Email Desk+243 993 109 992

Privacy Policy & POPIA Notice

In Compliance with the Protection of Personal Information Act (POPIA No. 4 of 2013) & PAIA Section 51

Responsible Party: KPS Express (Pty) Ltd (Registration No: 2021/782109/07)
Regional Operational Scope: Democratic Republic of Congo Corridor (Lubumbashi & Kolwezi Hubs)
Effective Date: September 2026

1. Introduction & Commitment to Privacy

KPS Express (Pty) Ltd ("KPS Express", "we", "our", or "us") operates an enterprise cross-border procurement and logistics platform serving industrial, mining, construction, electrical, and commercial enterprises across the Republic of South Africa, the Republic of Zambia, and the Democratic Republic of Congo.

We are unconditionally dedicated to safeguarding the privacy and confidential business information of all clients, corporate procurement officers, vendor partners, and website visitors. This Privacy Policy details the statutory grounds, procedures, and security controls we maintain under the Protection of Personal Information Act No. 4 of 2013 ("POPIA"), the Promotion of Access to Information Act No. 2 of 2000 ("PAIA"), the Zambian Data Protection Act of 2021, and the Congolese digital legal framework (Law No. 23/010 of 13 March 2023).

2. Designation of Information Officer

In compliance with Chapter 5 of POPIA and Section 17 of PAIA, KPS Express has formally designated an Information Officer and regional Deputy Information Officers who are accountable for monitoring organizational adherence to statutory privacy requirements:

Information Officer — KPS Express (Pty) Ltd

Physical Address: Johannesburg Logistics Hub, Gauteng, Republic of South Africa

Official Statutory Inquiries: popia@kpsexpress.co.za / drc@kpsexpress.co.za

Direct Telephone: +27 66 202 3081

Regional Deputy Desks: Copperbelt Hub (Ndola, Zambia) & Katanga Hub (Lubumbashi, DRC)

3. Eight Conditions for Lawful Processing (POPIA Chapter 3)

KPS Express processes all personal and commercial data in strict adherence to the eight statutory conditions codified under South African law:

  1. Accountability: We ensure that all processing protocols comply with POPIA obligations from collection to disposal.
  2. Processing Limitation: Processing is lawful, minimal, and justified by contract performance, statutory obligation, or explicit consent.
  3. Purpose Specification: Information is gathered strictly for specific, defined procurement, customs clearance, and freight execution purposes.
  4. Further Processing Limitation: Collected data is never processed for ancillary purposes inconsistent with original procurement intents.
  5. Information Quality: We take reasonable, practical steps to maintain data accuracy, completeness, and timeliness.
  6. Openness: Transparent disclosure of processing activities through this notice and related procurement contracts.
  7. Security Safeguards: High-grade cryptographic, physical, and administrative measures against loss, unauthorized access, or destruction.
  8. Data Subject Participation: Transparent procedures enabling data subjects to inspect, update, or demand deletion of their records.

4. Categories of Data We Collect and Process

A. Commercial Procurement & Corporate Identity Data

To issue legally binding quotations, conduct credit evaluations, process Request for Quotation (RFQ) packages, and handle cross-border trade documentation, we collect:

  • Company registered legal name, trade name, and country registration number (e.g. CIPC in SA, PACRA in Zambia, RCCM in DRC).
  • Tax identification numbers, VAT certificates, and customs import/export license codes.
  • Designated procurement officer names, corporate email addresses, phone numbers, and physical delivery coordinates.
  • Technical engineering specifications, CAD drawings, bills of quantities, and product compliance requirements.

B. Account & Access Authentication Data

When using the Buyer Procurement Portal (/buyer) or Staff Operations Center (/kps):

  • Hashed authentication credentials managed securely via Directus backend infrastructure.
  • Session security tokens (kps_session) and role-based access entitlements.
  • Audit logging of transactional milestones, quote approvals, document releases, and internal communications.

C. Financial & Transactional Data

Invoices, proformas, commercial quotes, SWIFT/EFT transaction receipts, milestone release confirmations, and customs clearance charges. (Note: KPS Express does not store raw credit card numbers; card transactions, where activated, are routed through licensed PCI-DSS Level 1 compliant processors).

