SnagMate Privacy Notice
How SnagMate collects, uses, shares, retains and protects personal information.
This notice explains how Tech Local (Pty) Ltd (registration number 2025/315373/07), operating the SnagMate construction snagging service ("SnagMate", "we", "us" or "our"), processes personal information under the Protection of Personal Information Act, 2013 ("POPIA"). It applies when you visit the SnagMate website, use an account or workspace, upload site records, receive communications, contact support, or otherwise use SnagMate.
1. Responsible party, operator roles and contact
Tech Local is the responsible party for SnagMate's website, account administration, billing, service communications, security, support and its own business records. A customer organisation may be the responsible party for personal information in its project workspace where it decides why and how that information is used. In that situation, Tech Local acts as an operator for the customer under the customer agreement and applicable data-processing terms.
- Responsible party and service provider: Tech Local (Pty) Ltd
- Registration number: 2025/315373/07
- Registered address: 18 Rosyth Road, Nahoon, East London, Eastern Cape, 5241, South Africa
- Privacy contact: Tania
- Privacy and PAIA email: tania@elitefacilities.co.za
If your request concerns information controlled by your employer, client, contractor company or another SnagMate customer, we may refer the request to that organisation or help it respond.
2. Personal information we collect
Depending on your role and how your organisation uses SnagMate, we may process:
- Account and identity information: name, email address, company, role, profile, membership, invitation, authentication and account-status records.
- Organisation, contractor and project and site information: organisation and contractor-company details, project and client names, site addresses, buildings, floors, units, rooms, trades, team rosters and assignments.
- Inspection and workflow records: report details, snag descriptions, categories, status, responsibility, comments, dates, review decisions, sign-offs, reminder settings and activity history.
- Site media and files: photos, annotations, project drawings, voice notes, transcripts, completion proof, report branding and generated client-ready reports.
- Communications: invitations, reminders, notifications, feedback, support enquiries and related delivery records.
- Billing information: subscription, invoice, entitlement and limited payment-status information where paid service features are enabled. Payment providers process payment credentials; SnagMate does not need your online-banking password or card PIN.
- Technical and security information: IP address, browser or device details, access times, session, authentication, audit, error, security and abuse-prevention logs, and necessary browser or device storage.
Site photos, drawings, voice notes or descriptions can incidentally include information about workers, residents, visitors or other people. Users should capture only what is relevant to the inspection and avoid unnecessary identity, health or other sensitive details.
3. Why we process personal information
We process personal information for specific, lawful purposes, including to:
- create, secure and administer accounts, organisations, contractor companies and role-based access;
- create projects and reports, capture and route snags, collect evidence, manage review and sign-off, and generate reports;
- transcribe a user-requested voice note and create a short draft snag title or description for human review;
- send invitations, operational reminders, security messages and service communications;
- provide support, investigate feedback and improve service reliability;
- manage subscriptions, billing and contractual entitlements where applicable;
- prevent misuse, enforce permissions, investigate incidents and protect users and the service;
- meet legal, accounting, tax, PAIA, POPIA and other applicable obligations; and
- establish, exercise or defend legal rights.
Depending on the purpose, processing is justified by consent, concluding or performing an agreement, complying with law, protecting a legitimate interest, or another ground permitted by section 11 of POPIA. Consent is requested where it is the appropriate legal basis and may be withdrawn without affecting processing already carried out lawfully.
4. Required information, sources and customer content
Account details and role information are required to secure access and apply project boundaries. Project, location and workflow details are required when your organisation uses the corresponding feature. Camera, photo-library or microphone access is optional at device level, but a chosen photo or voice feature cannot operate without the relevant permission and content.
We collect information directly from users, from the organisation or contractor company that invites or administers them, from authorised workspace participants, from systems used to deliver the service, and automatically through necessary technical events. Users and customers are responsible for having the authority, notices and permissions needed to submit information about other people, record voice, photograph a site, upload drawings and share project records.
5. Account messages and direct marketing
Operational messages—such as verification, invitation, assignment, reminder, security, billing and workflow notices—are part of providing and protecting SnagMate. Preference controls may limit optional channels, but necessary account and security messages may still be sent.
Electronic direct marketing is sent only where POPIA and other applicable law permit it. Where consent is required, it will be requested separately and will not be preselected. Marketing messages will identify the sender and provide a free, reasonably accessible way to object or unsubscribe. Opting out of marketing does not stop necessary service messages.
6. When we share information
We do not sell or rent personal information. We disclose only what is reasonably necessary to:
- authorised users within the relevant organisation, contractor company, project, report or assignment, according to their role;
- the customer that controls a workspace and its authorised representatives;
- Supabase for authentication, database, Edge Functions and private file storage;
- Vercel for website and application hosting;
- Resend for transactional email where email delivery is enabled;
- Groq for voice-note transcription and limited text summarisation where the voice feature is enabled;
- Slack for routing product feedback where that feedback integration is configured;
- PayFast for payment processing only where paid online checkout is enabled;
- accounting or other messaging providers where a customer enables the corresponding feature;
- professional advisers, insurers, regulators, courts or law-enforcement bodies where disclosure is lawful and necessary; and
- a successor in a lawful reorganisation or business transfer, subject to appropriate safeguards.
