Privacy and POPIA Policy
Last updated: 2 September 2026
1. Introduction
Veriserv (Pty) Ltd respects the privacy of clients, prospective clients, website visitors, business contacts, suppliers, service providers, employees, representatives, drivers and other persons whose personal information it processes.
This Privacy and POPIA Policy explains how Veriserv collects, uses, stores, shares and protects personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA), the Promotion of Access to Information Act 2 of 2000 (PAIA), the Electronic Communications and Transactions Act 25 of 2002 (ECTA), the Financial Advisory and Intermediary Services Act 37 of 2002 (FAIS), the Financial Intelligence Centre Act 38 of 2001 (FICA) and other applicable South African laws.
This Policy applies to personal information processed through:
- the Veriserv website at https://veriserv.co.za;
- website enquiry forms, email, telephone and other business communications;
- finance, insurance, risk management and related application processes;
- fleet, vehicle tracking, video telematics, dashcam and transport management solutions where Veriserv processes personal information;
- client or management portals made available by or through Veriserv, where applicable;
- supplier, partner and business administration processes; and
- other lawful interactions with Veriserv.
Separate agreements, product terms, platform notices or client-specific privacy notices may apply to particular services. If there is a conflict, the more specific document will apply to that service to the extent permitted by law.
2. Responsible party
The responsible party is:
Veriserv (Pty) Ltd
Company registration number: 2021/803977/07
Authorised Financial Services Provider: FSP 52630
Physical address: Vdara Office Park, 41 Rivonia Road, Floor 1, Suite 1, Sandton, Gauteng, 2196, South Africa
Website: https://veriserv.co.za
Information Officer: Morné van den Berg, Director
Privacy and POPIA email: admin@veriserv.co.za
Telephone: 071 682 3950
The Information Officer is responsible for encouraging and monitoring compliance with POPIA and PAIA and for handling access, correction, objection and deletion requests.
3. Meaning of personal information
Personal information is information relating to an identifiable living person and, where applicable, an identifiable existing juristic person. It includes information that identifies a person directly, information that can identify a person when combined with other information, and any opinion or correspondence relating to that person.
Processing includes collecting, receiving, recording, organising, storing, updating, using, sharing, restricting, deleting or destroying personal information.
4. Personal information Veriserv may process
The information processed depends on the relationship, enquiry or service involved. It may include:
4.1 Identity and contact information
- name and surname;
- identity or passport details where lawfully required;
- job title, employer or represented business;
- business and residential addresses;
- telephone number and email address;
- signatures and authorised representative information; and
- communication preferences.
4.2 Business and enquiry information
- company name, registration details and business contact information;
- province and operating locations;
- area of interest or service requirement;
- fleet size, vehicle types, equipment and operating environment;
- information included in messages, enquiries, proposals and supporting documents; and
- records of meetings, calls and correspondence.
4.3 Finance, insurance and compliance information
Where relevant to a requested or contracted service, Veriserv may process:
- financial statements, banking information and affordability information;
- asset, vehicle, equipment and transaction information;
- insurance requirements, policy information, risk information and claims-related records;
- debtor, customer, credit exposure and trade information;
- credit, fraud prevention and verification information obtained from authorised sources;
- beneficial ownership, director, shareholder and authorised representative information;
- tax, FICA, know-your-customer and other regulatory documentation; and
- information required by funders, banks, insurers, underwriters, credit providers, regulators or other authorised product and service providers.
Veriserv will not request payment card information through the general website enquiry form.
4.4 Fleet, telematics and vehicle information
Where a fleet or telematics service is implemented, information may include:
- vehicle registration, make, model and device identifiers;
- vehicle location, routes, trip history, speed, movement and geo-fence events;
- road-facing and cab-facing video, images and, where lawfully enabled, audio;
- driving events, alerts, risk indicators and driver behaviour information;
- driver identification or verification information, including assigned driver or NFC-related identifiers;
- device, platform, sensor, diagnostic and usage information;
- incident, claims, recovery, maintenance and service information; and
- portal users, access logs and support records.
Fleet and video information can relate to employees, contractors, passengers, road users and other identifiable persons. The client deploying the solution is responsible for ensuring that drivers and other affected persons receive the required workplace, monitoring and privacy notices and that the processing has a lawful basis. Veriserv's role as responsible party, joint responsible party or operator will depend on the service arrangement and must be recorded in the applicable agreement.
4.5 Website and technical information
- internet protocol address;
- browser, device, operating system and approximate location information;
- pages viewed, links selected, referring page and visit dates or times;
- website security, server and error logs;
- cookie identifiers and consent preferences; and
- information submitted through the website.
Further information appears in the separate Cookie Policy.
4.6 Special personal information and children's information
Veriserv does not intentionally request special personal information or children's personal information through its general website enquiry form. Such information should not be submitted unless it is necessary for a specific lawful purpose and Veriserv has authorised or requested it.
