Legal & Privacy
Privacy Policy
How EXRA Integrations collects, uses, protects and manages personal information across its website, services and digital platform.
Purpose and Scope
EXRA Integrations (Pty) Ltd (“EXRA”, “EXRA Integrations”, “we”, “us” or “our”) is committed to handling personal information responsibly, transparently and in accordance with applicable data-protection requirements.
This Privacy Policy explains how EXRA collects, receives, uses, stores, accesses, shares, protects, retains and otherwise processes personal information when individuals or organisations interact with EXRA, its website, communications, project services, network programmes or digital platform.
The purpose of this Policy is to provide individuals and organisations with clear information about:
- what personal information EXRA may process;
- where that information may come from;
- why EXRA processes the information;
- how the information may be used during project and platform operations;
- when information may be shared with technicians, suppliers, service providers or other authorised parties;
- how long information may be retained;
- how EXRA seeks to protect personal information;
- what rights a data subject may exercise; and
- how privacy-related questions, objections, corrections, access requests or complaints may be submitted.
This Policy applies to personal information processed through the EXRA website and through other EXRA-controlled interactions and systems where this Policy is made applicable.
This includes, where relevant, information processed during general enquiries, project initiation, assessments, project coordination, technician and supplier participation, account registration, project execution, handover, post-project support and other EXRA platform activities.
This Privacy Policy does not establish the commercial or contractual terms under which EXRA services are supplied. Matters such as service eligibility, project obligations, assessment charges, payment obligations, cancellations, warranties, user conduct, liability and other contractual conditions are addressed separately under the applicable Terms of Service and other service-specific terms or policies.
Responsible Party
For purposes of this Privacy Policy and applicable South African data-protection law, the responsible party is:
EXRA Integrations (Pty) Ltd
Trading as: EXRA
Registered address
Arboretum, 19 Klapperkop
Richards Bay, 3900
South Africa
The above address is EXRA’s registered business address and should not be interpreted as a public-facing or walk-in office. EXRA operates primarily through its digital platform, electronic communications and coordinated project activities.
Contact information
General information:
info@exra.co.za
Support and privacy enquiries:
support@exra.co.za
Telephone / WhatsApp:
+27 71 228 4481
Website:
exra.co.za
EXRA determines the purposes for which personal information under its control is processed and, where applicable, the manner in which that processing takes place.
EXRA may appoint authorised operators and service providers to process certain personal information on its behalf. Where EXRA continues to determine the purpose and means of that processing, the use of an operator or service provider does not by itself remove EXRA’s responsibilities as the responsible party.
In other circumstances, independent technicians, suppliers, payment providers or other organisations may process information under their own legal responsibilities where they independently determine the purposes or means of that processing. Their own privacy obligations may therefore apply in addition to the protections described in this Privacy Policy.
Information Officer
EXRA will identify the applicable Information Officer and publish the appropriate privacy contact information once the relevant registration and administrative details have been formally confirmed.
Until those details are confirmed, privacy-related enquiries and requests may be directed to support@exra.co.za.
Who This Privacy Policy Applies To
This Privacy Policy may apply to any natural or juristic person whose personal information is processed by EXRA in connection with its website, services, projects, communications, network activities or digital platform.
Depending on the circumstances, this may include:
Website visitors and enquirers
Individuals who browse the EXRA website, submit a contact enquiry, communicate with EXRA or interact with website functionality.
Prospective and existing clients
Individuals or organisations that request information, initiate a project, participate in an assessment, receive a quotation or proposal, approve project activities, make payments, interact with project tracking or receive post-project support.
Client representatives and site contacts
Individuals whose information is provided in connection with a project carried out for a company, organisation, property owner, portfolio manager or other client.
Technicians and technician applicants
Individuals or businesses that apply to participate in the EXRA technician network, provide professional or business information, receive project opportunities, complete assessments, perform project work or interact with EXRA technician systems.
Suppliers and supplier representatives
Individuals or organisations that apply to participate in the EXRA supplier network, provide business or contact information, receive procurement requests or interact with project supply processes.
Account holders and platform users
Individuals or organisations that use current or future EXRA accounts, dashboards, portals, authentication systems or other digital platform functionality.
Service providers and business contacts
Individuals or organisations that communicate or work with EXRA in connection with operational, technical, professional or business activities.
Job and candidate applicants
Individuals who submit employment or candidate information to EXRA if recruitment or candidate submission processes are introduced.
Where appropriate, candidate-specific processing may also be governed by a separate Candidate Privacy Notice.
Other affected individuals
Other individuals whose information is legitimately provided to or obtained by EXRA in connection with a project, legal obligation, support request, business relationship, security matter or other lawful activity.
Personal Information EXRA Collects and Processes
4.1 General principle
EXRA processes personal information that is reasonably necessary to operate its website and platform, respond to enquiries, assess and coordinate projects, administer client and network relationships, process transactions, maintain project records, provide support, protect the platform and comply with applicable legal and regulatory obligations.
The precise information processed depends on how a person interacts with EXRA. EXRA does not necessarily collect every category described in this Section from every individual or organisation.
4.2 Identity and contact information
EXRA may process identity, business and contact information including:
- first name;
- surname;
- business or organisation name;
- email address;
- telephone or mobile number;
- WhatsApp or other contact details where applicable;
- physical, service or project address;
- billing or business address;
- location information;
- preferred communication details;
- role within an organisation; and
- information identifying an authorised representative or project contact.
4.3 Enquiry and communication information
When a person contacts EXRA, EXRA may retain information contained in or associated with that communication.
This may include:
- contact-form enquiries;
- email correspondence;
- support enquiries;
- project-related messages;
- responses from EXRA;
- technician or supplier communications;
- complaints;
- warranty or support communications;
- dates and times of communications; and
- records of decisions, approvals or instructions supplied through the platform.
4.4 Project initiation information
When a person requests or initiates a project, EXRA may process information including:
- project location;
- project or site address;
- requested project type;
- project description;
- requested outcomes;
- preferred or required timeline;
- property or environment type;
- existing infrastructure details;
- technical requirements supplied by the client;
- access or contact information for the site;
- client instructions;
- relevant project constraints; and
- information required to determine whether EXRA has appropriate network coverage.
4.5 Assessment and site information
Where a project proceeds through an assessment, EXRA may process information generated before, during or after that assessment.
This may include:
- assessment request details;
- assessment date and time;
- site location;
- technician assignment;
- distance or travel-related information;
- assessment findings;
- technical observations;
- diagnostic information;
- measurements;
- identified project requirements;
- equipment or system condition;
- recommended work;
- estimated material requirements;
- photographs or other site evidence;
- uploaded assessment records;
- technician notes;
- assessment status; and
- related client communications.
4.6 Project execution and monitoring information
During project preparation, execution, monitoring, completion and handover, EXRA may process records relating to:
- assigned technicians;
- supplier participation;
- project status;
- scheduled dates;
- technician acceptance or decline status;
- start and completion times;
- project milestones;
- execution logs;
- progress updates;
- site photographs;
- evidence of completed work;
- checklists;
- exceptions or delays;
- escalation records;
- client approvals;
- completion confirmation;
- handover documentation;
- sign-off records;
- warranty activation; and
- post-project support history.
4.7 Client account and dashboard information
Where EXRA accounts, portals or dashboards are available, EXRA may process information associated with administration and use of those systems.
This may include:
- account identifier;
- registered name and contact details;
- role or permissions;
- authentication records;
- verification status;
- account creation and update history;
- login and security information;
- project associations;
- approvals;
- documents;
- invoices;
- payment status;
- warranty information;
- support activity;
- account preferences; and
- relevant user actions performed through the platform.
This category becomes applicable as relevant account and dashboard functionality is introduced or used.
4.8 Technician information
Where a person or business applies to, participates in or performs work through the EXRA technician network, EXRA may process information including:
- technician name;
- contact information;
- location and service regions;
- identity-verification information;
- business or trading information;
- company or business registration information;
- tax-related business information;
- qualifications;
- certifications;
- certificate-of-competence information where applicable;
- skills or service categories;
- portfolio or previous-work evidence;
- experience information;
- availability;
- project history within EXRA;
- assessment history;
- project acceptance or decline history;
- performance records;
- uploaded site evidence;
- quality or completion records;
- complaints or support matters;
- eligibility information relating to programmes such as EXRA Verified; and
- invoices or payment-related records.
Information relating specifically to a programme such as EXRA Verified becomes applicable when that programme is introduced and the relevant technician enters or becomes subject to that process.
4.9 Supplier information
Where a supplier or supplier representative participates in EXRA procurement or network processes, EXRA may process:
- representative or contact information;
- business name;
- registration details;
- tax or business information;
- service or delivery areas;
- supplier location;
- available product or material categories;
- stock or availability information;
- quotations;
- purchase-order records;
- collection or delivery information;
- invoice information;
- transaction records;
- project associations;
- supplier status or history; and
- communications with EXRA.
4.10 Payment and transaction information
EXRA may process information relating to project, assessment and other authorised transactions, including payment amounts, transaction references, payment status, dates, invoices, credits, refunds where applicable, outstanding balances and other accounting or transaction records.
Where card payments are processed through an authorised third-party payment gateway, payment-card information may be entered directly into systems operated by that payment provider.
EXRA should not be understood to store complete payment-card details merely because a card payment is made through the EXRA platform.
EXRA may receive limited payment-related information from the payment provider that is necessary to confirm or administer the transaction, such as the transaction status, payment reference, amount and related identifiers.
4.11 Financial and administrative records
EXRA may retain financial and administrative information including:
- invoices;
- quotations or proposals;
- receipts;
- transaction references;
- payment status;
- project financial records;
- credits;
- approved refunds;
- supplier invoices;
- technician invoices;
- accounting records;
- tax-related records where required; and
- records necessary for financial reconciliation or legal compliance.
4.12 Project documents and uploaded content
EXRA systems may process project-related documents and uploaded content including:
- quotations;
- proposals;
- invoices;
- project scopes;
- assessment reports;
- photographs;
- documents uploaded by clients;
- technician documentation;
- supplier documentation;
- certificates;
- completion documentation;
- warranty-related evidence;
- claims; and
- signed or approved records.
Where uploaded content contains personal information, that information may also be processed as part of the relevant project, account, support or network record.
4.13 Location information
Location information may be necessary for project coordination, network routing, assessments, procurement or service availability.
EXRA may process:
- project or site location;
- service area;
- technician operating region;
- supplier region;
- addresses;
- distance information used for assessments or routing;
- location information voluntarily supplied by a user; and
- system-generated location information where a future feature legitimately requires it.
EXRA does not treat this provision as authorisation for continuous GPS or location tracking. More precise or continuous location processing would require an appropriate operational purpose and privacy assessment before introduction.
4.14 Website, device and technical information
Depending on EXRA's website, hosting, security and platform infrastructure, technical information may include:
- IP address;
- browser type;
- device type;
- operating-system information;
- access timestamps;
- session information;
- security events;
- error logs;
- authentication logs;
- website or platform usage information; and
- cookie or similar-technology identifiers where applicable.
4.15 Security and fraud-prevention information
EXRA may maintain information reasonably necessary to protect accounts, transactions, projects, network participants and digital systems.
This may include:
- failed login attempts;
- suspected abuse;
- suspicious transaction or account activity;
- duplicate submissions;
- security alerts;
- access history;
- authentication or verification events;
- reports of misuse;
- investigation records; and
- technical logs relevant to security incidents.
4.16 Waiting-list and network-availability information
Where EXRA cannot yet support a requested project, service or operating area, EXRA may process waiting-list or availability information including:
- name;
- contact details;
- location;
- requested project or service type;
- date of interest;
- relevant project requirements; and
- communication preferences relating to future availability.
This category becomes relevant when a person elects to join or otherwise participate in an EXRA waiting-list or availability process.
4.17 Warranty and post-project support information
Where a completed project is subject to warranty or post-project support processes, EXRA may process:
- completed project reference;
- client or contact information;
- warranty period or status;
- issue reported;
- photographs or other evidence;
- diagnostic findings;
- support communications;
- technician involvement;
- resolution history; and
- claim outcome.
The existence of a warranty record in EXRA systems does not by itself determine whether a particular claim qualifies for warranty coverage. Applicable warranty rights, exclusions, periods and conditions are governed separately by the relevant Warranty Terms or Terms of Service.
4.18 Information obtained from other people
EXRA may receive personal information concerning a person from another individual or organisation.
This may occur, for example, where:
- a company representative provides the details of a site contact;
- a client provides details of another authorised person;
- a technician records relevant project-site contact information;
- a supplier identifies an authorised representative; or
- an organisation nominates an account user.
Where a person provides EXRA with personal information relating to another individual or organisation, that person should have an appropriate basis or authority to provide the information and should avoid supplying information that is unnecessary for the relevant purpose.
4.19 Information from service providers and platform partners
EXRA may receive transaction, verification, operational or technical information from authorised third parties involved in EXRA processes.
Depending on the relevant service, this may include information received from:
- payment providers;
- email or communications providers;
- security providers;
- identity or business-verification services;
- hosting or cloud-service providers;
- technicians;
- suppliers; and
- other service providers involved in an authorised EXRA project or platform workflow.
4.20 Special personal information
EXRA does not ordinarily require special personal information in order to provide its standard website, project coordination or network services and does not seek to collect such information unnecessarily.
Users should avoid submitting special personal information through general enquiry fields unless it is reasonably necessary for a specific legitimate purpose.
Where EXRA has a genuine need to process special personal information, it will do so only where an appropriate lawful basis and applicable data- protection requirements are satisfied.
If EXRA introduces higher-risk verification or processing involving categories such as biometric, criminal-behaviour, health or other specially protected information, that processing will require a specific privacy and compliance assessment before becoming operational.
4.21 Children's information
EXRA's services are not designed primarily for children and EXRA does not intentionally seek children's personal information through ordinary project, enquiry or network processes.
Where children's personal information becomes genuinely necessary for a lawful activity, EXRA will assess the additional legal and privacy requirements applicable to that processing before using or retaining that information.
How EXRA Collects Personal Information
5.1 General approach
EXRA may collect personal information through different channels depending on how an individual or organisation interacts with EXRA.
Information may be provided directly by the person concerned, supplied by an authorised representative or project participant, generated through project or platform activity, received from an authorised service provider, obtained during verification processes, or generated automatically through the operation and security of EXRA's website and digital systems.
EXRA seeks to collect personal information only through methods that are appropriate to the relevant purpose and does not intentionally collect information merely because it may be available.
5.2 Information provided directly by you
EXRA may collect personal information directly when a person:
- submits an enquiry;
- initiates or requests a project;
- provides project requirements;
- books or participates in an assessment;
- registers or maintains an account;
- completes a technician or supplier application;
- uploads documents or project evidence;
- makes or administers a payment;
- submits an approval or instruction;
- requests warranty or post-project support;
- reports an issue;
- joins a waiting list;
- contacts EXRA through email, telephone, WhatsApp or other authorised communication channels; or
- otherwise voluntarily provides information through an EXRA-controlled process.
5.3 Information supplied by another person or organisation
EXRA may receive personal information concerning one person from another individual or organisation where this is reasonably necessary for a legitimate project, business, support or platform purpose.
This may occur, for example, where:
- a property or portfolio manager provides the contact details of a site representative;
- an organisation nominates an employee or representative as a project contact;
- a client provides the details of a person who will provide site access;
- a supplier provides the details of its authorised representative; or
- an organisation nominates an authorised account user.
A person providing another individual's information to EXRA should have an appropriate basis or authority to do so and should provide only information relevant to the purpose for which it is required.
Where appropriate, EXRA may take reasonable steps to ensure that the affected person is informed of the processing.
Providing another person's details does not automatically give the submitting person authority to make all decisions on that person's behalf.
