Privacy Policy

How EPRlog collects, uses, and protects your information.

Controller: EPRlog, operated by the EPRlog entity named in your order form. For any request under this policy, contact [email protected].

Information we collect

Account data

Name, work email, organisation, role, and billing contact for the Customer and its authorised Users.

Operational data

  • Collection records: material, weight, timestamp, kiosk identifier and geo-coordinate.
  • Attached evidence photographs of collected material.
  • Informal-sector disbursement figures where the Customer records them.

Usage data

IP address, device and browser type, pages visited and time spent, and diagnostic identifiers used to keep the service secure and reliable.

How we use data

  • To provide, maintain and secure the service.
  • To generate the compliance reports and audit trails the Customer instructs us to produce.
  • To process subscriptions and, where enabled, route operator payouts via our licensed payment partner.
  • To contact you about your account, security and service changes.

Legal basis

We process personal data to perform our contract with the Customer, to meet our legal obligations, and on the basis of legitimate interests in operating and securing the service. Where required, we act as a Data Processor on the Customer's documented instructions.

Sharing

We share data only with sub-processors that support the service (hosting, payment processing, error monitoring), each bound by written data-protection terms; where legally compelled; and in connection with a corporate transaction, subject to this policy. We never sell personal data.

International transfers

Data may be processed outside your jurisdiction under appropriate safeguards (Standard Contractual Clauses or equivalent).

Retention

Operational compliance records are retained for the period the applicable regulation requires and for the term of the Customer agreement. Account data is deleted or returned on termination, save where retention is legally required.

Your rights

Subject to applicable law (including GDPR and POPIA) you may access, correct, delete, port or object to the processing of your personal data. Contact [email protected]; we respond within the statutory period.

Security

We apply industry-standard technical and organisational measures, including encryption in transit and at rest, least-privilege access, and continuous monitoring. No method of transmission is perfectly secure, but we notify affected parties of any qualifying breach without undue delay.

Children

The service is for business use and is not directed to children under 16.

Changes

We may update this policy and will notify Customers of material changes by email or in-product notice.