Legal

Privacy Policy

This policy explains how Radius Workforce Management collects, uses, stores and protects your personal information, and describes your rights as a data subject.

POPIA Compliant — South Africa CDPA Compliant — Zimbabwe Effective: 1 June 2026 Last updated: 11 August 2026

Contents

  1. Who we are and how this policy applies
  2. Personal information we collect
  3. Biometric data — face embeddings
  4. Location data and GPS geofencing
  5. Lawful basis for processing
  6. How we use your information
  7. Sharing and disclosure
  8. International transfers
  9. Retention periods
  10. Security safeguards
  11. Your rights under POPIA (South Africa)
  12. Your rights under the CDPA (Zimbabwe)
  13. Automated processing and profiling
  14. Children
  15. Changes to this policy
  16. Information Officer and contact details
  17. Regulatory complaints
01

Who we are and how this policy applies

Radius Workforce Management ("Radius WFM", "we", "us", "our") operates the workforce management platform available at radiuswm.app and its tenant subdomains. We are a multi-tenant SaaS provider headquartered and registered in Zimbabwe, operating in South Africa and Zimbabwe.

Data controller vs data processor

Your employer or organisation (the "Tenant") who subscribes to Radius WFM is the responsible party / data controller in relation to your personal information. Radius WFM acts as the operator / data processor, processing personal information only on the Tenant's instructions and on its behalf.

This policy applies to:

For employees: If you have questions about how your employer uses your data, or wish to exercise your rights, you should contact your employer's designated privacy officer in the first instance. Radius WFM will support and facilitate such requests.

Applicable law

This policy is drafted to comply with:

Where both laws apply, we comply with the more stringent requirement.


02

Personal information we collect

We collect only the personal information that is necessary to deliver the Radius WFM platform. The categories below apply to employees and workers whose employers use our platform.

Category Examples Source
Identity data Full name, employee ID, job title, department, date of birth Employer (admin import or self-registration)
Contact data Work email address, mobile phone number Employer or employee self-service
Biometric data Mathematical face embedding (512-dimensional vector) derived from a single enrolment selfie. The raw image is never stored. Employee enrolment (camera capture)
Location data GPS coordinates at clock-in / clock-out events; GPS coordinates during trip logs Employee device at moment of clock action
Attendance data Clock-in/out timestamps, shift assignments, late arrivals, early departures, overtime Platform (generated automatically)
Leave data Leave type, dates, reason (if provided), approval status Employee or manager input
Trip / errand data Purpose of departure, departure/return timestamps, vehicle registration (optional) Employee input at time of departure
Payroll data Hours worked, overtime, salary grade, PAYE / UIF / NSSA deductions, bank account details (if payslip delivery is configured) Employer configuration + attendance data (payroll module only)
Device / technical data Device type, operating system version, IP address at login, app version Automated collection at login
Enquiry data Name, company, email, phone, message (from the demo request form on radiuswm.app) Visitor submission

We do not collect or store special categories of personal information beyond biometric data (described in Section 3) and, where payroll is active, tax and banking data. We do not process racial or ethnic origin, political opinions, religious beliefs, trade union membership, or health data as part of normal platform operation.


03

Biometric data — face embeddings

Important: Biometric data is classified as special personal information under POPIA (Section 26) and as sensitive data under the CDPA. Its processing requires your explicit, informed, and freely given consent.

What we capture and what we store

During enrolment, a short video or series of frames is captured through your device camera solely to generate a face embedding — a mathematical representation of your facial geometry (512 numerical values). This embedding is used only to verify your identity at each clock-in event.

Liveness detection

To prevent spoofing, our system verifies that a live person is present (blink detection at enrolment; head-turn detection at clock-in). No additional biometric data is retained from these checks beyond confirming a pass or fail result.

Consent and withdrawal

Your employer must obtain your written consent before activating biometric enrolment. You may withdraw consent at any time by notifying your employer. Upon withdrawal, your face embedding will be deleted from the system. Note that withdrawal may affect your ability to clock in using the platform's face-recognition feature; your employer is responsible for making alternative arrangements.


04

Location data and GPS geofencing

Radius WFM uses GPS coordinates only at the moment a clock-in or clock-out action is initiated. We do not continuously track your location or build a movement history beyond the discrete events listed below.

Location data is not transmitted to third-party advertising or analytics services. It is used solely for the operational purpose of attendance verification and is retained as part of the attendance record subject to the retention periods in Section 9.


05

Lawful basis for processing

South Africa — POPIA POPIA

Under POPIA, processing must satisfy at least one condition set out in Section 11. The conditions we rely on are:

For special personal information (biometric data), processing is further authorised by explicit consent under Section 27(1)(a) of POPIA.

Zimbabwe — CDPA CDPA

Under the Cyber and Data Protection Act, we rely on the following lawful grounds:


06

How we use your information

We do not use personal information for marketing profiling, sale to third parties, or any purpose incompatible with the purposes listed above.


07

Sharing and disclosure

We share personal information only as follows:

We do not sell, rent, or trade personal information to any third party for commercial or marketing purposes.


