Privacy Policy
This policy explains how we handle personal information on this Platform (yowl.co.za). We try to collect as little as necessary and be clear about what we do with what we keep.
1. Who we are
CDSoft (Pty) Ltd (Registration No. 2023/618547/07) is a South African company at 16 Sering Street, Red Swallow Room, Stellenbosch, Western Cape, 7600. We operate this Platform. For the account information of our users we are the responsible party under the Protection of Personal Information Act 4 of 2013 (POPIA). For candidate data that organisations store on the Platform, the organisation is the responsible party and we act as their operator (see section 5).
2. What we collect
For account holders (recruiters and hiring organisations):
- Your name and email address (account creation)
- Organisation name and chosen Platform address (e.g. your-name.yowl.co.za)
- Job listing content you post
- Session data (login state, device type, browser — standard web auth)
- Preference cookies (e.g. your chosen sort order or filters) — functional only, no tracking or advertising cookies
For job applicants (people who apply by email):
- Your application email and its attachments (including your CV)
- A structured summary we extract from your CV (name, contact details, roles, skills, education)
- Where the organisation uses the assessment tools, an AI-generated summary, score, or ranking of your application against the role
- Your email address — used to create your applicant account and show you your application status
For all visitors:
- Basic usage logs (pages visited, actions taken) — used for debugging and improving the Platform
- IP address — retained briefly for security purposes, not used for analytics profiling
3. What we don’t collect
- Payment card details (handled entirely by PayFast — we never see your card number)
- Data from social networks unless you explicitly connect them
- Behavioural tracking across other websites
4. Why we collect it
| Data | Purpose |
|---|---|
| Email address | Account authentication, platform notifications |
| Organisation details | Your branded presence and job listings on the Platform |
| Application email, attachments & extracted CV summary | Deliver your application to the organisation and let it review your application |
| AI-generated summary / score / ranking | Help the organisation review and rank applications (decision-support — a person decides) |
| Usage logs | Debugging, platform reliability |
| Session data | Keep you logged in securely |
| Preference cookies | Remember your settings (sort order, filters) between visits |
Our lawful basis under POPIA is a combination of your consent (given when you register or accept our terms) and the performance of our contract with you to provide the Platform; for security and reliability logging we rely on our legitimate interest. We do not sell personal information. We do not use your content for advertising.
5. Candidate data in your organisation’s records
The Platform lets organisations store and manage candidate information — applications, CVs, contact details, notes. For that data, the organisation is the responsible party under POPIA and CDSoft (Pty) Ltd is an operator processing it on the organisation’s instructions. The organisation decides what is collected and why; we store and process it to provide the software — including, where the organisation uses them, AI-assisted tools that summarise and rank applications against a role (see section 7 for the AI provider involved).
If you are a candidate whose information is held in an organisation’s records on this Platform: your relationship is with that organisation. Requests for access, correction, or deletion should go to them. If you contact us directly, we will refer your request to the organisation and may act ourselves where the law requires.
If you applied to a role by email (to an address like j22@yowl.co.za): parts of that flow are run by CDSoft (Pty) Ltd as a responsible party in its own right — the consent step, the account created for you, the optional CV review, and the optional job-seeker profile on our affiliated boards. Those parts are covered by our Applicant Terms & Privacy Notice.
6. Employment contract documents
Organisations can generate employment contract documents on the Platform (section 4 of our Terms of Use). A generated contract contains the personal information of the person being hired — name, ID or passport number, home address, and pay — entered by the organisation. As with other records in an organisation’s account, the organisation is the responsible party for this information and CDSoft (Pty) Ltd stores and processes it as the organisation’s operator: we render the document to PDF and store it so the organisation can download and use it.
If you are named in a contract generated on the Platform: the document belongs to the employer that created it, so requests about it — access, correction, deletion — should go to that employer, in the same way as section 5. Contract documents are removed when the organisation deletes them or its account (section 9); employers are separately required by employment law to keep employment records for a period after employment ends — that duty is theirs.
Where a contract is sent for electronic signature through the Platform, we record the signature event — time, email address, and network (IP) address — as evidence of who signed, and the signed document is provided to both the employer and the signee.
7. Who we share data with
We use a small number of infrastructure providers to operate the Platform:
- Cloudflare — hosting, database, CDN, DDoS protection. Data may be processed on servers outside South Africa. Cloudflare is a POPIA-compliant data processor under a data processing agreement.
- Resend — transactional email delivery (login links, notifications). Your email address is shared only to send emails you’ve requested.
- PayFast — payment processing for paid features. The Platform passes you to PayFast’s secure environment to complete payment. We do not receive or store your card details.
- Anthropic (Claude API) — the Platform sends document content (e.g. CVs attached to applications) to Anthropic’s API to extract structured information and, where an organisation uses the assessment tools, to summarise and rank applications against a role. Anthropic does not use this data to train its models under our agreement, and does not retain content beyond the immediate API response.
- Sentry — error monitoring. When something breaks, technical error context (which can include your user ID, IP address, and request details) is sent to Sentry so we can diagnose and fix it. Not used for anything else.
Beyond these providers we do not sell or share your personal information. The only exceptions are things you actively choose: content you publish in your organisation’s listings and public pages, and — if you opt in — distributing a listing or creating a job-seeker profile on our affiliated boards gigz.co.za and permz.co.za, which are then governed by those boards’ own terms.
8. Cross-border transfers
Several of our providers operate outside South Africa, so your data may be processed abroad: Cloudflare, Anthropic, Resend, and Sentry (United States), and PayFast, whose parent company is based in the United Arab Emirates. This is permitted under POPIA Section 72 where the recipient is subject to equivalent protection obligations — each of these providers satisfies this requirement through its data processing agreement.
9. How long we keep your data
| Data | Retention |
|---|---|
| Active account | Held while your account is active |
| Deleted account | Account, organisation, and its records removed within 30 days of deletion |
| Inbound application where our terms were never accepted | After 14 days the email content, CV, and attachments are deleted and the record is irreversibly de-identified — only anonymous statistics remain (no name, address, or message content) |
| Usage logs | 90 days rolling |
| Payment records | 5 years (SARS compliance) |
If your account has been inactive for 12 months, we will email you before deleting it.
10. Your rights under POPIA
As an account holder you have the right to:
- Access — request a copy of the personal information we hold about you
- Correction — ask us to correct inaccurate information
- Deletion — ask us to delete your account and associated data
- Objection — object to specific processing (e.g. marketing emails)
- Automated decisions — where your application is assessed by automated tools, ask for the reasons, request review by a person, and object to a decision based solely on automated processing (section 71 of POPIA)
- Complaint — lodge a complaint with the Information Regulator at inforegulator.org.za
To exercise any of these rights, contact us. We will respond within 30 days. Candidates whose data is held in an organisation’s records: see section 5 and our Applicant Terms & Privacy Notice.
For how to request access to records CDSoft holds — including the applicable PAIA forms and fees — see our PAIA Manual.
11. Security
Connections to the Platform are encrypted (HTTPS). Data at rest is encrypted by Cloudflare’s storage infrastructure. Access to production systems is restricted to authorised personnel.
No system is completely immune to breach. If a breach occurs that poses a material risk to your rights, we will notify you and the Information Regulator as required by POPIA.
12. Age — 18 and over only
The Platform is for adults. You must be 18 or older to hold an account or to apply for a role through the Platform. We do not knowingly collect or process the personal information of anyone under 18; if we learn that a user or applicant is a minor, we delete their information.
13. Changes to this policy
If we make material changes to how we handle your personal information, we will notify active users by email at least 14 days before the change takes effect.
Information Officer: Brent Greeff — contact us