5.4 Information generated during an assessment
This collection method becomes relevant when an assessment is scheduled, performed or reviewed.
Information may be generated through the assessment process rather than being supplied directly by the client.
This may include:
- assessment findings;
- technical observations;
- measurements;
- site conditions;
- diagnostic information;
- equipment or system information;
- photographs;
- project requirements;
- technician comments;
- recommendations;
- assessment timestamps;
- status records; and
- relevant location information.
Assessment information may become part of the relevant project record where necessary to evaluate, plan, coordinate or subsequently support the project.
5.5 Information generated during project execution
This collection method becomes relevant when a project moves into preparation, execution, monitoring, completion, handover or post-project support.
EXRA systems and project participants may generate operational records including:
- project status;
- assigned technician;
- supplier allocation;
- milestone dates;
- technician acceptance or decline status;
- arrival, start or completion records;
- execution checklists;
- progress evidence;
- client approvals;
- project exceptions;
- escalation records;
- completion evidence;
- handover records;
- warranty activation; and
- post-project support activity.
Some information processed by EXRA is therefore generated through the operation of a project rather than being entered directly by the client.
5.6 Information supplied by technicians
This collection method becomes relevant when a technician participates in an assessment, project, support matter or EXRA network process.
EXRA may receive information including:
- assessment findings;
- site information;
- project evidence;
- photographs;
- checklists;
- status updates;
- completion records;
- invoices;
- reported project problems;
- project-related communications; and
- relevant records of client or site interaction.
Technicians should submit only information reasonably necessary for the assigned EXRA activity and should not use project access as a basis to collect unrelated personal information.
5.7 Information supplied by suppliers
This collection method becomes relevant when a supplier participates in procurement, fulfilment or an EXRA network process.
EXRA may receive information including:
- quotations;
- stock information;
- material availability;
- purchase-order information;
- fulfilment or collection status;
- delivery confirmation;
- invoices;
- representative information; and
- project-related communications.
5.8 Information received from payment providers
This collection method becomes relevant when a client or other authorised payer initiates a transaction through an integrated payment service.
Payment information may be entered directly into systems operated by an authorised payment provider rather than being submitted directly to EXRA.
Following a transaction attempt, EXRA may receive limited information from the payment provider that is reasonably necessary to administer the transaction.
This may include:
- payment amount;
- transaction identifier;
- transaction date or time;
- successful, failed or pending status;
- payment method category;
- refund status;
- settlement information; and
- other limited transaction information necessary to administer the payment.
Unless EXRA's payment architecture expressly changes, EXRA does not intend to receive or store complete card numbers, card security codes or other sensitive authentication data merely because a payment is made through the EXRA platform.
If the payment architecture changes materially, the privacy implications and applicable safeguards will be reviewed before the changed processing becomes operational.
5.9 Information obtained during identity, business or credential verification
This collection method becomes relevant where an individual or organisation applies for a role, programme or status that requires verification.
EXRA may obtain or verify information including:
- identity information;
- business registration information;
- tax or business details;
- professional certifications;
- certificate-of-competence information where applicable;
- qualifications;
- portfolio evidence;
- service region; and
- other professional information relevant to the verification process.
Additional verification relating to a programme such as EXRA Verified becomes applicable only once that programme is introduced and the relevant participant enters or becomes subject to that process.
5.10 Information obtained from official or legitimate sources
This collection method may become relevant where EXRA has a legitimate reason to verify information relating to eligibility, fraud prevention, compliance or business participation.
Depending on the circumstances, information may be checked or obtained from:
- official company or business registers;
- professional or certification registers;
- authorised verification service providers;
- publicly available professional or business information; and
- other lawful sources relevant to the verification purpose.
EXRA will not treat the public availability of personal information as unlimited permission to collect, profile or reuse that information for unrelated purposes.
5.11 Information generated through accounts and dashboards
This provision becomes operational when EXRA accounts, dashboards, portals or authenticated platform functionality are introduced and used.
The platform may generate information including:
- account identifier;
- user role;
- permissions;
- account status;
- login records;
- project relationships;
- approvals;
- workflow actions;
- uploaded records;
- notification history;
- selected preferences; and
- security events.
These records may be generated automatically as part of administering the account, maintaining security and recording authorised project or platform activity.
5.12 Information collected automatically through website or platform operation
EXRA's website, hosting infrastructure and digital systems may automatically generate limited technical records when users interact with them.
Depending on the system in use, this may include:
- IP address;
- browser information;
- device information;
- date or time of a request;
- visited page or resource;
- server logs;
- error information;
- session information; and
- security information.
Such information may be generated for purposes such as delivering website functionality, diagnosing technical errors, protecting infrastructure, detecting abuse, managing authentication, maintaining security or monitoring technical performance.
5.13 Cookies and similar technologies
EXRA may use technologies required for the operation, security or functionality of its website and digital platform.
Where EXRA introduces optional analytics, advertising, attribution, personalisation or similar technologies, their use will be assessed separately and, where required, governed by the applicable Cookie Notice and consent controls.
For example, introducing a marketing technology such as a social-media advertising pixel may trigger a review of consent requirements, cookie disclosures and the Privacy Policy before that technology becomes active.
5.14 Information received from security and fraud-prevention systems
This collection method becomes relevant where a potential security, account, transaction or platform-integrity event occurs.
EXRA may generate or receive information relating to:
- repeated failed login attempts;
- suspicious account access;
- duplicate project requests;
- transaction anomalies;
- unusual automated activity;
- reported abuse;
- suspected manipulation; and
- technical attack indicators.
Security monitoring should be proportionate to the identified risk and should not be used as an unrestricted mechanism for monitoring unrelated user behaviour.
5.15 Information arising from complaints, reports and investigations
This collection method becomes relevant when a complaint, report, dispute, safety matter or other investigation is opened.
Information may include:
- reporter information;
- information about the person or entity reported;
- the allegation or issue raised;
- communications;
- supporting evidence;
- screenshots or documents;
- project references;
- investigation notes; and
- the resulting outcome or action.
Separate reporting, conduct, safety or intellectual property policies may govern the underlying behaviour or complaint process. This Privacy Policy addresses the processing of personal information arising from those processes.
5.16 Information generated from customer support
This collection method becomes relevant when a support request is submitted, created or escalated.
EXRA may generate or receive:
- support category;
- support messages;
- project or account identifiers;
- supporting evidence;
- support history;
- escalation information;
- resolution information; and
- information identifying the relevant person or team handling the matter.
5.17 Information obtained through integrations
This provision becomes relevant where EXRA integrates its website or platform with another authorised service.
Possible integrations may include services for:
- payments;
- communications;
- mapping or location functionality;
- identity or business verification;
- document signing;
- analytics;
- authentication; or
- other platform functions.
EXRA may receive information from an integrated service according to the purpose of the integration, permissions granted, applicable contractual controls and applicable privacy requirements.
Before a materially new integration becomes operational, EXRA should assess what information is sent to the provider, what information is returned, why the information is required, where it is stored, how long it may be retained, whether cross-border processing occurs and whether EXRA's privacy documentation requires updating.
5.18 Information EXRA creates internally
Not all personal information processed by EXRA is collected from another source. Certain information may be created or derived internally through authorised operational processes.
This may include:
- internal project references;
- assessment statuses;
- eligibility results;
- workflow statuses;
- operational notes;
- allocation decisions;
- verification statuses;
- support classifications; and
- proportionate security or risk indicators where applicable.
5.19 Collection from public sources — limitation
EXRA does not regard personal information as freely reusable merely because it appears online or in a publicly accessible database.
Where information is obtained from a public or official source, EXRA will consider its relevance, purpose, reliability and applicable legal requirements before using it.
5.20 Changes to collection methods
EXRA's collection methods may develop as the platform introduces new functionality, integrations or operational processes.
Before introducing a materially new collection method, integration or category of personal information, EXRA should assess its purpose, necessity, risks, disclosure requirements and applicable legal obligations.
Where a change materially affects individuals, this Privacy Policy or an applicable specialised privacy notice will be updated before or when the new processing becomes operational, as appropriate.
Purposes and Lawful Justifications for Processing
6.1 General principle
EXRA processes personal information only where there is an identified and legitimate purpose connected to its website, digital platform, project activities, network operations, contractual relationships, legal obligations, security requirements or other lawful business functions.
EXRA does not rely on a single justification for every processing activity. The appropriate justification depends on the purpose of the processing, the relationship between EXRA and the affected person, the information involved and the circumstances in which the processing occurs.
Personal information should not be collected or retained merely because it may be useful in the future. The intended purpose should be identified before or when the processing takes place, and the information processed should be reasonably necessary and proportionate to that purpose.
EXRA currently operates from South Africa and is subject to applicable South African privacy and data-protection requirements, including the Protection of Personal Information Act 4 of 2013 (“POPIA”).
As EXRA makes its services or platform available in additional jurisdictions, other privacy and data-protection laws may also apply. Where another jurisdiction imposes additional or different requirements, EXRA will apply the requirements relevant to the particular processing activity and may provide supplementary privacy information where appropriate.
6.2 Lawful justifications
Depending on the circumstances, EXRA may process personal information on one or more lawful justifications recognised by applicable privacy and data-protection law.
Under POPIA, these may include processing based on:
- the consent of the data subject;
- processing necessary to carry out actions for the conclusion or performance of a contract;
- compliance with an obligation imposed by law;
- protection of a legitimate interest of the data subject;
- the proper performance of a public-law duty by a public body, where applicable; or
- pursuit of a legitimate interest of EXRA or an appropriate third party.
Where another country's privacy law applies, the terminology, legal basis or requirements may differ. EXRA will assess the lawful justification required under the law applicable to that processing rather than assuming that one jurisdiction's framework automatically applies everywhere.
6.3 Consent
EXRA may rely on consent where the relevant processing is optional and consent is an appropriate lawful justification.
This may become relevant where a person voluntarily joins an optional communication programme, enables an optional feature requiring additional processing, permits an optional analytics or advertising technology where consent is required, or agrees to a new processing purpose that is not otherwise appropriately justified.
Where EXRA relies on consent, the consent should be voluntary, specific and informed and should relate to the identified processing purpose.
EXRA will not treat acceptance of unrelated services, general website use or submission of an enquiry as unlimited consent for unrelated processing.
For example, submitting a contact enquiry does not automatically constitute consent to advertising, initiating a project does not automatically subscribe a client to promotional communications, and supplying a site address does not constitute consent to continuous location tracking.
Where processing depends specifically on consent, the affected person may withdraw that consent subject to applicable law. Withdrawal does not affect processing that was lawfully carried out before the withdrawal.
6.4 Pre-contractual actions and performance of a contract
EXRA may process personal information where the processing is reasonably necessary to take requested steps toward establishing a contractual relationship or to perform obligations arising from an existing contractual relationship.
This may include processing required to:
- review a project request;
- determine service or network availability;
- arrange an assessment;
- prepare a quotation or proposal;
- administer an accepted project;
- coordinate authorised technicians and suppliers;
- maintain relevant project records;
- communicate project instructions;
- record approvals;
- complete handover processes; and
- administer applicable post-project services.
The existence of a contractual relationship does not give EXRA unrestricted authority to use project information for unrelated purposes.
6.5 Enquiries and pre-project communications
EXRA may process contact details and enquiry information in order to receive, review and respond to communications, understand the assistance being requested and take reasonable steps requested by the person before any formal project or contractual relationship is established.
This may include general enquiries, project enquiries, service-availability questions, network enquiries or other legitimate communications sent to EXRA.
Where an enquiry does not progress further, the information will not automatically be converted into an unrelated marketing profile.
6.6 Project initiation, assessment and planning
EXRA may process project, site, location, technical and contact information to evaluate and structure a requested project, determine whether appropriate network capacity exists, arrange and document an assessment, identify relevant technical requirements and support preparation of an appropriate project proposal or execution plan.
Depending on the circumstances, this processing may be necessary for requested pre-contractual steps, performance of a contractual relationship or other appropriate lawful interests connected to project administration.
6.7 Project coordination and execution
EXRA may process personal information in order to allocate and coordinate authorised project participants, administer project schedules and milestones, communicate instructions, monitor execution, record progress, manage approvals and exceptions, maintain evidence of work performed and facilitate completion and handover.
Access to project information should be limited according to the role and reasonable operational need of the relevant participant.
The fact that a technician, supplier or other participant is involved in a project does not automatically entitle that participant to access every record associated with the client or project.
6.8 Technician and supplier network administration
EXRA may process technician and supplier information to receive and evaluate applications, verify submitted information where appropriate, administer network participation, determine suitable project allocation, maintain relevant service and performance records, administer procurement or project participation and protect the integrity of the EXRA network.
Where EXRA introduces a programme such as EXRA Verified, additional processing relating to programme eligibility, qualification and review becomes applicable only when the programme is operational and the relevant participant enters or becomes subject to that process.
Commercial or participation conditions applicable to such programmes are governed separately by the relevant network or programme terms.
6.9 Payment and financial administration
EXRA may process payment and transaction-related information in order to initiate or confirm authorised payments, reconcile transactions, maintain invoices and receipts, administer credits or refunds where applicable, maintain accounting records, identify outstanding balances and manage financial records associated with projects, technicians, suppliers or other authorised transactions.
Where payment-card information is entered directly into an authorised payment provider's systems, EXRA's purpose is to administer and confirm the resulting transaction rather than to independently obtain or store complete payment-card credentials.
The rules determining amounts payable, payment deadlines, cancellation rights, credits or refund eligibility are governed separately by the applicable Terms of Service, Payment Terms or other relevant commercial terms.
6.10 Procurement and supplier fulfilment
EXRA may process relevant project, supplier, transaction and fulfilment information to obtain quotations, administer purchase orders, coordinate material availability, arrange authorised collection or delivery, associate procurement with the appropriate project and maintain procurement records.
6.11 Accounts, authentication and dashboards
This processing becomes applicable when EXRA account, portal, dashboard or authenticated platform functionality is introduced and used.
EXRA may process account and activity information to:
- create and administer accounts;
- identify authorised users;
- authenticate access;
- determine authorised roles and permissions;
- associate users with appropriate projects or network functions;
- record approvals and workflow actions;
- provide relevant notifications;
- maintain account history; and
- protect platform and account security.
Access controls should follow the user's authorised role and operational need rather than providing unrestricted access merely because the person has an EXRA account.
6.12 Support, warranty and post-project administration
EXRA may process project history, contact information, evidence, communications and technical records to administer project handover, maintain applicable warranty records, receive support requests, investigate reported issues, coordinate diagnostic or remedial action and maintain an auditable support history.
Processing a warranty or support record does not by itself determine whether the reported issue qualifies for warranty coverage. Warranty rights, exclusions, periods and conditions are governed separately by the applicable Warranty Terms or Terms of Service.
6.13 Compliance with legal obligations
EXRA may process and retain personal information where doing so is reasonably necessary to comply with an obligation imposed by applicable law.
Depending on the jurisdiction and circumstances, this may include:
- taxation requirements;
- accounting and financial recordkeeping;
- corporate or regulatory obligations;
- court or legal processes;
- lawfully issued information requests;
- mandatory preservation requirements; and
- other statutory obligations applicable to EXRA.
A request for personal information does not automatically become lawful merely because the requester claims to represent an authority.
Where reasonably possible and legally permitted, EXRA should verify the nature, authority, scope and validity of a request before disclosing personal information in response to it.
6.14 Protecting legitimate interests of the affected person
EXRA may process information where doing so is reasonably necessary to protect a legitimate interest of the affected person and the applicable privacy law recognises such processing.
Depending on the circumstances, this could become relevant to situations involving account security, urgent support or safety matters, prevention of significant harm or other circumstances where the affected person's legitimate interests require appropriate protection.
This justification should not be treated as general permission to process information merely because EXRA considers the processing useful.
