Legal
Privacy Policy
Your information should help you find opportunity—not become a risk. This policy explains what Vonk collects, why we use it, who may receive it, and the choices available to you.
Effective: 15 September 2026Last updated: 15 September 2026
1. Who we are
Vonk is a South African employment platform owned and operated as a division of Forwardly (Pty) Ltd (“Forwardly”, “Vonk”, “we”, “us” or “our”). This policy applies when you visit or use the Vonk website, applications, communications, and related services.
For purposes of the Protection of Personal Information Act 4 of 2013 (“POPIA”), Forwardly is the responsible party for personal information processed through Vonk. Employers and agencies may also act as responsible parties for information they receive and use independently.
2. Information we collect
- Account information, including your name, email address, telephone number, login details, account type, and verification status.
- Identity-verification information where you choose to complete a gig-worker trust check. ID verification for gig workers is a separate trust check, not a requirement to browse or express interest. A verified badge will only appear after Vonk has reviewed the required identity evidence. Do not send an ID copy through a listing or chat. [PLACEHOLDER — confirm the approved verification provider or manual process, which ID fields are checked, whether an ID image is retained, where it is processed, and the deletion period before accepting ID documents.]
- Work-seeker information, including your location, work radius, availability, skills, experience, education, profile photograph, CV details, preferences, certifications, and references.
- Organisation information, including employer or agency names, representatives, registration and verification details, listings, stated terms, billing records, and account activity.
- Platform activity, including searches, viewed listings, expressions of interest, matches, messages, reports, ratings, support requests, and safety-screening results.
- Technical information, such as browser and device information, IP address, timestamps, diagnostic records, security events, and cookie or similar technology data.
- Payment information required to record subscriptions and payment status. Payments are processed by PayFast; Vonk does not store full payment-card details.
- Information you choose to upload or share, including documents delivered to another user. Where Vonk describes a document as one-time or temporary, it is removed according to that feature’s stated process, subject to limited security, legal, or backup requirements.
3. How we collect information
We collect information directly from you when you register, build a profile, publish or respond to an opportunity, communicate, make a payment, request verification, report content, or contact support. We also collect limited information automatically when you use Vonk.
We may receive information from an employer, agency, payment provider, identity or business-verification source, authentication provider, or another user where permitted by law. If you provide information about another person, you must be authorised to do so.
4. Why we use your information
- To create and operate accounts, profiles, CVs, listings, search, matching, chat, support, and related platform services.
- To show relevant opportunities or candidates using information such as skills, availability, preferences, location, and work radius.
- To facilitate mutual contact between work seekers and organisations and to deliver documents or messages you choose to share.
- To verify employers and agencies, detect suspicious activity, screen listings, investigate reports, enforce our rules, and protect users.
- To process subscriptions, maintain transaction records, administer plan limits, and meet tax, accounting, and legal duties.
- To understand and improve Vonk, measure platform performance, troubleshoot problems, and develop features.
- To send service messages and, where you have agreed, relevant updates or marketing that you may opt out of.
- To comply with the law, respond to lawful requests, establish or defend legal rights, and prevent fraud or abuse.
5. Lawful processing
We process personal information where it is necessary to provide services you request, carry out an agreement, comply with a legal obligation, protect a legitimate interest, or where you have given consent. Where we rely on consent, you may withdraw it, although this does not affect processing that was already lawful.
Vonk does not make a final hiring decision for an employer or agency. Automated tools may help rank relevance or identify possible safety risks, but people and organisations remain responsible for employment decisions and material enforcement decisions.
6. When we share information
- With another user when you choose to make information visible, express interest, match, chat, apply, share a document, or otherwise interact.
- With employers or agencies as reasonably required for recruitment, verification, and communication, subject to your actions and visibility settings.
- With service providers supporting hosting, storage, authentication, communications, analytics, safety, verification, customer support, and payments, under appropriate confidentiality and data-protection terms.
- With regulators, courts, law-enforcement bodies, professional advisers, or other parties where required or permitted by law or necessary to protect rights and safety.
- As part of a genuine corporate restructuring, financing, sale, or transfer, subject to appropriate safeguards.
7. Public and user-shared information
Published job and gig summaries may be visible without signing in. Profile, match, chat, contact, private organisation, and uploaded-document information is restricted according to account permissions and your actions.
Information you send to an employer, agency, or another user may be retained or used by that recipient outside Vonk. Review what you share, do not send PINs or one-time passwords, and follow the guidance in our Safety Centre.
8. Storage, transfers, and retention
We may use service providers that process information in South Africa or other countries. Where information crosses borders, we take reasonable steps required by POPIA to ensure appropriate protection.
We keep information only for as long as reasonably necessary for the purposes described here, including operating your account, resolving disputes, preventing fraud, maintaining transaction and audit records, and meeting legal obligations. Retention periods differ by record type. We may anonymise information so it can no longer identify you.
9. Security
We use reasonable organisational and technical safeguards, including access controls and restricted storage, to protect personal information. No internet service is completely secure. Keep your login details private and tell us promptly if you believe your account or information has been compromised.
10. Your privacy rights
Email privacy@forwardly.co.za to exercise a right. We may need to verify your identity before acting on a request, and legal exceptions may apply. You may also contact the Information Regulator through its official website at inforegulator.org.za.
- Ask whether we hold personal information about you and request access to it.
