WPPBX Pty Ltd (Registration No. 2026/314638/07), trading as WPPBX. Referred to below as “WPPBX”.
This Privacy Policy explains how WPPBX handles personal information
collected through the WPPBX Partner Network, including the public Site at
partners.wppbx.com, the Reseller Portal, and related
authenticated interfaces. It is written to satisfy the Protection of
Personal Information Act, 2013 (South Africa) ("POPIA")
and the EU General Data Protection Regulation ("GDPR") in
respect of in-scope processing activities.
Personal information processed on behalf of our customers (for example, end-user call metadata or voicemail inside a Tenant) is covered by the relevant customer contract and by the Non-User Privacy Policy.
1. Who We Are
1.1 The data controller for the processing described in this Policy is WPPBX Pty Ltd, a company registered in South Africa under registration number 2026/314638/07, trading as WPPBX.
1.2 You can reach our privacy team at [email protected].
2. Information We Collect
2.1 We collect the following categories of personal information:
- Application data, name, email, phone, company, country, city, website, message and any other fields you submit on the "Become a Partner" form;
- Contact-form data, name, email, phone (optional), company (optional) and message when you contact a listed Partner;
- Reseller account data, company details, billing address, tax identifier, designated contact persons, banking or payment instrument information and login credentials for the Reseller Portal;
- Technical data, IP address, user-agent, browser language and approximate geolocation derived from IP, logged for security and anti-abuse purposes;
- Cookies and analytics data, see section 8 below.
3. How We Collect It
3.1 We collect personal information directly from you when you submit it to us through a form on the Site or in the Reseller Portal. We also collect technical data automatically when your browser or device connects to us. We may receive limited information from our subprocessors about the delivery of emails we send you and about challenge results from our anti-abuse provider.
4. How We Use It
4.1 We use personal information to:
- Operate the Site and the Reseller Portal;
- Process Partner applications and manage the Partner relationship;
- Deliver contact-form submissions to the Partner you selected;
- Respond to your queries and provide support;
- Send you transactional and policy-related notifications;
- Detect, prevent and respond to fraud and abuse;
- Comply with our legal and regulatory obligations.
5. Legal Basis for Processing
5.1 Under the GDPR, we rely on the following legal bases:
- Performance of a contract, where processing is necessary to provide the Services you or your organisation have purchased;
- Legitimate interests, for security, anti-abuse, service operation, product improvement and direct communication about your account, balanced against your rights and freedoms;
- Consent, where required by law (for example, non-essential cookies), and only until you withdraw it;
- Legal obligation, where processing is required by applicable law.
5.2 Under POPIA, processing is carried out on equivalent bases recognised by section 11 of that Act.
7. International Transfers
7.1 Our primary hosting is located in the European Union. Certain subprocessors (including Stripe and SMTP2GO) are located in the United States. Where personal information is transferred outside the European Economic Area to a country not recognised as providing adequate protection, we put in place appropriate safeguards, including the European Commission’s Standard Contractual Clauses for cross-border transfers.
9. Retention
9.1 We retain personal information only as long as is necessary for the purpose for which it was collected, or to comply with a legal obligation. Indicative retention periods are:
- Contact-form submissions, up to twenty-four (24) months from submission, or until you request deletion;
- Unsuccessful Partner applications, up to twelve (12) months;
- Reseller account records, for the duration of the account and up to seven (7) years thereafter for financial, tax and dispute reasons;
- Security logs, up to twelve (12) months;
- Aggregated analytics, indefinitely, in a form that does not identify individuals.
10. Your Rights
10.1 Subject to applicable law you have the right to:
- Access the personal information we hold about you;
- Correct or update inaccurate information;
- Object to or restrict processing in certain circumstances;
- Request the deletion of your information (the "right to be forgotten");
- Receive your information in a portable format;
- Withdraw consent where we rely on it;
- Lodge a complaint with a supervisory authority, in South Africa, the Information Regulator; in the EU, the Data Protection Authority in your country of residence.
10.2 To exercise any of these rights, email [email protected]. For the specific case of a contact-form submission, the fastest route is the Delete my contact submission form.
11. Security
11.1 We use reasonable technical and organisational measures to protect personal information, including transport-layer encryption, web application firewalling, rate limiting, audit logging, encryption at rest on managed storage and role-based access control. No system is completely secure; where we become aware of a personal-data breach, we will notify affected individuals and regulators in accordance with applicable law.
12. Children
12.1 The Site is not directed at children under sixteen (16). We do not knowingly collect personal information from children. If you believe a child has submitted data to us, please contact [email protected] so that we can remove it.
13. Changes to this Policy
13.1 We may revise this Policy from time to time. Each revision is published through the Policy Manager with an effective date and a summary of material changes. Historical versions are available at partners.wppbx.com/legal/privacy/versions.
14. Contact
Privacy questions, rights requests and complaints can be directed to [email protected].