Skip to content
Legal

Privacy Policy

Effective date: 6 August 2026

This Privacy Policy describes how PremInspect ("we," "us," or "our") collects, uses, processes, and shares your information when you use our Software as a Service (SaaS) product, PremInspect, accessible at preminspect.tech (the "Service"). We are committed to protecting your privacy and handling your data transparently and securely.

By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

1. Information We Collect

We collect various types of information to provide and improve our Service to you.

1.1. Information You Provide Directly to Us

When you register for an account, configure inspections, or interact with our Service, you may provide us with the following personal information:

  • Account and Contact Information: Your company name, your name and surname, email address, and cell phone number.
  • Billing and Payment Information: Details necessary for processing subscriptions and payments.
  • User-Generated Content and Inspection Data: As part of using PremInspect, you can upload various images and input data through custom workflow inspections. This includes images (any images you choose to upload, which may range from personal images, identity documents, and registration documents to general pictures related to assets or inspections; we do not use biometric processing on these workflow-uploaded images; facial verification for time and attendance is a separate, opt-in feature described in section 1.4) and custom workflow inputs (data you configure and input into custom fields within your inspection workflows, such as rules for who does what, cost assignments, and other descriptive text or values, which can vary widely based on your specific configurations).
  • Support and Feedback: Information you provide when you contact us for support or submit feedback.

1.2. Information Collected Automatically

When you access and use our Service, we automatically collect certain information, including:

  • Usage Data: This may include your device's Internet Protocol (IP) address, browser type and version, device type, operating system, unique device identifiers, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, and other diagnostic data.
  • Cookies and Tracking Technologies: We use cookies, web beacons, and similar tracking technologies to monitor activity on our Service and store certain information. This helps us analyze user behavior and improve the Service.
  • Marketing Website Analytics: Our public marketing pages (preminspect.tech) use Vercel Web Analytics and Vercel Speed Insights, which are cookieless: no cookie or other identifier is stored on your device, and visitors are counted using a request-derived hash that rotates daily and cannot track you across other websites. We also record which marketing calls-to-action are clicked (as fixed, non-identifying labels such as "trial" or "talk to us") to understand which pages convert.
  • Enquiry Provenance: When you submit an enquiry or register interest on our marketing site, we record, alongside the details you provide, the campaign parameters (UTM tags) and referring page that brought you to us, and a salted, daily-rotating hash of your IP address (never the raw IP) used solely for abuse prevention. This lands in our own database and is not shared with advertising platforms. We only send you marketing communications if you expressly opt in via the checkbox on the form; you can unsubscribe at any time, and we will still respond to your enquiry either way.

1.3. Information from Third Parties

We may receive information about you from third-party services that we integrate with or utilize to provide our Service, such as:

  • Database and Hosting Providers: cloud database and web hosting providers, and providers of background and scheduled processing (including notification delivery, invoicing, and facial-verification matching).
  • Payment Processing: payment processors handling subscription billing and card authorisation.
  • Communication Services: providers delivering email, messaging, and push notifications.
  • Marketing and CRM Tools: customer-relationship and newsletter tools used to send newsletters and marketing communications.

1.4. Biometric Data (Facial Verification for Attendance)

Where your organisation enables PremInspect's optional facial-verification feature for time and attendance, we process facial images as biometric data, which is "special personal information" under POPIA and a "special category" of personal data under the GDPR. This is used solely to confirm a worker's identity when they clock in or out, applies only where a site is configured to require an identity photo, and is processed only with the worker's explicit opt-in consent, which is captured at enrolment and can be withdrawn at any time.

At enrolment we store a reference facial image (a selfie, or a face cropped from an identity document) as the trusted reference. At each clock-in or clock-out that requires it, we capture a probe image and compare it against that reference to produce a match score. Facial images and references are stored privately and encrypted, are used for no purpose other than attendance identity verification, and are never sold or used for marketing. Face matching runs on infrastructure operated by or for PremInspect. Your organisation acts as the data controller (responsible for informing its workers and obtaining any further consents required) and PremInspect acts as the data processor. See sections 5 and 7 for retention and for how to withdraw consent or request deletion.

1.5. Time and Attendance Data (Location and Verification)

Where your organisation uses PremInspect's time and attendance feature, we collect precise device location (latitude, longitude, and accuracy) at clock-in and at clock-out where the site requires it or the attendance flow supplies it. A site configured not to require a location check may record none, and a clock-out may store none. Where a manager clocks a worker in or out on their behalf, the location recorded is the MANAGER's device location, captured on a best-effort basis. We also collect, where a site is configured to require it, an identity selfie, a signature, and answers to any clock-in/clock-out form. This confirms where and when work was performed. We do not sample your location at intervals during a shift. This data is scrubbed or deleted when the associated account is deleted (see sections 5 and 7).