08

International transfers

Radius WFM's primary infrastructure is hosted in cloud data centres located in the Africa region. Where data is processed or stored outside the country of origin of the data subject, we ensure that adequate safeguards are in place as required by POPIA (Section 72) and the CDPA.

Safeguards include:

Upon request, we will provide information about the specific safeguards applicable to any cross-border transfer of your personal information.


09

Retention periods

Data type Retention period Basis
Attendance records 5 years from date of record Labour Act (ZW) / BCEA (ZA) — inspection liability period
Payroll records 5 years from tax year end Income Tax Act (ZA); Income Tax Act (ZW); ZIMRA requirements
Leave records 3 years from date of record Contractual and statutory basis
Face embeddings (biometric) Duration of employment + 30 days Deleted automatically 30 days after employee deactivation or consent withdrawal
Clock-in attempt logs (including failed attempts) 12 months Security audit and dispute resolution
Trip / errand logs 12 months Operational and dispute resolution
System and access logs 12 months Security and POPIA / CDPA compliance
Demo / enquiry data 24 months from last contact Legitimate interest (sales pipeline)

Upon expiry of the applicable retention period, personal information is securely deleted or anonymised. Employers (Tenants) may request earlier deletion of employee data subject to applicable statutory retention requirements that take precedence.


10

Security safeguards

We implement appropriate technical and organisational measures to protect personal information against loss, unauthorised access, disclosure, alteration or destruction, as required by POPIA (Section 19) and the CDPA.


11

Your rights under POPIA (South Africa) POPIA

If your employer is a South African company or you are a South African data subject, you have the following rights under POPIA:

Right of access

You may request confirmation of whether we hold your personal information and a copy of that information (POPIA s.23).

Right to correction

You may request correction or deletion of inaccurate, outdated, or incomplete personal information (POPIA s.24).

Right to object

You may object to the processing of your personal information on grounds of legitimate interest (POPIA s.11(3)).

Right to withdraw consent

Where processing is based on consent (including biometric data), you may withdraw consent at any time without detriment beyond the consequences inherent to withdrawal.

Right to complain

You may submit a complaint to the Information Regulator if you believe your rights under POPIA have been infringed.

Right not to be subject to automated decisions

You have the right not to be subject to a decision based solely on automated processing that significantly affects you, in circumstances where no human review is available.

To exercise these rights, contact your employer's Information Officer in the first instance. Where Radius WFM is the appropriate point of contact (for example, for technical deletion), contact us at the details in Section 16.


12

Your rights under the CDPA (Zimbabwe) CDPA

If your employer is a Zimbabwean company or you are a Zimbabwean data subject, you have the following rights under the Cyber and Data Protection Act:

Right of access

You may request access to your personal data held by us or your employer, and receive it in an intelligible form.

Right to rectification

You may request that inaccurate or incomplete personal data be corrected without undue delay.

Right to erasure

You may request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to overriding statutory retention obligations.

Right to data portability

You may request that your personal data be provided to you in a structured, commonly used, and machine-readable format.

Right to object

You may object to processing based on legitimate interests, including profiling, where your fundamental rights override those interests.

Right to withdraw consent

Where processing (especially of biometric data) is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of prior processing.

To exercise these rights, contact your employer or Radius WFM using the details in Section 16. We will respond within 30 days. Where a request is refused or cannot be fulfilled, we will provide reasons in writing.


13

Automated processing and profiling

Radius WFM uses automated processing in the following ways:

No decision that significantly and adversely affects an individual (such as termination of employment) is made by automated means without human review. The automated outputs described above are presented to responsible humans who make the final determination.


14

Children

Radius WFM is a business-to-business platform intended for use by employers and adult employees in the workplace. We do not knowingly process personal information relating to children (persons under the age of 18) as part of normal platform operation. Employers are responsible for ensuring that only adults are enrolled on the platform. If we become aware that personal information of a child has been collected without appropriate legal basis, we will delete it promptly.


15

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or regulatory guidance. When we make material changes, we will:

The current version of this policy is always available at radiuswm.app/privacy.html. Continued use of the platform after notification of changes constitutes acceptance of the revised policy.


16

Information Officer and contact details

Radius WFM has designated an Information Officer as required by POPIA (Section 55) and the CDPA. The Information Officer is responsible for ensuring compliance with data protection law, handling data subject requests, and serving as the point of contact with supervisory authorities.

Radius Workforce Management — Information Officer

CompanyRadius Workforce Management (Pvt) Ltd
South Africa+27 74 762 6867

We aim to acknowledge all data subject requests within 5 business days and to respond substantively within 30 days, consistent with the requirements of POPIA and the CDPA.


17

Regulatory complaints

If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with the relevant supervisory authority.

South Africa — Information Regulator POPIA

Phone+27 10 023 5200
AddressJD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Zimbabwe — Postal and Telecommunications Regulatory Authority (POTRAZ) CDPA

Phone+263 (0)8677 000 700
AddressOld Mutual Centre, Third Floor, Jason Moyo Avenue, Harare, Zimbabwe
Before lodging a complaint with a regulator, we encourage you to contact us first at privacy@radiuswm.app so that we have an opportunity to resolve your concern directly. Many issues can be resolved quickly without the need for formal regulatory intervention.