Privacy Policy
This policy explains, in plain terms, what personal information Seven Twenty Degrees (Pty) Ltd collects, why, where it is stored, who it is shared with, how long it is kept and the rights you have. It is written under South Africa's Protection of Personal Information Act 4 of 2013 (POPIA), with a section for users in the United States (section 17). We would rather state a limitation plainly than overstate a safeguard.
On this page
- Who we are
- Our two roles: responsible party and operator
- Whose information we process
- What we collect, and why
- Location at clock-in and on the job
- Clock-in photos, sign-in on the phone and other special information
- Website analytics
- 7Assistant and outside services that help us
- Automated decision-making
- The monthly records file
- Who we share information with
- Where information is stored, and cross-border transfers
- How we protect information
- How long we keep information
- Your rights, and how to use them
- Children
- Users in the United States
- Changes to this policy, and previous versions
1. Who we are
Seven Twenty Degrees (Pty) Ltd (registration number 2023/212025/07), incorporated in South Africa and based in Pietermaritzburg, makes 7Maintain, maintenance and compliance software for industrial plants. For the information described in this policy we are the "responsible party" under POPIA, except where we act as an operator (section 2).
Information Officer: Terence Grenfell. Postal address: 52 Wilkes Road, Prestbury, Pietermaritzburg, South Africa. Email: admin@720degree.co.za.
2. Our two roles: responsible party and operator
- Responsible party — for information about our own account holders, website visitors, people who enquire with us, and people who apply to work with us as consultants. We decide why and how it is processed, and this policy governs it.
- Operator (processor) — for the information a customer organisation puts into 7Maintain about its own business, in particular its employees and contractors. The customer is the responsible party; we process that information on its instructions to provide the service. The customer is responsible for having the right to load its people's information and for telling them about it. If you use 7Maintain through your employer and want to exercise a right over your information, please contact your employer; we will help them as their operator. You may also contact us directly.
3. Whose information we process
- Account users — the people who sign up for, administer and use a 7Maintain account.
- Customer employees and contractors — people a customer records in 7Maintain (we are the operator).
- Website visitors.
- Leads and enquiries — people who fill in a form or contact us about 7Maintain.
- Consultant applicants — people who apply to introduce 7Maintain to plants on our behalf.
4. What we collect, and why
(a) Account users — we are the responsible party
Name, work email, company, phone number, role, and a password stored only as a bcrypt hash (never in plain text). To keep accounts secure we record sign-in activity — sign-in and session records including the IP address and browser or device used, two-factor verification details, and, for each signed-in request, which account made it, from which IP address and to which part of the service. Purpose: to provide, bill, support and secure the service. Lawful basis: performing our contract with you (POPIA s 11(1)(b)) and our legitimate interest in security (s 11(1)(f)).
(b) Customer employees and contractors — we are the operator
On the customer's instruction, 7Maintain stores what the customer chooses to record, which can include: name, employee number, work email, phone number, profile photo, job title or role, department or trade, shift pattern, a work PIN (stored as a secure hash), an RFID/NFC badge identifier, skills, competencies, certifications and training records (course, date and result). It also records work tied to a person: job assignments, notes, photos taken on the job, hand-drawn and electronic sign-offs, clock-in and clock-out times and locations (section 5), the identifier of the phone registered for clock-in, voice-note transcripts (text only — audio is transcribed on the phone and not stored), and leave or unavailability records.
What we do not collect about employees: there are no fields for national ID or passport numbers, date of birth, home address, next of kin, bank account, salary, race or gender.
(c) Website visitors
First-party, cookie-free analytics (section 7) and standard web-server logs (IP address, time, browser, page requested, referring page, response code), kept for security and abuse handling. Lawful basis: our legitimate interest in running and securing the sites (s 11(1)(f)).