- Ask us to correct, update, delete, or destroy information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, unlawfully obtained, or no longer authorised to be retained.
- Object to certain processing, withdraw consent, request restriction where appropriate, or opt out of direct marketing.
- Complain to us or lodge a complaint with South Africa’s Information Regulator.
11. Cookies and similar technology
Vonk uses necessary cookies or local storage to keep you signed in, remember security settings, store your cookie choice, and operate the service. These are available without analytics consent because the service cannot work securely without them.
We record first-party page views only after you select “Accept”. If you decline, Vonk does not create a visitor identifier or record analytics page views. You can change your decision at any time below; a new choice applies to future visits and does not alter records created while an earlier choice applied.
12. Children
Vonk is not intended for children under 18. We do not knowingly create accounts for children. If you believe a child has provided personal information, contact us so that we can investigate and take appropriate action.
13. Changes to this policy
We may update this policy when our services, practices, or legal duties change. We will publish the revised version here, update the date above, and provide additional notice where a change is material.
14. Information Officer
Our registered Information Officer under POPIA is [PLACEHOLDER — registered Information Officer, full name].
Contact the Information Officer at [PLACEHOLDER — Information Officer email address], by post at [PLACEHOLDER — physical street address, city, province, postal code], or by telephone on [PLACEHOLDER — support telephone number]. You may also email privacy@forwardly.co.za and your request will be routed to them.
[PLACEHOLDER — confirm the Information Officer's registration reference with the Information Regulator and any deputy Information Officer appointed.]
15. How long we keep information
We keep each record type only as long as the purpose or the law requires. The periods below apply unless a longer period is needed for an active dispute, investigation, or legal obligation.
| Record type | Retention period |
|---|---|
| Account and profile records | [PLACEHOLDER — e.g. for the life of the account, then X months] |
| CV, skills and public CV cards | [PLACEHOLDER] |
| Listings and listing screening results | [PLACEHOLDER] |
| Matches, expressions of interest and chat messages | [PLACEHOLDER] |
| Documents delivered between users | Removed at the stated expiry of the delivery, subject to backups |
| Payment and subscription records | [PLACEHOLDER — note the 5-year tax record requirement] |
| Support tickets and replies | [PLACEHOLDER] |
| Safety reports, flags and enforcement decisions | [PLACEHOLDER] |
| Login attempt and security logs | [PLACEHOLDER] |
| Site analytics and page views | [PLACEHOLDER] |
| Backups | [PLACEHOLDER — backup retention window] |
16. Processors and hosting region
We use the following processors (operators) to run Vonk. Each is bound by confidentiality and data-protection terms and may only process information on our instructions.
- Hosting, database, authentication and file storage: Lovable Cloud, built on Supabase infrastructure. Hosting region: [PLACEHOLDER — confirm data-centre region, e.g. eu-west-1].
- Payments: Payfast (Pty) Ltd, South Africa. Card details are handled by Payfast and never stored by Vonk.
- Automated safety screening: Google Gemini models accessed through the Lovable AI gateway. Processing region: [PLACEHOLDER — confirm region].
- Transactional email: [PLACEHOLDER — email sending provider and region].
- Analytics: first-party page-view records stored in Vonk's Lovable Cloud database, only after consent.
- Error monitoring: Sentry, when configured, receives technical fault details without account identity, form contents, request bodies, cookies, or session replay.
- [PLACEHOLDER — any further processor, its role, country, and the cross-border transfer safeguard relied on under POPIA section 72.]
17. If there is a security breach
If we have reasonable grounds to believe your personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and you as soon as reasonably possible after discovering and containing the incident, as POPIA section 22 requires.
Our notice will describe what happened, the information involved, the likely consequences, the steps we have taken, and what you can do to protect yourself. We will notify you by email to your account address and, where the risk is high, by an in-app notice as well.
[PLACEHOLDER — the internal notification deadline you commit to, e.g. within 72 hours of confirming a reportable breach, and the incident-response owner.]
18. ID verification for gig workers
ID verification is separate from employer and agency verification. It is intended to confirm that a gig worker's stated identity passed the applicable check; it does not certify their qualifications, conduct, or suitability for a job.
ID verification for gig workers is a separate trust check, not a requirement to browse or express interest. A verified badge will only appear after Vonk has reviewed the required identity evidence. Do not send an ID copy through a listing or chat. [PLACEHOLDER — confirm the approved verification provider or manual process, which ID fields are checked, whether an ID image is retained, where it is processed, and the deletion period before accepting ID documents.]
Until the process and retention terms above are confirmed, do not submit an ID document through chat or ordinary document delivery. Vonk will display the final notice and obtain any required consent before accepting identity evidence.
19. Appealing an automated safety flag
Vonk screens listings and messages for scam and safety risks automatically. A flag can add a warning banner, pause a listing, or restrict an account. No automated flag is, on its own, a final decision about you.
- You will see the reason on the affected listing or account notice, together with a reference.
- To appeal, open a support ticket inside Vonk or email [PLACEHOLDER — support email address] with that reference and anything that shows the listing or conduct is genuine.
- A member of our trust and safety team — a person, not a model — reviews the appeal and can clear the flag, keep it, or escalate it.
- [PLACEHOLDER — appeal acknowledgement and decision turnaround times, and the escalation contact if you remain unhappy.]
- You may also complain to the Information Regulator if you believe an automated decision was made unlawfully.