Privacy Policy
How SOPManagerPRO handles personal information across the public website and multi-company SaaS platform.
Contents
- 1. Scope and our role
- 2. Information we collect
- 3. How we use information
- 4. Legal bases
- 5. AI-assisted features
- 6. Sharing and service providers
- 7. International transfers
- 8. Retention
- 9. Security
- 10. Your privacy rights
- 11. South Africa / POPIA
- 12. Children
- 13. Cookies and similar technology
- 14. Changes to this policy
- 15. Contact and controller identification
1. Scope and our role
This Privacy Policy explains how SOPManagerPRO processes personal information through the public website and the SOPManagerPRO software service. In most customer workspaces, the subscribing company determines why and how business-user and controlled-document data are processed and acts as the customer/controller or responsible party; SOPManagerPRO generally acts as its service provider/processor or operator. For account administration, billing, security, website operation and our own business records, SOPManagerPRO may act as an independent controller/responsible party.
If your employer or another organisation created your account, its own privacy notices and instructions may also apply.
2. Information we collect
Depending on how you use the service, we may process:
- Account and contact data such as name, business email, company, role and authentication information.
- Company subscription and billing administration data, plan selection and account status.
- Controlled-document content, attachments, training records, electronic-signature records, distribution records, quality-system records and audit-trail data uploaded or generated by authorised users.
- Security and technical data such as IP address, login timestamps, failed-login events, browser/device information, session identifiers and server logs.
- Support communications and information you submit through forms or email.
- AI request content when an authorised user deliberately invokes an enabled AI feature.
3. How we use information
We use personal information to provide and secure the service; authenticate users; isolate company workspaces; administer subscriptions; generate controlled documents; maintain audit, training and distribution history; respond to support requests; prevent abuse; diagnose errors; improve reliability; meet legal obligations; and establish, exercise or defend legal claims. We do not use customer controlled-document content for targeted advertising.
4. Legal bases
Where GDPR or similar laws apply, processing may rely on performance of a contract, steps requested before entering a contract, legitimate interests in operating and securing a business SaaS service, compliance with legal obligations, or consent where required. Where South Africa's POPIA applies, processing is undertaken on applicable lawful grounds and subject to purpose limitation, security safeguards and data-subject rights.
5. AI-assisted features
AI functionality is optional and must be enabled by an Organisation Admin. When an authorised user chooses AI Import, Analyse, Compare or quiz drafting, relevant content may be transmitted to the configured AI provider to fulfil that request. Customers are responsible for deciding whether content is suitable and lawfully permitted to be submitted to an AI service. AI output is advisory and must be reviewed by qualified personnel before controlled use.
6. Sharing and service providers
We may disclose information to infrastructure, hosting, email, security, support, payment and AI service providers acting under appropriate contractual restrictions; to professional advisers; where required by law or valid legal process; in connection with a corporate transaction; or as instructed by the subscribing company. We do not sell personal information for money and do not use customer data for cross-context behavioural advertising.
7. International transfers
SOPManagerPRO and its service providers may process data in countries other than the user's own. Where required, we use legally recognised transfer mechanisms or other appropriate safeguards. Customers with specific data-residency or regulated-transfer requirements should contact us before placing such data in the service.
8. Retention
We retain account and service data for as long as needed to provide the service, meet contractual and legal obligations, maintain security, resolve disputes and preserve controlled-record traceability. Customer administrators control many document-retention decisions within their workspace. Some audit, approval, training or controlled-document records may need to be retained even after a user account is disabled. Backup copies may persist for a limited period after deletion from active systems.
9. Security
We use administrative, technical and organisational safeguards appropriate to a business SaaS service, including authenticated access, role-based controls, optional/required 2FA, audit trails, secure transport and tenant scoping. No internet service can guarantee absolute security. Customers must protect credentials, assign roles appropriately and notify us promptly of suspected compromise.
10. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, restrict or object to processing; obtain a copy or portability of information; withdraw consent; and complain to a supervisory authority. California residents may also have applicable rights to know, delete, correct, opt out of sale/sharing and limit certain sensitive-information uses. Because customer companies control much workspace data, we may redirect a request to the relevant customer administrator where appropriate.
We will not discriminate against an individual for exercising a legally protected privacy right.
11. South Africa / POPIA
Where POPIA applies, individuals may contact the responsible party or Information Officer regarding access, correction, objection or complaints. Individuals may also lodge a complaint with the Information Regulator of South Africa where applicable. Customer companies are responsible for appointing and publishing their own Information Officer details where required.
12. Children
SOPManagerPRO is a business service and is not directed to children. Individuals who are not legally able to enter into the applicable agreement should not create an account without appropriate authorisation.
13. Cookies and similar technology
We use essential session and security technologies necessary for login, authentication and operation of the service. The public site may use optional Google Analytics to understand website usage when enabled by the Platform Administrator. The default SOPManagerPRO integration requires visitor consent before Analytics loads and excludes authenticated customer-workspace activity. We do not use this integration for cross-context behavioural advertising. See the Cookie Policy for details.
14. Changes to this policy
We may update this Privacy Policy as the service, providers or legal requirements change. We will update the date above and, where required, provide additional notice of material changes.
15. Contact and controller identification
The service is offered under the SOPManagerPRO brand. The contracting legal entity is the entity identified on your order form, subscription record or invoice. Privacy questions and data-subject requests can be sent to privacy@sopmanagerpro.com. Customers should ensure their own company identity, privacy notices and Information Officer/DPO details are configured where required.
Privacy matters: privacy@sopmanagerpro.com · General/legal matters: support@sopmanagerpro.com