6.15 Legitimate interests of EXRA or an appropriate third party
Where permitted by applicable law, EXRA may process personal information where the processing is reasonably necessary for a legitimate interest pursued by EXRA or an appropriate third party, provided that the processing is lawful, proportionate and appropriately balanced against the rights and interests of the affected person.
Legitimate interests may include appropriate activities relating to:
- platform and account security;
- fraud prevention;
- project integrity;
- network integrity;
- prevention of abuse;
- maintenance of accurate operational records;
- reasonable internal administration;
- establishing, exercising or defending legal rights; and
- protecting EXRA, its users or authorised third parties against legitimate operational risks.
Before relying on legitimate interests for processing that could materially affect an individual, EXRA should consider the purpose of the processing, whether it is reasonably necessary, the person's reasonable expectations, the nature of the information, possible consequences and available safeguards.
6.16 Public-law duties
POPIA recognises processing necessary for the proper performance of a public-law duty by a public body.
EXRA is presently a private company and does not ordinarily rely on this justification for its own processing activities.
If EXRA's legal status, role or relationship with a public body materially changes in a manner that makes such a justification relevant, the applicable processing and privacy requirements will be reviewed before EXRA relies upon it.
6.17 Security, fraud prevention and platform integrity
EXRA may process limited account, transaction, device, technical and operational information where reasonably necessary to protect its systems, users, projects and network against fraud, unauthorised access, abuse, manipulation, technical attacks or other legitimate security risks.
This may include measures intended to:
- protect accounts;
- protect payments and transactions;
- identify suspicious access;
- detect attempted technical attacks;
- prevent fraudulent activity;
- identify abusive platform behaviour;
- maintain security audit records; and
- investigate legitimate security incidents.
Security processing should remain proportionate to the identified risk and should not be repurposed into unrestricted behavioural surveillance.
6.18 Complaints, disputes and legal claims
EXRA may process relevant information to receive and investigate complaints, maintain necessary evidence, establish relevant facts, protect the rights of affected parties, resolve disputes and establish, exercise or defend legal rights or claims where lawful.
This processing may become relevant in connection with project disputes, network complaints, reports of misconduct, safety concerns, intellectual property complaints, payment disputes or other legitimate investigations.
6.19 Platform administration, performance and improvement
EXRA may process proportionate operational or technical information to maintain the reliability of its website and platform, diagnose faults, measure system performance, determine whether core functions operate as intended and make evidence-based improvements to systems and workflows.
This purpose does not automatically authorise behavioural advertising, unrelated profiling or cross-service tracking.
Where platform improvement involves optional analytics, advertising or tracking technologies requiring consent or additional disclosure, those technologies will be governed separately by the applicable Cookie Notice and consent controls.
6.20 Direct marketing
EXRA distinguishes operational or service communications from direct marketing.
Communications reasonably necessary to respond to an enquiry, administer an account, coordinate a project, provide a transaction update, communicate assessment information, administer support or fulfil another requested service are not treated as marketing merely because they are delivered electronically.
Where EXRA wishes to use personal information for direct marketing, it will do so subject to the privacy, electronic-communications, consent, objection and opt-out requirements applicable in the relevant jurisdiction.
Submitting an enquiry, initiating a project or providing contact details for operational purposes does not automatically enrol a person into unrelated promotional communications.
6.21 Waiting-list and availability communications
Where a person voluntarily joins an EXRA waiting list or availability process, EXRA may use the information provided to administer that request and communicate relevant developments concerning the requested service, project type or operating area.
Participation in a waiting-list or availability process does not by itself constitute consent to unrelated promotional marketing.
6.22 Further processing and new purposes
EXRA will not assume that personal information collected for one purpose may automatically be used for another.
Before materially repurposing existing personal information, EXRA should assess:
- the relationship between the original and proposed purpose;
- the nature of the information involved;
- the circumstances in which the information was originally obtained;
- the reasonable expectations of affected persons;
- possible consequences of the new processing;
- whether another lawful justification is required;
- whether additional notice or consent is required; and
- whether the proposed processing remains necessary and proportionate.
Where a new purpose materially changes the privacy impact on affected persons, this Privacy Policy or the relevant specialised privacy notice should be updated as appropriate before or when the new processing becomes operational.
6.23 When providing information is mandatory
Depending on the relevant process, providing certain personal information may be necessary to enable EXRA to perform the requested activity.
For example, EXRA may be unable to:
- respond appropriately to an enquiry without sufficient contact information;
- determine project availability without relevant location information;
- coordinate an assessment without appropriate project and site information;
- administer a transaction without information required by the authorised payment provider; or
- establish an authenticated platform account without sufficient identity and security information.
Where reasonably practicable, EXRA will indicate when requested information is required and, where relevant, explain the consequences of not providing it.
6.24 Withdrawal of consent and objections
Where EXRA relies specifically on consent, the affected person may withdraw that consent subject to applicable law.
Where applicable privacy law provides a right to object to particular processing, EXRA will provide an appropriate mechanism for that objection to be submitted and considered.
Withdrawal of consent or submission of an objection does not necessarily require EXRA to erase every related record immediately where another lawful justification, legal claim, contractual requirement or mandatory retention obligation continues to apply.
6.25 Internal purpose and justification standard
Before introducing a materially new processing activity, feature or integration, EXRA should be able to identify:
- what information will be processed;
- whose information is involved;
- why the information is required;
- which lawful justification applies;
- whether all of the information is necessary;
- who will receive or access the information;
- how long it should be retained;
- what risks may arise from the processing;
- what safeguards should apply;
- whether international or cross-border processing is involved; and
- whether the affected person requires additional notice, consent, choice or another rights mechanism.
A new feature, integration or operational process should not be treated as privacy-ready merely because it is technically possible to build.
Where a proposed feature introduces materially new processing, its privacy and compliance implications should be assessed before the processing becomes operational.
Data Minimisation, Accuracy and Information Quality
7.1 General principle
EXRA seeks to process personal information that is reasonably appropriate, relevant and necessary for the identified purpose.
EXRA should not request, obtain, use or retain a greater amount of personal information merely because its website, platform or technical systems are capable of doing so.
EXRA also seeks to take reasonably practicable steps to ensure that personal information used for operational, project, verification, financial, security or other material purposes is sufficiently complete, accurate, not misleading and updated where necessary, having regard to the purpose for which the information is processed.
7.2 Collecting only what is necessary
Before EXRA requests a category of personal information, there should be an identifiable reason for requiring that information.
The amount and type of information requested should be proportionate to the particular process, role, transaction, project stage or other legitimate purpose.
Information should not be requested merely because it could potentially become useful at some unspecified point in the future.
7.3 Progressive collection
EXRA may structure its processes so that additional personal information is requested progressively when it becomes relevant to a particular stage of an interaction, project or network process.
Information that is unnecessary at an earlier stage should not ordinarily be requested merely because it may become relevant at a later stage.
For example, a general enquiry may require only basic contact and enquiry information, while a project assessment, technician verification, payment process or authenticated account may legitimately require additional information once that specific process is reached.
7.4 Mandatory and optional information
Where reasonably practicable, EXRA should distinguish information that is required for a particular process from information that is optional.
A field should not be designated as mandatory merely for convenience where the relevant service or process can reasonably be provided without that information.
Where information is mandatory, the requirement should be connected to an identified operational, contractual, security, legal or other legitimate purpose.
7.5 Role-based information collection
EXRA should tailor information collection according to the role and purpose of the relevant participant rather than applying identical information requirements to every platform user.
Client information requirements may therefore differ from technician, supplier, administrator or other participant information requirements.
The information requested from each role should be reasonably connected to the functions, obligations, permissions or activities associated with that role.
7.6 Project and assessment information
Technicians and other authorised project participants should collect, record or submit only information reasonably connected to the assigned assessment, project, support activity, safety requirement or other authorised EXRA process.
Access to a project or site should not be treated as authority to collect, photograph, record or document unrelated persons, property, communications or activities unnecessarily.
7.7 Photographs, video and project evidence
Photographs, video or other visual evidence should be captured only where reasonably relevant to an assessment, project milestone, technical condition, completion record, warranty matter, safety issue or other authorised project purpose.
Where reasonably practicable, irrelevant personal information appearing incidentally within project evidence should be avoided, excluded, obscured or otherwise appropriately limited.
The ability to upload photographs or video through an EXRA platform feature does not create unrestricted permission to record people or property unrelated to the authorised project purpose.
7.8 Technician and supplier verification
Where EXRA uses information to determine network eligibility, professional suitability, certification, project allocation, supplier status or verification status, EXRA should take reasonable steps appropriate to the significance of the decision to assess whether the relevant information is reliable and sufficiently current.
Verification may include appropriate review of business registration information, professional certifications, certificates of competence, service-region information, portfolio evidence or other records relevant to the role being assessed.
EXRA should not request verification information unrelated to the role, service or eligibility requirement being assessed.
7.9 Information received from third parties
Information received from clients, technicians, suppliers, verification providers, official sources or other authorised third parties should not automatically be treated as infallible merely because it originated from another source.
Where information may materially affect a project, account, verification outcome, payment, safety matter or other significant decision, EXRA should consider the reliability, age, context and source of the information before relying upon it.
7.10 Information supplied by the affected person
EXRA may generally rely on information supplied directly by an individual or authorised representative where it is reasonable to do so.
EXRA may nevertheless seek confirmation or verification where information is material to identity, account security, payment administration, network eligibility, professional qualification, project execution, legal compliance or another significant operational decision.
7.11 Conflicting, disputed or uncertain information
Where EXRA becomes aware that material information is disputed, inconsistent, incomplete or potentially inaccurate, EXRA should avoid presenting the information as established fact where doing so could materially affect another person.
Where appropriate, EXRA may temporarily identify the relevant information or status as unverified, disputed, incomplete or under review while reasonable verification steps are taken.
The existence of an allegation, complaint or automated indicator does not by itself establish that the underlying allegation or conclusion is factually correct.
7.12 Correction of inaccurate information
Where EXRA identifies or is informed that personal information used for a relevant purpose is materially inaccurate, incomplete, outdated or misleading, EXRA should take reasonably practicable steps to verify and, where appropriate, correct, update, annotate or otherwise address the information.
The appropriate action may depend on the purpose of the information, its source, the significance of the error and whether the underlying record must be preserved for legal, accounting, audit, historical or evidentiary purposes.
7.13 User-initiated corrections
EXRA may provide mechanisms through which affected persons can request the correction or updating of relevant personal information.
Depending on the information concerned, EXRA may require reasonable verification before applying a requested change, particularly where the change affects identity, payment administration, account security, legal records, professional verification, business information or another significant record.
A request to change information does not automatically require EXRA to alter a record where the requested change cannot reasonably be verified or where applicable law requires the original record to be preserved.
7.14 Historical records and audit trails
Maintaining accurate information does not always require EXRA to erase or overwrite an earlier record where that earlier record accurately reflects what occurred at the relevant time.
Where appropriate, EXRA may preserve historical records while recording subsequent corrections, amendments, status changes or other updates so that project, transaction, verification, support and operational histories remain accurate and auditable.
7.15 Derived information and internal classifications
Where EXRA creates an internal status, classification, eligibility outcome, risk indicator, project allocation decision or other derived information concerning a person, the information used and the significance attributed to the resulting outcome should be appropriate to the relevant purpose.
Derived information should not be presented as objectively established fact where it is based on incomplete, disputed, uncertain or probabilistic information.
7.16 Automated and system-generated information
Where information is generated automatically through technical systems, EXRA should consider the reliability and limitations of that information before using it for decisions that materially affect a person.
This principle may become relevant where EXRA introduces features involving automated fraud indicators, technician ranking, project routing, availability scoring, duplicate-submission detection, approximate location information or other system-generated assessments.
A machine-generated flag, score or classification should not automatically be treated as conclusive evidence of the underlying facts.
7.17 Outdated information
EXRA should consider whether personal information remains sufficiently current for the purpose for which it is being used.
Information that was accurate when originally collected may become unreliable over time, particularly where it relates to:
- contact information;
- service regions;
- professional certifications;
- business status;
- technician or supplier availability;
- authorised representatives;
- account permissions; or
- other information capable of changing over time.
Where the continued accuracy of information is material to a process, EXRA may require reasonable updating or re-verification.
7.18 Duplicate information and unnecessary copies
EXRA should avoid creating unnecessary duplicate copies of personal information where the same legitimate operational purpose can reasonably be achieved through an appropriately controlled central or authoritative record.
Where duplicate records are operationally necessary, reasonable controls should be used to reduce the risk that inconsistent, incomplete or outdated versions are relied upon.
7.19 Special or higher-risk personal information
EXRA should apply greater restraint when determining whether special, sensitive or otherwise higher-risk personal information is necessary.
Such information should not be requested merely to make verification or administration easier where a less intrusive method can reasonably achieve the same legitimate purpose.
Where a proposed feature would introduce materially higher-risk processing, including biometric or similarly sensitive verification, EXRA should assess the necessity, proportionality, legal requirements and available alternatives before introducing the processing.
7.20 New forms, fields and integrations
Before introducing a materially new form field, mandatory data requirement, integration or collection mechanism, EXRA should assess:
- whether the information is necessary for an identified purpose;
- whether a less intrusive alternative could reasonably achieve the same purpose;
- how the accuracy and quality of the information will be maintained;
- whether the field should be mandatory or optional;
- who will have access to the information; and
- whether applicable privacy information requires updating.
A possible future use of information, without a sufficiently defined purpose, should not ordinarily be treated as sufficient reason to collect the information.
7.21 Information quality does not permit unlimited verification
EXRA's responsibility to maintain appropriate information quality does not justify unlimited verification, monitoring or collection.
Verification measures should be proportionate to the significance, sensitivity, risk and intended use of the information concerned.
A low-risk enquiry, for example, should not ordinarily require the same level of verification as a process involving professional network access, project-site access, significant financial activity, sensitive account permissions or another higher-risk function.
7.22 Relationship with retention
Information that is no longer necessary should not be kept indefinitely merely for the purpose of maintaining information quality.
The periods for which EXRA retains information, the criteria used to determine those periods and the circumstances requiring deletion, preservation, restriction or anonymisation are addressed separately under the retention provisions of this Privacy Policy.
7.23 Relationship with data-subject rights
Requests by affected persons to access, correct, update, restrict or delete personal information will be handled in accordance with the applicable data-subject rights provisions of this Privacy Policy and the privacy law applicable to the relevant processing activity.
7.24 International application
The principles in this Section form part of EXRA's general privacy and information-governance standard regardless of where a particular processing activity occurs.
Where applicable law in a particular jurisdiction imposes stricter or additional requirements concerning data minimisation, accuracy, verification, correction or information quality, EXRA will apply those additional requirements to the relevant processing activity.
7.25 Internal EXRA information-quality standard
EXRA seeks to design its systems and operational processes so that privacy, necessity and information quality are considered both when information is collected and when that information is subsequently relied upon.
Before collecting or materially relying upon personal information, EXRA should consider whether:
- the information is genuinely required;
- the information is relevant to the purpose;
- the amount collected is proportionate;
- the source is appropriate;
- the information is sufficiently accurate for the intended decision;
- the information remains sufficiently current;
- any material information is disputed;
- additional verification is proportionate;
- an appropriate correction mechanism is available where required; and
- unnecessary duplicate records can reasonably be avoided.
Information governance should therefore be incorporated into EXRA's platform and operational design rather than addressed only after an information-quality or privacy problem occurs.
Sharing, Disclosure and Third Parties
8.1 General principle
EXRA does not treat possession of personal information as permission to distribute that information freely.
Personal information may be shared, disclosed or made accessible only where there is an identified operational, contractual, legal, security or other lawful purpose and where the recipient's access is reasonably connected to that purpose.
