Skip to content
shiftsync
FeaturesBCEA and sectorsPricingSecurity
Sign inTry the demoSign up
FeaturesBCEA and sectorsPricingSecurityContactSign inTry the demoSign up

Policies

  • Terms of Service
  • Privacy Policy
  • Refund and Cancellation Policy
  • Cookie Policy
  • Acceptable Use Policy
  • Operator Agreement (POPIA)
  • PAIA Manual
  • Security
  • Contact us

Operator Agreement (POPIA)

Last updated 26 September 2026. OTK Industries (Pty) Ltd, registration number 2023/955560/07, trading as ShiftSync.

When your business uses ShiftSync, you are the responsible party for your employees' personal information and OTK Industries (Pty) Ltd is your operator. Sections 20 and 21 of the Protection of Personal Information Act require a written contract between the two. This agreement is that contract. It forms part of our Terms of Service and applies from the moment you accept them.

1. What we process, and why

  • People: your employees, managers and HR staff, and people you invite.
  • Information: names, contact details, usernames, positions, pay rates, contracted hours, rosters and shifts, leave and requests, clock-in times, notes and medical certificates you choose to collect.
  • Purpose: only to provide the ShiftSync service to you: scheduling, compliance checks, leave, timesheets, notifications, reports and support. We don't use it for anything else, and never sell it.
  • Duration: while your subscription lasts, then as set out in section 8.

2. Your instructions

We process the information only on your documented instructions, which are these terms and how you set up and use ShiftSync, unless the law requires otherwise (in which case we'll tell you first, unless the law forbids that).

3. Confidentiality

Everyone at OTK Industries (Pty) Ltd who can access your information is bound to keep it confidential and has access only as far as needed to run and support the service.

4. Security measures (section 19)

  • Encryption in transit (HTTPS) and at rest.
  • Each business's data is kept apart by database row-level security; roles limit what each person sees.
  • Sign-in by one-time email link, or username and PIN with lockout after repeated wrong tries.
  • Medical certificates are only available to the employee and their managers.
  • Changes our staff make to your account are recorded in an audit log.

More detail is on our Security page. We review these measures regularly and update them as risks change.

5. Sub-operators

You authorise us to use these sub-operators, each bound by written terms that protect the information at least as well as this agreement:

  • Supabase (database, sign-in and sign-in emails), Frankfurt, Germany.
  • Vercel (application hosting), Frankfurt, Germany.
  • Paystack (card payments; receives billing details, not employee records), South Africa and Nigeria.
  • Browser push services (Apple, Google, Mozilla) for notifications staff turn on; they receive only the notification text.

We'll tell you at least 30 days before adding or replacing a sub-operator that processes employee records. If you object on reasonable grounds and we can't accommodate it, you may cancel.

6. Transfers outside South Africa (section 72)

The information is stored in the European Union, whose General Data Protection Regulation provides protection substantially similar to POPIA, and our providers are bound by binding agreements to protect it.

7. Helping you

  • Requests from employees: you can view, correct and export most information yourself. If an employee contacts us directly, we'll refer them to you and help you respond.
  • Security compromises (section 22): we'll tell you without undue delay, and in any event within 72 hours, after we become aware of unauthorised access to your information, with what we know and what we're doing, so you can notify the Information Regulator and the people affected.
  • Audits: we'll answer reasonable written questions about how we protect your information once a year, or after a security compromise.

8. When the subscription ends

You can export your data for 30 days after your workspace closes. We then delete it within 90 days, apart from what the law requires us to keep (such as billing records) and backup copies, which are removed in the normal backup cycle. Keep the employment records the BCEA requires you to hold for three years.

9. Your responsibilities

You confirm you have a lawful basis to process your employees' information in ShiftSync and have told them about it. A template notice you can give staff is set out below.

Template notice for your employees

We use ShiftSync, a scheduling service provided by OTK Industries (Pty) Ltd, to plan shifts, handle leave and requests, record when you clock in and out, and work out hours for payroll. It holds your name, contact details, position, pay rate, shifts, leave, clock-in times and any sick notes you give us. Only you, your managers and HR can see your personal details; colleagues see only the published roster. The information is stored securely in the European Union. You can ask HR to see or correct your information at any time.

Contact

Questions about this agreement: support@shiftsync.co.za.

Full name
OTK Industries (Pty) Ltd, trading as ShiftSync
Registration number
2023/955560/07
Email
support@shiftsync.co.za
Physical address
18 Diemersdal Road, De Bron, 7530
Website
www.shiftsync.co.za
shiftsync

Staff rosters, leave and timesheets for South African shift work.

Product

FeaturesBCEA and sector rulesPricingLive demoSign upSign in

Support

Contact usSecuritysupport@shiftsync.co.za

Legal

TermsPrivacyRefundsCookiesAcceptable useOperator agreementPAIA manual

© 2026 OTK Industries (Pty) Ltd (registration number 2023/955560/07). ShiftSync is a trading name and division of OTK Industries (Pty) Ltd.