Version 2.0 — Effective date: 2026-07-01. Supersedes all previous versions.
The purpose of this Privacy Policy:
- Is to help you understand how we collect, use, store and share personal data about you;
- It describes our commitment to preserving the privacy and security of your personal data; and
- It forms part of our Standard Terms & Conditions of Service and applies to all users of our products and services, including visitors to our website.
All references herein to us, our or we are to SYBU DATA (Pty) Ltd.
PERSONAL DATA WE COLLECT AND HOW WE USE IT
The following information is collected, and is dependent on which of the following SYBU DATA products or services you use:
SYBU JS-Blocker and SYBU for Kodi Apps:
We do not collect or store personal information when you download and use either our SYBU JS-Blocker or SYBU for Kodi applications.
SYBU DATA Cloud Applications:
When you sign up to a SYBU DATA Cloud Application, i.e. SYBU CloudBroker, SYBU CloudScale, SYBU CloudSD, or SYBU Licensing, personal information is collected, in a variety of ways, which may vary according to your use of the service and your account settings. The categories of personal information collected may include:
- Contact and profile information
- Account and authentication information from third-party integrated services
- Location information
- Information about your browser or device
- Operational and workforce data captured by client systems — for example packer names or identifiers and packing performance data recorded by SYBU CloudScale — for which the client operating the system is the responsible party
- Non-personal information which may be linked to your personal information, such as order number and installation
PLEASE NOTE that, with the exception of the SYBU Licensing platform, the responsible party (controller) for the information housed and processed in the Cloud Applications we develop is the organisation operating the system and collecting the information — whether they obtained the system from us directly or through an authorised SYBU DATA partner. SYBU DATA acts as an operator (processor) on the responsible party’s behalf. We may, from time to time, based on the responsible party’s requests, access this information as part of our ongoing product support, and we will process it in accordance with our documented security practices, applicable data protection law, and any additional standards agreed with the responsible party in writing.
SYBU ScaleMaster runs on-premise on a computer at the client’s site and is entirely controlled by the client; the personal information it holds does not reach our servers except to the extent the client uses the hosted SYBU CloudScale service.
SYBU Contracted Clients
When you engage with us for consulting services, or purchasing bespoke software or hardware solutions for your business, we will collect the following personal information: company name and registration, company address, details of your directors and company owners, email addresses, and telephone numbers. This information is used:
- for the purpose of managing your affairs with us; and
- to contact, request and obtain any information at any time and from any credit provider (or potential credit provider) or registered credit bureau in order to assess the behaviour, profile, payment patterns, indebtedness, whereabouts, and creditworthiness of our clients.
SYBU DATA Website Visitors
We utilise Google Analytics to track user behaviour on our website. Google Analytics collects first-party cookies, data related to your device/browser, IP address and on-site activities to measure and report statistics about user interactions on our website.
Types of Data We Collect
We facilitate three kinds of user data to deliver our services: (i) contact and profile information; (ii) information from integrated sign-on services; and (iii) service/diagnostic data. All are treated securely with respect for privacy and data confidentiality, but there are important technical and usage differences.
(i) Contact and profile information
When you create an account for any of our SYBU DATA Cloud Applications you will provide personal information including your name and email address. After you register, you may also provide additional information in your profile, company name, location and other personal or demographic information. In addition, we may ask you for personal information at other times, such as when you contact our technical support team, send us an email, complete a user survey, or otherwise communicate with us.
(ii) Information from integrated sign-on services (Google OAuth user data)
If you decide to register through, or otherwise grant access to, a third-party social networking or integrated service (an “Integrated Service”), such as Facebook, Google or a similar single sign-on service, the following may apply: our applications will collect and store personal information — your email address, name, surname and profile picture — that is already associated with your Integrated Service account. You may also have the option of sharing additional information through an Integrated Service, as controlled through your settings on that Integrated Service.
(iii) Service and/or diagnostic data
All of our applications maintain user logs and diagnostic data. We do not collect, receive or process this information. We may access this information to perform maintenance and diagnostic work at our client’s request. Wherever possible, personal information contained in these logs has been masked. When we do access this data, the information is never or seldom downloaded or retrieved to our servers; however, on rare occasions where it is necessary to do so, we apply our strictest data protection policies and safeguards to maintain your data privacy. This data is permanently deleted from our systems once the problem has been resolved.
Where Do We Store Your Personal Information?
Our service is managed from South Africa, but the Cloud Applications and related personal information are hosted by the third-party service providers stipulated in the section “Third-Party Processors We Use” below.
To the extent that you have chosen to share information with us directly via email, service requests, user surveys, or any other means of communication, this information is stored securely at our offices.
How Do We Ensure the Security of Information?
We only utilise top-rated service providers to host and deploy our cloud-based applications (as listed below under “Third-Party Processors We Use”). We review their data privacy and security policies and compliance reports (where available) on an annual basis to ensure that they remain fit for purpose, and to ensure that the highest acceptable industry standards are utilised to protect your information.
All data is encrypted via SSL/TLS when transmitted from the third-party processors to your browser.
On-site information collected and directly controlled by us is stored on secured servers which are password protected; firewall protocols are maintained and antivirus software is installed on all computers.
We periodically review our security protocols to ensure that vulnerabilities are minimised and strengthened, and that reasonably foreseeable potential risks to personal data are appropriately managed.
