Legal
Privacy Policy
This policy explains how Deviare (Pty) Ltd collects, uses, shares, protects and retains personal information when people visit our website, contact us, participate in our programmes, use our digital platforms or obtain a Deviare solution through Microsoft Marketplace or another channel. It is written to support compliance with the Protection of Personal Information Act 4 of 2013, commonly known as POPIA, and applies to our website and to Deviare services that refer or link to this policy.
- Effective date
- 22 September 2026
- Last updated
- 22 September 2026
- Policy owner
- Deviare Information Officer
1. Who we are
Deviare (Pty) Ltd is a South African digital capability, talent and technology company. In this policy, "Deviare", "we", "us" and "our" refer to Deviare (Pty) Ltd, registration number 2017/263701/07, with its principal place of business at 33 Ballyclare Drive, Bryanston, Johannesburg, 2196, South Africa.
Depending on the service and the contractual arrangement, Deviare may process personal information as a responsible party, which means we determine why and how it is processed, or as an operator acting on the documented instructions of a client that is the responsible party.
2. Scope of this policy
This policy applies when you:
- visit deviare.africa or another Deviare website or landing page that links to this policy;
- create an account or use a Deviare digital service, including our Learning Hub, Talent Platform, Recruitment Platform, assessment services, Vortex-enabled matching capabilities, ScholarGo, eSubmission or another listed solution;
- apply for a programme, opportunity, placement, contractor role or employment;
- participate in training, assessments, labs, coaching, workplace experience, placement or support;
- buy, subscribe to, activate or use a Deviare solution through Microsoft Marketplace or another channel;
- interact with our marketing, events, surveys, support desk, sales team or social media; or
- act for a customer, partner, supplier, funder, institution or other organisation that deals with us.
A specific contract, product notice, learner notice, employee notice or client instruction may provide additional detail. If there is a conflict, the applicable law and the specific contractual or product terms will govern for that processing activity.
3. Personal information we collect
3.1 Information you provide
- Identity and profile information, such as your name, username, date of birth, identity or passport details, demographic information and profile photograph.
- Contact information, such as your email address, telephone number, physical address and communication preferences.
- Education, employment and talent information, such as qualifications, CV, employment history, skills, certifications, availability, remuneration expectations, references and work eligibility.
- Programme and learning information, such as enrolment records, attendance, participation, submissions, assessment results, progress, completion, feedback, placement and support records.
- Account and transaction information, such as organisation, role, subscription, order, licence, billing reference and payment status. Payment card data may be processed directly by an authorised payment provider and not stored by Deviare.
- Communications and support information, including enquiries, correspondence, call or meeting notes, service tickets and feedback.
- Content you submit through a service, including documents, forms, files, images and data supplied for processing by the solution.
3.2 Information collected automatically
- Device and network information, such as IP address, browser type, operating system, device identifiers and general location derived from an IP address.
- Usage and diagnostic information, such as pages viewed, features used, clicks, session times, referral source, error logs, performance records and audit trails.
- Cookie and similar technology information, subject to your choices and applicable law.
3.3 Information from other sources
- Customers, employers, education institutions, programme funders, delivery partners, recruitment partners and authorised representatives.
- Microsoft and other marketplaces or identity providers, where you acquire or access a Deviare service through them.
- Reference providers, qualification bodies, background-screening providers and public or professional sources, where lawful and relevant.
- Public registers, websites and professional platforms where the information is lawfully available.
4. Special personal information and children
We process special personal information, criminal-behaviour information or personal information of children only when it is necessary for a defined purpose and a lawful basis or authorisation exists. This may arise in youth programmes, accessibility support, employment equity reporting, programme eligibility, safeguarding, background screening or services delivered for education and government clients.
Where a service is intended for a child, we will provide an appropriate notice and obtain consent from a competent person when required, unless another lawful authorisation applies. We do not knowingly use children's information for behavioural advertising.
5. How and why we use personal information
- Provide, activate, administer and support our websites, platforms, programmes, products and professional services.
- Register users, authenticate access, manage accounts, subscriptions, licences and marketplace entitlements.
- Recruit, assess, match, train, support and place learners, candidates, employees and independent contractors.
- Deliver assessments and capability intelligence, produce reports and recommend learning, talent or deployment pathways.
- Operate customer support, communicate service information, resolve incidents and maintain service quality.
- Manage sales, proposals, contracting, invoicing, supplier and partner relationships.
- Protect users, systems and data, prevent fraud and misuse, monitor security, keep audit records and enforce our terms.
- Measure website and service performance, conduct research and analytics, and improve accessibility, content and user experience.
- Meet legal, regulatory, accreditation, funding, reporting, tax, audit and contractual obligations.
- Send marketing where permitted, manage preferences and maintain suppression records for people who opt out.
- Establish, exercise or defend legal claims and protect our legitimate interests and those of our stakeholders.
6. Our lawful grounds for processing
We process personal information only when permitted by POPIA and other applicable law. Depending on the context, we rely on one or more of the following grounds:
- you consented to the processing;
- processing is necessary to conclude or perform a contract with you;
- processing complies with an obligation imposed by law;
- processing protects your legitimate interest;
- processing is necessary for the proper performance of a public-law duty by a public body; or
- processing is necessary to pursue our legitimate interests or those of a third party, provided those interests do not unjustifiably override your rights.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that was lawful before withdrawal and may affect our ability to provide an optional feature or communication.
