<- Trust Center
Privacy & Data Protection

Privacy Policy

How Flex collects, uses, protects and shares Personal Information.

Effective Date: 1 August 2026Last Updated: 14 July 2026Version: 2.1Document Owner: Flex Online (Pty) Ltd

1. Introduction

Flex Online (Pty) Ltd (“Flex”, “we”, “our” or “us”) respects the privacy of individuals whose personal information we process.

This Privacy Policy explains how we collect, use, store, disclose and protect personal information in connection with:

  • the Flex website available at www.flexonline.io and related public web pages operated by Flex (the “Website”);
  • our commercial and business relationships;
  • the cloud-based software platform and related services developed and operated by Flex (the “Flex Platform”); and
  • communications, support services, events and other interactions with Flex.

Flex is established in the Republic of South Africa. We primarily process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”).

Where the circumstances require it, we also process personal information in accordance with other applicable privacy and data protection legislation, including the European Union General Data Protection Regulation (“EU GDPR”), the United Kingdom General Data Protection Regulation (“UK GDPR”) and applicable national data protection laws.

This Privacy Policy should be read together with our:

  • Website Terms;
  • Platform Terms;
  • Cookie Policy;
  • Acceptable Use Policy;
  • Responsible AI Policy; and
  • other applicable policies published within the Flex Trust Centre.

2. Scope

This Privacy Policy applies to personal information relating to:

2.1 Website Visitors

Individuals who visit the Website, submit an enquiry, request information, register for an event, subscribe to communications or otherwise interact with Flex through our public channels.

2.2 Customer Representatives

Individuals who act for, work for or represent an organisation that purchases, evaluates or engages with Flex, including commercial, contractual, billing, administrative, technical and support contacts.

2.3 Platform Users

Individuals who are authorised by a Customer to access or use the Flex Platform, irrespective of the permissions, responsibilities or role assigned to them.

2.4 Other Business Contacts

Individuals who interact with Flex as prospective customers, service providers, business partners, contractors, advisers, job applicants or other professional contacts.

This Privacy Policy does not replace any privacy notice or policy issued by a Customer. Customers may have their own legal obligations and policies governing how they collect and use personal information through their implementation of the Flex Platform.

3. Definitions

For the purposes of this Privacy Policy:

Customer means an organisation that has entered into an agreement with Flex to access or use the Flex Platform.

Customer Content means information, documents, materials, records, media, data and other content uploaded to, stored within or generated through the Flex Platform by or on behalf of a Customer or its Platform Users.

Data Subject means the individual to whom personal information relates.

Operator has the meaning given to it under POPIA and generally refers to a person or organisation that processes personal information for a Responsible Party under a contract or mandate.

Personal Information means information relating to an identifiable living individual and, where applicable under POPIA, an identifiable existing juristic person. Where another applicable law uses the term “personal data”, references to Personal Information in this Privacy Policy include personal data.

Platform User means an individual authorised by a Customer to access or use the Flex Platform.

Processing means any operation or activity concerning Personal Information, including collecting, receiving, recording, organising, storing, updating, retrieving, using, sharing, transmitting, restricting, deleting or destroying it.

Responsible Party has the meaning given to it under POPIA and generally refers to the person or organisation that determines the purpose of and means for Processing Personal Information. Where the EU GDPR or UK GDPR applies, the equivalent term is generally “controller”.

Special Personal Information means categories of Personal Information afforded additional protection under applicable law, which may include health information, biometric information, information concerning race or ethnic origin, religious or philosophical beliefs, political persuasion, trade union membership or sexual life.

4. Flex’s Role

Flex’s legal role depends on the context in which Personal Information is processed.

4.1 Flex as Responsible Party

Flex generally acts as the Responsible Party where we determine why and how Personal Information is processed. This includes Personal Information processed for:

  • Website operation and analytics;
  • responding to enquiries;
  • sales and business development;
  • Customer relationship management;
  • contracting, billing and account administration;
  • events, surveys and marketing communications;
  • recruitment;
  • supplier and business-partner management;
  • security, fraud prevention and legal compliance; and
  • operating Flex’s own internal business functions.

4.2 Flex as Operator

When a Customer uses the Flex Platform to process Personal Information for its own purposes, the Customer will generally act as the Responsible Party and Flex will generally act as its Operator.

In this context:

  • the Customer determines the purposes for which Personal Information is processed;
  • the Customer determines which individuals may access the Flex Platform and what permissions they receive;
  • Flex processes Personal Information on the Customer’s documented instructions and as necessary to provide, secure and support the Flex Platform; and
  • requests relating to Personal Information controlled by the Customer should ordinarily be directed to that Customer.

Where the EU GDPR or UK GDPR applies, Flex will generally act as a processor and the Customer as the controller in these circumstances.

4.3 Customer Responsibilities

Each Customer is responsible for:

  • ensuring that it has a lawful basis for collecting and processing Personal Information through the Flex Platform;
  • giving Platform Users and other Data Subjects appropriate privacy notices;
  • obtaining consent where consent is legally required;
  • configuring access permissions appropriately;
  • responding to Data Subject requests relating to information under its control; and
  • complying with any sector-specific or jurisdiction-specific legal obligations applicable to it.

5. Personal Information We Collect

The Personal Information we collect depends on the nature of your relationship with Flex, the Customer’s configuration of the Flex Platform and the services being used.

5.1 Website and Enquiry Information

We may collect:

  • name and surname;
  • organisation and position;
  • email address and telephone number;
  • country or region;
  • enquiry details;
  • communication preferences;
  • event-registration information;
  • information submitted through forms; and
  • correspondence with Flex.

