Privacy & Legal Disclaimer

Last updated: 31 August 2026

1. Overview

HowdyBru (“we”, “us”, the “platform”) is a visitor and vehicle access management service operated by the HowdyBru team, a South African technology company. This page explains how we collect, use, store, and share personal data, and the legal basis on which we do so. It applies to visitors, tenants, guards, operators, and administrators (“users”) who interact with the platform.

This notice is designed to meet the requirements of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the South African Protection of Personal Information Act 4 of 2013 (“POPIA”). Where any term differs between the two, the stricter standard applies.

2. Data Controller

The legal entity that operates the establishment (estate, building, or business park) at which you are visiting or working is the data controller for the visitor and access data collected at that site. HowdyBru acts as a data processor on behalf of that controller, and as the controller for the account and billing data of its own customers.

To exercise any data-protection right, contact the establishment directly or reach HowdyBru at support@howdybru.com.

3. Personal Data We Collect

  • Visitor data: full name, ID or driver’s licence number, phone number, vehicle registration plate, ID document photo, vehicle plate photo, optional selfie/face thumbnail, purpose of visit, entry and exit times, assigned gate, and the tenant being visited.
  • Tenant / resident data: name, unit, street address, email, phone number, preferred notification channel, and pairing keys for mobile devices.
  • Staff data: name, email, role (admin, guard, operator, tenant), site memberships, and login activity.
  • Account & billing data: establishment details, subscription plan, payment provider identifiers (processed by Stripe or PayFast), and invoice history.
  • Custom fields: any additional fields an administrator configures for your site (text, number, yes/no, photo, or text extracted from an image).

4. Legal Basis for Processing (GDPR Art. 6 & 9)

  • Legitimate interests (Art. 6(1)(f)): processing visitor identity and vehicle data for the security, safety, and access-control purposes of the establishment.
  • Contract (Art. 6(1)(b)): processing necessary to provide the service to our customers and to fulfil access-management obligations.
  • Legal obligation (Art. 6(1)(c)): retaining entry logs where required by law or regulation.
  • Consent (Art. 6(1)(a)): capturing a visitor’s face photo, receiving marketing or WhatsApp messages, and enabling any optional custom field. Consent can be withdrawn at any time.
  • Special category data (Art. 9): ID photos may contain biometric information. Where biometric data is processed for unique identification, explicit consent is obtained; otherwise ID photos are used only for visual verification of identity at the gate.

5. How We Use Your Data

  • To verify visitor identity and authorise or deny site access.
  • To notify tenants that a visitor has arrived and to record their approval decision.
  • To maintain an auditable, time-stamped entry and exit log for security and incident investigation.
  • To send visitor invitations, calendar invites, OTP codes, and arrival notifications via email or WhatsApp.
  • To generate daily and on-demand reports for site administrators, and to sync those reports to Google Sheets or Microsoft Excel.
  • To manage subscriptions, billing, and optional add-ons.

6. Data Retention

Each establishment configures its own retention period for entry logs; the default is 30 days. Trial and demo establishments are locked to a maximum of 3 days. Expired visitor invites are marked expired automatically, and aged logs are deleted on the schedule configured by the administrator. Optional add-ons allow the retention period to be extended by one, two, or three months for paid plans.

Where full ID number storage is not licensed, ID numbers are masked — only the first six and last three digits are stored and the middle portion is replaced. Biometric or facial data captured during self-registration is cleared once a guard has verified the visitor.

7. Data Sharing & Sub-Processors

We do not sell personal data. Data is shared only as needed to operate the service:

  • Within the establishment: guards, operators, and the tenant being visited see the relevant visitor record.
  • Integrations you enable: Google Sheets and Microsoft Excel for reporting, and supported VMS / access-control systems (Milestone, Gallagher, Hikvision, Dahua, Impro, Genetec) when configured by an administrator.
  • Communication providers: Resend (email), the WhatsApp Business API (Meta Platforms), and Telegram for notifications.
  • Payment providers: Stripe and PayFast for subscription and add-on billing. Card data is handled entirely by these providers and never touches our servers.

Some sub-processors (Meta, Google, Stripe, Resend) process data outside the European Economic Area. We rely on the standard contractual clauses and each provider’s certified safeguards for such transfers, and only transfer the minimum data necessary to deliver the service.

8. Your Rights (GDPR Art. 12–22)

You have the right to:

  • Be informed about how your data is used (this notice).
  • Access a copy of the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data (“right to be forgotten”), subject to lawful retention requirements for security logs.
  • Restrict or object to processing, including objection to marketing.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time for processing based on consent (e.g. face photo, marketing messages), without affecting processing already carried out.
  • Lodge a complaint with your local data-protection authority, or with the Information Regulator (South Africa) for POPIA matters.

To exercise any right, email support@howdybru.com. We respond within 30 days, free of charge.

9. Cookies & Local Storage

The platform uses browser local storage to remember your session, selected site, and user interface preferences. We do not use advertising or third-party tracking cookies. Analytics, where enabled, are limited to aggregated usage statistics and do not profile individual users.

10. Security

Data is stored in an access-controlled database with row-level security, so a user can only see the records their role and establishment permit. Access to personal data is logged. ID numbers are masked by default and only stored in full where the Full ID Numbers Storage add-on is licensed. We review our security posture regularly, but no system can be guaranteed perfectly secure; you engage with the platform on that understanding.

11. Children

The platform is not directed at children under 16, and we do not knowingly collect their personal data. If a visitor under 16 is registered by a host, processing is based on the host’s legitimate interest and any consent given by a parent or guardian. Contact us if you believe a child’s data has been collected in error.

12. Marketing & WhatsApp

Visitor invitation and OTP messages are sent through the WhatsApp Business API using pre-approved message templates. Marketing messages are only sent with your consent, and you can opt out at any time by replying STOP. OTP and transactional messages (such as “visitor at the gate”) are not marketing and are sent as necessary to operate the service.

13. Acceptable Use & Disclaimer of Liability

HowdyBru is provided “as is”. To the maximum extent permitted by law, we exclude all liability for indirect, incidental, or consequential loss arising from use of, or inability to use, the platform. We do not warrant that the service will be uninterrupted or error-free. Administrators are responsible for configuring their establishment’s retention period, ID-number masking, custom fields, and integrations in line with their own legal obligations. You agree not to misuse the platform, submit false visitor data, or attempt to access data for sites you are not authorised to manage.

14. Changes to This Notice

We may update this notice as the platform evolves or to reflect changes in the law. We will update the “Last updated” date above whenever we do. Material changes will be communicated through the app or by email to affected users where practicable.

15. Contact

For privacy requests, data-protection questions, or to lodge a complaint, contact HowdyBru at support@howdybru.com. If we cannot resolve your concern, you may complain to your local data-protection authority or, for POPIA matters, the South African Information Regulator.