Who Will We Share Your Information With?
We do not sell any of your personal data to any third parties. However, as part of the solutions we deliver, and only to the extent necessary, our applications may use certain third-party processors to process and store some or all of your personal information.
Third-Party Processors We Use
- Google Analytics — web analytics service for our website.
- Microsoft Azure — cloud services provider used to deploy and host our applications and store your data.
- SendGrid, Twilio — email messaging service, used for email notifications and password resets.
- SMSPortal — SMS messaging service based in South Africa, used to send OTPs for logins to our Cloud Applications.
Google Analytics, Microsoft Azure and SendGrid are located in the European Union and the United States of America. Where personal information is transferred outside South Africa or the EEA, we rely on transfers to jurisdictions with adequate protection or on appropriate safeguards, as required by section 72 of POPIA and, where applicable, the GDPR standard contractual clauses.
Authorities
We may disclose necessary information to authorities, such as regulatory bodies, if we are required by law or you agreed to it (for instance, for anti-money laundering or counter-terrorism). We will not hand your data over to law enforcement unless a court order says we have to. We will inform you when such requests are made, unless instructed otherwise by law enforcement or other regulatory bodies.
Divestments
We may transfer any personal information we hold about you to any entity involved in a re-organisation of SYBU DATA (where such re-organisation may be by way of a merger, sale, dissolution, disposal of all or part of our assets or similar event).
Promotion of Access to Information Act
Access to your personal information held by us may also be requested by third parties. The Promotion of Access to Information Act, 2000 (“PAIA”) regulates and sets out the procedure for such a request and under which circumstances such access may be refused.
Should you wish to exercise your right of access to information, please send us a formal request via email or by completing the contact form on our website.
We will attend to all requests for access to personal information within a reasonable time. You may be required to pay a prescribed fee to receive copies or descriptions of records, or information about third parties. Your request for access may be refused in certain circumstances and access may be limited by applicable legislation.
Your Rights Regarding the Information That We Process
We adhere to the Protection of Personal Information Act, 2013 (“POPIA”) as well as the data protection requirements under the General Data Protection Regulation (“GDPR”). These laws give people under their protection certain rights with respect to their personal information collected by us. Accordingly, we recognise and will comply with those rights, except as limited by applicable law. Your rights include:
- Right of Access. This includes your right to access the personal information we gather about you, and your right to obtain information about the sharing, storage, security and processing of that information.
- Right to Correction. This is your right to request correction of your personal information.
- Right to Erasure. This is your right to request, subject to certain limitations under applicable law, that your personal information be erased from our possession (also known as the “Right to be Forgotten”). However, if applicable law requires us to comply with your request to delete your information, fulfilment of your request may prevent you from using our services and may result in closing your account.
- Right to Object. This is your right to object, on reasonable grounds, to the processing of your personal information, including for direct marketing purposes.
- Right to Restrict Processing. This is your right to request restriction of how and why your personal information is used or processed.
- Right to Portability. This is your right to receive the personal information we have about you and the right to transmit it to another party.
- Right to Withdraw Consent. Where processing is based on your consent, you may withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal.
Many of these rights can be exercised by signing in and directly updating your account information. If you have questions about exercising these rights or need assistance, please contact us using the contact form on our website. Our designated Information Officer (as required under POPIA) can be reached through the same channel.
Deleted Data
When you cancel your account, account data is deleted from our servers within 30 days, subject to the data-retention period of your subscription plan, backup purge cycles, and any legal retention obligations. Anything you delete on your account while it is active will also be purged within 30 days. You are responsible for exporting production data you wish to keep before deletion takes effect.
Cookies
Cookies are small text files that are placed on your machine to help the site provide a better user experience. In general, cookies are used to retain user preferences, store information for things like shopping carts, and provide anonymised tracking data to third-party applications like Google Analytics. As a rule, cookies will make your browsing experience better. However, you may prefer to disable cookies on this site and on others. The most effective way to do this is to disable cookies in your browser. We suggest consulting the Help section of your browser or taking a look at the About Cookies website, which offers guidance for all modern browsers. For details of the cookies used on this site, see our Cookie Policy.
Compliance and Enforcement of This Privacy Policy
Our compliance with this Privacy Policy will be monitored on a regular basis. We reserve the right to modify this Privacy Policy with any updates to our business processes and security policies. The Privacy Policy posted via our website shall be deemed to be the Privacy Policy currently in effect. We therefore encourage you to check this page regularly for any updates.
Any queries regarding this Privacy Policy, the way in which your personal information is treated, or any aspects of our service may be made by using the contact form on our website.
Breach Notification
In the event of a breach, we recognise our responsibility to our customers and to the public to disclose the nature of the risk and provide a transparent account of the events without undue delay, including notification to the Information Regulator and affected data subjects where required by section 22 of POPIA.
Governing Law
This Privacy Policy and all disputes and claims arising from it shall be governed by and construed in accordance with the laws of the Republic of South Africa.
Supervisory Authority
If you have concerns or complaints about this policy or our practices that you do not feel you can resolve through contacting us, please refer to the South African Information Regulator Website.
Contacting SYBU DATA
Please contact SYBU DATA with any questions or comments by sending us an email or by completing the contact form on our website.