This policy explains how Radius Workforce Management collects, uses, stores and protects your personal information, and describes your rights as a data subject.
Contents
Radius Workforce Management ("Radius WFM", "we", "us", "our") operates the workforce management platform available at radiuswm.app and its tenant subdomains. We are a multi-tenant SaaS provider headquartered and registered in Zimbabwe, operating in South Africa and Zimbabwe.
Your employer or organisation (the "Tenant") who subscribes to Radius WFM is the responsible party / data controller in relation to your personal information. Radius WFM acts as the operator / data processor, processing personal information only on the Tenant's instructions and on its behalf.
This policy applies to:
This policy is drafted to comply with:
Where both laws apply, we comply with the more stringent requirement.
We collect only the personal information that is necessary to deliver the Radius WFM platform. The categories below apply to employees and workers whose employers use our platform.
| Category | Examples | Source |
|---|---|---|
| Identity data | Full name, employee ID, job title, department, date of birth | Employer (admin import or self-registration) |
| Contact data | Work email address, mobile phone number | Employer or employee self-service |
| Biometric data | Mathematical face embedding (512-dimensional vector) derived from a single enrolment selfie. The raw image is never stored. | Employee enrolment (camera capture) |
| Location data | GPS coordinates at clock-in / clock-out events; GPS coordinates during trip logs | Employee device at moment of clock action |
| Attendance data | Clock-in/out timestamps, shift assignments, late arrivals, early departures, overtime | Platform (generated automatically) |
| Leave data | Leave type, dates, reason (if provided), approval status | Employee or manager input |
| Trip / errand data | Purpose of departure, departure/return timestamps, vehicle registration (optional) | Employee input at time of departure |
| Payroll data | Hours worked, overtime, salary grade, PAYE / UIF / NSSA deductions, bank account details (if payslip delivery is configured) | Employer configuration + attendance data (payroll module only) |
| Device / technical data | Device type, operating system version, IP address at login, app version | Automated collection at login |
| Enquiry data | Name, company, email, phone, message (from the demo request form on radiuswm.app) | Visitor submission |
We do not collect or store special categories of personal information beyond biometric data (described in Section 3) and, where payroll is active, tax and banking data. We do not process racial or ethnic origin, political opinions, religious beliefs, trade union membership, or health data as part of normal platform operation.
During enrolment, a short video or series of frames is captured through your device camera solely to generate a face embedding — a mathematical representation of your facial geometry (512 numerical values). This embedding is used only to verify your identity at each clock-in event.
To prevent spoofing, our system verifies that a live person is present (blink detection at enrolment; head-turn detection at clock-in). No additional biometric data is retained from these checks beyond confirming a pass or fail result.
Your employer must obtain your written consent before activating biometric enrolment. You may withdraw consent at any time by notifying your employer. Upon withdrawal, your face embedding will be deleted from the system. Note that withdrawal may affect your ability to clock in using the platform's face-recognition feature; your employer is responsible for making alternative arrangements.
Radius WFM uses GPS coordinates only at the moment a clock-in or clock-out action is initiated. We do not continuously track your location or build a movement history beyond the discrete events listed below.
Location data is not transmitted to third-party advertising or analytics services. It is used solely for the operational purpose of attendance verification and is retained as part of the attendance record subject to the retention periods in Section 9.
Under POPIA, processing must satisfy at least one condition set out in Section 11. The conditions we rely on are:
For special personal information (biometric data), processing is further authorised by explicit consent under Section 27(1)(a) of POPIA.
Under the Cyber and Data Protection Act, we rely on the following lawful grounds:
We do not use personal information for marketing profiling, sale to third parties, or any purpose incompatible with the purposes listed above.
We share personal information only as follows:
We do not sell, rent, or trade personal information to any third party for commercial or marketing purposes.
Radius WFM's primary infrastructure is hosted in cloud data centres located in the Africa region. Where data is processed or stored outside the country of origin of the data subject, we ensure that adequate safeguards are in place as required by POPIA (Section 72) and the CDPA.