Where reasonably practicable, EXRA limits the information disclosed to what the recipient requires for the relevant activity.
8.2 EXRA does not sell personal information
EXRA does not sell personal information.
EXRA does not disclose personal information to unrelated organisations in exchange for payment merely so that those organisations may independently advertise to, profile or otherwise commercialise affected persons.
Payment to a technician, supplier, payment provider, hosting provider or other service provider for performing an authorised service does not mean that EXRA has sold the personal information reasonably necessary to perform that service.
8.3 Project participants
EXRA may share relevant project information with authorised technicians, suppliers and other project participants where this is reasonably necessary to assess, coordinate, execute, supply, complete or support a project.
Access should be based on the participant's authorised role, project association and reasonable operational need.
Participation in an EXRA project does not provide unrestricted access to the client's, technician's, supplier's or another participant's information.
Information obtained through an EXRA project should not be used for unrelated marketing, solicitation or other independent purposes without an appropriate lawful justification.
8.4 Payment and service providers
EXRA may use authorised third-party providers for functions such as:
- payment processing;
- hosting and cloud infrastructure;
- email and communications;
- security services;
- identity or business verification;
- authentication;
- analytics or similar technologies where lawfully introduced; and
- other technical or operational platform services.
These providers may receive or process information reasonably necessary to provide the relevant service.
Some providers may process information solely on EXRA's behalf, while others may have independent legal or regulatory responsibilities.
EXRA should assess the nature of each material processing relationship and apply appropriate contractual, privacy and security controls where required.
8.5 Operators, processors and Data Processing Agreements
Where another organisation processes personal information on EXRA's behalf, EXRA seeks to apply appropriate contractual and organisational safeguards in accordance with the privacy law applicable to that processing.
Where required, this may include a Data Processing Agreement, operator agreement or equivalent arrangement addressing matters such as:
- authorised processing instructions;
- purpose and scope of processing;
- confidentiality;
- security measures;
- authorised personnel;
- subprocessors or downstream providers;
- security-incident notification;
- retention and deletion;
- international transfers; and
- other safeguards required by applicable law or the relevant processing relationship.
The need for a Data Processing Agreement or equivalent arrangement depends on the actual processing relationship and is not determined merely by the title or category of the service provider.
8.6 Professional advisers, authorities and legal disclosures
EXRA may disclose relevant information to professional advisers or authorised administrative providers where reasonably necessary for legitimate legal, accounting, audit, tax, insurance, compliance, dispute-resolution or similar business purposes.
EXRA may also disclose personal information where disclosure is required or lawfully authorised by applicable law, a valid court process, regulatory requirement or another legitimate legal mechanism.
A request for information is not automatically accepted merely because the requester claims to represent a government body, regulator, law-enforcement authority or similar organisation.
Where reasonably possible and legally permitted, EXRA should assess the identity, authority, scope and validity of the request before disclosure.
8.7 User-directed and safety-related disclosures
EXRA may disclose information according to a valid instruction from an appropriately authorised user, subject to reasonable identity, authority, security and legal checks.
This may include circumstances where an authorised client requests that another representative or project participant be provided with access to relevant project information.
Where permitted by applicable law, EXRA may also disclose limited information where reasonably necessary to respond to a genuine emergency, material safety risk, threat of serious harm or another circumstance requiring protection of legitimate interests.
These circumstances do not provide general permission for unrestricted information-sharing.
8.8 Confidentiality, security and onward use
Persons and organisations receiving personal information through an authorised EXRA process are expected to protect that information and use it only for the authorised purpose, subject to applicable law, contractual obligations and other relevant safeguards.
Where appropriate, EXRA considers the recipient's security practices, confidentiality obligations and use of subprocessors or other downstream service providers.
A recipient should not pass information to another party or repurpose it for unrelated activities merely because that recipient originally obtained lawful access through EXRA.
Where access to personal information exists because of a particular project, assignment, account role or service relationship, that access should be reviewed, restricted or removed when the relevant need ends, subject to legitimate retention, audit or legal requirements.
8.9 International recipients and changing providers
EXRA may use service providers or authorised recipients located in countries different from the country in which EXRA or the affected person is located.
Where information is transferred or made accessible across national borders, EXRA will assess the privacy and data-protection requirements applicable to that processing and apply appropriate safeguards where required.
EXRA may change service providers as its platform, geographic reach and operational requirements develop.
Before introducing a provider that materially changes the nature, location or risk of personal information processing, EXRA should assess whether its privacy notices, contracts, transfer mechanisms or other safeguards require updating.
More detailed requirements governing international processing and cross-border transfers are addressed separately in the international-transfer provisions of this Privacy Policy.
8.10 Controlled access and purpose limitation
Access to personal information should remain connected to the purpose for which that access was granted.
Information supplied for one authorised EXRA activity should not automatically be reused by a recipient for an unrelated purpose merely because that recipient obtained access through the original activity.
Where proportionate to the nature and risk of a disclosure, EXRA may maintain records identifying relevant details such as the recipient, purpose, authority, information disclosed and date of disclosure.
EXRA seeks to design information-sharing into its systems as controlled access for defined purposes rather than unrestricted movement of personal information between platform participants.
International and Cross-Border Transfers
9.1 General principle
EXRA may process, transfer or make personal information accessible across national borders where this is reasonably necessary for its digital platform, projects, service providers, business operations or international expansion.
Cross-border processing does not remove EXRA's responsibility to consider the privacy and data-protection requirements applicable to the information concerned.
9.2 When a cross-border transfer may occur
International processing or transfer may occur, depending on the relevant system or activity, where:
- EXRA uses hosting, cloud or infrastructure services located in another country;
- a payment provider processes an authorised transaction internationally;
- an email, communications, security, authentication or verification provider operates across national borders;
- an authorised project or platform participant accesses information from another country;
- EXRA introduces a service provider with international processing infrastructure; or
- EXRA begins providing services or operating projects in additional countries.
The inclusion of these circumstances in this Privacy Policy does not mean that every EXRA record is currently transferred internationally.
Whether a cross-border transfer occurs depends on the particular provider, project, user location, system architecture and processing activity involved.
9.3 Appropriate legal safeguards
Before materially transferring or making personal information accessible across national borders, EXRA should identify the legal requirements applicable to that transfer and apply an appropriate transfer mechanism or safeguard where required.
Depending on the applicable jurisdiction, this may include:
- recognition that the destination provides an adequate level of protection;
- appropriate contractual safeguards;
- standard or approved contractual clauses where legally recognised;
- binding or equivalent organisational arrangements where applicable;
- valid consent where applicable law permits reliance on consent for the specific transfer;
- another legally recognised transfer mechanism; or
- a lawful exception applicable to the specific circumstances.
The appropriate safeguard depends on the countries involved, the nature of the information, the recipient, the purpose of the transfer and the law applicable to the processing.
9.4 Service providers and infrastructure
EXRA may use service providers whose infrastructure, personnel, subprocessors or technical systems are located outside South Africa or outside the country in which the affected person is located.
Before introducing a provider that materially changes where personal information is processed, EXRA should consider:
- the provider's processing role;
- the countries in which processing occurs;
- the categories of information involved;
- the purpose of the processing;
- the provider's security measures;
- applicable contractual protections;
- use of subprocessors;
- international-transfer requirements; and
- whether EXRA's privacy documentation or agreements require updating.
9.5 European Union and EEA processing
This provision becomes relevant where a particular EXRA processing activity is subject to European Union or European Economic Area data-protection requirements.
Where such requirements apply to an international transfer, EXRA will assess and apply the transfer mechanism and safeguards required for that processing activity.
Additional regional privacy information or contractual safeguards may be introduced where necessary rather than attempting to place every jurisdiction-specific requirement into the global Privacy Policy.
9.6 South African processing
EXRA currently operates from South Africa.
Where personal information is transferred from South Africa to a recipient or processing environment in another country, EXRA will assess the requirements of POPIA and any other applicable law before relying on that transfer.
South Africa therefore remains EXRA's current home privacy jurisdiction while this Privacy Policy is structured so that additional legal requirements can be applied as EXRA expands internationally.
9.7 No uncontrolled international transfer
The fact that EXRA operates digitally or expands internationally does not provide unrestricted authority to move personal information between countries, systems, providers or participants.
Cross-border access or transfer should remain connected to an identified lawful purpose and, where reasonably practicable, should be limited to the information necessary for that purpose.
International access to one authorised project or system does not automatically create permission to access unrelated EXRA information.
9.8 Expansion into new countries or providers
Where EXRA enters a new country, introduces a materially new international provider or changes the geographic location of significant processing, the relevant privacy and compliance requirements should be reviewed before the new processing becomes operational.
That review should consider matters such as:
- which privacy laws may apply;
- where information will be processed;
- whether a recognised international-transfer mechanism is required;
- whether additional contractual safeguards are necessary;
- whether users require additional notice, consent or rights mechanisms; and
- whether EXRA's Privacy Policy, regional notices or service-provider documentation requires updating.
International expansion should therefore trigger a privacy review rather than requiring EXRA to redesign its entire global privacy framework from the beginning.
9.9 Transparency
Where reasonably required by applicable law or the nature of the processing, EXRA will provide appropriate information concerning material international processing, relevant categories of recipients or safeguards applicable to the transfer.
Where a particular jurisdiction requires more detailed information than is appropriate for the global Privacy Policy, EXRA may provide a jurisdiction-specific privacy notice, supplement or other regional disclosure.
9.10 EXRA international transfer standard
EXRA seeks to maintain appropriate protection for personal information when that information moves between countries.
International expansion should not be treated as a reason to reduce the privacy, confidentiality, security or accountability safeguards applicable to personal information.
EXRA's objective is to support international platform growth while ensuring that cross-border processing remains connected to a legitimate purpose, an appropriate legal framework and safeguards proportionate to the information and risks involved.
Security and Protection of Personal Information
10.1 General security principle
EXRA seeks to protect the integrity, confidentiality and availability of personal information through technical, organisational and operational safeguards appropriate to the nature of the information, the processing activity and the risks involved.
Security measures should be proportionate to the likelihood and potential impact of unauthorised access, loss, misuse, alteration, disclosure, destruction or other compromise of personal information.
10.2 No absolute-security guarantee
EXRA cannot guarantee that any website, network, database, communication channel or digital system will be completely immune from security incidents.
EXRA therefore does not represent that personal information can never be compromised. Instead, EXRA seeks to maintain reasonable safeguards appropriate to identified risks and to improve those safeguards as technology, threats and platform operations develop.
10.3 Access controls and need-to-know principle
Access to personal information should be limited to authorised persons whose role or legitimate operational responsibility requires access to that information.
Account ownership, employment, technician participation, supplier participation or administrative status does not automatically justify unrestricted access to all EXRA information.
10.4 Authentication and account security
This provision becomes applicable as authenticated accounts, dashboards, portals or other protected platform functions are introduced.
EXRA may use security controls such as passwords, verification codes, session controls, role-based permissions, login monitoring, account recovery procedures or additional authentication measures where appropriate.
Authentication credentials should not be intentionally exposed to other users or stored in a manner that unnecessarily reveals them in readable form.
10.5 Role-based permissions
EXRA should structure platform permissions according to authorised roles, project association and operational need.
Where a person's role changes, a project ends or access is no longer required, relevant permissions should be reviewed and adjusted or removed as appropriate.
10.6 Protection of payment information
Payment-card and other sensitive payment credentials should, where reasonably practicable, be processed through authorised payment systems designed for that purpose rather than unnecessarily stored within EXRA's own platform.
EXRA may retain transaction references, payment status, amounts and other administrative records reasonably necessary to administer transactions without requiring storage of complete payment-card credentials.
10.7 Encryption and protective technologies
EXRA may use encryption, secure communication protocols, access restrictions, pseudonymisation or other protective technologies where appropriate to the information and processing risk.
The specific safeguards used may differ between systems and may evolve as EXRA's technology and security requirements develop.
10.8 Website and infrastructure security
EXRA may maintain safeguards designed to protect its website, servers, databases, applications and associated infrastructure against unauthorised access, malicious activity, technical vulnerabilities or accidental loss.
Depending on the relevant system, safeguards may include software updates, security monitoring, access restrictions, controlled backups, configuration controls, logging, malware protection or other appropriate measures.
10.9 Backups and availability
Where appropriate, EXRA may maintain controlled backups or recovery mechanisms designed to support restoration of information or platform functionality following a technical failure, security incident or other disruption.
Backup copies should remain subject to appropriate access, retention and security controls and should not become uncontrolled duplicate databases.
10.10 Security of project information
Project information, assessment evidence, photographs, documents and support records should be accessible only through authorised project or administrative processes.
Participants should not download, copy, distribute or retain project information beyond what is reasonably necessary for their authorised role, subject to applicable legal or contractual requirements.
10.11 Devices used by authorised participants
Where authorised participants access EXRA information through their own devices, reasonable care should be taken to prevent unauthorised persons from gaining access to project or personal information.
EXRA may introduce device, session, authentication or access requirements proportionate to the sensitivity and risk of the platform functionality involved.
10.12 Service-provider security
Where another organisation processes material personal information on EXRA's behalf, EXRA should consider whether that provider offers security safeguards appropriate to the nature and risk of the processing.
Where required, contractual arrangements should require the provider to establish and maintain appropriate security measures.
10.13 Confidentiality
Persons who obtain personal information through an authorised EXRA role should maintain appropriate confidentiality and should not disclose that information except where authorised, necessary for the proper performance of their responsibilities or required by law.
10.14 Internal and external security risks
EXRA's security assessment should consider both internal and external risks.
Internal risks may include inappropriate permissions, human error, unauthorised disclosure, weak account practices or misuse by an authorised participant.
External risks may include unauthorised account access, malicious software, phishing, credential attacks, system exploitation, fraud or other threats to EXRA infrastructure or users.
10.15 Human error and security awareness
EXRA should seek to ensure that persons handling personal information understand the confidentiality and security expectations relevant to their role.
Where appropriate, EXRA may provide guidance, procedures, training or access restrictions intended to reduce accidental disclosure, improper handling or misuse of personal information.
10.16 Security monitoring and logs
EXRA may maintain proportionate security logs and monitoring designed to identify unauthorised access, suspicious activity, technical failures, abuse or potential security incidents.
Security monitoring should be used for legitimate security and platform-integrity purposes and should not become unrestricted surveillance of unrelated user behaviour.
10.17 Security testing and review
Security controls should not be treated as permanently adequate merely because they were appropriate when first implemented.
EXRA should periodically review relevant safeguards and update them where changing technology, platform functionality, identified vulnerabilities, security incidents or new risks make changes reasonably necessary.
10.18 Security-by-design for new features
Materially new EXRA features should be assessed for security implications before deployment where they introduce new access to personal information, new integrations, new user roles, sensitive processing or materially increased risk.
Security requirements should therefore be considered during design and implementation rather than only after a feature becomes operational.
10.19 Security incidents
Where EXRA becomes aware of a suspected security incident involving personal information, EXRA should assess the nature and scope of the incident, seek to contain or limit further exposure, preserve relevant evidence, investigate the circumstances and take reasonable remedial action.
Additional requirements concerning notification of affected persons, regulators or other authorities will be handled according to applicable law and the relevant security-incident provisions of this Privacy Policy.
10.20 User contribution to account security
Users can contribute to account and information security by protecting authentication credentials, maintaining appropriate control of authorised devices and reporting suspected unauthorised access through available EXRA support or security channels.
Contractual obligations concerning account misuse or user conduct are addressed separately under the applicable Terms of Service or participant terms.
10.21 Security reports
EXRA may provide channels through which users or other persons can report suspected account compromise, security vulnerabilities, unauthorised access or other information-security concerns.
Reports should include sufficient relevant information to allow EXRA to assess the concern without encouraging unnecessary disclosure of personal or confidential information.
