Docs

Privacy Policy

Effective date: 1 January 2025  |  truID (Pty) Ltd, South Africa

This policy applies to the developer.truid.io developer portal and SDK package registry operated by truID (Pty) Ltd. For the general truID platform privacy policy, please refer to the truid.co.za website.

1. Who we are

truID (Pty) Ltd (“truID”, “we”, “us”) is a company registered in South Africa. We operate the truID Connect SDK developer portal at developer.truid.io and the private package registry at packages.truid.io.

2. Information we collect

When you use the developer portal we may collect:

  • Account information — name and email address provided via your identity provider (Cognito) when you sign in.
  • API keys — metadata for API keys assigned by portal administrators to brands linked to your company.
  • Access logs — requests to the package registry are logged by AWS infrastructure for security and operational purposes.

We do not use tracking pixels, third-party analytics, or advertising networks on this portal.

3. How we use your information

  • To authenticate your access to the developer portal and package registry.
  • To manage API keys that authorise your SDK package downloads.
  • To maintain security, investigate abuse, and comply with legal obligations.

4. Legal basis (POPIA & GDPR)

We process your personal information on the following lawful grounds:

  • Contract performance — processing necessary to provide you with access to the SDK and documentation.
  • Legitimate interests — security logging and fraud prevention.
  • Legal obligation — compliance with applicable South African law (POPIA) and any other applicable legislation.

5. Data retention

Account session data is retained for the duration of your session. API key metadata is retained until you delete the key. Access logs are retained for a maximum of 90 days. We do not retain personal information beyond what is necessary for the purposes described above.

6. Data sharing

We do not sell or rent your personal information. We share data only with our infrastructure providers (AWS) under appropriate data processing agreements, and where required by law.

Our infrastructure is hosted in the AWS Cape Town region (af-south-1) to keep data within South Africa where operationally possible.

7. Your rights

Under POPIA you have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion of your personal information (subject to legal retention requirements).
  • Object to processing of your personal information.
  • Lodge a complaint with the Information Regulator of South Africa.

To exercise any of these rights, contact us at privacy@truid.co.za.

8. Security

We implement technical and organisational measures to protect your personal information, including encryption in transit (TLS), encryption at rest, and access controls. Our SDK development practices align with OWASP Top 10 mitigation and privacy-by-design principles.

9. Cookies

The developer portal uses a single session cookie (“next-auth.session-token”) to maintain your authenticated session. No third-party cookies or tracking cookies are set. The session cookie is HttpOnly and Secure.

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by updating the effective date above. Continued use of the portal after changes constitutes acceptance of the updated policy.

11. Contact

truID (Pty) Ltd
South Africa
privacy@truid.co.za
www.truid.co.za