Legal
Privacy Policy
Last updated: 14 August 2026
This Privacy Policy explains how UniApplyForMe Labs (Pty) Ltd ("we", "us", "our") collects, uses, and protects your personal information when you use the UniApplyForMe Labs Data API and API Console.
1. Information We Collect
We collect: (a) account information: your email address, full name, and optionally company name, website, and use case description when you register; (b) API usage data: endpoint paths, response times, HTTP status codes, IP addresses, and user agent strings for every API request made using your tokens; (c) billing information: payment records processed by Yoco; we do not store card numbers or CVV codes; (d) communications: any support requests or emails you send to us.
2. How We Use Your Information
We use your information to: provide, operate, and improve the Service; send transactional emails including email verification, billing receipts, and service notices; enforce rate limits and detect abuse; provide usage analytics in your dashboard; and comply with legal obligations. We do not sell, rent, or trade your personal information to any third party.
3. API Usage Logs
Every API request is logged with your token ID, IP address, endpoint, response time, and status code. These logs are used for your dashboard analytics, rate limit enforcement, and abuse detection. Logs are retained for 90 days and then deleted. IP addresses are not shared with third parties.
4. Terms Acceptance Records
We record the date, time, IP address, and version of our Terms of Service at the time you accept them. This record is kept for the lifetime of your account and for a period of 5 years after account deletion, as required for legal compliance purposes.
5. Data Storage and Security
Your data is stored in a PostgreSQL database hosted on AWS infrastructure via Supabase, located in regions compliant with applicable data protection standards. API tokens are stored as one-way cryptographic hashes; we cannot retrieve your raw token value after it is shown to you at creation. We implement reasonable technical and organisational measures to protect your data against unauthorised access, loss, or disclosure.
6. Cookies
We use session cookies solely for authentication purposes. We do not use tracking, analytics, or advertising cookies.
7. Your Rights under POPIA
Under the Protection of Personal Information Act 4 of 2013 (POPIA), you have the right to: access the personal information we hold about you; request correction of inaccurate information; request deletion of your account and associated personal data; object to the processing of your information; and lodge a complaint with the Information Regulator of South Africa (https://www.inforegulator.org.za/). To exercise any of these rights, contact us at data@labs.org.za. Account deletion requests are processed within 30 days.
8. Data Retention
We retain your account data for as long as your account is active. Upon account deletion, personal data is removed within 30 days, except for terms acceptance records (5 years) and billing records (as required by South African tax law).
9. Third-Party Services
We use the following third-party services: Supabase (database and authentication infrastructure), Yoco (payment processing), AWS SES (transactional email), and Cloudflare (edge hosting and caching). Each operates under its own privacy policy. We do not share your personal data with these providers beyond what is necessary to deliver the Service.
10. Contact and Complaints
For privacy-related requests, questions, or complaints, contact us at data@labs.org.za. If you are not satisfied with our response, you may lodge a complaint with the Information Regulator of South Africa.