POPIA Notice
Last updated: 13 July 2026
Ambassadex Workforce processes personal information in line with the Protection of Personal Information Act, 2013 (POPIA). POPIA requires responsible parties to process personal information lawfully, for defined purposes, with appropriate openness, security safeguards and data-subject participation.
1. Responsible Party
Ambassadex (Pty) Ltd operates the Ambassadex Workforce platform. For requests about personal information, contact info@ambassadex.co.za.
2. Categories of Personal Information
The Platform may process names, contact details, login/account information, identity numbers or passport details, professional registration and qualification information, uploaded verification documents, facility licensing documents, employment/staff records, rosters, shift and attendance records, clock-in and clock-out events, limited location information for attendance verification, leave records, payroll calculation inputs, messages, support requests, payment-reference details, audit logs and security logs.
3. Purposes
Information is processed to provide workforce coordination, verify regulated professionals and facilities, manage facility staff, administer shifts, rosters, leave, timesheets, HR documents and payroll-support calculations, run subscription and account administration, detect and investigate misuse, maintain audit trails, respond to support requests, and comply with legal or regulatory duties.
4. Recipients
Personal information is accessible only to the users and administrators who need it for their role. Facilities can access records for their own staff and operational workflows. Healthcare professionals can access their own profile and records. Ambassadex administrators can access records for verification, support, billing, security, audit and compliance. Service providers may process information under contract for hosting, authentication, email, notifications, storage, analytics with consent, error monitoring and payment administration.
5. Security Safeguards
Ambassadex applies role-based access, authentication controls, encrypted transport, restricted storage access, audit logging, administrative controls and operational monitoring. Users must also protect their own credentials and must not share unauthorised screenshots, documents or personal information.
6. Data-Subject Rights
Under POPIA, you may request confirmation that Ambassadex holds your personal information, access to that information, correction or deletion where legally permitted, objection to certain processing, and information about suspected unauthorised access where applicable. Some records may need to be retained for labour, payroll, accounting, audit, legal, dispute-resolution or security reasons.
Contact: info@ambassadex.co.za.