(d) Leads and enquiries
When you submit a form (for example "apply" or the compliance pack) we collect the name, work email, company, phone number, country and any equipment details you enter, your consent tick, and — to prevent abuse — the IP address and browser used. To prepare for a conversation with your business we may research it using the company name, the domain of your email address and the location you entered, with the outside service named in section 8. We may pass an enquiry to one of our consultants — people who introduce 7Maintain to plants on our behalf — so they can follow it up. We open accounts only for organisations in South Africa at present. A sign-up from any other country (including the United States) is recorded in the same way, as an enquiry: we keep the name, work email, company, phone number if given, the country and your consent, and we do not open an account. Lawful basis: your consent (s 11(1)(a)) and steps you asked us to take towards a contract (s 11(1)(b)).
(e) Consultant applicants
Your name, contact details and what you tell us about your experience, used to assess the application and, if accepted, to set up your consultant account and record the training you complete. Lawful basis: steps towards a contract (s 11(1)(b)).
5. Location at clock-in and on the job
7Maintain uses location to show that work was done where it says it was done. In the Android app and the web app:
- At clock-in and clock-out the app records the phone's precise GPS position (latitude, longitude and accuracy), whether the phone reported a simulated location, and the name and access-point identifier of the Wi-Fi network it is connected to.
- While a job is in progress and the app is open on it, the phone sends its position and Wi-Fi details every 5 minutes so the system can confirm the person is in the job's work area.
- Before Android asks for the location permission, the app explains all of this on one screen. The person can choose Not now and still clock in without location.
- The app uses location only while it is open. It does not track location in the background, and it does not use location for advertising.
How long: the 5-minute on-job checks are deleted automatically after 12 months. Clock-in and clock-out positions are part of the customer's attendance record and are kept with it for as long as the organisation keeps its account, then deleted with the organisation's data or on request (section 15).
6. Clock-in photos, sign-in on the phone and other special information
No face recognition
7Maintain does not use face recognition and does not collect biometric information. An optional face-recognition clock-in existed until 19 September 2026; it was removed from 7Maintain on that day, and all stored face data (face templates, enrolment photos, consent records and face-check results) was deleted.
Clock-in photos
A customer can ask for a photo at clock-in as evidence of attendance (for new organisations this is set to optional). This is an ordinary photo, which may show the person, stored as an image for a person to look at; nothing measures or matches a face in it. It is deleted automatically after 90 days by default (the customer can choose between 7 and 365 days).
Signing in with the phone's fingerprint or face unlock
A user may choose to sign in with a passkey, using the phone's own fingerprint or face unlock. That check happens on the phone; we receive and store only a cryptographic public key, never a fingerprint or a face.
Health-adjacent leave reasons
Leave records may carry a reason such as "sick", which can imply health information. We hold it only so the customer can plan work; it is entered by the customer's managers.
7. Website analytics
- No cookies, no third-party analytics, no advertising or tracking pixels. The web app keeps your sign-in in your browser's local storage, not in a cookie.
- We do not store your IP address for analytics. It is used for a moment, in memory, to look up a coarse country, region and city in a database on our own server (no outside lookup service), and to compute a one-way visitor code that changes every day. The random value mixed into that code is deleted after one day, after which the code cannot be linked back to an IP address.
- What we keep: the page visited, the referring site (not the full address), campaign (UTM) tags and the name of the advertising platform if you arrived from an advert (never the click identifier), device type, coarse location and time.
- Analytics records are deleted automatically after 400 days.
8. 7Assistant and outside services that help us
7Assistant, the helper built into 7Maintain, and every other feature that uses an AI model on a customer's information run on our own hardware in South Africa, reached over an encrypted private network. They fail closed: if that hardware is unavailable, the feature switches off and says so. It never falls back to an outside service. Nothing from a customer's use of 7Maintain is sent to any outside AI provider — there is no setting that allows it, and the software refuses such a request.
This includes spare-parts research, supplier suggestions and finding a manufacturer's agent. To find public information for them, our own search service (on our hardware) sends the manufacturer and model of the machine as a search query, with words such as "spare parts list", to public web search engines, and our server opens the public pages the search returns — for example a manufacturer's manual or an agent's contact page. No name, organisation, serial number or location goes with the query.
We use one outside AI provider, Anthropic (United States), for our own sales work only — never inside 7Maintain and never with a customer's operational data:
- Researching businesses in our sales records — businesses that enquire with us, and businesses we may approach — using the company name, the domain of the contact's email address and the location recorded.