10.22 Security does not justify unlimited collection
The need to protect EXRA's platform does not itself justify unlimited collection, monitoring or surveillance of personal information.
Security measures should remain proportionate to the identified threat, sensitivity of the information, purpose of the processing and potential consequences of compromise.
10.23 International security standard
EXRA seeks to apply reasonable security principles across its platform regardless of where processing occurs.
Where a jurisdiction, industry standard, contractual relationship or particular category of information requires additional safeguards, EXRA will assess and apply those requirements to the relevant processing activity.
10.24 Ongoing security responsibility
EXRA seeks to treat information security as an ongoing governance and platform responsibility rather than a one-time technical configuration.
The objective is to identify and reduce reasonable security risks, improve controls as EXRA develops and respond appropriately when weaknesses or incidents are identified, without representing that every possible risk can be eliminated.
Security Incidents, Data Breaches and Notification
11.1 General incident-response principle
Where EXRA becomes aware of a suspected or confirmed security incident involving personal information, EXRA will seek to respond in a manner appropriate to the nature, scale and potential consequences of the incident.
The response may include identifying the incident, containing further exposure, protecting affected systems, preserving relevant evidence, determining the information and persons affected, assessing applicable legal obligations and taking reasonable remedial action.
11.2 Security incident versus reportable data breach
Not every technical malfunction, attempted attack, suspicious event or security alert necessarily means that personal information has been compromised or that a legally reportable personal-data breach has occurred.
EXRA will assess the circumstances of the incident, including whether personal information was lost, destroyed, altered, disclosed, accessed, acquired or otherwise processed without appropriate authorisation.
11.3 Immediate response and containment
Where reasonably practicable, EXRA should take prompt steps to prevent or limit additional unauthorised access, disclosure, loss or other harm arising from a security incident.
Depending on the circumstances, those steps may include restricting compromised accounts, terminating affected sessions, changing permissions, isolating systems, temporarily disabling vulnerable functionality, securing exposed records or contacting an affected service provider.
11.4 Incidents involving service providers
Where an operator, processor or other authorised provider becomes aware of a security compromise involving personal information processed on EXRA's behalf, the provider should notify EXRA in accordance with applicable law and relevant contractual requirements.
EXRA should maintain appropriate incident- notification expectations in material processing arrangements where the nature of the relationship requires them.
11.5 Incident assessment
As far as reasonably possible, EXRA should assess:
- what occurred;
- when the incident occurred;
- when EXRA became aware of it;
- which systems or services were affected;
- what categories of personal information were involved;
- which persons may have been affected;
- whether information was actually accessed or acquired;
- who may have obtained access, where known;
- the possible consequences of the incident;
- whether the incident remains active; and
- what corrective or protective measures are available.
11.6 Notification to regulators or authorities
Where applicable law requires a security compromise or personal-data breach to be reported to a privacy, data-protection or other competent authority, EXRA will seek to make the required notification within the period and through the process applicable to that incident.
Notification thresholds and deadlines may differ between jurisdictions. EXRA will therefore assess the legal requirements relevant to the particular incident rather than assuming that one reporting rule applies globally.
11.7 Notification to affected persons
Where applicable law requires affected persons to be notified, EXRA will seek to provide notification in an appropriate manner that enables those persons to understand the incident and take reasonable protective measures.
The requirement to notify affected persons will depend on the applicable law, nature of the compromise, information involved and other relevant circumstances.
11.8 Information included in a notification
Depending on applicable law and the information reasonably available, a security notification may include:
- a description of what occurred;
- when EXRA became aware of the incident;
- the categories of information concerned;
- possible consequences;
- measures taken or proposed by EXRA;
- reasonable protective steps the affected person may consider;
- appropriate EXRA contact information; and
- other information required by the law applicable to the incident.
11.9 Timing and incomplete information
EXRA should not unnecessarily delay a legally required notification merely because every fact concerning the incident has not yet been established.
Where permitted by applicable law, EXRA may provide an initial notification based on information reasonably available at the time and supplement or update that notification as the investigation develops.
11.10 Lawful delay or restriction of notification
Where applicable law, a competent regulator, court or other lawful authority permits or requires a notification to be delayed, restricted or provided through a particular method, EXRA will comply with the applicable requirement.
11.11 Accuracy during incident communications
EXRA should seek to communicate confirmed information accurately and should distinguish established facts from matters that remain under investigation.
EXRA should not knowingly identify or accuse a particular person, technician, supplier, service provider or other party as responsible for an incident before there is an appropriate factual basis for doing so.
11.12 Protective measures for affected persons
Where appropriate, EXRA may recommend reasonable protective actions to affected persons according to the nature of the incident.
Such recommendations may include changing authentication credentials, reviewing suspicious account activity, enabling additional authentication controls, being alert to phishing or fraudulent communications, contacting an appropriate payment provider or contacting EXRA support.
Protective guidance should be proportionate to the information and risks actually involved.
11.13 Incident records and evidence
EXRA may preserve records reasonably necessary to investigate, document and respond to a security incident.
These records may include technical logs, access records, communications, affected-system information, response actions, notifications and other relevant evidence.
Information reasonably required for an incident investigation, legal obligation, dispute or evidentiary purpose may be retained even where ordinary deletion processes would otherwise apply.
11.14 Remediation and lessons learned
Following a material incident, EXRA should assess whether reasonable changes to technical controls, permissions, procedures, provider arrangements, training or platform design are necessary to reduce the likelihood or consequences of a similar incident occurring again.
EXRA's objective is to reduce identifiable risks and improve its safeguards as weaknesses or incidents become known rather than to represent that every possible security problem can be eliminated.
11.15 Incidents caused by users or project participants
The source of a security incident does not remove EXRA's responsibility to assess the effect of that incident on personal information under EXRA's responsibility.
Where a client, technician, supplier, account user, service provider or other participant caused or materially contributed to an incident, separate contractual, disciplinary, recovery or legal rights may apply under the relevant Terms of Service, participant terms or applicable law.
11.16 No admission of liability merely by notification
Providing a security notification, cooperating with an investigation, taking protective measures or carrying out remedial action does not by itself constitute an admission of legal liability by EXRA or another party.
Any question of legal responsibility or liability will be determined according to the applicable law, contractual arrangements and circumstances of the incident.
11.17 International incident response
Where an incident affects personal information subject to the laws of more than one country, EXRA should assess the notification, regulatory, timing and user-communication requirements applicable in the relevant jurisdictions.
Compliance with the requirements of one jurisdiction does not automatically mean that all obligations arising in another affected jurisdiction have been satisfied.
11.18 Ongoing incident-response standard
EXRA seeks to maintain an incident-response process that enables security concerns to be recorded, assessed, contained, investigated and remediated in a proportionate manner.
Where required, that process should also support regulator notification, affected-person communication, evidence preservation and post-incident review.
Security incidents should therefore be treated as events requiring appropriate investigation and improvement rather than as matters to be ignored or concealed merely because their disclosure may be inconvenient.
Retention, Deletion and Record Preservation
12.1 General retention principle
EXRA retains personal information only for as long as reasonably necessary for the purpose for which it was collected or subsequently lawfully processed, unless a longer period is required or permitted by applicable law, contract, legal claim, regulatory requirement or another lawful justification.
The appropriate retention period may differ according to the type of information, the relevant project or relationship, the purpose for which the information is held and the legal or operational requirements applicable to that record.
12.2 Purpose-based retention
EXRA does not apply one universal retention period to every category of personal information.
Retention should be determined according to the purpose, significance and circumstances associated with the relevant record.
Information should not be retained indefinitely merely because storage remains technically available.
12.3 Project and assessment records
EXRA may retain project, assessment, execution, monitoring, completion, handover and related records for periods reasonably necessary to administer the project, maintain an accurate project history, provide support, administer applicable warranties, resolve disputes and satisfy legitimate legal, contractual or business requirements.
These records may include project scopes, assessment findings, approvals, execution evidence, photographs, completion records, relevant communications and other information forming part of the authorised project history.
12.4 Financial and transaction records
EXRA may retain invoices, payment records, transaction references, receipts, credits, refunds, supplier records, technician payment records and other financial information where retention is reasonably necessary for accounting, taxation, reconciliation, audit, dispute-resolution or other lawful purposes.
A request to close an account or end a project does not automatically require EXRA to destroy financial records that remain subject to legitimate legal, accounting or evidentiary requirements.
12.5 Technician and supplier records
EXRA may retain technician and supplier information for as long as reasonably necessary to administer network participation, verification, project history, payments, procurement, quality records, complaints, disputes, legal obligations and other legitimate operational requirements.
Where participation ends, EXRA should review whether all information contained in an active technician or supplier profile remains necessary rather than automatically preserving the complete active-profile dataset indefinitely.
12.6 Account and dashboard information
Where EXRA accounts, portals or dashboards are introduced, active account information may be retained while the account remains operational and for an appropriate period afterward where records remain reasonably necessary for project history, security, dispute resolution, legal compliance, financial administration or another legitimate purpose.
Closing or deactivating an account does not automatically require immediate deletion of every historical record associated with that account.
12.7 Waiting-list and availability information
Information collected solely for a waiting-list, network-availability or future-service purpose should not ordinarily be retained indefinitely after that purpose has expired or become irrelevant.
EXRA should periodically review dormant waiting-list and availability information and determine whether continued identifiable retention remains reasonably justified.
12.8 Warranty and support information
Warranty, diagnostic and post-project support records may be retained for periods reasonably necessary to administer the relevant warranty or support process, maintain evidence of the project history, investigate reported issues, address subsequent disputes or meet other lawful requirements.
12.9 Security, complaint and investigation records
Security, fraud-prevention, complaint, investigation or incident records may be retained where reasonably necessary to investigate the matter, preserve evidence, protect legal rights, comply with reporting obligations, demonstrate how EXRA responded or reduce the likelihood of similar incidents occurring again.
Ordinary deletion processes should not require EXRA to destroy information that remains legitimately required for an active investigation or related legal purpose.
12.10 Legal holds, disputes and proceedings
Where information is relevant to an existing or reasonably anticipated legal claim, regulatory investigation, dispute, complaint, audit or other formal proceeding, EXRA may preserve the relevant information for as long as reasonably necessary to establish, exercise or defend legal rights or comply with applicable obligations.
Ordinary deletion or disposal processes may be suspended for affected records while such a preservation requirement remains in effect.
12.11 Records used for material decisions
Where EXRA uses personal information to make a material decision concerning an individual, technician, supplier, account holder or other affected person, EXRA should retain sufficient relevant records for any period required by applicable law or for an appropriate period that supports legitimate review, accountability or access rights.
12.12 Deletion, destruction and de-identification
When EXRA is no longer authorised or reasonably required to retain personal information, EXRA should delete, destroy or appropriately de-identify that information as soon as reasonably practicable, subject to applicable technical, legal and operational requirements.
Where information is destroyed, reasonable measures should be used to prevent the information from remaining readily reconstructable or recoverable in an intelligible form through ordinary access.
12.13 De-identified or anonymised information
Where information has been genuinely de-identified or anonymised so that it no longer reasonably identifies the relevant person under applicable law, EXRA may retain or use that information for legitimate purposes such as statistics, operational analysis, research, security analysis or platform improvement, subject to appropriate safeguards.
Removing a name alone should not automatically be treated as sufficient anonymisation where other information still enables the person to be reasonably identified.
12.14 Restriction instead of immediate deletion
In circumstances recognised by applicable law or reasonably required by the relevant process, EXRA may restrict the use of personal information instead of immediately deleting it.
This may become relevant where information is disputed, temporarily required for verification, necessary for the establishment or defence of legal rights, or otherwise subject to a legitimate preservation requirement.
Restricted information should not be used for unrelated ordinary processing merely because EXRA continues to retain the record.
12.15 Backups and deletion
Personal information may temporarily remain within controlled backup, archive or disaster-recovery systems after deletion from active systems where immediate deletion from every backup is not reasonably practicable.
Information remaining within such systems should remain subject to appropriate security and access controls and should not ordinarily be restored into active use except where necessary for legitimate recovery, security, legal or continuity purposes.
12.16 Service-provider retention
Where a service provider processes personal information on EXRA's behalf, EXRA should use appropriate contractual or operational controls concerning the retention, return, deletion, destruction or de-identification of that information where required by the processing relationship and applicable law.
12.17 Requests for deletion
A person may request deletion or destruction of personal information where applicable law provides that right.
EXRA will assess the request against the purpose for which the information is held, applicable legal obligations, contractual requirements, financial recordkeeping requirements, legal claims, security needs and other lawful grounds for continued retention.
A deletion request therefore does not necessarily require immediate destruction of every record associated with the requesting person.
12.18 Expiry of the original purpose
Where the original purpose for retaining personal information ends, EXRA should assess whether another lawful reason continues to justify retention.
Personal information should not simply remain indefinitely because the relevant system has not been reviewed or because storage capacity remains available.
12.19 Internal Retention Schedule
EXRA intends to maintain an internal retention schedule identifying appropriate retention or review periods for material categories of personal information and the legal, operational, security or other reasons supporting those periods.
The internal retention schedule may distinguish between categories such as:
- general enquiries;
- project and assessment records;
- financial and transaction records;
- technician verification records;
- supplier and procurement records;
- account records;
- security and technical logs;
- waiting-list information;
- warranty and support records;
- complaints and investigations; and
- other categories introduced as EXRA's platform develops.
Exact numerical retention periods will be determined through that internal governance process and may be updated as applicable laws, platform functions, contractual requirements, project operations and geographic expansion develop.
EXRA does not assign arbitrary numerical retention periods merely for the purpose of making this Privacy Policy appear more specific.
12.20 International retention requirements
Where different jurisdictions impose different mandatory retention, preservation or deletion requirements, EXRA will apply the requirements relevant to the affected processing activity.
A jurisdiction-specific requirement may therefore require certain information to be retained longer, deleted sooner or handled differently from EXRA's ordinary internal retention schedule.
12.21 No unnecessary permanent archive
EXRA does not intend to maintain personal information as a permanent identifiable archive merely because storage is technically available.
Continued retention should remain connected to a lawful purpose, legitimate recordkeeping requirement, project need, legal obligation, security requirement, evidentiary purpose or other appropriate justification.
Where continued identifiable retention is no longer justified, information should be appropriately reviewed, restricted, de-identified, deleted or destroyed in accordance with applicable requirements.
Privacy Rights and Requests
13.1 Rights depend on applicable law
Individuals may have rights concerning personal information processed by EXRA under applicable privacy and data-protection laws.
The precise rights, conditions, exceptions, procedures and response periods may differ according to the jurisdiction and processing activity concerned.
EXRA will assess a request according to the law applicable to that request rather than representing that every privacy right applies identically in every jurisdiction.
13.2 Right to know and request access
Where applicable law provides the right, a person may ask whether EXRA processes personal information relating to them and may request access to that information and relevant information concerning its processing.
Access may include information concerning the purposes of processing, categories of personal information, relevant recipients and other information required by applicable law.
13.3 Correction of inaccurate information
A person may request correction or updating of personal information that is inaccurate, incomplete, misleading, outdated or otherwise subject to correction under applicable law.
EXRA may request reasonable supporting information where necessary to establish the correct information or protect the integrity of project, payment, verification or other material records.
13.4 Deletion or destruction requests
A person may request deletion or destruction of personal information where applicable law provides that right.
EXRA will evaluate such requests against its lawful authority or obligation to retain the relevant information.
13.5 Deletion is not absolute
A request for deletion does not automatically require EXRA to delete information that it remains legally or legitimately authorised or required to retain.
EXRA may retain relevant information where necessary for purposes including legal compliance, financial recordkeeping, project administration, warranty administration, security, fraud prevention, dispute resolution, legal claims, investigations or other lawful grounds.
