Last updated: 31 August 2026
HowdyBru (“we”, “us”, the “platform”) is a visitor and vehicle access management service operated by the HowdyBru team, a South African technology company. This page explains how we collect, use, store, and share personal data, and the legal basis on which we do so. It applies to visitors, tenants, guards, operators, and administrators (“users”) who interact with the platform.
This notice is designed to meet the requirements of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the South African Protection of Personal Information Act 4 of 2013 (“POPIA”). Where any term differs between the two, the stricter standard applies.
The legal entity that operates the establishment (estate, building, or business park) at which you are visiting or working is the data controller for the visitor and access data collected at that site. HowdyBru acts as a data processor on behalf of that controller, and as the controller for the account and billing data of its own customers.
To exercise any data-protection right, contact the establishment directly or reach HowdyBru at support@howdybru.com.
Each establishment configures its own retention period for entry logs; the default is 30 days. Trial and demo establishments are locked to a maximum of 3 days. Expired visitor invites are marked expired automatically, and aged logs are deleted on the schedule configured by the administrator. Optional add-ons allow the retention period to be extended by one, two, or three months for paid plans.
Where full ID number storage is not licensed, ID numbers are masked — only the first six and last three digits are stored and the middle portion is replaced. Biometric or facial data captured during self-registration is cleared once a guard has verified the visitor.
We do not sell personal data. Data is shared only as needed to operate the service:
Some sub-processors (Meta, Google, Stripe, Resend) process data outside the European Economic Area. We rely on the standard contractual clauses and each provider’s certified safeguards for such transfers, and only transfer the minimum data necessary to deliver the service.
You have the right to:
To exercise any right, email support@howdybru.com. We respond within 30 days, free of charge.
The platform uses browser local storage to remember your session, selected site, and user interface preferences. We do not use advertising or third-party tracking cookies. Analytics, where enabled, are limited to aggregated usage statistics and do not profile individual users.
Data is stored in an access-controlled database with row-level security, so a user can only see the records their role and establishment permit. Access to personal data is logged. ID numbers are masked by default and only stored in full where the Full ID Numbers Storage add-on is licensed. We review our security posture regularly, but no system can be guaranteed perfectly secure; you engage with the platform on that understanding.
The platform is not directed at children under 16, and we do not knowingly collect their personal data. If a visitor under 16 is registered by a host, processing is based on the host’s legitimate interest and any consent given by a parent or guardian. Contact us if you believe a child’s data has been collected in error.
Visitor invitation and OTP messages are sent through the WhatsApp Business API using pre-approved message templates. Marketing messages are only sent with your consent, and you can opt out at any time by replying STOP. OTP and transactional messages (such as “visitor at the gate”) are not marketing and are sent as necessary to operate the service.
HowdyBru is provided “as is”. To the maximum extent permitted by law, we exclude all liability for indirect, incidental, or consequential loss arising from use of, or inability to use, the platform. We do not warrant that the service will be uninterrupted or error-free. Administrators are responsible for configuring their establishment’s retention period, ID-number masking, custom fields, and integrations in line with their own legal obligations. You agree not to misuse the platform, submit false visitor data, or attempt to access data for sites you are not authorised to manage.
We may update this notice as the platform evolves or to reflect changes in the law. We will update the “Last updated” date above whenever we do. Material changes will be communicated through the app or by email to affected users where practicable.
For privacy requests, data-protection questions, or to lodge a complaint, contact HowdyBru at support@howdybru.com. If we cannot resolve your concern, you may complain to your local data-protection authority or, for POPIA matters, the South African Information Regulator.