Privacy Policy

SWS-Global Privacy & Data Protection Policy.

[Note: This Policy has been drafted based on the information made available to the drafter by the Client/Company as at the date of publication. Certain assumptions have been made regarding the collection, processing, storage, transfer, and security of personal data. Should the Client/Company’s actual data processing activities, website functionality, third-party integrations, technical infrastructure, or operational practices differ from these assumptions, this Policy may require amendment to ensure ongoing accuracy and compliance.]

Smart Workforce Solutions is committed to protecting the privacy and security of the personal data we process. This Global Privacy and Data Protection Policy (the “Policy”) outlines our data protection practices across our international operating network, which includes SMART WORKFORCE SOLUTIONS PTY LTD (Australia), INTEGRITYX FZCO (Dubai, UAE), and their corporate affiliates (collectively, “the Company”, “we”, “us”, or “our”).

This Policy applies to personal data collected via our website, digital interfaces, and during the standard administration of our international business-to-business (B2B) project consultancy portfolios.

Regulatory Framework & Annual Review Mandate
  • The Company’s operations comply with the relevant data protection frameworks within the jurisdictions of our corporate entities and global partners:
  • Australia: The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
  • United Arab Emirates: Federal Decree-Law No. 45 of 2021 on Personal Data  Protection (UAE PDPL).
  • Republic of South Africa: The Protection of Personal Information Act, No. 4 of 2013 (POPIA).
  • United Kingdom: The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
  • United States of America: Applicable state-level comprehensive data privacy enactments.
  • Statutory Notice & Compliance Update Policy: The legislative frameworks enumerated above are accurate as of the publication date of this Policy. The Company reviews this Policy at least once per calendar year to ensure ongoing alignment with international statutory amendments. Revised policies are published directly to this website upon the conclusion of each annual review.
Data Minimisation & Passive Browsing Protections
  • The Company enforces strict data minimisation protocols to ensure user privacy and reduce unnecessary data retention.
A. Website Visitors (Absolute Zero-Collection)
  • No Telemetry Harvest: We do not collect, log, track, or process any technical telemetry, network indicators, or behavioral analytics from individuals who merely browse our public website.
  • Exclusions: The Company explicitly does not collect or store Internet Protocol (IP) addresses, precise geolocation data, browser configurations, operating system types, or device identifiers from passive website visitors. No tracking pixels or automated background harvesting tools are deployed on our public web properties.
B. Voluntary Information Submission
  • Personal data is only processed when a user intentionally and affirmatively provides it to us, such as by completing an online contact form, submitting a project inquiry, or uploading a professional profile. By voluntarily submitting this information, you authorise the Company to process and transmit your data strictly for the purpose of evaluating and responding to your commercial inquiry or project placement suitability.
Categories of Data We Process
  • The scope of personal data processing is strictly confined to information required to administer our corporate service portfolios:
  • Candidates & Independent Subcontractors: Legal names, contact details (email, phone, address), nationality, professional histories, qualifications, certifications, references, and necessary financial disbursement credentials required for project-based payment processing.
  • Enterprise Corporate Clients: Professional nomenclature, corporate email addresses, business phone numbers, job titles, and transactional engagement histories.
Lawful Bases for Processing
  • We process personal data only under valid legal grounds:
  • Contractual Necessity: To evaluate project placement criteria, manage independent subcontracting agreements, administer corporate client accounts, and execute our B2B service mandates.
  • Legitimate Interests: To maintain network security, verify professional credentials, manage corporate risk, and conduct targeted business-to-business communications.
  • Statutory Obligation: To satisfy mandatory fiscal regulations, corporate accounting metrics, and international cross-border reporting laws.
Technical Architecture & Cross-Border Data Access
  • To comply with international data-localisation mandates, the Company utilises a decentralised, client-segregated data management infrastructure.
  • While central commercial administration, project scoping, and contract compliance are managed by INTEGRITYX FZCO and SMART WORKFORCE SOLUTIONS PTY LTD, daily project data and task-specific deliverables are processed within secure, client-allocated cloud networks or enterprise environments. To support data residency compliance and enterprise perimeter security, independent subcontractors access these designated client environments directly from their local workspace in South Africa.
  • To secure these cross-border pathways, the Company deploys standard international transfer mechanisms:
  • United Kingdom Data Safeguards: Data flows involving United Kingdom enterprise clients are governed by a mandatory UK International Data Transfer Agreement (IDTA) executed by the Company, and fully supported by a Transfer Risk Assessment (TRA) in compliance with the Information Commissioner’s Office.
  • South African Data Safeguards: Data processed within South Africa is contractually protected by strict data processing covenants within our independent contractor frameworks, aligning with POPIA Section 72 cross-border standards.
Strategic Allocation of Responsibility
  • The Company maintains clear legal boundaries regarding data liability across its professional networks:
  • Client-Controlled Environments: Once an independent contractor interfaces with a corporate client’s internal digital systems, communication software, or proprietary networks, the client assumes exclusive status as the primary Data Controller (or Responsible Party). The client bears sole legal accountability for the security and privacy oversight of that environment.
  • Independent Third Parties: Placements operate as independent professional subcontractors. While the Company contractually mandates strict adherence to data protection standards, we explicitly disclaim liability for autonomous, unauthorised data processing or localised privacy violations executed by a contractor completely outside our centralised systems or corporate directives.
Data Security and Retention
  • Security Controls: We utilise enterprise-grade technical and organisational measures , including end-to-end encryption for data at rest and in transit, multi-factor authentication, and secure firewalls, to prevent unauthorised access, loss, or modification.
  • Retention Boundaries: Personal data is retained only for the duration necessary to satisfy the primary processing purposes outlined above, or to comply with statutory legal, tax, and financial reporting mandates.
Global Data Subject Rights
  • Data subjects hold specific statutory rights based on their geographic residency:
  • United Kingdom: Rights include data erasure (“right to be forgotten”), data portability, processing restrictions, and the right to lodge complaints with the Information Commissioner’s Office .
  • South Africa: Rights include accessing, rectifying, or demanding the destruction of personal data, with recourse to the South African Information Regulator.
  • Australia: Rights include requesting access to and correction of personal datasets, with recourse to the Office of the Australian Information Commissioner.
  • UAE : Rights include data erasure, processing restrictions, and data portability through our compliance channels.
  • United States: Residents of states with comprehensive privacy laws hold rights to know, delete, correct, and opt out of data sharing configurations.
Corporate Governance Contact
  • To exercise your statutory rights or submit an inquiry regarding this Policy, please contact our Global Data Protection Compliance Office:
  • Primary Compliance Endpoint: [insert email address]
  • Australia Node: [insert email address]
  • UAE Operational Node: [insert email address]

