Privacy notice

Privacy Policy

This policy explains how personal information is handled when you use the STS Management UI. The service is an administrative system intended only for authorised users.

Last updated:

1. Scope and responsibility

This policy applies to the STS Management UI operated by Subrospace (Pty) Ltd ("Subrospace", "we", "us" or "our"). It covers personal information processed through this application and its connected identity, reference-data, trade-capture, and collaboration services.

Your organisation may determine why and how information is processed in the service. In that case, your organisation is the responsible party and Subrospace processes the information on its behalf. Your organisation's own privacy notices and policies may also apply.

2. Information we process

Depending on your role and how you use the service, we may process:

  • Account and identity information, such as your name, username, email address, user identifier, roles, permissions, and other access-control attributes.
  • Authentication and session information, such as sign-in and sign-out events, session identifiers and status, token metadata, IP address, browser or user-agent information, and session activity times.
  • Administrative activity, including changes you make to users, client registrations, scopes, permissions, system settings, and reference data, together with related audit records.
  • Information you submit, including files, records, configuration values, and other content uploaded or entered while performing authorised administrative tasks.
  • Technical and support information, such as request details, error information, diagnostic logs, and information included in a support request.

Please do not enter personal information that is not required for the authorised task you are performing.

3. Why we process it

We process personal information only where it is necessary to:

  • authenticate users and maintain secure sessions;
  • apply roles, permissions, and other access controls;
  • provide the administrative functions requested by you or your organisation;
  • record and review administrative actions for security, accountability, and audit purposes;
  • operate, monitor, troubleshoot, and improve the reliability and security of the service;
  • investigate suspected misuse, fraud, or security incidents; and
  • meet contractual and legal obligations.

We rely on the grounds permitted by applicable law, including performance of a contract, compliance with legal obligations, and the legitimate interests of Subrospace or your organisation in operating and securing the service. Where consent is required, it may be withdrawn, without affecting processing that was lawful before withdrawal.

4. Cookies and local storage

The application uses a strictly necessary authentication cookie to keep you signed in and protect your session. It also stores your theme preference and a recent-activity timestamp in your browser's local storage. The activity timestamp supports the automatic idle sign-out security feature across open tabs.

These technologies are used for security and functionality, not advertising or cross-site tracking. Blocking the authentication cookie may prevent you from signing in. You can clear cookies and local storage using your browser settings; doing so may sign you out and reset your theme preference.

5. Sharing and transfers

We may disclose personal information only as needed to:

  • authorised administrators and personnel within your organisation;
  • service providers that host, maintain, secure, or support the service under appropriate confidentiality and data-protection obligations;
  • professional advisers, auditors, or insurers where reasonably necessary; and
  • regulators, courts, law-enforcement bodies, or other parties where required or permitted by law.

We do not sell personal information and do not use it for third-party advertising. If personal information is transferred outside South Africa, we use the safeguards required by applicable data-protection law.

6. Retention

We keep personal information only for as long as needed for the purposes described above, or as required by law, contract, audit, security, or your organisation's retention rules. Retention periods vary by record: for example, the Management UI authentication session expires after five minutes of inactivity, while the application's rolling diagnostic log files are configured to retain up to 14 days. Audit and business records may be retained for longer where accountability or legal obligations require it.

When information is no longer required, it is deleted, anonymised, or securely isolated from further use, subject to backup and legal-hold requirements.

7. Security

We use reasonable technical and organisational safeguards designed to protect personal information. These include encrypted transport, role-based access controls, short idle-session timeouts, audit trails, and operational monitoring. No system is completely secure, so promptly report suspected unauthorised access or disclosure through your organisation's established support or security channel.

8. Your rights

Subject to the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable law, you may have the right to ask whether your personal information is held, request access to it, ask for inaccurate information to be corrected or deleted, object to certain processing, or withdraw consent where processing relies on consent. Some requests may be limited where information must be retained or processed by law.

Submit a request through your organisation's Information Officer, privacy contact, or service desk. We may need to verify your identity before acting on a request. If Subrospace processes the information for your organisation, we may refer the request to that organisation for a response.

9. Contact and complaints

For questions, privacy requests, or concerns, contact your organisation's Information Officer or the Subrospace support or privacy contact identified in your service agreement. This ensures that your request reaches the party responsible for the relevant deployment and records.

If you believe your personal information has been processed contrary to POPIA, you may also lodge a complaint with the Information Regulator (South Africa).

10. Changes to this policy

We may update this policy when the service, our processing practices, or legal requirements change. The revised version will be published on this page with a new "Last updated" date.