If special personal information or children's information is required for a particular service, it will be processed only where POPIA or another law permits it and appropriate safeguards are in place.
5. Sources of personal information
Veriserv may collect personal information:
- directly from the person concerned;
- from an employer, company, client, authorised representative or other person authorised to provide it;
- through website forms, email, telephone, meetings and business correspondence;
- from finance, insurance, fleet, tracking or telematics applications and platforms;
- from banks, funders, insurers, underwriters, credit providers, credit bureaus, verification providers and other authorised institutions;
- from suppliers, installers, service providers and business partners involved in delivering a requested service;
- from public records, company registers, professional directories, websites and information deliberately made public;
- from regulators, law enforcement or other public bodies where lawful; and
- automatically through devices, systems, logs and cookies when a website, device or platform is used.
When personal information is provided about another person, the provider must be authorised to do so and must ensure that the person has received any notice required by law.
6. Whether providing information is voluntary or mandatory
Providing information through the general enquiry form is voluntary. However, Veriserv may be unable to respond properly or assess the requirement if necessary contact or business information is not provided.
Information required for finance, insurance, FICA, fraud prevention, credit assessment, contract administration, claims, fleet services or regulatory reporting may be mandatory under law, an applicable product requirement or a service agreement. Failure to provide required information may prevent Veriserv or a third-party provider from proceeding with an application, quotation, product or service.
7. Purposes of processing
Veriserv may process personal information to:
- receive, route and respond to enquiries;
- verify identity, authority and business information;
- understand a client's finance, insurance, risk, fleet or operational requirement;
- prepare, submit, motivate, manage and follow up on applications or proposals;
- obtain or facilitate quotations, assessments, underwriting, credit decisions and product terms;
- perform FICA, fraud prevention, sanctions, customer due diligence and other compliance checks;
- arrange and administer authorised financial services and related support;
- supply, install, configure, support and maintain fleet, tracking, video telematics and related solutions;
- provide platform access, event information, storage, reporting and technical support where included in the selected service;
- manage contracts, client relationships, billing, complaints and service records;
- communicate operational, product, service, security and regulatory information;
- maintain website functionality, security, analytics and performance;
- conduct direct marketing where permitted by law;
- protect Veriserv, its clients, service providers, systems, assets and legal rights;
- detect, prevent and investigate misuse, fraud, security incidents or unlawful activity;
- establish, exercise or defend legal claims;
- meet legal, regulatory, accounting, audit and reporting duties; and
- compile aggregated or de-identified statistics that do not identify a person.
Veriserv will not process personal information in a manner incompatible with the purpose for which it was collected unless the further processing is permitted by law.
8. Grounds that justify processing
Depending on the circumstances, Veriserv processes personal information because:
- the data subject has consented;
- processing is necessary to take requested steps before concluding a contract or to perform a contract;
- processing is required to comply with a legal or regulatory obligation;
- processing protects a legitimate interest of the data subject;
- processing is necessary for Veriserv's legitimate interests or those of an authorised third party, provided those interests do not unjustifiably prejudice the data subject; or
- another ground permitted by POPIA or applicable law applies.
Consent is not treated as the only basis for all processing. Where processing depends on consent, that consent may be withdrawn, but withdrawal will not affect processing already carried out lawfully or processing justified on another legal ground.
9. Sharing personal information
Veriserv may share personal information only where necessary and lawful with:
- authorised Veriserv directors, employees, representatives and contractors;
- banks, funders, rental providers, credit providers and finance institutions;
- insurers, underwriting managers, brokers, reinsurers, loss adjusters and claims service providers;
- credit bureaus, identity, company, fraud, sanctions and verification providers;
- fleet, tracking, recovery, telematics, dashcam, cloud platform, storage, installation and technical support providers;
- professional advisers, auditors, accountants, attorneys and compliance service providers;
- website hosting, email, communications, analytics, cybersecurity, backup and IT providers;
- debt collection, dispute resolution and legal process providers;
- regulators, ombuds, courts, law enforcement, government bodies and other authorities where required or permitted by law;
- a purchaser, successor or adviser involved in a lawful business restructuring or transaction, subject to suitable safeguards; and
- other persons authorised by the data subject or required to deliver the requested service.
Third parties that independently decide why and how to process information are responsible parties for their own processing and may provide separate privacy notices. Operators processing information for Veriserv must be subject to appropriate confidentiality and security obligations.
Veriserv does not sell personal information.
10. Cross-border processing
Some hosting, email, cloud, analytics, fleet management, video storage or support providers may process or store information outside South Africa. Veriserv will transfer personal information outside South Africa only where permitted by section 72 of POPIA, including where the recipient is subject to adequate legal or contractual protection, the data subject consents where appropriate, or the transfer is necessary for a contract or requested pre-contractual steps.
