Legal

Privacy & POPIA Notice

We collect the minimum information needed to trade with you, protect it by role and centre, encrypt sensitive documents, transfer it responsibly across borders, and delete what we no longer need.

1. Who we are

Brand Drive Connect is a South African FMCG wholesale and distribution network operating in South Africa, Mozambique, Kenya, Tanzania and Somalia. We are the responsible party for the personal information described in this notice.

You can reach us at info@branddriveconnect.co.za or on 073 318 0955 / 069 304 3939.

2. What we collect

For trading partners we collect business identity details: business or shop name, reseller shop code, trading address, the centre or route you are served by, and the name of the person we deal with.

For staff and agents we collect employment identity details needed for payroll, role assignment and compliance, plus performance data such as visits logged and outlets serviced.

Where the law requires identity verification (KYC), we collect the specific documents that regulation requires and nothing more — typically a form of identification and proof of the business relationship.

3. What we deliberately do not collect

Our visitor and customer records do not store cell phone numbers, email addresses or other direct contact details. Visitor logs are keyed on the reseller shop code instead. This is a design decision to minimise the personal information we hold, not an oversight.

4. Why we process it

To fulfil orders, plan delivery routes and confirm deliveries; to invoice, take payment and reconcile accounts; to provide support and resolve tickets; to meet legal, tax and KYC obligations; and to detect fraud or misuse of our systems.

We do not sell personal information, and we do not use it for advertising profiling.

5. Cookies and analytics

We use only the cookies and local storage that are strictly necessary to run this website and the platform — for example, keeping you signed in and remembering basic display preferences. We run lightweight, first-party analytics to understand which pages are useful and where the site is slow, using aggregated numbers rather than individual profiles.

We do not run third-party advertising trackers, do not build behavioural advertising profiles, and do not sell or share browsing data with advertisers.

6. How we protect it

Access is restricted by role and by centre: staff only see the records belonging to the area they are responsible for. KYC documents are encrypted at rest with AES-256-GCM. Administrative actions are written to an audit trail.

Automated security reviews run over our systems, and privileged database operations are restricted to server-side, authenticated paths. Passwords and credentials are never stored in plain text.

7. How long we keep it

KYC documents are retained for six months and then deleted on an automated schedule. Administrators are alerted two months and one month before a deletion window so that any legal or dispute hold can be applied first.

Trading, invoicing and tax records are kept for the periods South African law requires, and for the equivalent periods required in the other markets we serve.

8. Cross-border transfers

Because we operate across South Africa, Mozambique, Kenya, Tanzania and Somalia, information relating to cross-border orders may be processed in more than one of these markets — for example, to clear goods, settle payment or coordinate a delivery corridor.

Where information is transferred across a border, we use contractual protections with the receiving party to ensure it is handled with the same care and confidentiality required in South Africa, regardless of which market it is processed in.

9. Sharing

We share information only with parties who need it to deliver the service: transport partners for delivery, payment providers for settlement, and regulators or auditors where the law requires. Each is bound to protect the information they receive and to use it only for the purpose it was shared.

10. Security incident handling

If we identify a security incident that puts personal information at risk, we contain it immediately, assess what information and how many people are affected, and fix the underlying cause.

Where the incident is likely to result in a real risk of harm, we notify the Information Regulator of South Africa and the affected individuals or businesses as required under POPIA, explaining what happened, what information was involved and what steps we have taken.

Every incident, however minor, is logged in our internal register and reviewed to reduce the chance of recurrence.

11. Your rights

You may ask what we hold about you, ask us to correct it, object to processing, or ask us to delete it where we have no legal obligation to keep it. Contact us using the details above and we will respond within a reasonable period.

If you are not satisfied, you may lodge a complaint with the Information Regulator of South Africa.

12. Changes

We update this notice as our systems, markets or obligations change. The date below reflects the most recent update, and material changes will be highlighted on this page.

Last updated: 2026