Privacy notice
Privacy Policy
This policy explains how personal information is handled when you use the STS Management UI. The service is an administrative system intended only for authorised users.
Last updated:
1. Scope and responsibility
This policy applies to the STS Management UI operated by Subrospace (Pty) Ltd ("Subrospace", "we", "us" or "our"). It covers personal information processed through this application and its connected identity, reference-data, trade-capture, and collaboration services.
Your organisation may determine why and how information is processed in the service. In that case, your organisation is the responsible party and Subrospace processes the information on its behalf. Your organisation's own privacy notices and policies may also apply.
2. Information we process
Depending on your role and how you use the service, we may process:
- Account and identity information, such as your name, username, email address, user identifier, roles, permissions, and other access-control attributes.
- Authentication and session information, such as sign-in and sign-out events, session identifiers and status, token metadata, IP address, browser or user-agent information, and session activity times.
- Administrative activity, including changes you make to users, client registrations, scopes, permissions, system settings, and reference data, together with related audit records.
- Information you submit, including files, records, configuration values, and other content uploaded or entered while performing authorised administrative tasks.
- Technical and support information, such as request details, error information, diagnostic logs, and information included in a support request.
Please do not enter personal information that is not required for the authorised task you are performing.
3. Why we process it
We process personal information only where it is necessary to:
- authenticate users and maintain secure sessions;
- apply roles, permissions, and other access controls;
- provide the administrative functions requested by you or your organisation;
- record and review administrative actions for security, accountability, and audit purposes;
- operate, monitor, troubleshoot, and improve the reliability and security of the service;
- investigate suspected misuse, fraud, or security incidents; and
- meet contractual and legal obligations.
We rely on the grounds permitted by applicable law, including performance of a contract, compliance with legal obligations, and the legitimate interests of Subrospace or your organisation in operating and securing the service. Where consent is required, it may be withdrawn, without affecting processing that was lawful before withdrawal.
6. Retention
We keep personal information only for as long as needed for the purposes described above, or as required by law, contract, audit, security, or your organisation's retention rules. Retention periods vary by record: for example, the Management UI authentication session expires after five minutes of inactivity, while the application's rolling diagnostic log files are configured to retain up to 14 days. Audit and business records may be retained for longer where accountability or legal obligations require it.
When information is no longer required, it is deleted, anonymised, or securely isolated from further use, subject to backup and legal-hold requirements.
7. Security
We use reasonable technical and organisational safeguards designed to protect personal information. These include encrypted transport, role-based access controls, short idle-session timeouts, audit trails, and operational monitoring. No system is completely secure, so promptly report suspected unauthorised access or disclosure through your organisation's established support or security channel.
8. Your rights
Subject to the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable law, you may have the right to ask whether your personal information is held, request access to it, ask for inaccurate information to be corrected or deleted, object to certain processing, or withdraw consent where processing relies on consent. Some requests may be limited where information must be retained or processed by law.
Submit a request through your organisation's Information Officer, privacy contact, or service desk. We may need to verify your identity before acting on a request. If Subrospace processes the information for your organisation, we may refer the request to that organisation for a response.
9. Contact and complaints
For questions, privacy requests, or concerns, contact your organisation's Information Officer or the Subrospace support or privacy contact identified in your service agreement. This ensures that your request reaches the party responsible for the relevant deployment and records.
If you believe your personal information has been processed contrary to POPIA, you may also lodge a complaint with the Information Regulator (South Africa).
10. Changes to this policy
We may update this policy when the service, our processing practices, or legal requirements change. The revised version will be published on this page with a new "Last updated" date.