Where your organisation configures a site to remind workers or to clock them out automatically when they leave, the app also monitors your location in the background while you have an open shift at that site, including when the app is closed, so that leaving the site can be detected. This begins when you clock in and stops when you clock out; it is never active outside an open shift. Only entry to and exit from the configured site are recorded, together with the location fix that confirmed the exit; we do not record a continuous trail of your movements while in the background. Background monitoring requires a separate permission on your device, which you may decline or withdraw at any time in your device settings. The feature simply stops detecting exits, and clocking in and out continues to work normally.

2. How We Use Your Information

We use the collected information for various purposes, primarily to provide, maintain, and improve our Service, and to communicate with you.

  • To Provide and Maintain Our Service: This includes managing your account, enabling asset inspections, facilitating custom workflow creation and execution, and providing customer support.
  • To Improve and Personalize Your Experience: We analyze usage patterns and feedback to enhance user experience, develop new features, and optimize existing functionalities.
  • To Communicate with You: We use your contact information to send you service updates, important notices, and, with your consent, marketing communications and newsletters via WhatsApp or email.
  • To Process Payments: We use billing information to manage subscriptions and process payments securely.
  • To Ensure Platform Security and Prevent Fraud: We use data to maintain the stability, integrity, and security of the PremInspect platform, including detecting and preventing fraudulent activities and unauthorized access.
  • To Comply with Legal Obligations: We may process your information to fulfill regulatory requirements, respond to legitimate legal requests, and prevent fraud.
  • For Business Transfers: In the event of a merger, acquisition, divestiture, or sale of assets, your information may be transferred as part of the transaction.
  • For Sale to Third Parties: We may sell aggregated or anonymized data related to costs assigned to assets, if we develop a data pool that enables us to provide costing insights. This is the only type of data currently intended for sale. Any such sale will be conducted in compliance with applicable data protection laws, including obtaining necessary consent or providing opt-out mechanisms where required.

3. How We Share Your Information

We may share your information with the following categories of third parties:

  • Service Providers: We engage third-party companies and individuals to facilitate our Service, provide the Service on our behalf, perform Service-related services, or assist us in analyzing how our Service is used. These fall into the following categories: cloud hosting and database providers; background and scheduled processing providers, including facial-verification matching; communication providers, for the delivery of email, messaging and push notifications; mapping and location providers; diagnostics providers, for error and crash reporting; payment processors; and customer-relationship and newsletter tools.
  • For Business Transfers: If PremInspect is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.
  • Law Enforcement and Legal Obligations: We may disclose your Personal Data in the good faith belief that such action is necessary to comply with a legal obligation, protect and defend the rights or property of PremInspect, prevent or investigate possible wrongdoing in connection with the Service, protect the personal safety of users of the Service or the public, or protect against legal liability.

Important Note on User-Configured Data: When you use PremInspect's custom workflow features to collect data, including images, you (as the PremInspect client) act as the "data controller," determining the purpose and means of processing that data. PremInspect acts as a "data processor," processing this data on your behalf. You are responsible for ensuring you have the necessary legal bases and consents for any personal data you collect through your custom workflows, especially if it includes sensitive information or images of individuals. We recommend that you have a comprehensive Data Processing Addendum (DPA) in place with us to define the responsibilities of both parties.

4. International Data Transfers

PremInspect is a SaaS platform that will be sold globally. As such, your information, including Personal Data, may be transferred to, and maintained on, computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place, including the security of your data and other personal information. This may include reliance on Standard Contractual Clauses (SCCs) or other legally recognized transfer mechanisms where applicable.

5. Data Retention

We retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements).

We apply the following best practices for data retention:

  • Account and Billing Data: Retained for the duration of your active account with PremInspect and for a period thereafter as required by legal and financial regulations (e.g., typically 7+ years for financial records).
  • Usage Logs and Analytics Data: Typically retained for 12–24 months for product improvement and performance monitoring.
  • Inspection Records and Images: Retained for as long as required by your client contract and any relevant industry-specific legal minimums.
  • Identity Documents and Personal Images (if uploaded by users): Retained for the shortest period necessary to fulfill the specific purpose for which they were uploaded, and securely deleted thereafter, or upon your request, unless a legal obligation requires longer retention.
  • Biometric Face References and Attendance Images: Retained only while facial verification remains enabled for the worker, and securely deleted upon consent withdrawal, disenrolment, or account closure, subject to any short period required to complete a pending match or to meet a legal obligation.
  • Time and Attendance Location Data: Precise clock-in and clock-out location, and (where a site uses leave-site detection) the site entry and exit events for an open shift, are retained for your organisation's attendance and payroll needs, and are scrubbed when the associated account is deleted.
  • Legal Holds: In cases of litigation, regulatory investigations, or other legal requirements, data deletion may be suspended to ensure relevant data is preserved.

