Martoza Privacy Notice
Version 2026.08 · effective 2026-08-26
Plain-language overview. This notice explains how Martoza processes personal information under the Protection of Personal Information Act 4 of 2013 (POPIA). It must be read with the Terms of Service and Cookie Policy.
1. Responsible party and operator roles
GCR Suppliers (Pty) Ltd (registration 2020/186834/07) operates the Martoza platform. For platform accounts, subscriptions, security and support, the operator determines why and how information is processed. For employee, customer, supplier, sales and market records entered by a business or organiser, that business or organiser generally determines the purpose and Martoza processes the information to provide the service.
Information Officer: Gert Cornelis Rosslee · info@martoza.co.za. Address: 36B Gladstone Avenue, Geduld Extension, Springs, 1559.
2. Information collected
- Identity and contact information, account credentials and business membership.
- Business, employee, customer, supplier, product, sale, invoice, stock, booking and support information entered by authorised users.
- Subscription, EFT reference and PayFast transaction status. Martoza does not store full card details processed on PayFast pages.
- Security, audit, device, app-version, IP-address and diagnostic records needed to protect and operate the service.
- Uploaded logos, market maps, receipts and documents supplied by authorised users.
3. Sources, purposes and justification
Information comes from the person concerned, their authorised business or organiser, platform administrators and service providers used to complete a requested payment or communication. It is processed to create and secure accounts, perform subscriptions and transactions, provide POS/stock/market services, communicate, support users, prevent fraud, keep audit evidence and meet legal obligations. Processing is limited to consent where required, contractual necessity, legal obligations, protection of legitimate interests and other grounds permitted by section 11 of POPIA.
4. Required information and consequences
Fields marked required are needed to create an account or perform the requested service. Without them Martoza may be unable to register the user, process a booking, secure the account or provide support. Optional profile and branding information may be omitted.
5. Sharing and service providers
Access is restricted by business membership, role and permission. Information may be disclosed to hosting, backup, email, support, PayFast/payment and communication providers only as needed for the service, or to regulators, courts and law-enforcement bodies when lawfully required. Current service-provider description: Payment processing, hosting and email delivery providers used only to deliver the requested Martoza services.
Martoza does not sell personal information.
6. Cross-border processing
No routine cross-border processing is knowingly conducted. Any future transfer will be assessed and documented under section 72 of POPIA before personal information is processed outside South Africa.
7. Retention and deletion
Operational customer-controlled records are retained for up to 2,555 days by default. Encrypted backups are ordinarily retained for up to 30 days. Shorter or longer periods may apply where records remain necessary for tax, accounting, employment, payment, dispute, fraud-prevention, legal-hold or contractual purposes. At the end of the applicable period, records are securely deleted, de-identified or retained only where law permits.
8. Security safeguards
Martoza uses HTTPS, password hashing, access control, rate limiting, encrypted tenant credentials and backups, audit/security logs, restricted uploads and restore safeguards. No system can guarantee absolute security. Users must protect credentials, remove former staff access and report suspected compromise immediately.
9. Your rights
Subject to POPIA and other applicable law, a data subject may ask whether information is held; request access; request correction, deletion or restriction; object to processing; withdraw consent where consent is relied upon; and complain to the Information Regulator. Identity is verified before information is released or changed. A deletion request may be refused or limited where retention is legally required. Prescribed POPIA objection and correction/deletion forms remain available from the Information Regulator.
Submit an access, correction, deletion or objection request Official POPIA forms
10. Direct marketing, children and automated decisions
Martoza does not authorise unsolicited electronic marketing without the consent or existing-customer conditions required by law, and opt-out requests must be honoured. The service is intended for persons able to enter binding business arrangements; information about children must not be entered without lawful authority. Martoza does not make solely automated legal or similarly significant decisions about individuals.
11. Security compromises
Suspected compromises must be reported without delay to security@martoza.co.za. Martoza records, contains and assesses incidents and will notify the Information Regulator and affected data subjects as soon as reasonably possible where POPIA requires it, subject to lawful delay.
12. Contact and complaints
Privacy requests: privacy@martoza.co.za. You may also complain to the Information Regulator (South Africa). See the PAIA information page for access-to-record guidance.
This operational notice supports compliance but does not constitute legal advice. The operator and each customer business remain responsible for obtaining professional advice appropriate to their activities.