5. Transborder Information Flows (Section 72 POPIA)

As a cross-border operator in the Southern African Development Community (SADC) and African Continental Free Trade Area (AfCFTA), fulfillment of international freight and procurement agreements requires the transmission of commercial data across borders between South Africa, Zambia, the DRC, Senegal, Côte d'Ivoire, Seychelles, and Mauritius.

Under Section 72 of POPIA, KPS Express ensures that transborder disclosures only occur where:

  • The recipient jurisdiction maintains data protection legislation providing an adequate level of protection substantially similar to POPIA; or
  • The transfer is directly necessary for the conclusion or performance of a procurement contract concluded between the data subject and KPS Express; or
  • The recipient is bound by binding corporate agreements or standard contractual clauses guaranteeing rigorous data security and confidentiality.

Transmitted documentation includes road manifests, bills of lading, customs declarations for the South African Revenue Service (SARS), the Zambia Revenue Authority (ZRA), and the Direction Générale des Douanes et Accises (DGDA) in the DRC.

6. Your Statutory Rights Under POPIA

Every data subject whose personal information is processed by KPS Express possesses enforceable statutory rights:

Right of Access (Section 23)

You have the right to request confirmation of whether we hold personal information regarding you or your organization, and to receive a certified copy thereof.

Right to Correction & Deletion (Section 24)

You may formally request that we correct, destroy, or delete personal information that is inaccurate, irrelevant, excessive, outdated, or unlawfully obtained.

Right to Object (Section 11(3))

You may object on reasonable grounds to the processing of your personal information, unless legislation specifically mandates such retention (e.g. SARS tax law).

Right to Dispute Direct Marketing (Section 69)

We do not transmit unsolicited direct electronic marketing without prior opt-in consent. You can unsubscribe at any instant.

To exercise these statutory rights, please complete the official Form 1 (Objection) or Form 2 (Correction/Deletion) prescribed by the POPIA Regulations and submit it to our Information Officer at popia@kpsexpress.co.za.

7. Right to Complain to the Information Regulator

If you believe that your personal information has been processed in contravention of POPIA, or if you are dissatisfied with our response to a statutory request, you have the right to lodge a formal complaint with the South African Information Regulator:

The Information Regulator (South Africa)

Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Postal Address: P.O. Box 31533, Braamfontein, Johannesburg, 2017

Complaints Email (POPIA): POPIAComplaints@inforegulator.org.za

General Enquiries: enquiries@inforegulator.org.za

Official Portal: inforegulator.org.za

8. PAIA Section 51 Manual Notice

In terms of Section 51 of the Promotion of Access to Information Act No. 2 of 2000 (PAIA), private bodies are required to compile and maintain a manual outlining records held by the company and the formal protocol for requesting access.

The KPS Express PAIA Manual is available for inspection at our registered office in Johannesburg and upon written request to our Information Officer. Access requests must be submitted using the prescribed PAIA Form C and accompanied by the statutory request fees prescribed by the Department of Justice and Constitutional Development.

9. Data Security, Retention & Incident Protocols

We implement industry-standard technical and organizational safeguards to prevent accidental loss, damage, or unauthorized alteration of commercial records. All web traffic is encrypted via Transport Layer Security (TLS 1.3), database tokens are managed via server-side Directus BFF architecture, and multi-factor authentication is enforced across administrative systems.

Commercial and tax documentation is retained for a statutory minimum period of 5 (five) years to satisfy the South African Tax Administration Act and customs record-keeping obligations, after which records are irreversibly anonymized or destroyed. In the event of an identified security compromise involving personal data, KPS Express will notify both the Information Regulator and affected data subjects without undue delay in accordance with Section 22 of POPIA.

10. Contact Information

For all privacy inquiries, data subject access requests, or compliance communications:

KPS Express (Pty) Ltd — Legal & Compliance Directorate

Email: drc@kpsexpress.co.za

POPIA Desk: popia@kpsexpress.co.za

Head Office: Johannesburg, Gauteng, South Africa

Phone: +27 66 202 3081