When you delete your account, or when a retention period expires, we anonymise the associated Personal Data (replacing your name and email address with a non-identifying placeholder and deleting your phone number, password, and any biometric face references), and we permanently delete private files such as attendance identity photos and signatures. We retain a de-identified audit record of the deletion (including any reason you choose to provide) and we keep records of completed inspections and tasks linked to that anonymised placeholder, where permitted by law for audit, security, and legal-obligation purposes.

6. Data Security

We are committed to protecting the security and integrity of your data. Our platform is built using secure, modern web frameworks and hosted on reputable, industry-leading cloud infrastructure providers. All API routes and databases are secured with access control layers, encryption, and continuous monitoring.

Our security measures include:

  • Authentication & Access Control: APIs are protected using short-lived, cryptographically signed JSON Web Tokens (JWTs) that expire every 15 minutes; refresh tokens are securely stored and valid for 7 days to enable seamless session continuation while maintaining security; and access is role-based, restricting system functionality according to user permissions and adhering to the principle of least privilege.
  • Data Encryption: In transit, all data is encrypted using TLS 1.2 or higher; at rest, sensitive data is encrypted using modern cryptographic standards (e.g., AES-256) when stored on servers or databases.
  • Audit & Monitoring: We log critical system events and monitor for unauthorized activity, with regular internal reviews and automated alerting to help us quickly identify and respond to potential threats.
  • Incident Response: We maintain a structured incident response plan, including rapid detection, containment, user notification (if required by law), and thorough post-incident reviews.

7. Your Data Rights

Depending on your location and applicable data protection laws (such as GDPR, CCPA, and POPIA), you may have the following rights regarding your Personal Data:

  • Right to Be Informed: The right to know what personal data is collected, the purposes for its collection, and how it will be used and shared.
  • Right of Access: The right to request and obtain a copy of your personal data held by us.
  • Right to Rectification/Correction: The right to request corrections to inaccurate or incomplete personal data.
  • Right to Erasure ("Right to Be Forgotten"): The right to request the deletion of your personal data under specific circumstances.
  • Right to Object to Processing: The right to opt-out of or restrict certain data processing activities, particularly those related to direct marketing or profiling.
  • Right to Opt-Out of Sale/Sharing (CCPA): If you are a California resident, you have the right to opt-out of the sale or sharing of your personal information.
  • Right to Data Portability (GDPR): The right to request your data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

How to Exercise Your Rights: You can exercise your rights by contacting us at legal@preminspect.tech. We will respond to your request in accordance with applicable law. If you are in South Africa, you also have the right to lodge a complaint with the Information Regulator (South Africa).

7.1. Deleting Your Account

You can delete your account at any time from within the app. When you request deletion, your account is immediately deactivated and enters a 30-day grace period. The deletion can be cancelled during this period to restore your account and data; because requesting deletion signs you out, you may need to ask your organisation's administrator or contact support to cancel once your session has ended. After 30 days, your Personal Data is permanently anonymised or deleted as described in section 5. An administrator of your organisation can also delete a team member's account; administrator-initiated deletions take effect immediately. During the grace period we notify your organisation's administrators so that any outstanding inspection or task work can be reassigned.

For notifications, marketing, and newsletters, we will provide clear opt-in/opt-out mechanisms, allowing you to control your communication preferences.

8. Children's Privacy

Our Service is not directed to individuals under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from anyone under the age of 13 without verification of parental consent, we take steps to remove that information from our servers.

If users upload images that contain identifiable children, the PremInspect client (as the data controller) is responsible for obtaining explicit parental or guardian consent, especially given the stringent requirements under laws like POPIA, which strongly advise against identifiable images of children due to heightened risks.

9. Changes to This Privacy Policy

We may update our Privacy Policy from time to time to reflect changes in our practices, legal requirements, or technological advancements. We will notify you of any significant changes by posting the new Privacy Policy on this page, and by email or a prominent notice on our Service, prior to the change becoming effective.

We recommend reviewing this Privacy Policy periodically for any changes.

10. Contact Us

If you have any questions about this Privacy Policy, please contact us by email: legal@preminspect.tech

11. Data Protection Contact (POPIA)

For data-protection matters under South Africa's Protection of Personal Information Act (POPIA), including access, correction, or deletion requests, you can contact PremInspect at legal@preminspect.tech. You also have the right to lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za.