Currently processing reports

Privacy Policy

ReportIt™ Privacy Policy

Effective date: 10 August 2026 | Version: 1.0

1. Purpose

This Privacy Policy explains how ReportIt™ collects, uses, stores, shares and protects personal information when you use ReportIt.Africa, register, submit a report, use the Evidence Vault or contact ReportIt™.

2. Legal framework

ReportIt™ intends to process personal information in accordance with POPIA and other applicable South African law. Processing may also be affected by PAIA, contractual obligations, legal proceedings and regulatory requirements.

3. Information we may collect

  • Identity and contact information.
  • Account credentials and membership information.
  • Payment and subscription information handled through payment providers.
  • Reports, statements, correspondence and supporting documents.
  • Photographs, audio, video and other evidence.
  • Information about people or organisations identified in a report.
  • IP address, browser/device data, logs and security events.
  • Support and complaint communications.

4. Sensitive information

Reports may contain health, criminal, financial, children’s or other sensitive information. Users should submit only information reasonably necessary for the report. Additional access controls may apply.

5. Why we process information

  • Create and administer accounts and memberships.
  • Receive, record, organise and track reports.
  • Provide Evidence Vault and case-management functions.
  • Process payments and subscriptions.
  • Communicate with users and provide support.
  • Maintain security and prevent abuse.
  • Comply with legal, regulatory and contractual obligations.
  • Improve platform reliability and functionality.
  • Perform authorised AI-assisted processing described in the AI Notice.

6. Lawful processing

ReportIt™ will seek an appropriate lawful basis, including consent where required, contract, legal obligation, legitimate interests where permitted, or protection of rights or safety where applicable.

7. Sharing and disclosure

Information may be shared with authorised personnel and necessary service providers, payment processors, technology providers or professional providers where lawful and necessary. Disclosure may also occur where required or permitted by law, court order, regulatory process, or necessary to protect rights or safety.

8. Third-party processors

ReportIt™ may use providers for hosting, payments, email, analytics, security, communications, AI and infrastructure. Appropriate contractual and security controls should apply where providers process information on ReportIt’s behalf.

9. International transfers

Where providers process information outside South Africa, ReportIt™ will apply applicable POPIA requirements and appropriate safeguards.

10. Retention

Information will be retained as reasonably necessary to provide services, maintain evidence and audit records, resolve disputes, comply with law or protect ReportIt™ and users. Retention periods may differ by category and legal requirement.

11. Security

ReportIt™ will implement reasonable technical and organisational safeguards appropriate to processing risks. No internet-based service can guarantee absolute security.

12. User rights

Subject to applicable law and lawful limitations, individuals may have rights concerning access, correction, deletion, objection and complaints. Requests should be made through the published privacy contact.

13. Children

Users should not submit unnecessary information about a child. Where processing involves a child’s information, ReportIt™ will apply applicable legal requirements and appropriate safeguards.

14. Cookies and technical data

The website may use cookies and similar technologies for essential functionality, authentication, security, preferences, analytics and disclosed purposes.

15. Marketing

Marketing communications will be handled according to applicable consent, opt-out and direct-marketing requirements. Transactional messages necessary to administer an account may still be sent.

16. Data breaches

Where a security compromise involving personal information occurs, ReportIt™ will follow applicable incident-response and notification requirements, including POPIA requirements where applicable.

17. PAIA

Requests for access to information held by ReportIt™ will be handled under applicable law and, where applicable, PAIA. ReportIt™ will publish the required information-access procedures and PAIA Manual when applicable.

18. Changes

This Policy may be updated to reflect changes to the platform, law, processing practices or security arrangements. Material changes will be communicated through appropriate channels.

19. Contact

ReportIt™ | ReportIt.Africa | Privacy contact: info@reportit.africa | Information Officer: S J Esterhuyse [PAIA contact]

Scroll to Top