Compliance
POPIA
We process employee data as your Operator under a signed Data Processing Agreement, with a registered Information Officer, published PAIA Manual, breach response within 72 hours, and documented retention and deletion rules. Full detail: our POPIA Compliance Statement below.
SARS payroll compliance
The payroll engine implements the current tax year's PAYE tables, rebates, medical scheme fees tax credits, UIF ceiling, and SDL rules, verified against SARS publications, covered by 200+ automated tests, and updated every March. How we verify: our payroll calculations and auditing documentation (available on request).
BCEA
Default leave policies meet BCEA minimums (annual, sick, family responsibility, maternity, parental), payslips carry the section 33 particulars, and records are retained beyond the 3-year requirement.
What stays your responsibility
NovaHR is software, not a tax practitioner: filing EMP201/EMP501, paying SARS, and UI-19 declarations remain yours, with our reports giving you the exact figures. Plain-language detail: Compliance Disclaimer and Customer Responsibilities.
NovaHR POPIA Compliance Statement
Version: 1.0 (Draft, pending legal review)
Effective date: [to be confirmed]
Review cycle: Annual, and on any material change to processing
1. Our Commitment
NovaHR processes some of the most sensitive information a business holds: employee identity numbers, salaries, bank details, and leave records. We treat compliance with the Protection of Personal Information Act 4 of 2013 ("POPIA") as a core product requirement, not an afterthought.
2. How the Eight Conditions Are Met
| POPIA condition | How NovaHR complies |
|---|---|
| 1. Accountability (s 8) | A designated Information Officer is appointed and registered with the Information Regulator. A documented compliance programme (policies, ROPA, training) is maintained and reviewed annually. |
| 2. Processing limitation (ss 9-12) | We process personal information only as needed to provide the Service, on the lawful bases identified in our Privacy Policy, and under customer instruction for tenant data (Data Processing Agreement). |
| 3. Purpose specification (ss 13-14) | Purposes are defined in the Privacy Policy and DPA. Retention is limited per our Data Retention Policy, honouring statutory minimums (SARS 5 years for payroll records, BCEA 3 years for certain employment records). |
| 4. Further processing limitation (s 15) | Customer payroll data is never used for marketing, profiling, or sale. Aggregated, de-identified statistics only. |
| 5. Information quality (s 16) | Customers control and can correct their data directly in the app at any time. Validation rules reduce capture errors (ID number checksums, banking field validation). |
| 6. Openness (ss 17-18) | Privacy Policy and PAIA Manual are publicly available. Data subjects are informed of processing via their employer and our published notices. |
| 7. Security safeguards (ss 19-22) | Encryption in transit and at rest, database-level tenant isolation, role-based access, audit logs, daily backups, breach response plan with 72-hour notification, written contracts with all sub-operators. |
| 8. Data subject participation (ss 23-25) | Access, correction, and deletion request procedures with published forms; employees are routed via their employer (the Responsible Party), whom we assist. |
3. Roles
- For customer tenant data (employee records, payroll): the customer is the Responsible Party; NovaHR is the Operator under a written Data Processing Agreement (POPIA ss 20-21).
- For our own account, billing, and marketing contacts: NovaHR is the Responsible Party.
4. Sub-Operators
We use a small set of vetted infrastructure providers (Supabase, Vercel, Resend), each SOC 2 Type II certified and bound by contract. Cross-border transfers comply with POPIA section 72. The current list, regions, and roles are published in our Data Processing Agreement.
5. Breach Response
We maintain a tested Data Breach Response Policy: containment, assessment, and notification of the Information Regulator and affected Responsible Parties as soon as reasonably possible, and in any event within 72 hours of confirming a compromise (POPIA s 22).
6. Data Subject Requests
Requests may be submitted using the forms referenced in our PAIA Manual to sales@novabos.co.za. Employees of NovaHR customers should contact their employer first; we assist employers in fulfilling requests.
7. Governance
- Information Officer: [to be confirmed], registered with the Information Regulator on [to be confirmed].
- Policy suite: Privacy Policy, Data Processing Agreement, Data Retention Policy, Data Deletion Policy, Data Breach Response Policy, Access Control Policy, Encryption Policy, Password Policy, Backup Policy, Audit Log Policy.
- Training: All personnel with data access complete POPIA awareness training on joining and annually.
8. Contact
Information Officer, NOVA BUSINESS OS (PTY) LTD, sales@novabos.co.za.
Complaints may also be lodged with the Information Regulator: enquiries@inforegulator.org.za, inforegulator.org.za.