The countries, providers and safeguards involved may vary according to the selected platform or service. Further details relevant to a specific service may be provided in the applicable proposal, agreement or platform notice.
11. Cookies and similar technologies
The website may use essential cookies and, subject to the website configuration and consent choices, functional, analytics or embedded-content technologies. These technologies may process device and usage information and may involve third-party providers.
Non-essential cookies should not be activated before the user has made the required choice where consent is relied on. Users can manage available choices through the website cookie control and browser settings. More information appears in the Cookie Policy.
12. Direct marketing
Veriserv may send electronic direct marketing only where POPIA, ECTA and other applicable law permit it. This may be based on valid consent or, where applicable, an existing client relationship for Veriserv's own similar products or services.
Marketing communications will identify the sender and provide a simple method to object or unsubscribe. A person may object to direct marketing at any time without charge. Veriserv may retain a minimal suppression record to ensure that the opt-out is respected.
Submitting a general enquiry does not by itself amount to consent to receive unrelated marketing.
13. Automated decisions and third-party assessments
Veriserv does not intend to make decisions through the public website that have legal or similarly significant effects based solely on automated processing.
Banks, funders, insurers, credit bureaus, telematics platforms or other service providers may use scoring, risk models, automated alerts or automated assessment tools under their own processes. Their terms and privacy notices will apply to that processing. Where Veriserv itself makes a decision subject to section 71 of POPIA, it will provide the protections required by law.
14. Security safeguards
Veriserv will use appropriate and reasonable technical and organisational measures to protect personal information against loss, damage, unauthorised destruction, unlawful access and unlawful processing. Measures may include, where appropriate:
- access controls and user authentication;
- role-based permissions and confidentiality duties;
- secure transmission and storage controls;
- system monitoring, logging, backups and malware protection;
- supplier and operator security requirements;
- staff awareness and incident procedures;
- physical security; and
- periodic review of foreseeable risks and safeguards.
No internet transmission or storage system is completely secure. Users must protect passwords and access credentials and notify Veriserv promptly of suspected unauthorised access.
If Veriserv has reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, it will notify the Information Regulator and affected data subjects as required by POPIA.
15. Retention and destruction
Veriserv retains personal information only for as long as necessary for the purpose for which it was collected, an authorised compatible purpose, a contract, a legitimate business requirement, a legal or regulatory retention period, or the establishment, exercise or defence of legal claims.
Retention periods vary according to the record. Relevant considerations include:
- FAIS, FICA, insurance, financial, tax, corporate and accounting requirements;
- application, quotation and contractual timeframes;
- product, platform, footage and cloud-storage arrangements;
- complaint, audit and legal prescription periods;
- security and fraud prevention requirements; and
- instructions from the client where Veriserv acts as an operator.
Video and telematics retention depends on the selected device, platform, service and client configuration. Product information indicating that footage may be stored in the cloud for up to six months does not mean that every recording will be retained for six months. The applicable service configuration and agreement determine actual retention.
When Veriserv is no longer authorised or required to retain personal information, it will securely delete, destroy or de-identify it, subject to lawful exceptions.
16. Data subject rights
Subject to POPIA, PAIA and applicable limitations, a data subject may:
- ask whether Veriserv holds personal information about them;
- request access to that personal information;
- request correction or deletion of inaccurate, irrelevant, excessive, out-of-date, incomplete, misleading or unlawfully obtained information;
- request destruction or deletion of information Veriserv is no longer authorised to retain;
- object, on reasonable grounds, to processing based on legitimate interests;
- object to direct marketing at any time;
- withdraw consent where processing relies on consent;
- request restriction of processing where provided by law;
- submit a complaint to Veriserv; and
- lodge a complaint with the Information Regulator.
Veriserv may need to verify the requester's identity and authority before acting on a request. Access may be subject to the procedure, fees and lawful grounds for refusal in PAIA. Veriserv's PAIA Manual explains the access process.
Requests should be sent to:
Information Officer
Email: admin@veriserv.co.za
Physical address: Vdara Office Park, 41 Rivonia Road, Floor 1, Suite 1, Sandton, Gauteng, 2196, South Africa
17. Complaints to the Information Regulator
A person who believes that Veriserv has interfered with the protection of their personal information may first contact the Veriserv Information Officer so that the matter can be investigated.
A complaint may also be submitted to the Information Regulator (South Africa):
Information Regulator (South Africa)
Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Telephone: 010 023 5200
Toll-free: 0800 017 160
General enquiries: enquiries@inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
Website: https://inforegulator.org.za
18. Third-party websites and services
The website may link to or display third-party websites, maps, platforms or services. Veriserv does not control the privacy practices of independent third parties. Users should read the privacy notices and terms that apply before providing information to those services.
19. Changes to this Policy
Veriserv may update this Policy to reflect changes in law, services, systems or processing practices. The latest version will be published on the website with its revision date. Material changes may also be communicated through an appropriate channel where required.