- Drafting our own sales approaches — a company's name, sector and region.
9. Automated decision-making
POPIA section 71 gives you rights around decisions made only by automated means. The honest position:
- Some work is assigned automatically. When a job is created, the system may assign it to a technician based on skills, who is on shift, workload and area, without a manager confirming. One such rule (assigning a job when exactly one qualified technician is on shift in that area) is on by default; broader automatic assignment is off by default and switched on per organisation. Review work may be routed to a checker automatically.
- The system produces individual performance summaries (for example jobs completed and first-time-fix rate) with coaching flags, shown to managers. This is profiling, but it drives no automatic action on its own.
- No automated decision takes an adverse action about a person. There is no automatic discipline, suspension, deactivation or dismissal; a person makes every such decision.
If you are subject to an automatic assignment and want a person to look at it, you or your manager can reassign the work, and you may contact our Information Officer to object or ask for human review.
10. The monthly records file
Each month 7Maintain prepares a records file for each customer organisation, so the customer holds its own copy of its maintenance evidence. It contains the month's work orders and their history (including the names of the people who acted on them), sign-offs and the sealed sign-off certificates, training records, the audit pack, and the files attached to those records — photos, hand-drawn signatures, manuals and documents. The file carries a digital signature so that any later change can be detected.
- It is kept on our server in South Africa for 30 days.
- A download link is emailed to the organisation's managers and to any other recipients the customer adds. The link works for 7 days without signing in, so anyone who has the email can download the file. Customers should add only recipients they trust and keep these emails private.
11. Who we share information with
We do not sell personal information, and we do not share it for advertising. We use no SMS or WhatsApp services. We share information only with the service providers needed to run 7Maintain:
| Who | What they receive, and why | Where |
|---|---|---|
| Linux Tech (Pty) Ltd (trading as DcData) | Hosts our servers and runs the web firewall in front of them, which inspects traffic to block attacks. Our data sits on an encrypted disk, and under our agreement they have no access to it. | South Africa (Teraco, Durban) |
Our email host (a managed hosting provider, mail.720degree.co.za) | Delivers our emails — verification codes, sign-in links, password resets, notifications and the monthly records link (recipient name, email and message). | South Africa |
| Paystack (payments) | When an account subscribes: the account holder's name and email and our internal reference numbers. For a quote: nothing until the recipient presses Pay on our own payment page; then their email, the amount and our quote reference. Card details are entered on Paystack's own page and never reach our servers. | Outside South Africa |
| Google (Firebase Cloud Messaging) | Delivers notifications to the Android app. Google receives only the phone's notification address, the word "7Maintain" and one fixed line for the kind of event (for example "A job needs your attention") — no names, job details or other text. The detail is shown inside the app, from our own server. | Outside South Africa |
| Browser push services | Deliver notifications to the web app. The content is encrypted end to end; the service sees only that a message was sent. | Outside South Africa |
| Anthropic | Only for our own sales research (section 8): a business's name, email domain and location, or its name, sector and region. Nothing from a customer's use of 7Maintain. Deleted by Anthropic within 30 days; not used to train its models. | United States |
| Our consultants (people who introduce 7Maintain to plants on our behalf) | When we assign an enquiry to one of them: the enquirer's name, contact details, company and what they told us, so they can follow it up. Every such hand-over is recorded. | Where the consultant works |
| Public web search engines | A machine's manufacturer and model as a search query, when parts research, supplier suggestions or a search for a manufacturer's agent is used (section 8). | Outside South Africa |
We may also disclose information where the law requires it, or to protect the rights, property or safety of our users, the public or ourselves. We require every provider to protect personal information consistent with this policy and POPIA.
12. Where information is stored, and cross-border transfers
- Hosting: 7Maintain's database and files are hosted in South Africa, at Teraco's data centre in Durban, by Linux Tech (Pty) Ltd, on an encrypted disk.
- Backups: the database and files are backed up every night on the same server, and encrypted copies are sent every night to hardware we own at our premises in KwaZulu-Natal, South Africa. Occasional encrypted copies on removable media are kept at our premises.