13.6 Right to object
Where applicable law provides the right, a person may object to particular processing of personal information.
EXRA will assess the objection according to the legal basis, purpose and circumstances of the relevant processing and any rights or exceptions recognised by applicable law.
13.7 Withdrawal of consent
Where EXRA relies specifically on consent as the lawful basis for particular processing, the person may withdraw that consent where applicable law permits.
Withdrawal does not ordinarily invalidate processing that was lawfully performed before the withdrawal became effective.
Withdrawal of consent relating to one processing activity does not automatically cancel an unrelated project, payment, contractual obligation or other lawful relationship with EXRA.
13.8 Restriction of processing
Where applicable law provides the right, a person may request that EXRA restrict particular processing instead of deleting the relevant information.
Restricted information may continue to be stored or processed where permitted for legal claims, regulatory obligations, protection of rights, record preservation or other lawful purposes.
13.9 Data portability
Where applicable law provides a right to data portability and the relevant legal conditions are satisfied, a person may request eligible personal information in a structured, commonly used or machine-readable form.
Where legally required and technically feasible, eligible information may also be transferred to another provider or recipient according to the applicable legal framework.
Data portability does not apply automatically to every category of information held by EXRA.
13.10 Automated decisions
Rights relating specifically to automated decision-making, profiling or decisions produced through automated systems are addressed separately in Section 16 of this Privacy Policy.
13.11 Identity verification
Before providing access to personal information or acting on a request that could materially affect an account, record or person's rights, EXRA may take reasonable steps to verify the identity or authority of the requester.
Verification measures should be proportionate to the sensitivity of the information, the nature of the request and the risk of unauthorised disclosure, alteration or deletion.
13.12 Requests submitted by representatives
Where another person submits a privacy request on behalf of an individual or organisation, EXRA may require reasonable evidence showing that the representative is authorised to act for the relevant person.
Additional verification may be required where necessary to protect the affected person's information or rights.
13.13 Rights and information belonging to other people
EXRA may limit, redact or otherwise appropriately handle information where providing it to a requester would unlawfully disclose personal information, confidential information, security information or protected rights belonging to another person or organisation.
A person's right of access to their own information does not automatically create a right to receive unrelated confidential or personal information concerning technicians, suppliers, employees, clients, service providers or other third parties.
13.14 Requests that cannot be fully granted
Where EXRA cannot fully comply with a request because an exception, legal obligation, conflicting right or other lawful restriction applies, EXRA may refuse or partially fulfil the request to the extent permitted by applicable law.
Where required, EXRA should explain the relevant outcome and any complaint, review or regulatory mechanism available to the requester.
13.15 Repetitive, excessive or abusive requests
EXRA may take measures permitted by applicable law where privacy requests are manifestly unfounded, excessive, repetitive or otherwise abusive.
Any fee, refusal, limitation or other measure should only be applied where legally permitted and should not be used merely to discourage legitimate privacy requests.
13.16 Fees
EXRA will not impose a fee for exercising privacy rights except where a fee is permitted by applicable law or an applicable access-to- information procedure.
Where a lawful fee applies, EXRA should communicate the relevant requirement through the applicable process.
13.17 Response periods
EXRA will seek to respond to valid privacy requests within the period required by applicable law.
Where the applicable legal framework permits additional time because of complexity, request volume or another recognised circumstance, EXRA may use that additional period subject to any notice or other requirement imposed by applicable law.
13.18 How privacy requests may be made
Privacy-related requests may be submitted through the contact method identified by EXRA for privacy enquiries or through another method required or accepted under applicable law.
EXRA may introduce dedicated request forms, account controls, identity-verification processes or privacy-management tools as the platform develops.
13.19 Records of privacy requests
EXRA may retain appropriate records of privacy requests, verification steps, correspondence and outcomes where reasonably necessary to demonstrate compliance, prevent fraud or misuse, resolve disputes, maintain accountability or satisfy legal obligations.
A request for deletion does not necessarily require EXRA to destroy a compliance record showing that the request itself was received and handled where continued retention of that record is lawful.
13.20 Privacy rights and unrelated obligations
Exercising a privacy right does not automatically cancel a project, reverse a payment, terminate a valid contract, remove lawful financial obligations or invalidate other rights and obligations unrelated to the processing affected by the request.
Privacy rights will be handled according to applicable privacy and data-protection law, while contractual, commercial and project-related matters remain governed by the applicable Terms of Service, project terms and mandatory law.
Direct Marketing and Communication Preferences
14.1 Service communications versus marketing
EXRA may send communications reasonably necessary to administer a person's enquiry, account, assessment, transaction, project, warranty, support request or other relationship with EXRA.
These communications may include enquiry responses, quotations, approvals, payment confirmations, assessment notifications, project-status updates, technician or supplier coordination notices, account or security messages, warranty and support communications, privacy notices and other communications reasonably necessary to operate the relevant relationship.
Such operational or service communications are not automatically treated as optional promotional marketing merely because they are sent by email, SMS, messaging service or another electronic channel.
14.2 Direct marketing
Direct marketing generally refers to communications directed to a particular person for the purpose of promoting EXRA's services, opportunities, offers or other commercial activities, subject to the definition and requirements imposed by applicable law.
Direct-marketing channels may include email, SMS, telephone communications, messaging platforms, direct messages, push notifications or other communication technologies introduced by EXRA.
14.3 Lawful basis for direct marketing
EXRA should process personal information for direct marketing only where there is an appropriate lawful basis under the privacy, communications and marketing laws applicable to the relevant activity.
Where consent is required, EXRA should obtain appropriate consent before sending the relevant marketing communication.
Where applicable law permits direct marketing under another recognised basis or existing-customer relationship, EXRA may rely on that basis only where the relevant legal conditions are satisfied.
14.4 Marketing consent is separate from service acceptance
Acceptance of EXRA's Terms of Service, Project Terms, quotation, payment conditions or other contractual terms does not by itself constitute unlimited consent to receive optional promotional marketing.
Where marketing consent is legally required, EXRA should present that consent separately and clearly enough for the person to understand that the marketing choice is distinct from acceptance of the service or contractual relationship.
Acknowledgement of this Privacy Policy also does not automatically constitute consent to every form of direct marketing.
14.5 No forced optional marketing consent
EXRA should not make optional direct-marketing consent a condition of obtaining an unrelated project, assessment, account or service where applicable law requires marketing consent to be freely given.
Refusing optional marketing should not, by itself, prevent a person from using an otherwise available EXRA service.
14.6 Existing-customer communications
Where applicable law permits certain direct marketing to an existing customer without requiring a new marketing consent, EXRA may rely on that permission only within the conditions and limitations imposed by the relevant law.
An existing commercial relationship does not give EXRA an unrestricted right to use customer information for every future promotional purpose.
14.7 Marketing preferences and opt-out
Where applicable law provides the right, a person may withdraw marketing consent, object to eligible direct marketing or use an available unsubscribe or preference mechanism.
EXRA should honour valid marketing objections, withdrawals and unsubscribe requests within the period and manner required by applicable law.
EXRA may provide different preference controls for different communication channels as the platform develops.
14.8 Suppression and opt-out records
EXRA may retain limited personal information reasonably necessary to record and respect a marketing objection, withdrawal or unsubscribe request.
Such a suppression record may be necessary to prevent a person's information from being unintentionally reintroduced into an eligible marketing audience after the person has opted out.
Suppression information should not itself be used as a basis for renewed promotional marketing.
14.9 Marketing opt-out does not stop essential communications
Opting out of promotional marketing does not prevent EXRA from sending non-promotional communications reasonably necessary for an active enquiry, account, assessment, transaction, project, warranty, support matter, security issue, legal obligation or other existing relationship.
EXRA should distinguish between optional promotional communications and communications that remain reasonably necessary to provide, administer, secure or complete an existing service or obligation.
14.10 Effect of withdrawing marketing consent
Withdrawal of marketing consent or an objection to direct marketing ordinarily affects future eligible marketing processing.
It does not ordinarily make earlier lawful processing or communications unlawful merely because the person's preference later changed.
14.11 Third-party and purchased marketing lists
EXRA should not assume that personal information obtained from a third-party list, directory, partner, lead provider, public source or other external source may automatically be used for direct marketing.
Before using externally obtained personal information for marketing, EXRA should establish whether the acquisition and proposed use are lawful and whether any applicable notice, consent, objection or other requirement has been satisfied.
14.12 Public advertising and social-media promotion
EXRA may promote its services through public websites, search engines, social-media platforms, advertising services or other public promotional channels.
Where personal information, tracking technologies, audience matching, behavioural advertising or personalised advertising is involved, the applicable privacy, cookie, tracking and advertising requirements will apply.
Cookies and similar technologies are addressed separately in Section 15 of this Privacy Policy.
14.13 Marketing service providers
EXRA may use authorised service providers to support communication or marketing activities, including email delivery, messaging, customer relationship management, analytics or advertising services.
Such providers should receive access only as reasonably necessary for the authorised purpose and should remain subject to appropriate confidentiality, security, data-processing or contractual controls according to the nature of the relationship.
Engagement of a marketing or communications provider does not automatically transfer ownership of EXRA's customer or participant information to that provider.
14.14 Records of consent and communication preferences
EXRA may retain appropriate records showing whether marketing consent was provided, what the consent covered, when it was provided, relevant communication channels, subsequent preference changes, withdrawals, objections or unsubscribe requests.
These records may be retained where reasonably necessary to demonstrate compliance, manage preferences, resolve disputes or prevent inappropriate marketing.
14.15 International marketing requirements
Direct-marketing, electronic-communications and consent requirements may differ between jurisdictions.
Where regional or local requirements govern a particular recipient or marketing activity, EXRA should apply those requirements to the relevant processing.
EXRA does not assume that compliance with one jurisdiction's marketing rules automatically satisfies the requirements applicable in every country.
14.16 Marketing preferences and contractual commitments
Changing a marketing preference, withdrawing marketing consent or unsubscribing from promotional communications does not automatically cancel an existing quotation acceptance, assessment, transaction, payment, project, account obligation, contractual commitment or other unrelated relationship with EXRA.
Marketing preferences govern the relevant promotional processing and should not be treated as a mechanism for reversing otherwise valid commercial or project commitments.
Cookies, Tracking and Similar Technologies
15.1 What these technologies are
EXRA may use cookies and similar technologies to operate, secure, improve and support its website, platform and related services.
These technologies may include browser cookies, local or session storage, pixels, tags, device or browser identifiers, software-development-kit technologies where applications are introduced, and other comparable technologies used by EXRA or authorised service providers.
The specific technologies used may change as EXRA's platform develops.
15.2 Strictly necessary technologies
Some technologies may be reasonably necessary to operate, secure or provide a website, platform function or service requested by the user.
These technologies may support functions such as:
- maintaining secure sessions;
- authentication and account access;
- security and fraud prevention;
- form and transaction integrity;
- essential preference management;
- technical traffic management;
- platform availability and reliability; and
- other functions reasonably necessary to provide or protect the requested service.
Strictly necessary technologies should not be treated as optional advertising technologies merely because they operate through cookies or similar mechanisms.
15.3 Functional technologies
EXRA may use functional technologies to remember choices or improve usability.
These may include preferences relating to appearance, language, region, accessibility or other user-selected settings.
Where applicable law treats a particular functional technology as optional or consent-based, EXRA should apply the relevant legal requirements.
15.4 Analytics and performance technologies
EXRA may use analytics or performance technologies to understand how its website or platform is used and how its services perform.
These technologies may support analysis of matters such as page usage, navigation patterns, technical errors, service performance, feature engagement and general platform improvement.
EXRA should not represent that a particular analytics provider or technology is in use unless that provider or technology has actually been implemented.
15.5 Advertising and audience technologies
If EXRA introduces advertising pixels, audience matching, remarketing, behavioural advertising, personalised advertising or similar technologies, those technologies should be used in accordance with applicable privacy, cookie, advertising and consent requirements.
The existence of this Privacy Policy does not mean that EXRA currently operates every form of advertising or audience technology described in this section.
15.6 First-party and third-party technologies
Some cookies or similar technologies may be set or controlled directly by EXRA.
Others may be provided through authorised third parties supporting functions such as hosting, security, payment processing, analytics, embedded content or advertising.
Third-party involvement does not remove EXRA's responsibility to understand the material technologies it intentionally deploys through its services.
15.7 Consent and lawful use
Where applicable law requires consent before a non-essential cookie or similar technology is placed, accessed or used, EXRA should obtain the required consent before using that technology.
Where consent is not legally required, EXRA may use another lawful basis or exemption where the applicable legal framework permits it.
EXRA should assess the legal requirements relevant to the particular technology and jurisdiction rather than assuming that one consent rule applies globally.
15.8 Meaningful preference controls
Where applicable law requires cookie or tracking preferences to be provided, EXRA should seek to offer controls that enable users to make an appropriate and understandable choice.
Preference mechanisms should not be designed merely to obscure or frustrate a legally required ability to reject or manage optional technologies.
15.9 Changing or withdrawing choices
Where users are provided with cookie or tracking preferences, they should be able to change or withdraw eligible consent through an appropriate mechanism where required by applicable law.
A change in preference ordinarily applies to future eligible processing and does not automatically make earlier lawful processing unlawful.
15.10 Browser and device controls
Users may also be able to manage or block certain cookies and similar technologies through their browser, device or operating-system settings.
Restricting certain technologies may affect the operation of features such as authentication, appearance preferences, project portals, payments, forms or other website and platform functionality.
EXRA cannot guarantee that every service will function normally where technologies reasonably necessary for that service have been disabled by the user.
15.11 Authentication and security technologies
Technologies used for authentication, session integrity, fraud prevention, security monitoring, abuse prevention or related protective functions may be reasonably necessary to provide or secure the requested service.
Such technologies may remain necessary even where a user has declined unrelated analytics or advertising technologies.
15.12 Payment technologies
Where EXRA integrates an authorised payment provider, that provider may use cookies or similar technologies for purposes such as secure payment processing, authentication, fraud prevention and transaction completion.
Payment-provider technologies may also be subject to the provider's own privacy, security or cookie terms.
15.13 Embedded third-party content
EXRA may introduce embedded or integrated third-party content or functionality such as video, maps, messaging tools, social-media content, support tools or other external widgets.
Such providers may use their own cookies or similar technologies when the relevant content is loaded.
Where applicable law requires consent before optional third-party tracking content is activated, EXRA should apply the relevant consent or preference process.
15.14 No assumption of unlimited tracking consent
Accepting EXRA's Terms of Service, Project Terms or other contractual terms does not automatically constitute consent to every optional cookie, tracking or advertising technology.
Acknowledgement of this Privacy Policy also does not by itself amount to consent where applicable law requires a separate affirmative choice for a particular technology or category.
15.15 Records of cookie choices
Where appropriate, EXRA may retain records of cookie or tracking preferences, including consent status, categories selected, date or time, consent version and subsequent preference changes.
Such records may be used to operate preference controls, demonstrate compliance, resolve disputes or avoid repeatedly requesting the same preference where the applicable system and law permit.
15.16 Retention of cookie-related information
The duration of cookies and related technologies may differ according to their purpose, technical function, provider and applicable legal requirements.
EXRA does not assign arbitrary cookie durations merely for the purpose of making this Privacy Policy appear more specific.
Where appropriate, specific cookie durations should be documented in EXRA's Cookie Notice, Cookie Register or preference interface once the relevant technologies have actually been implemented.
15.17 International cookie and tracking requirements
Cookie, tracking and consent requirements may differ between jurisdictions.
Where regional or local rules require different treatment, EXRA should adapt the relevant consent, preference or technology controls for the affected processing activity.
Compliance with one country's cookie requirements does not automatically mean that all requirements applicable in another jurisdiction have been satisfied.