Safeguards include:
Upon request, we will provide information about the specific safeguards applicable to any cross-border transfer of your personal information.
| Data type | Retention period | Basis |
|---|---|---|
| Attendance records | 5 years from date of record | Labour Act (ZW) / BCEA (ZA) — inspection liability period |
| Payroll records | 5 years from tax year end | Income Tax Act (ZA); Income Tax Act (ZW); ZIMRA requirements |
| Leave records | 3 years from date of record | Contractual and statutory basis |
| Face embeddings (biometric) | Duration of employment + 30 days | Deleted automatically 30 days after employee deactivation or consent withdrawal |
| Clock-in attempt logs (including failed attempts) | 12 months | Security audit and dispute resolution |
| Trip / errand logs | 12 months | Operational and dispute resolution |
| System and access logs | 12 months | Security and POPIA / CDPA compliance |
| Demo / enquiry data | 24 months from last contact | Legitimate interest (sales pipeline) |
Upon expiry of the applicable retention period, personal information is securely deleted or anonymised. Employers (Tenants) may request earlier deletion of employee data subject to applicable statutory retention requirements that take precedence.
We implement appropriate technical and organisational measures to protect personal information against loss, unauthorised access, disclosure, alteration or destruction, as required by POPIA (Section 19) and the CDPA.
If your employer is a South African company or you are a South African data subject, you have the following rights under POPIA:
You may request confirmation of whether we hold your personal information and a copy of that information (POPIA s.23).
You may request correction or deletion of inaccurate, outdated, or incomplete personal information (POPIA s.24).
You may object to the processing of your personal information on grounds of legitimate interest (POPIA s.11(3)).
Where processing is based on consent (including biometric data), you may withdraw consent at any time without detriment beyond the consequences inherent to withdrawal.
You may submit a complaint to the Information Regulator if you believe your rights under POPIA have been infringed.
You have the right not to be subject to a decision based solely on automated processing that significantly affects you, in circumstances where no human review is available.
To exercise these rights, contact your employer's Information Officer in the first instance. Where Radius WFM is the appropriate point of contact (for example, for technical deletion), contact us at the details in Section 16.
If your employer is a Zimbabwean company or you are a Zimbabwean data subject, you have the following rights under the Cyber and Data Protection Act:
You may request access to your personal data held by us or your employer, and receive it in an intelligible form.
You may request that inaccurate or incomplete personal data be corrected without undue delay.
You may request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to overriding statutory retention obligations.
You may request that your personal data be provided to you in a structured, commonly used, and machine-readable format.
You may object to processing based on legitimate interests, including profiling, where your fundamental rights override those interests.
Where processing (especially of biometric data) is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of prior processing.
To exercise these rights, contact your employer or Radius WFM using the details in Section 16. We will respond within 30 days. Where a request is refused or cannot be fulfilled, we will provide reasons in writing.
Radius WFM uses automated processing in the following ways:
No decision that significantly and adversely affects an individual (such as termination of employment) is made by automated means without human review. The automated outputs described above are presented to responsible humans who make the final determination.
Radius WFM is a business-to-business platform intended for use by employers and adult employees in the workplace. We do not knowingly process personal information relating to children (persons under the age of 18) as part of normal platform operation. Employers are responsible for ensuring that only adults are enrolled on the platform. If we become aware that personal information of a child has been collected without appropriate legal basis, we will delete it promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or regulatory guidance. When we make material changes, we will:
The current version of this policy is always available at radiuswm.app/privacy.html. Continued use of the platform after notification of changes constitutes acceptance of the revised policy.
Radius WFM has designated an Information Officer as required by POPIA (Section 55) and the CDPA. The Information Officer is responsible for ensuring compliance with data protection law, handling data subject requests, and serving as the point of contact with supervisory authorities.
We aim to acknowledge all data subject requests within 5 business days and to respond substantively within 30 days, consistent with the requirements of POPIA and the CDPA.
If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with the relevant supervisory authority.