- Our own processing hardware (7Assistant, photo checks, document reading, parts research and our search service) is also ours and in South Africa.
What leaves South Africa is limited to the transfers listed in section 11: payment details to Paystack; a fixed notification line through Google (Android) and encrypted notifications through browser push services; a machine's manufacturer and model, as search queries, to public search engines; and the details of businesses in our sales records, in section 8, to Anthropic. Nothing else of your operational data leaves South Africa. These transfers rely on POPIA section 72 (a recipient bound by comparable protection, your consent, or necessity for the contract).
Phone backups: from app version 2026.09.18 the Android app excludes its data from Android's cloud backup and from phone-to-phone transfer. Earlier versions allowed Android to include the app's data in the owner's Google backup, if that owner had backup switched on.
13. How we protect information
- In transit: encrypted with TLS (HTTPS).
- At rest: the database and files are on an encrypted disk volume (LUKS2); backup copies sent off the server are encrypted (AES-256).
- Extra encryption (AES-256-GCM) inside the application for the most sensitive items — supplier banking details and signing keys.
- Passwords are hashed with bcrypt; work PINs use a stronger bcrypt setting, with lockout after repeated failures. Signing in with an e-mail address and password from a device we do not recognise needs a second step — a code sent to that address. Signing in with a work PIN is limited to the 7Maintain app on a phone, and the account is locked after repeated failures.
- Separation between customers: every request is checked against the user's organisation and role in the application, and the database itself enforces row-level security on the main tables that hold personal information, so one organisation's records cannot be read in another organisation's session.
- Audit logging of security-relevant actions and access.
- Traffic to our own processing hardware runs over an encrypted WireGuard tunnel.
14. How long we keep information
| Information | How long |
|---|---|
| Account and operational data (including attendance records and clock-in/out positions) | While the account is active, and until deletion is requested (section 15) |
| On-job location checks (every 5 minutes while a job is open) | 12 months, then deleted automatically |
| Clock-in photos | 90 days by default (customer can choose 7–365 days), then deleted automatically |
| Photos taken of tools and equipment for checks | About 6 months by default, then deleted automatically |
| 7Assistant conversations | 180 days by default; your organisation can set anything from 30 to 730 days |
| Record of which account made each signed-in request (with IP address) | 90 days in detail; after that only a daily count per account is kept |
| Performance timing records (no IP address or account) | 30 days |
| Website analytics | 400 days (the daily random value: 1 day) |
| Sales prospect research | 180 days. If you ask us not to be contacted, we keep only what is needed to honour that — the company name and the e-mail address we were asked to suppress. The contact’s name and role, and the rest of the research, are deleted |
| Monthly records files | 30 days on our server; download links expire after 7 days |
| Backups | Nightly database copies about 14 days; nightly file restore points 8 days; off-server encrypted copies 14 days. Deleted data leaves all backups within 90 days |
| Records the law requires us to keep — electronic work-order sign-offs and their audit trail (Electronic Communications and Transactions Act 25 of 2002, s 14), financial, procurement and tax records | Up to 5 years, even after a deletion request, then deleted or fully anonymised |
15. Your rights, and how to use them
Under POPIA you may ask us to confirm whether we hold your personal information and to give you access to it, to correct or delete it, or to object to its processing (including direct marketing), and you may complain to the Information Regulator.
How this works in practice: requests are handled by our team; there is no one-click export or delete. Email admin@720degree.co.za. We verify your identity (to protect you from fraudulent requests) and respond within 30 days. Deletion is actioned on request; it is not automatic when an account stops being used. Our account deletion page sets out exactly what is deleted and what the law requires us to keep.
If your information is held in 7Maintain by your employer, the employer is the responsible party; you can ask them, or us, and we will help them as their operator.
Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 — inforegulator.org.za.
16. Children
7Maintain is workplace software for adults. It is not directed at children, and we do not knowingly collect personal information from anyone under 18 (including children under 13). If we learn we hold a child's information, we delete it. Contact us if you believe we do.