15.18 Separate Cookie Notice and Cookie Register
EXRA may maintain a separate Cookie Notice, Cookie Register or cookie-preference interface providing more detailed and current information concerning technologies actually in use.
That information may identify relevant categories, purposes, providers, durations and available user choices.
Separating the detailed technical inventory from this Privacy Policy enables EXRA to update cookie information as its website, platform and authorised providers develop without unnecessarily rewriting the broader privacy framework.
Automated Processing, Profiling and Decision Systems
16.1 Automation within the EXRA platform
EXRA may use automated rules, algorithms, artificial-intelligence-assisted tools and similar technologies to support the operation, security, administration and development of its website, platform and related services.
Such processing may support functions including request routing, service-coverage checks, technician or supplier matching, availability checks, verification pre-checks, duplicate detection, project-status automation, security and fraud indicators, administrative recommendations and other operational processes.
The use of automation within a process does not necessarily mean that a final decision concerning a person is made solely by an automated system.
16.2 Routine workflow automation
EXRA may automate routine operational processes where doing so reasonably improves efficiency, consistency, security, reliability or service delivery.
Routine automation may include validating required fields, calculating relevant project information, routing requests into appropriate workflows, generating status notifications, identifying expired documentation, prioritising operational tasks or performing similar administrative functions.
Routine workflow automation does not automatically create a right to human intervention every time an automated process is used.
16.3 Matching, ranking and project allocation
EXRA may use automated criteria to assist with the matching, ranking, prioritisation, recommendation or allocation of technicians, suppliers, projects or other platform opportunities.
Relevant criteria may include factors such as location, availability, verification status, relevant certification, project requirements, service capacity, previous EXRA project history, quality indicators and other legitimate operational considerations.
A ranking, score, recommendation, match or eligibility indicator does not create an entitlement to a project, assignment, minimum volume of work, approval or particular commercial outcome.
16.4 Changes to automated criteria
EXRA may revise matching, ranking, verification, prioritisation, security and risk criteria as the platform develops, provided that material personal-information processing remains consistent with applicable law.
EXRA is not required to permanently preserve a particular algorithm, weighting, scoring method or operational rule merely because that method was previously used.
Where a material change creates a legal obligation concerning notice, assessment or other safeguards, EXRA should apply the relevant requirements.
16.5 Automated security and fraud protection
EXRA may use automated systems to identify or respond to activity that may indicate account compromise, fraud, abuse, suspicious transactions, duplicate identities, abnormal access, platform manipulation or other security concerns.
Depending on the circumstances, an automated security process may trigger measures such as additional verification, temporary protective restrictions, investigation, escalation or requests for further information.
A security flag, risk indicator or temporary protective restriction does not necessarily constitute a final determination that a person has committed fraud, misconduct, illegality or another violation.
16.6 High-impact automated decisions
Before EXRA relies solely on automated processing to make a decision that produces legal consequences, substantially affects a person or otherwise falls within a regulated category of automated decision-making, EXRA should determine whether that form of processing is permitted under applicable law.
EXRA should also determine what safeguards, conditions, notices, review mechanisms or other protections are required for the relevant decision.
Higher-impact decisions may include matters such as permanent platform exclusion, final eligibility rejection, material financial decisions, permanent account suspension, final fraud determinations or other decisions that significantly affect a person's participation, rights or opportunities.
16.7 Human consideration, review and representations
Where applicable law requires safeguards for a qualifying automated decision, EXRA should provide the relevant opportunity for human consideration, representations, review, reconsideration or challenge required by that law.
This does not mean that every automated routing, ranking, notification, validation or security event must automatically receive individual human review.
The appropriate safeguard should reflect the nature and consequence of the relevant automated decision.
16.8 Meaningful information without unnecessary disclosure
Where applicable law requires EXRA to provide information concerning a qualifying automated decision, EXRA may provide meaningful information about the principal factors, categories or logic relevant to the decision to the extent legally required.
EXRA is not required to disclose source code, proprietary algorithms, confidential scoring formulas, security thresholds, anti-fraud rules, trade secrets or information whose disclosure would materially enable circumvention or manipulation of the platform, except to the extent applicable law specifically requires otherwise.
16.9 Artificial-intelligence-assisted tools
EXRA may introduce artificial-intelligence-assisted tools for administrative, analytical, support, matching, security, verification, communication or other operational purposes.
Automated or AI-generated output should not automatically be assumed to be accurate, complete or appropriate merely because it was generated by an automated system.
Depending on the nature and consequence of the use, EXRA may apply validation, additional information, human consideration, confidence thresholds, escalation or other reasonable safeguards.
16.10 Data quality, testing and reasonable safeguards
EXRA should take reasonable measures appropriate to the nature and impact of an automated system to reduce foreseeable errors, misuse, materially unreliable outcomes, inappropriate bias or other unreasonable effects.
Relevant safeguards may include testing, monitoring, audit records, threshold reviews, manual override capabilities, incident review, provider assessment or other controls appropriate to the system concerned.
EXRA does not represent that automated systems can eliminate every possible error, bias, security risk or incorrect outcome.
16.11 No guarantee from automated outputs
Automated scores, recommendations, rankings, forecasts, eligibility indicators, matching results and other system-generated outputs may be used to support EXRA's operational processes.
Such outputs do not constitute guarantees of approval, future performance, suitability, eligibility, assignment, availability, project allocation, commercial opportunity or other outcome unless EXRA expressly states otherwise.
16.12 International and future automated systems
Automated-processing, profiling and automated-decision requirements may differ between jurisdictions.
EXRA will assess the legal requirements relevant to the particular automated system, processing activity and affected jurisdiction rather than assuming that one automated-decision rule applies globally.
As EXRA's platform develops, higher-impact automated systems may be subject to additional internal governance, risk assessment, testing, documentation, review or oversight requirements before deployment.
Special or Sensitive Personal Information and Children
17.1 Special or sensitive personal information
Certain categories of personal information may receive additional protection under applicable privacy and data-protection laws.
Depending on the jurisdiction, these categories may be described as special personal information, sensitive personal information or otherwise specially protected information.
Relevant categories may include information concerning health, biometric characteristics, criminal behaviour or proceedings, race or ethnic origin, religious or philosophical beliefs, political views, trade-union membership, sex life or other categories recognised by applicable law.
17.2 No unnecessary collection of sensitive information
EXRA does not intend to collect special or sensitive personal information merely because such information is available.
Such information should only be processed where it is genuinely relevant to an authorised purpose and where the processing is lawful, necessary and proportionate to the circumstances.
17.3 Circumstances in which sensitive information may arise
Special or sensitive personal information may arise in limited circumstances connected with matters such as identity or verification processes, safety incidents, security-infrastructure projects, technician or supplier compliance, fraud or security investigations, disputes, legal requirements or future employment and recruitment activities.
The description of a possible category in this Privacy Policy does not mean that EXRA currently collects every category described.
17.4 Lawful authorisation
EXRA should process special or sensitive personal information only where an applicable legal ground, exception, authorisation, consent requirement or other lawful basis permits the relevant processing.
The existence of consent alone should not be treated as permission to conduct processing that would otherwise be unnecessary, disproportionate or unlawful.
17.5 Biometric information
Where EXRA introduces biometric identity verification, biometric access functionality or another service involving biometric information, EXRA should assess the purpose, necessity, lawful basis, security safeguards, retention requirements, disclosure risks and other applicable obligations before introducing that processing.
EXRA's coordination of a project involving biometric equipment does not automatically require EXRA to collect, receive or retain the biometric templates, fingerprints, facial templates or other biometric records generated or stored by the client's own system.
Where EXRA does not reasonably require access to such biometric records, the system architecture should seek to avoid unnecessary transfer or duplication of that information.
17.6 Criminal-behaviour and related information
Where EXRA lawfully performs, receives or processes information concerning alleged offences, convictions, legal proceedings, fraud or other criminal-behaviour information, that information should be processed only where relevant, proportionate and lawfully authorised.
Allegations, reports, security flags or unresolved claims should not automatically be treated as established facts merely because they have been recorded or reported to EXRA.
17.7 Health and safety information
Health-related information may arise in connection with workplace or project-site incidents, emergencies, accessibility requirements, insurance matters, support requests or other legitimate safety-related circumstances.
Where EXRA processes such information, it should seek to limit the information to what is reasonably relevant to the authorised purpose and apply appropriate confidentiality and security safeguards.
17.8 Other specially protected characteristics
Where information concerning protected characteristics such as race, ethnicity, religion, political beliefs, trade-union membership, sex life or similar specially protected matters comes into EXRA's possession, EXRA should not use that information for unrelated profiling, project allocation or commercial decision-making unless a lawful and appropriate reason specifically permits that processing.
17.9 Children and EXRA's services
EXRA's core project-coordination and technical- infrastructure services are primarily intended for persons who are legally capable of entering or participating in the relevant service, commercial or project relationship.
EXRA does not intentionally design its core project-coordination services for children acting independently where applicable law requires the involvement or authorisation of a parent, guardian, competent person or other legally authorised representative.
17.10 Children's information arising incidentally
Personal information concerning children may nevertheless arise incidentally through project photographs, site information, residential communications, support records, incident reports or other legitimate project material.
Where such information is not intentionally collected as part of a child-focused service, EXRA should process it only to the extent reasonably necessary for the relevant authorised purpose and with safeguards appropriate to the circumstances.
17.11 Consent and authorised adult involvement
Where applicable law requires consent, authorisation or involvement from a parent, guardian, competent person or other legally authorised adult before children's information may be processed, EXRA should obtain or verify the required authority before carrying out the relevant processing.
Because age and consent requirements differ between jurisdictions, EXRA does not assume that one universal global age threshold applies to every service or processing activity.
17.12 Verification of authority
Where EXRA reasonably needs to rely on instructions, consent or another authorisation provided on behalf of a child, EXRA may take proportionate steps to verify the identity and authority of the person providing that instruction or consent.
The level of verification should reflect the sensitivity and risk associated with the relevant processing.
17.13 Marketing and profiling involving children
EXRA should not intentionally use children's personal information to create behavioural advertising profiles or specifically target children with behavioural direct marketing unless a future service specifically requires such processing and that processing has first been assessed as lawful and appropriate.
The existence of incidental children's information in project records does not create permission to use that information for unrelated marketing.
17.14 Automated processing involving children
Where automated processing materially concerns or affects a child, EXRA should apply additional caution and any safeguards required by applicable law, particularly where the processing may produce a significant effect.
The automated-processing principles described in Section 16 also apply where relevant to children's personal information.
17.15 Sharing sensitive or children's information
Special, sensitive or children's personal information should only be disclosed where the disclosure is lawful, reasonably necessary for the authorised purpose and appropriately limited to the recipient's legitimate need for the information.
Access to one part of a project does not automatically entitle a technician, supplier, client, service provider or other participant to receive unrelated sensitive information concerning another person.
17.16 Security safeguards
The sensitivity, nature and potential consequences of unauthorised access to personal information should inform the level of access restriction, confidentiality, storage protection and other security safeguards applied by EXRA.
Relevant security principles are addressed further in Section 10 of this Privacy Policy.
17.17 Retention of specially protected information
Special, sensitive or children's personal information should not be retained for longer merely because of its sensitivity.
EXRA should retain such information only while an appropriate lawful, operational, legal, security, evidentiary or other legitimate retention purpose continues to apply.
The retention principles described in Section 12 apply to these records together with any additional requirements imposed by applicable law.
17.18 Unrequested sensitive information
A person may sometimes voluntarily provide special or sensitive personal information that EXRA did not request and does not reasonably require.
Where such information is unnecessary for the relevant purpose, EXRA may limit its use, restrict access, redact it, delete it, de-identify it or otherwise handle it appropriately in accordance with applicable law and legitimate recordkeeping requirements.
17.19 International requirements
Definitions, lawful-processing conditions, age thresholds and safeguards for sensitive information and children's personal information may differ between jurisdictions.
EXRA will assess the legal requirements relevant to the particular information, processing activity and affected jurisdiction rather than assuming that one standard applies globally.
17.20 Future higher-risk processing
Before deliberately introducing materially higher-risk processing involving biometric databases, criminal-record screening, child-focused functionality, large-scale health information, sensitive-category profiling or similar activities, EXRA should conduct an appropriate privacy, legal, security and operational review.
Such a review may consider necessity, proportionality, lawful authority, security, retention, access, disclosure, international requirements and whether additional safeguards or governance controls are required.
This review requirement does not prohibit EXRA from introducing legitimate future functionality. Its purpose is to ensure that higher-risk processing is deliberately assessed before deployment rather than introduced without appropriate consideration.
Third-Party Platforms, Links and External Services
18.1 Third-party services
EXRA may interact with, integrate or rely on third-party services to support the operation, security, communication, payment, infrastructure and development of its website, platform and related services.
These services may include payment processors, hosting or infrastructure providers, email and messaging services, social-media platforms, analytics services, mapping or location services, authentication services, embedded-content providers, technical systems and other authorised external services introduced as EXRA develops.
The description of a possible category does not mean that EXRA currently uses every type of service described in this section.
18.2 Links to external websites and platforms
EXRA's website or platform may contain links to third-party websites, applications, platforms, resources or services that EXRA does not operate.
When a user leaves an EXRA-controlled environment and interacts directly with an independent third-party service, that third party's own privacy policy, terms, security practices and other rules may apply.
18.3 Independent third parties
EXRA does not control the privacy, security, content or operational practices of an independent third-party service merely because EXRA provides a link, reference or integration enabling a user to access that service.
This does not remove EXRA's responsibilities for personal information processed under EXRA's own control or for third parties specifically appointed to process information on EXRA's behalf.
18.4 Service providers acting on EXRA's behalf
Where a third-party provider processes personal information on EXRA's behalf, EXRA should apply appropriate contractual, confidentiality, security, access-control and data-processing requirements according to the nature and risk of the relationship.
Such providers should receive access only to the information reasonably necessary for the authorised purpose.
18.5 Independent responsible parties or controllers
Some external organisations may independently determine the purposes and means of processing personal information obtained through their own services.
Depending on applicable law, such an organisation may act as an independent responsible party, controller or equivalent entity and may have its own legal obligations concerning that processing.
18.6 Payment providers
EXRA may use authorised third-party payment providers to facilitate payments, refunds, transaction authentication, fraud prevention or related financial functions.
Depending on the integration, a user may provide payment information directly to the payment provider rather than to EXRA.
EXRA should avoid unnecessarily collecting or retaining full payment-card credentials where an authorised payment provider can securely process that information directly.
18.7 Social-media platforms
EXRA may maintain profiles, pages or communication channels on third-party social-media platforms.
Where a person interacts with EXRA through such a platform, the platform may independently process information concerning that interaction according to its own privacy practices.
EXRA may also process information received through the interaction where necessary to respond, administer the relationship, protect its rights or perform another lawful function.
18.8 Messaging services
EXRA may use third-party messaging or communication services to communicate with clients, technicians, suppliers or other participants.
The communication provider may separately process metadata, device information or other information according to its own terms and privacy practices.
EXRA remains responsible for its own subsequent use of personal information contained in communications under EXRA's control.
18.9 Embedded content and integrations
EXRA may introduce embedded or integrated third-party functionality such as video, maps, messaging tools, social-media content, support tools, external forms or other widgets.
Loading or interacting with such functionality may result in information being transmitted to the relevant external provider.
Where optional integrations involve cookies, tracking or similar technologies, the principles in Section 15 of this Privacy Policy also apply.
18.10 Information provided directly to third parties
Where a person voluntarily provides information directly to an independent third party, that information may be governed primarily by the third party's own privacy practices and legal responsibilities.
For example, information entered directly into an independent payment provider's secure checkout may be processed by that provider even where the payment relates to an EXRA project.