IMPORTANT LEGAL NOTICE & DISCLAIMER.

Jurisdictional Limitation of Practice:

This document/work product (including any accompanying drafts, commentary, or advice) has been prepared by Lillian Liebenberg, an attorney admitted to practice law exclusively within the Republic of South Africa (Listed on the non-practicing role). The drafter is not admitted, licensed, or qualified to practice law, nor do they hold themselves out as an expert in the municipal laws of the Commonwealth of Australia, the United Arab Emirates (including Dubai), the United Kingdom, or the United States of America.

Purpose and Character of the Draft:

This draft has been prepared solely for the internal corporate review and compliance planning of the Client. It is based strictly on the factual parameters and operational instructions provided by the Client and is structured using standardised international data privacy principles. It does not constitute definitive, actionable legal advice or a binding legal opinion under the laws of any jurisdiction inside or outside of South Africa.

Mandatory Local Legal Review:

Because data protection, tax compliance (including UK IR35 regulations), and corporate licensing frameworks vary significantly across borders, the Client is strictly required to have this policy reviewed, modified, and finalised by locally qualified legal counsel within each respective jurisdiction (Australia, UAE, UK, and the US) before publishing, deploying, or relying upon it.

Complete Exclusion of Liability & Assumption of Risk:

To the maximum extent permitted by applicable law, the drafter disclaims any and all liability, responsibility, losses, regulatory penalties, or damages (whether direct, indirect, or consequential) arising out of or in connection with the use, reliance, deployment, or modification of this document in any territory or jurisdiction worldwide, including the Republic of South Africa. This document is provided strictly as a preliminary operational template, and the Client assumes all legal, regulatory, tax, and commercial risk associated with its finalisation, publication, and deployment.