statutory rights you may have under POPIA.
Annex A — Reconciled Sub-Operator & Recipient List
This is the single, consolidated recipient table referred to in Section 7 (Cross-Border Transfers) above: it lists every sub-processor and external recipient authorised to process personal information within the IDToday infrastructure, whether the transfer is domestic or cross-border, together with the transfer mechanism relied on in each case. IDToday updates this table — and this table alone — whenever a new sub-processor or cross-border recipient is engaged.
Factiva Limited (Dow Jones) is listed below as a data recipient for cross-border transfer purposes only. Unlike the other entities in this table, Factiva does not process data as IDToday’s sub-processor or on IDToday’s instructions: under the Data Processing Terms Schedule to the Dow Jones Partner Agreement, Dow Jones is an independent third-party controller of its own Watchlist database, and IDToday is a separate controller of the Service Results it receives.
| Recipient Legal Entity | Service Function | Country / Data Location | Transfer Mechanism / Basis (POPIA Section 72) |
|---|---|---|---|
| Factiva Limited (a Dow Jones company) — independent controller, not a sub-processor | Risk, PEP, RCA, and Sanctions screening API data feeds | United States | Section 72(1)(a) — DPA incorporating Standard Contractual Clause-equivalent safeguards, and confirming Factiva’s role as an independent controller — not IDToday’s sub-processor — of the Dow Jones Watchlist database, with IDToday acting as a separate controller of the screening results it receives, in each case pursuant to the Data Processing Terms Schedule to the Dow Jones Partner Agreement. |
| Cognito Forms | Cloud form collection interface | United States | Section 72(1)(a) — DPA does not itself reference POPIA. Transfer is supported on a risk basis by (i) the DPA’s general security, confidentiality, breach-notification and sub-processor accountability obligations, and (ii) IDToday’s operational controls, under which submissions are transferred automatically to IDToday’s secure GCP host and deleted from Cognito Forms near-instantly, with deletion logged for audit. See IDToday’s Section 72 Transfer Risk Memorandum (3 August 2026), retained on file, which can be provided upon request. |
| Google Cloud Platform (Firestore) | Core database compute and cloud storage | Belgium (European Union) | Section 72(1)(a) — Recipient bound by the Google Cloud DPA, which imposes safeguards substantially similar to POPIA’s conditions for lawful processing. |
| Amazon Web Services (Pty) Ltd | Secondary cloud data backups | Johannesburg, South Africa | Local Storage — No cross-border transfer; primary database back-up hosted locally. |
| IDToday Secure Data Solutions (Pty) Ltd | Intra-group operational support & platform management | Namibia | Binding Intra-Group Data Transfer Agreement establishing standard protection clauses equivalent to POPIA. |