Privacy Notice
Last updated: 20 August 2026
Who is responsible
Katleho Motseki is a South African sole proprietor trading as Schedinary and is Schedinary's registered Information Officer. Schedinary provides booking software; participating businesses independently provide their own appointment-based services.
For Schedinary account, application, security and platform-support information, Schedinary decides why and how that information is used. For customer information processed to deliver a participating business's appointments, the business determines the service purpose and Schedinary processes the information under the written pilot and data-processing terms. The signed agreement records the parties' responsibilities for each activated business.
Information we collect
- Business applications: owner name, business name, business type, email, telephone number, location count, city and optional notes.
- Customer bookings after controlled activation: name, South African mobile number, optional email address and consent record.
- Appointment information: business, location, service, staff member, date, time, price, status and management activity.
- Owner-managed operating information: locations, staff, services, schedules, availability and time off.
- Security and service records: limited correlation identifiers, hashed rate-limit subjects, audit actions, notification delivery status and diagnostics designed not to contain form contents.
Schedinary does not ask customers for card details, bank credentials, identity documents, biometric information or health information during this pilot. Fictional demonstration records are clearly labelled and must not use another person's details.
Why we use information
- reviewing and preparing a requested business pilot;
- creating, confirming and managing requested appointments;
- enabling authorised owners to operate their diaries;
- sending booking and service communications requested by users;
- preventing spam, fraud, double-booking and unauthorised access;
- handling verified access, correction and deletion requests;
- keeping necessary financial, security and compliance records.
The lawful ground depends on the activity and may include consent, steps requested before entering an arrangement, performance of an agreement, legitimate operational and security interests, and legal duties. Withdrawing consent does not invalidate earlier lawful processing or processing supported by another lawful ground.
What is required
Required fields are identified on each form. A customer name, valid South African mobile number, service and appointment time are needed to create a live booking. Email is optional for ordinary bookings. If required information is not supplied, the booking or request cannot be completed.
Who receives information
The booked business and its authorised owner receive the information needed to provide and manage the appointment. Database policies isolate one business from another. A restricted Schedinary administrator may access information only for pilot support, security, billing administration or a verified privacy request.
Technology operators may process limited information for database hosting and authentication, website hosting, spam protection, error monitoring, business subscription payments and optional WhatsApp delivery. The current pilot uses Supabase, the Schedinary hosting platform, Cloudflare Turnstile and Sentry. Paystack processes the owner email and payment information needed for a business subscription checkout. Schedinary records only the verified payment result and does not receive full card details. Automated Meta/WhatsApp delivery remains feature-flagged.
International processing
The primary Supabase pilot database is configured in Ireland. Hosting, security and monitoring providers may process limited information in other countries. Schedinary records the relevant provider terms, processing locations and contractual safeguards in its operator register and applies the cross-border requirements of POPIA before activating a business.
Controlled-pilot retention
- rejected or withdrawn business applications: up to 90 days;
- active business records: for the pilot relationship and 90 days afterwards;
- customer and booking details: up to 12 months after the last appointment, unless an earlier verified deletion applies or longer retention is lawfully required;
- notification message content: up to 30 days; delivery status: up to 12 months;
- privacy-request and minimum audit records: up to three years;
- backups: removed through the applicable provider's normal secure backup cycle.
When authorised retention ends, information is deleted, destroyed or irreversibly de-identified. The business-specific agreement may adopt a shorter period where practical.
Security and incidents
Safeguards include tenant isolation, server-side booking transactions, restricted platform administration, hashed and revocable booking-management tokens, anti-bot checks, rate limits, audit records and monitoring configured to exclude customer form contents. Safeguards are tested and updated as risks change.
If there are reasonable grounds to believe personal information was accessed or acquired by an unauthorised person, Schedinary will investigate, preserve necessary evidence and follow the applicable POPIA notification process with the Information Regulator, affected business and affected people as soon as reasonably possible.
Your choices and rights
After suitable identity verification, you may:
- ask whether Schedinary holds personal information about you;
- request access to that information;
- request correction, deletion or destruction where applicable;
- object to certain processing or withdraw consent;
- complain to the Information Regulator.
Children
Schedinary is not designed for children to create accounts or manage bookings independently. A parent or guardian must make or authorise a booking for a person under 18. The pilot does not use solely automated decisions with legal or similarly significant effects.
Contact and complaints
Schedinary Information Officer: Katleho Motseki, katlehomotseki37@gmail.com. Formal business and service-address details are provided in each signed pilot agreement and may be requested through this address.
The Information Regulator (South Africa) can be contacted at enquiries@inforegulator.org.za, 010 023 5200 or 0800 017 160.