Privacy notice summary
This notice explains how FutureSoft's customer portal handles personal information when you use the service. FutureSoft develops, operates and supports this portal. This notice should be read together with any privacy notice from the organisation managing your account and FutureSoft's broader information-protection policies.
FutureSoft and this portal
FutureSoft (Pty) Ltd is responsible for the operation, support and security of the portal and determines how portal engagement analytics are processed. Where account or collection information is made available by a FutureSoft client, that organisation determines the purposes and lawful basis for the underlying account services. FutureSoft handles that information under documented instructions and applies safeguards appropriate to the services it provides.
FutureSoft's privacy commitment
FutureSoft is committed to protecting personal information, preventing data breaches and meeting its obligations under the Protection of Personal Information Act, 2013 (POPIA) and other applicable data-protection laws. Information is processed only for stated, relevant purposes, supported by responsible data-management practices and appropriate technical and organisational controls.
Information used for portal reporting
In addition to the account information needed to provide requested portal services, the reporting dataset contains only the engagement information needed to operate, support and evidence use of the service:
- portal session start, last activity and end times;
- the logical page visited, entry and exit times, visible time and active time;
- coarse device, browser and operating-system categories;
- approximate country and province derived from the network address;
- events and outcomes for payments, arrangements, callback requests and statement requests; and
- random portal analytics identifiers that allow authorised reports for a person or account.
Page time is capped and distinguishes a visible page from recent user interaction. It is an estimate and does not prove that a person read or understood particular content. The analytics do not record keystrokes, page content, payment-card details, message text, uploaded documents, exact GPS location or campaign identifiers.
Separately from this reporting dataset, security and operational audit logs may record the request path, response status and duration, network address, browser user-agent and approximate location. Those logs support security, fault investigation and reliable operation; they are not copied into the engagement-reporting tables.
Why the information is used
- to show individual and aggregate portal engagement;
- to evidence requested actions and distinguish started, submitted, accepted and verified outcomes;
- to support users and investigate failed journeys;
- to support collection follow-up using factual portal activity; and
- to assess whether communications lead to portal activity, without storing a campaign identifier.
Processing is limited to what is adequate and relevant for these purposes. Depending on the activity, the lawful basis may include delivering a service you request, complying with legal duties, or the legitimate interests of securely operating, supporting and evidencing the portal. Consent will be requested where the law requires it.
Approximate location and local storage
Your network address may be sent securely to a location service solely to return country and province. The new engagement analytics do not store the network address. The browser stores a random session identifier in session storage, which is normally removed when the browser tab or window session ends. Authentication and security cookies are also used to keep you signed in and protect requests against misuse.
Access, sharing and automated decisions
Authorised personnel of the organisation managing your account and authorised FutureSoft personnel may access information where needed for reporting, support, security or administration. Service providers may process limited information when they host or support the portal, supply approximate location, process a payment, or complete a requested action. The new engagement analytics remain in the portal database and are not synchronised to Gryphon.
Engagement analytics are not used to score or rank people, decide whether or how they should be contacted, or change how they are treated. A person should review the underlying facts before relying on analytics for follow-up or support.
Retention
These periods apply to portal engagement analytics. After these periods, analytics records are deleted or their link to the portal user and account is removed. Account, contractual or business records may follow a separate retention period set by the organisation responsible for those records, documented client instructions and applicable legal requirements. Records may be kept longer where a legal duty, dispute or documented preservation requirement applies.
A record of each security-code message sent to you is kept for 90 days and then deleted. It notes the account the message related to, whether it reached the mobile network, and whether the code was used to sign in. It does not store your mobile number or the code itself.
Staff at LGR can download reports on how this portal is being used. A copy of each report is kept for 90 days, so that it can be downloaded again without being produced afresh, and is then deleted. Reports are made up of counts and totals for the firm as a whole. Where activity is broken down by account, your account number appears alongside the number of actions recorded against it and the date of the most recent one. Reports do not contain your name, identity number, contact details, or anything you have entered into the portal.
Security
Access is tenant-restricted, account references are encrypted, lookup values are one-way protected, and access is limited to authorised purposes. FutureSoft's protection programme includes risk assessments, access and risk controls, security-incident procedures and regular information-security awareness. Reasonable technical and organisational safeguards are used, although no internet service can promise absolute security.
Children's privacy
FutureSoft's products and services are intended for a general or business audience and are not directed to children under 13. FutureSoft does not knowingly collect, use or disclose personal information from anyone under 13. If FutureSoft learns that it received a child's personal information without verified parental or guardian consent, it will take steps to delete that information as soon as possible. A parent or guardian who believes a child supplied personal information can contact FutureSoft using the details below.
Your choices and rights
Subject to POPIA, you may ask whether personal information is held, request access or correction, ask for deletion where legally available, object to certain processing, and withdraw consent where processing depends on consent. Start with the organisation managing your account or use the FutureSoft contact below. Identity may need to be verified before a request is completed.
You may also contact or complain to South Africa's Information Regulator . Its website publishes the current request, objection, correction and complaint processes.