Providers are limited to the information needed for their function. Operator and service-provider arrangements must include appropriate confidentiality, processing and security obligations.
7. Processing outside South Africa
Some providers may store or process information outside South Africa. Before a cross-border transfer, Tech Local or the relevant customer must use a basis permitted by section 72 of POPIA, such as adequate foreign protection, a binding agreement with substantially similar safeguards, consent, or a transfer necessary for a contract or the data subject's benefit. The applicable customer setup, provider region and transfer safeguard should be confirmed from the production configuration because they may change over time.
8. Cookies and browser or device storage
SnagMate currently uses necessary cookies or similar storage for authentication sessions, security, route continuity, app preferences and guided-onboarding state. The marketing site does not currently use advertising pixels or behavioural advertising cookies. If optional analytics, advertising or profiling technologies are introduced, this notice and any required choices will be updated before they are used.
9. How long we keep information
We keep information only for as long as the purpose, customer agreement, law, security need, dispute, audit requirement or legitimate operational need reasonably requires. Typical periods are:
| Record | Typical retention approach |
|---|---|
| Account, organisation and billing metadata | While the account or customer relationship is active and up to five years afterwards where needed for contract, tax, audit, fraud prevention or disputes. |
| Project, report, snag and evidence records | For the project or customer-agreed lifecycle and afterwards as configured or reasonably needed for handover, contractual records, disputes and legal obligations. |
| Voice notes, transcripts and generated draft fields | As part of the related project record until deleted under workspace controls, the customer agreement or the applicable retention schedule. |
| Invitations, notifications and reminder delivery records | For the active workflow and a limited period afterwards for delivery, security, audit and dispute handling. |
| Support and feedback communications | Typically up to two years after resolution, unless a longer period is justified. |
| Security, access and diagnostic logs | Typically 90 to 180 days, with longer retention only where reasonably needed for an incident, investigation or legal claim. |
| Marketing preferences | While marketing continues and afterwards as needed to honour and prove an objection or opt-out. |
Authorised users may delete eligible snags, reports or an entire project through guarded controls; deleting a project queues its linked private media for cleanup. Issued or completed evidence can be retained as an immutable project record until the applicable retention rule permits deletion. Backups may retain limited copies temporarily until overwritten in the ordinary backup cycle.
10. How we protect information and handle compromises
Safeguards include authenticated access, least-privilege roles, tenant and project boundaries, database row-level security, private storage buckets, signed upload and download controls, encrypted connections, restricted service credentials, audit records, input validation, idempotency controls and incident-response processes. No online service is entirely risk-free.
If there are reasonable grounds to believe personal information was accessed or acquired by an unauthorised person, Tech Local will notify the Information Regulator and identifiable affected data subjects as soon as reasonably possible, subject to any lawful delay. An operator must notify the responsible party immediately when it discovers a compromise.
11. Your POPIA rights
Subject to POPIA and other applicable laws, you may ask to:
- confirm whether personal information about you is held and request access to it;
- identify third parties or categories of third parties who had access where the law provides;
- correct or update inaccurate, irrelevant, excessive, outdated, incomplete or misleading information;
- delete or destroy information that is no longer authorised or required;
- object to certain processing, restrict use where appropriate, or withdraw consent;
- stop direct marketing; and
- request safeguards or a representation regarding a solely automated decision that has a legal or similarly significant effect.
Email tania@elitefacilities.co.za. Requests and objections are free to submit and may also be made through another reasonably accessible channel we provide. We may verify identity and authority. Where the 2025 POPIA Regulations apply, an outcome following a correction or deletion request will be communicated within 30 days. A request cannot override information that must lawfully be retained; if access or deletion is limited, we will explain why.
12. Children and special personal information
SnagMate is a business service intended for authorised site-team users who are at least 18 years old. It is not intended for children. Do not create an account for a child or deliberately submit children's or special personal information unless the responsible party has confirmed a lawful, necessary use and the required safeguards. Site media should avoid identifiable people whenever that information is not needed for the snag record.
13. Questions and complaints
Contact Tania at tania@elitefacilities.co.za first so that Tech Local can investigate and respond. You may also complain to the Information Regulator (South Africa):
- POPIA complaints: POPIAComplaints@inforegulator.org.za
- Website: inforegulator.org.za
- Telephone: 010 023 5200
- Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
14. Changes to this notice
We may update this notice when SnagMate's features, providers, customer arrangements or legal duties change. The effective date and version identify the published notice. If a change materially affects existing information, we will give appropriate notice and request consent where required.