18.11 Availability and reliability of external services
EXRA cannot guarantee that every external platform, integration or provider will remain continuously available, unchanged, uninterrupted or free from technical problems.
More detailed service-availability and commercial consequences associated with third-party interruptions may be addressed in the applicable Terms of Service.
18.12 Third-party security incidents
Where a third-party provider experiences a security incident affecting personal information for which EXRA remains responsible, EXRA should assess and respond to that incident according to applicable law and the security and incident-response principles described in Sections 10 and 11.
EXRA cannot guarantee that an independent third party will never experience a security incident, cyberattack, technical failure or unauthorised access event.
18.13 Provider and integration changes
EXRA may add, replace, modify or discontinue third-party providers, technologies or integrations as its platform, commercial requirements, security needs, technical architecture or geographic operations develop.
EXRA is not permanently committed to a particular hosting provider, payment provider, communications service or other third party merely because that provider was previously used.
Where a provider change materially affects the processing of personal information, EXRA should address any notice, assessment, contractual or other privacy requirement imposed by applicable law.
18.14 Provider due diligence
EXRA should apply reasonable due diligence proportionate to the nature and risk of a provider relationship before materially entrusting personal information to that provider.
Relevant considerations may include security, confidentiality, processing purpose, access, retention, geographic location, incident response and other matters appropriate to the relationship.
Reasonable provider assessment does not constitute a guarantee that a third party will never experience failure, error or security compromise.
18.15 User consideration of independent services
Where appropriate, users should review the privacy, security and contractual practices of independent third-party services before providing information directly to those services.
This expectation does not transfer EXRA's own legal responsibilities to the user where EXRA remains responsible for the relevant processing.
18.16 Third-party terms and EXRA terms
A third party's privacy policy, terms or service conditions govern that third party's own activities and do not automatically replace EXRA's Privacy Policy, Terms of Service, Project Terms or other applicable EXRA agreements.
More than one set of terms or privacy rules may therefore apply to different parts of a transaction or service relationship.
18.17 International third parties
Some authorised providers may process or store information in countries outside South Africa or outside the country in which the affected person is located.
Where this creates an international transfer of personal information for which EXRA is responsible, the principles in Section 9 of this Privacy Policy apply.
18.18 No endorsement merely from a link or integration
The presence of a link, reference, integration or external service within an EXRA environment does not necessarily mean that EXRA endorses every product, statement, policy, practice or activity of the relevant third party.
18.19 Reporting third-party concerns
Users who identify a suspicious, misleading, broken or potentially unsafe third-party link, payment destination, integration or external service associated with EXRA may report the matter through an appropriate EXRA support or contact channel.
EXRA may investigate the report and may disable, replace, restrict or otherwise address an integration where reasonably appropriate.
18.20 Relationship with other privacy provisions
Third-party processing may also involve sharing, international transfers, security, incident response, cookies, tracking, marketing, retention or other matters addressed elsewhere in this Privacy Policy.
The relevant provisions should be read together according to the nature of the processing concerned.
Complaints, Regulators and Privacy Disputes
19.1 Raising a privacy concern
A person may contact EXRA where they believe that personal information relating to them has been processed unlawfully, disclosed improperly, accessed without appropriate authorisation, retained without sufficient justification, handled inaccurately or otherwise processed in a manner that raises a legitimate privacy concern.
EXRA encourages persons to provide sufficient information to enable the concern to be understood and investigated appropriately.
19.2 Internal privacy-complaint process
EXRA should assess privacy complaints reasonably, proportionately and in good faith.
Depending on the nature of the matter, the process may include receiving and recording the complaint, verifying identity or authority where necessary, gathering relevant records, identifying the applicable privacy issue, investigating the facts, assessing applicable law and determining an appropriate response or remedial action.
19.3 Information EXRA may request
EXRA may request information reasonably necessary to understand, verify and investigate a privacy complaint.
This may include:
- the complainant's name and contact details;
- relevant account or project references;
- a description of the privacy concern;
- the approximate date or period involved;
- the personal information believed to be affected;
- relevant correspondence or supporting evidence; and
- the outcome or remedy the complainant is requesting.
EXRA should avoid requesting information that is disproportionate to the nature of the complaint.
19.4 Identity, authority and confidentiality
EXRA may take reasonable steps to verify the identity or authority of a complainant before disclosing personal information or taking action that could materially affect another person's privacy rights or records.
A person does not automatically obtain access to another individual's information merely because they submitted a complaint concerning that person, project, account or relationship.
19.5 Investigation does not establish wrongdoing
EXRA's decision to investigate a privacy complaint does not mean that EXRA accepts the complainant's allegation as established fact or admits that a privacy violation, legal breach or other wrongdoing has occurred.
Findings should be based on the available evidence, applicable law, relevant records and the circumstances of the matter.
19.6 Possible complaint outcomes
Depending on the complaint and applicable law, EXRA's response may include:
- confirming that no privacy breach was identified;
- correcting or updating information;
- restricting access or processing;
- deleting information where required or appropriate;
- stopping inappropriate processing;
- contacting an authorised service provider;
- opening a security or incident investigation;
- introducing additional safeguards;
- partially granting a request;
- refusing a request where a lawful reason permits or requires refusal; or
- taking another proportionate action appropriate to the circumstances.
19.7 Complaints involving service providers
Where a privacy complaint involves an authorised provider processing personal information on EXRA's behalf, EXRA may engage that provider where reasonably necessary to investigate, contain, correct or resolve the relevant matter.
The involvement of a service provider does not automatically remove EXRA's responsibilities where EXRA remains responsible for the relevant processing under applicable law.
19.8 Complaints involving independent third parties
Where a complaint concerns processing independently controlled by a third party, EXRA may direct the complainant to that third party where appropriate.
Where EXRA's own conduct also forms part of the complaint, EXRA should separately assess the processing for which EXRA remains responsible.
19.9 Complaints revealing security incidents
Where a privacy complaint indicates that a security incident or possible personal-information compromise may have occurred, EXRA may escalate the matter into the incident-response process described in Section 11 of this Privacy Policy.
A complaint and a security incident may therefore be handled through connected processes where the facts require both forms of investigation.
19.10 Complaints to privacy regulators
Where applicable law provides the right, a person may lodge a complaint with the competent privacy, data-protection or information authority concerning alleged interference with or unlawful processing of personal information.
In South Africa, this may include the Information Regulator acting under applicable privacy and access-to-information legislation.
Where another jurisdiction applies, the competent authority may differ.
19.11 Opportunity for internal resolution
Where appropriate, EXRA encourages persons to raise privacy concerns directly with EXRA first so that EXRA has a reasonable opportunity to investigate and seek an appropriate resolution.
This does not prevent a person from approaching a competent regulator, authority or other body where applicable law allows them to do so without first completing EXRA's internal process.
19.12 Cooperation with regulators and authorities
EXRA should cooperate appropriately with lawful investigations, enquiries, directives or requests made by competent privacy regulators, courts or other authorities acting within their lawful powers.
Cooperation should remain subject to applicable legal requirements, confidentiality obligations, procedural protections and the scope of the authority's lawful request.
19.13 Verification of regulatory or governmental requests
Before disclosing personal information in response to a purported regulator, court, law-enforcement or governmental request, EXRA may take reasonable steps to verify the identity, authority, scope and validity of the request.
EXRA should not disclose personal information merely because a person claims to represent an authority without an appropriate legal or factual basis.
19.14 Preservation of records during complaints
Where a privacy complaint, investigation, regulatory enquiry, anticipated dispute or other formal matter is active, EXRA may preserve relevant records for as long as reasonably necessary to investigate the matter, demonstrate compliance, establish the facts or protect legal rights.
Ordinary deletion processes may therefore be suspended for affected records where a legitimate preservation requirement applies.
The retention principles in Section 12 remain applicable.
19.15 No retaliation for legitimate privacy concerns
EXRA should not disadvantage a person merely because they raised a legitimate privacy concern, exercised a recognised privacy right or submitted a lawful complaint.
This does not prevent EXRA from taking appropriate action based on separate matters such as fraud, abuse, non-payment, misconduct, security threats, breach of contract or other legitimate reasons unrelated to the person's exercise of privacy rights.
19.16 Privacy complaints and commercial obligations
Filing a privacy complaint does not automatically cancel a project, reverse a payment, invalidate a quotation acceptance, terminate a valid agreement, suspend lawful financial obligations or create an automatic entitlement to compensation or refund.
Any commercial, contractual or financial consequence must be assessed separately under the applicable Terms of Service, Project Terms, cancellation or refund provisions and mandatory law.
19.17 Corrective and remedial measures
Where EXRA confirms that a privacy problem has occurred, EXRA may take reasonable corrective or remedial measures proportionate to the nature, cause and consequences of the issue.
Such measures may include correcting information, restricting access, stopping inappropriate processing, deleting information where required, updating a provider configuration, strengthening safeguards, making legally required notifications or taking other appropriate action.
The appropriate remedy will depend on the facts, applicable law and circumstances of the complaint.
19.18 Complaints involving multiple jurisdictions
Where a privacy complaint concerns processing subject to the laws of more than one jurisdiction, EXRA should determine which legal requirements, regulators, complaint procedures and response obligations apply to the matter.
Handling a complaint under one jurisdiction's procedure does not automatically mean that every requirement applicable in another affected jurisdiction has been satisfied.
19.19 Records of privacy complaints
EXRA may retain appropriate records of privacy complaints, identity or authority verification, investigations, correspondence, evidence, regulatory interactions, remedial actions and final outcomes where reasonably necessary.
Such records may be used for compliance, accountability, dispute resolution, security, auditing, legal claims and improvement of EXRA's privacy practices.
19.20 Internal complaints and regulatory-response procedure
EXRA intends to maintain an internal process for receiving, classifying, investigating, escalating and closing privacy complaints and regulatory matters.
That process may include complaint intake, case ownership, identity verification, evidence preservation, investigation, response, regulatory correspondence, corrective action, closure and post-matter review.
The internal procedure may develop over time as EXRA's platform, regulatory obligations, operating regions and volume of privacy matters change.
Policy Changes, Regional Requirements and Contact
20.1 Policy version and effective date
This Privacy Policy is maintained as a versioned governance document so that material changes to EXRA's privacy framework can be identified and managed over time.
Version 1.0 of this Privacy Policy was approved and became effective on 30 August 2026.
The effective date and version number shown in this Privacy Policy identify the version currently in effect.
20.2 Changes to this Privacy Policy
EXRA may amend this Privacy Policy where reasonably necessary to reflect changes in applicable law, platform functionality, business operations, security practices, service providers, processing activities, organisational structure, governance requirements or geographic expansion.
The existence of an earlier version does not prevent EXRA from developing its platform or adopting lawful new processing activities, safeguards or operational practices.
20.3 Material changes
Where a change materially affects the way personal information is processed, EXRA should provide an appropriate notice where required by applicable law or where additional notice is otherwise reasonably appropriate in the circumstances.
Depending on the nature of the change, notice may be provided through the website, platform, dashboard, email, another appropriate communication channel or a combination of methods.
EXRA is not required to use every available communication channel for every policy update.
20.4 Continued use and consent
Continued use of an EXRA service after publication of an updated privacy notice may acknowledge that the updated notice has been made available where appropriate.
Continued use should not automatically be treated as consent where applicable law requires a separate affirmative consent for a particular processing activity.
Where new consent is legally required, EXRA should obtain that consent through an appropriate process.
20.5 Policy changes do not rewrite historical processing
An amendment to this Privacy Policy does not retrospectively make processing lawful where that processing was unlawful when it occurred.
Similarly, a later policy amendment does not by itself make earlier processing improper where that processing was lawful and appropriately governed at the relevant time.
Rights and obligations that have already arisen under applicable law remain subject to the law and circumstances relevant to that processing.
20.6 Global core privacy framework
This Privacy Policy is intended to operate as EXRA's global core privacy framework.
EXRA is currently based in South Africa and its privacy-governance framework recognises applicable South African privacy and data-protection requirements.
The policy is also structured so that additional requirements arising in other jurisdictions can be incorporated as EXRA's services and geographic operations expand.
20.7 Regional requirements and supplements
Where a jurisdiction imposes additional or different privacy requirements, EXRA may issue a regional privacy notice, supplement, disclosure or other jurisdiction-specific material applicable to persons or processing activities within that jurisdiction.
A regional supplement should be read together with this global Privacy Policy where both apply.
20.8 Mandatory regional requirements
Where a mandatory regional privacy or data-protection requirement provides greater, additional or different protection from the general wording of this Privacy Policy, EXRA will apply the mandatory requirement to the affected processing to the extent required by applicable law.
Nothing in this Privacy Policy is intended to remove a mandatory right or obligation that applicable law does not permit EXRA to exclude or modify.
20.9 Changes in privacy and data-protection law
Privacy, data-protection, electronic-communications and related laws may change over time.
EXRA may update terminology, procedures, rights explanations, regulator information, international transfer safeguards, consent mechanisms, security requirements and other privacy-governance provisions where reasonably necessary to reflect such legal developments.
20.10 Related privacy and governance documents
EXRA may maintain separate privacy, compliance and governance documents that supplement this Privacy Policy where relevant.
These documents may include:
- a Cookie Notice and Cookie Register;
- a PAIA Manual or access-to-information material;
- regional privacy supplements;
- privacy-request procedures;
- an internal retention schedule;
- data-processing agreements;
- provider or subprocessor disclosures;
- security or incident notices;
- candidate or recruitment privacy notices; and
- other privacy or compliance documents introduced as EXRA develops.
EXRA's Terms of Service and other commercial or project terms remain separate from this Privacy Policy.
This Privacy Policy primarily governs the processing and protection of personal information, while the applicable Terms of Service and project terms govern the relevant service, contractual and commercial relationship.
20.11 Privacy enquiries and requests
Persons may contact EXRA regarding privacy questions, access or correction requests, deletion requests, objections, consent matters, marketing preferences, complaints, suspected misuse of personal information or other privacy-related concerns.
Until EXRA designates a separate privacy-specific communication channel, an appropriate published EXRA contact or support channel may be used for privacy enquiries.
20.12 Information Officer and privacy governance
EXRA will maintain the privacy-governance roles and responsibilities required by applicable law.
Where applicable law requires an Information Officer, Data Protection Officer, representative or other designated privacy role, the relevant details should be confirmed and made available in the manner required by the applicable legal framework.
EXRA should not publish unconfirmed privacy-officer information merely for the purpose of making this Privacy Policy appear complete.
20.13 Changes to contact information
EXRA may update its registered information, physical address, email addresses, telephone details, support channels or privacy-contact information where those details change.
An administrative change to contact information does not necessarily require substantive revision of the remainder of this Privacy Policy.
20.14 Questions about this Privacy Policy
A person who requires clarification regarding how a provision of this Privacy Policy applies to their personal information may contact EXRA through the applicable published privacy, support or contact channel.
EXRA may request sufficient information to understand the enquiry and identify the relevant processing activity before providing a response.
20.15 Publication, accessibility and previous versions
EXRA should make the current published version of this Privacy Policy reasonably accessible through its website or another relevant service interface.
EXRA may retain previous versions internally for governance, audit, dispute-resolution, legal or historical purposes.
Where appropriate, EXRA may identify the current version number and effective date so that users can determine which version is presently in effect.
20.16 Final interpretation principle
This Privacy Policy should be interpreted in a manner consistent with applicable privacy and data-protection law.
Where a provision of this Privacy Policy cannot lawfully limit, exclude or modify a mandatory privacy right, protection or obligation, the applicable mandatory requirement will prevail to the extent required.
EXRA seeks to maintain a privacy framework that supports responsible platform growth, reasonable risk reduction, accountability and continuous improvement without representing that every possible privacy, security or operational risk can be completely eliminated.