17. Users in the United States
7Maintain can be installed from Google Play in the United States, but our United States hosting region is not open yet, and we do not open accounts for organisations in the United States (or in any country other than South Africa). If you sign up from the United States, we record your enquiry — your name, work email, company, phone number if you give it, and your consent — in our sales records in South Africa, and one of our consultants may contact you (section 4(d)). Any account that does exist is hosted in South Africa and handled as this policy describes. We will update this policy, and tell account holders, before any customer's data is hosted in the United States.
- What we collect and who receives it: sections 4 to 6 list the categories of personal information we collect; section 11 lists the categories of third parties who receive it.
- No sale, no sharing for advertising. We do not sell personal information, share it for cross-context behavioural advertising, or use it for targeted advertising.
- Do Not Track and Global Privacy Control: we do not track visitors across other websites or services over time, and we do not allow other companies to do so on our sites or in our app. Because there is no such tracking to switch off, our practices are the same whether or not your browser sends a Do Not Track or Global Privacy Control signal.
- California "Shine the Light": we do not disclose personal information to third parties for their own direct marketing.
- Your rights: the rights in section 15 — access, correction and deletion — are available to you wherever you live, through the same process, and we will not treat you differently for using them.
- No biometric information. 7Maintain does not collect biometric information (section 6). Face recognition was removed on 19 September 2026 and the stored face data deleted.
- Contact: we are a South African company with no office in the United States. Contact us at admin@720degree.co.za.
18. Changes to this policy, and previous versions
We may update this policy. The current version and its effective date are always published at the addresses at the top of this page. We tell account holders about material changes by email or in the app, and we keep every previous version available below.
What changed in version 2.2 (19 September 2026): face recognition was removed from 7Maintain on 19 September 2026, and all stored face data — templates, enrolment photos, consent records and face-check results, all of which belonged to our own test organisation — was deleted; sections 6, 12, 13, 14 and 17 no longer describe it, and section 6 now explains signing in with the phone's fingerprint or face unlock. Nothing from a customer's use of 7Maintain is sent to Anthropic any more: version 2.1 said that parts research, supplier suggestions and finding a manufacturer's agent could send a machine's make, model and category to Anthropic when an organisation switched this on; those features now run only on our own hardware, and Anthropic is used only for our own sales research (sections 8, 11 and 12). A sign-up from any country other than South Africa, not only the United States, is now recorded as an enquiry, and our enquiry form asks for the country (section 4(d)). For a quote, Paystack is now contacted only when the recipient presses Pay, and no longer receives the company name (section 11).
What changed in version 2.1 (18 September 2026, later the same day): Android notifications through Google now carry only a fixed line, never names or job details; the app explains location before asking for it, and on-job location checks are deleted after 12 months; section 8 now says exactly what goes to Anthropic (a machine's make, model and category from the asset register — the earlier wording called this "public" text without saying where it came from) and that the organisation's "off" setting stops every such send; public search engines are named; sign-ups from the United States are recorded as enquiries, not accounts; and enquiries may be passed to one of our consultants, who are named in section 11.
What changed in version 2.0 (18 September 2026): one policy now covers both websites and the app. We corrected the website address to 7maintain.co.za and named the Durban data centre. We added the location recorded at clock-in and during jobs, clock-in photos, the face-recognition reference photo, the monthly records file, the use of Google for Android notifications and of Anthropic for the tasks in section 8, the email host as a managed provider, backups and retention periods, a section for users in the United States, and the Android backup change. We removed the statement that we store no GPS positions, which was not correct. We also record that from late July to 17 September 2026 some pages of 7maintain.co.za loaded a Google Ads measurement tag, contrary to the earlier versions of this policy; it was removed on 17 September 2026.
- Version 2.2 — 19 September 2026 — this page.
- Version 2.1 — 18 September 2026 (in force until 19 September 2026).
- Version 2.0 — 18 September 2026 (in force for part of the same day).
- Version 1.0 — 30 June 2026 (published on 7maintain.co.za).
- Version 1.0 — 30 June 2026, earlier wording (published on app.720degree.co.za; its cookies clause differed).
- Edition of 20 July 2026 (published on 720degree.co.za).
- Interim notice of 20 April 2026 (published on 720degree.co.za).