Who is responsible
Stemma Global (Pty) Ltd is responsible for the personal information it processes for its consultancy, software, project-delivery and business-administration activities. This notice applies to stemmaglobal.com, EngOS, enquiries, proposals, engagements and authorised integrations used to run the business.
We apply the Protection of Personal Information Act, 2013 (POPIA) and, where relevant, the EU General Data Protection Regulation. This notice is general information and does not replace engagement-specific contractual or statutory requirements.
What we process
Depending on your interaction with us, we may process contact and company details, enquiry and scope information, correspondence, proposals, approvals, project records, time and delivery evidence, invoices, payment status and technical security or audit records.
Scope documents submitted to the public Estimate Engine are processed to prepare the requested response and are not intentionally retained by that public workflow. Instant Engagement and governed Service Product attachments are different: EngOS validates their integrity, associates them with the request and engagement, and retains them under the confidentiality and retention controls of the accepted Service Product and applicable legal, contractual and audit requirements.
Do not upload information you are not authorised to share. Where a Service Product prohibits external-model processing, its governed attachments are not supplied to an external model.
Why we use information
We use information to respond to enquiries; assess, price and deliver work; communicate with clients; administer contracts; maintain project and accounting records; meet legal obligations; secure our systems; and establish, exercise or defend legal rights.
Our grounds for processing may include taking steps at your request, performing a contract, complying with law, consent where required, and legitimate interests that do not override your rights.
Xero accounting data
When an authorised administrator connects EngOS to Xero, EngOS may send and retrieve the minimum accounting information needed to create and reconcile contacts, invoices and payment records. This may include client names, company names, business email addresses, invoice line descriptions, references, dates, currencies, amounts and payment status.
Xero API data is used only for the approved accounting and reconciliation functions. It is not used to train, fine-tune, adapt or enhance artificial-intelligence or machine-learning models, and is not sold or used for advertising.
EngOS keeps the official Stemma invoice number, records reconciliation evidence and stores Xero access credentials in encrypted form. Access is limited to authorised administrators and service processes. An administrator may disconnect Xero, after which EngOS stops using the connection; accounting records already required for legal or audit purposes may still be retained.
Location and road-route data
When you ask for a service that permits road travel, the location text or map point you choose is sent through Stemma's server to OpenStreetMap-based geocoding and routing services. We use it to calculate the road distance and journey time from our stated office, determine whether remote delivery is required, and prepare the travel component of the quotation. A selected destination and the resulting route evidence may be retained with the enquiry, quotation and engagement record; payment-card information is not involved in this calculation.
Paystack-hosted payments
When a prepaid Instant Engagement or governed Service Product offers Paystack checkout, Paystack hosts the payment page. Stemma and EngOS do not receive or store the card or bank credentials you enter on that page.
We send Paystack the information needed to initiate and reconcile the payment, which may include your business email address, service description, engagement reference, accepted quotation and acceptance identifiers, amount, currency and a unique payment reference. We receive and retain governed transaction evidence such as provider identifiers, status, amount, currency, paid timestamp, channel, fees, gateway response and verification or reversal information. EngOS verifies payment status server-side and links that evidence to the accepted, version-controlled quotation.
We use this information to collect payment, prevent duplicate or fraudulent processing, reconcile accounting records, administer cancellations, refunds and disputes, and meet legal, tax and audit duties. Paystack processes payment information under its own privacy and security obligations. Payment data is not sold, used for advertising or used to train artificial-intelligence models by Stemma.
Security and retention
We use role-based access, authenticated integrations, encryption of connector credentials, audit records, recoverable processing queues, controlled project storage and data-minimisation measures. No system can guarantee absolute security; suspected incidents are investigated and notified where required by law or contract.
We retain information only for as long as needed for the purpose collected, contractual delivery, legal and accounting obligations, dispute management and legitimate audit requirements. Retention periods depend on record type and applicable law.
Access and correction
You may ask whether we hold personal information about you and request access, correction or deletion where applicable. You may also object to or request restriction of certain processing, withdraw consent where processing depends on it, or raise a complaint with the Information Regulator of South Africa or another competent authority.
Send requests to [email protected]. We may need to verify your identity before acting. We will update this notice when our processing or legal obligations materially change.