Legal

Privacy Policy

Last updated: 24 June 2026  ·  POPIA Compliant

Contents

  1. Who We Are
  2. What Information We Collect
  3. How We Use Your Information
  4. Who We Share It With
  5. How Long We Keep It
  6. How We Protect It
  7. Your Rights (POPIA)
  8. Cookies
  9. Children's Privacy
  10. Changes to This Policy
  11. Contact & Complaints
This Privacy Policy explains how Business Direct Medi (BDM) collects, uses, and protects personal information in connection with the Digitot Loyalty platform. We are committed to compliance with the Protection of Personal Information Act 4 of 2013 (POPIA).

1. Who We Are

Responsible Party: Business Direct Medi (BDM)
Platform: Digitot Loyalty (digitot-loyalty.co.za)
Email: support@digitot-loyalty.co.za
Phone: 0861 10 11 70

As the operator of the Digitot Loyalty platform, BDM acts as the Responsible Party for data collected directly from Business and Customer accounts. Individual Businesses act as Responsible Parties for their own customer loyalty data collected through the platform.

2. What Information We Collect

From Business Owners:

From Customers:

Automatically collected:

We do not collect or store payment card details. All billing is handled externally.

3. How We Use Your Information

Purpose Legal Basis (POPIA)
Creating and managing your accountContractual necessity
Processing stamp collections and rewardsContractual necessity
Sending account and transactional emailsContractual necessity
Providing customer supportLegitimate interest
Preventing fraud and securing the platformLegitimate interest
Syncing customer records with DigitotPOSContractual necessity / consent
Sending onboarding email sequences to new businessesLegitimate interest
Generating invoices and billing recordsLegal obligation
Improving the platformLegitimate interest

We do not use your personal information for unsolicited marketing without your consent.

4. Who We Share It With

We do not sell personal information. We may share information with:

All third parties are bound by confidentiality obligations and may only process data as instructed by us.

5. How Long We Keep It

6. How We Protect It

We implement appropriate technical and organisational measures to protect personal information, including:

In the event of a data breach that is likely to result in harm, we will notify affected parties and the Information Regulator as required by POPIA.

7. Your Rights Under POPIA

As a data subject under POPIA, you have the right to:

To exercise any of these rights, contact us at support@digitot-loyalty.co.za. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Regulator of South Africa at www.justice.gov.za/inforeg/.

8. Cookies

The Platform uses cookies strictly necessary for operation, including:

We do not use advertising cookies, analytics cookies from third-party trackers, or tracking pixels. No cookie consent banner is required as we only use strictly necessary cookies.

9. Children's Privacy

The Platform is not intended for use by persons under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected information from a minor, please contact us immediately and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify registered Business users by email.

Continued use of the Platform after any changes constitutes your acceptance of the updated policy.

11. Contact & Complaints

For privacy-related requests or complaints, contact our Information Officer:

Business Direct Medi (BDM)
Email: support@digitot-loyalty.co.za
Phone: 0861 10 11 70
Subject line: Privacy Request

If you are not satisfied with our response, you may lodge a complaint with the Information Regulator of South Africa.