7. When providing information is required
Some information is required by law, contract or the functional needs of a service. We will indicate required fields where practical. If you do not provide required information, we may be unable to create an account, assess eligibility, deliver the service, process a transaction, issue a credential, make a placement or meet a legal obligation.
8. Automated processing, matching and profiling
Some Deviare services use rules, analytics or artificial intelligence to support skills assessment, candidate matching, learning recommendations, document processing, fraud detection or service prioritisation. These tools may generate scores, rankings, recommendations or extracted data.
We do not intend to make a decision that produces legal effects or similarly significant consequences for an individual solely through automated processing unless the decision is permitted by law and appropriate safeguards apply. Where applicable, you may request meaningful information about the logic involved, ask for human review, provide additional information and challenge an outcome.
AI-assisted outputs can be incomplete or incorrect. Deviare staff, customers or authorised decision-makers remain responsible for evaluating material decisions according to the applicable service and contract.
10. Microsoft Marketplace and connected services
If you find, acquire or manage a Deviare solution through Microsoft Marketplace, Microsoft processes information under its own privacy terms and may provide Deviare with customer, administrator, subscription, transaction and entitlement information required to activate and manage the offer. Deviare processes that information under this policy and the applicable order, plan and service terms.
A Deviare marketplace solution may use Microsoft Azure, Microsoft Entra ID or other Microsoft services for hosting, identity, security, monitoring, storage, integration or billing. The relevant offer documentation will describe any material product-specific processing that is not reasonably covered by this policy.
11. International transfers
Our service providers, clients, partners or technical infrastructure may be located outside South Africa. When personal information is transferred to another country, we take reasonable steps to ensure that the recipient is subject to a law, binding corporate rules, contract or other arrangement that provides an adequate level of protection, or that another ground permitted by section 72 of POPIA applies.
You may contact us for more information about safeguards relevant to a material cross-border transfer, subject to confidentiality and security restrictions.
12. Security
We use reasonable and appropriate technical and organisational safeguards designed to protect the confidentiality, integrity and availability of personal information. Measures may include access controls, least-privilege permissions, authentication, encryption where appropriate, logging, backups, vulnerability management, staff awareness, supplier controls, secure development practices and incident-response procedures.
No system is completely secure. You are responsible for keeping account credentials confidential and for notifying us promptly if you suspect unauthorised access or misuse.
13. Security incidents
Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will investigate and notify the Information Regulator and affected data subjects as required by POPIA, subject to any lawful delay directed by the relevant authorities. Notices may describe the possible consequences, measures taken or planned, and steps the affected person can take.
14. Retention and deletion
We keep personal information only for as long as necessary for the purpose for which it was collected, to meet contractual, accreditation, audit, tax, funding, employment or legal requirements, to resolve disputes, or to establish or defend legal claims. Retention periods differ by record type and service.
When information is no longer required, we delete, destroy or de-identify it in a manner that prevents reconstruction in a reasonably foreseeable form. Backups may retain protected copies for a limited period until they are overwritten under our normal processes.
16. Direct marketing
We may send marketing to existing customers where permitted by law or to other people who have consented. Every electronic marketing communication will provide a reasonable way to opt out. You can also contact us to change your preferences. We may retain minimal suppression information so that we can respect an opt-out.
17. Your rights
Subject to POPIA and any lawful limitations, you may:
- ask whether we hold personal information about you and request access to it;
- ask us to correct, update, delete or destroy inaccurate, irrelevant, excessive, outdated, incomplete, misleading or unlawfully obtained information;
- object to processing on reasonable grounds where the law permits;
- withdraw consent where processing depends on consent;
- object to direct marketing and opt out of marketing communications;
- request information about relevant automated decision-making and ask for appropriate reconsideration where applicable; and
- submit a complaint to the Information Regulator.
We may need to verify your identity and authority before acting on a request. We will respond within the time required by law and may refuse or limit a request where POPIA, PAIA or another law permits or requires us to do so.
18. How to contact us
For privacy questions, requests or complaints, contact:
- Responsible party
- Deviare (Pty) Ltd
- Registration number
- 2017/263701/07
- Information Officer
- Lubabalo Dyantyi
- Privacy email
- connect@deviare.africa
- Postal or physical address
- 33 Ballyclare Drive, Bryanston, Johannesburg, 2196, South Africa
- Website
- https://deviare.africa
If we cannot resolve your concern, you may contact the Information Regulator South Africa using the current contact details published at inforegulator.org.za.
19. Third-party websites and services
Our websites and services may link to or integrate with third-party websites, identity providers, marketplaces or services. Their privacy practices are governed by their own notices. We encourage you to review them before providing information.
20. Changes to this policy
We may update this policy to reflect changes in law, our services, technology, suppliers or processing practices. We will publish the revised version at the same stable web address, update the "Last updated" date and provide additional notice where a change materially affects your rights or our use of personal information.
Questions about this policy? Contact us or email connect@deviare.africa.
