Data Retention and Data Subject Access Requests (DSAR)

Last updated: 2026-07-15

DRAFT (revamp 2026-07) — for SA attorney review; not legal advice; not for publication. All statutory references in this draft are indicative and must be verified by counsel against the current text of each Act before any reliance or publication.

This policy sets out how long eRunna (Pty) Ltd (registration number [TBD: company registration number]) retains personal information, the legal bases for each retention period, and how data subjects may exercise their access, correction, and deletion rights under the Protection of Personal Information Act 4 of 2013 (POPIA). Where eRunna is or may become an accountable institution under the Financial Intelligence Centre Act 38 of 2001 (FICA), the applicable customer due-diligence (CDD) and transaction-record obligations are set out separately below. [ATTORNEY-REQUIRED: confirm whether eRunna currently meets the FICA definition of an "accountable institution" under Schedule 1, and if so, which category applies — this determines whether the FICA retention obligations in §3 are currently operative or prospective.]

1. Retention principles (POPIA s14)

We retain personal information no longer than is necessary to achieve the purpose for which it was collected (POPIA s14(1)), unless:

Once the retention period expires (or its purpose lapses), personal information is deleted or de-identified as soon as reasonably practicable.

2. POPIA retention schedule

The periods below are our operational defaults. Where a legal minimum exceeds the operational default, the legal minimum governs.

Category Retention period Primary basis
Account and identity data (customers, runners, merchants, partners) While the account is active; deleted within 30 days of a verified deletion request, subject to legal-hold exceptions below Contract (POPIA s11(1)(a)); legal obligation
Order/errand records (including pricing, route, and timestamps) 5 years from the date of the transaction Financial and tax reporting obligations; dispute resolution
Payment transaction metadata (Paystack tokens and authorisation codes; no full PANs stored — see Refunds & Payments) 5 years from the date of the transaction Financial/tax reporting; POPIA s14; potential FICA obligation (see §3)
Runner assignment and delivery-event records 5 years from the date of the errand Dispute resolution; potential tax and labour-law obligations [ATTORNEY-REQUIRED: confirm minimum retention period in light of runner classification — employee vs independent contractor — and applicable labour/ SARS record-keeping requirements]
Precise location / route-tracking data Up to 12 months from collection; aggregated or de-identified thereafter Service improvement; safety and fraud prevention (POPIA s11(1)(f))
Support communications and in-app chat logs 24 months from the date of the communication Customer support; dispute evidence
Technical logs and diagnostics 12 months; aggregated where possible Security monitoring; service integrity
Marketing consent records (waitlist sign-ups, mall-activation opt-ins) For the duration of the marketing relationship, plus 3 years after opt-out or last contact, as evidence of consent POPIA s11(1)(b); CPA compliance; evidence of lawful processing
KYC / onboarding documents for merchants and partners 5 years from end of business relationship, or longer if required by FICA (see §3) Legal obligation; fraud prevention

3. FICA record-keeping obligations

[ATTORNEY-REQUIRED: Confirm accountable-institution status and applicable Schedule 1 category before publishing this section. The analysis below frames the obligation; the attorney must verify whether it currently binds eRunna and, if so, specify the correct category and any applicable exemptions.]

To the extent that eRunna constitutes an accountable institution under FICA, the following obligations apply in addition to the POPIA schedule above:

4. Your rights as a data subject (POPIA s5, s23, s24)

Under POPIA, you have the following rights in relation to your personal information held by eRunna:

Certain rights may be limited where retention is required by law (e.g., FICA record-keeping), to protect the rights of another person, or to exercise or defend a legal claim. We will always inform you of the basis for any limitation.

5. How to submit a DSAR

We will verify your identity before processing any DSAR. We aim to respond within 30 days of receiving a complete request. Where a request is complex or we receive multiple requests, we may extend this period by a further 30 days and will notify you accordingly.

Where a deletion is actioned, we will notify relevant processors and sub-processors of the deletion obligation within a reasonable time.

6. Deletion procedures

Deletion is carried out as a logical deletion followed by a physical purge in accordance with the schedule in §2. Backup copies are purged within 30 days of the scheduled purge date. Aggregated or de-identified data (from which you cannot reasonably be identified) may be retained beyond the retention period for analytical purposes.

FICA records (§3) are subject to separate archival procedures and are not subject to data-subject deletion requests where lawful retention is mandated.

7. Exceptions and legal holds

We may depart from the standard retention schedule in the following circumstances:

Where a legal hold is applied, we will document the hold, its scope, and its basis, and will notify the data subject to the extent permitted by law.

8. PAIA manual

Private bodies are required to compile and make available a manual under the Promotion of Access to Information Act 2 of 2000 (PAIA), including the categories of records held and how to submit an access request. [ATTORNEY-REQUIRED: The PAIA manual is a separate statutory requirement under PAIA (the manual obligation is commonly associated with s51 — confirm the current operative section and its sub-parts). A prior exemption for certain small private bodies has been reported to have lapsed [ATTORNEY-REQUIRED: confirm the exemption's expiry date and whether any private body currently qualifies for exemption]. eRunna must prepare and publish a PAIA manual. This document does NOT substitute for that obligation.] Until the PAIA manual is published, access requests may be directed to info@erunna.app.

9. Data collection at physical activations and waitlist sign-ups

Where personal information is collected at in-person mall activations or via the "Join the waitlist" web form, the following applies:

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via in-app notification and/or email. The "Last updated" date at the top of this page reflects the most recent revision. Your continued use of the Services after a material change constitutes acknowledgement of the updated policy.