5.2 Customer and Business Information

We may collect:

  • business contact details;
  • job title, department and organisation;
  • contractual and account information;
  • billing and transaction information;
  • meeting records and correspondence;
  • implementation and support information;
  • account-administration details; and
  • records of business interactions.

5.3 Platform User Information

Depending on the Customer’s requirements and configuration, the Flex Platform may process:

  • identity and contact information;
  • usernames, authentication details and account identifiers;
  • organisational information;
  • demographic information;
  • enrolment, participation and attendance records;
  • learning, skills-development and activity records;
  • assessment information and results;
  • uploaded documents, media, evidence and portfolios;
  • feedback, comments and communications;
  • competency, achievement and certification records;
  • electronic acknowledgements, approvals or signatures;
  • support requests;
  • audit trails, access logs and activity records;
  • device, browser and network information; and
  • other information entered into or generated through the Flex Platform.

The Customer determines which categories of Personal Information it requires and is permitted to process through its implementation of the Flex Platform.

5.4 Technical and Usage Information

When you use the Website or Flex Platform, we may automatically collect:

  • internet protocol address;
  • device and browser type;
  • operating system;
  • date, time and duration of access;
  • referring and destination pages;
  • pages, features or functions accessed;
  • system logs;
  • performance and diagnostic information;
  • approximate location derived from an internet protocol address;
  • cookie and similar-technology identifiers; and
  • information relating to suspected security incidents or misuse.

5.5 Support and Communications Information

When you contact Flex for support or communicate with us, we may process:

  • your contact information;
  • the contents of your request;
  • correspondence and support history;
  • screenshots, recordings or attachments you provide;
  • diagnostic information; and
  • information reasonably required to investigate and resolve the matter.

5.6 Special Personal Information

The Flex Platform is configurable and may, where directed by a Customer, process Special Personal Information or information relating to children.

Flex does not require Customers to upload Special Personal Information unless it is reasonably necessary for their lawful use of the Flex Platform.

Customers remain responsible for ensuring that any such Processing is lawful and appropriately authorised. Flex applies additional safeguards where required by applicable law, contractual commitments or the nature of the information.

6. How We Collect Personal Information

We may collect Personal Information:

  • directly from you;
  • from a Customer that authorises your use of the Flex Platform;
  • from other Platform Users acting under the Customer’s authority;
  • automatically when you access the Website or Flex Platform;
  • through cookies and similar technologies;
  • through third-party services or integrations selected by Flex or the Customer;
  • from publicly available sources;
  • from business partners, event organisers or referral sources; and
  • where permitted by law, from other legitimate sources.

Where Personal Information is collected from someone other than the Data Subject, the Customer or other party supplying it is responsible for ensuring that the collection and disclosure are lawful.

7. Why We Process Personal Information

We may process Personal Information for the following purposes:

7.1 Providing the Flex Platform

To:

  • create and administer accounts;
  • authenticate Platform Users;
  • provide configured platform functionality;
  • host, organise and display Customer Content;
  • support workflows configured by the Customer;
  • provide reporting and analytics;
  • maintain records and audit trails;
  • facilitate integrations;
  • provide technical support; and
  • otherwise perform our contractual obligations.

7.2 Operating the Website

To:

  • display Website content;
  • respond to enquiries;
  • provide requested information;
  • improve Website functionality;
  • understand Website usage;
  • manage events or subscriptions; and
  • protect the Website against misuse and security threats.

7.3 Managing Customer Relationships

To:

  • manage commercial and contractual relationships;
  • administer subscriptions and services;
  • issue invoices and process payments;
  • provide implementation, training and support;
  • communicate service information;
  • manage renewals and account changes; and
  • maintain business records.

7.4 Improving Products and Services

To:

  • monitor performance;
  • diagnose errors;
  • improve usability;
  • develop and test new functionality;
  • conduct internal research and analysis;
  • understand aggregated usage patterns; and
  • improve the reliability, security and effectiveness of the Flex Platform.

Where reasonably possible, Flex uses aggregated or de-identified information for these purposes.

7.5 Security and Integrity

To:

  • authenticate users;
  • manage permissions;
  • prevent unauthorised access;
  • detect fraud, abuse or malicious activity;
  • investigate suspected breaches;
  • preserve platform integrity;
  • maintain audit records; and
  • protect Flex, Customers, Platform Users and third parties.

7.6 Legal and Regulatory Compliance

To:

  • comply with applicable laws, court orders and regulatory requirements;
  • exercise or defend legal rights;
  • respond to lawful requests from public authorities;
  • maintain records required by law;
  • enforce our agreements and policies; and
  • assist Customers with their lawful compliance obligations where contractually required.

7.7 Communications and Marketing

Where permitted by law, we may use business contact information to:

  • provide information about Flex;
  • communicate product or service updates;
  • invite individuals to events;
  • distribute relevant content; and
  • manage marketing preferences.

You may opt out of non-essential electronic marketing communications at any time by using the unsubscribe mechanism provided or contacting us.

8. Lawful Grounds for Processing

Flex processes Personal Information only where an appropriate lawful ground exists.

Depending on the context and applicable law, these grounds may include:

  • consent;
  • performance of a contract;
  • taking steps at a person’s request before entering into a contract;
  • compliance with a legal obligation;
  • protection of a legitimate interest of the Data Subject;
  • pursuit of a legitimate interest of Flex, a Customer or a third party, provided that the Data Subject’s rights and interests are appropriately considered;
  • performance of a public-law duty by a public body;
  • compliance with the lawful instructions of a Customer acting as Responsible Party; or
  • another lawful ground recognised under applicable legislation.

Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of Processing that occurred before consent was withdrawn.

Where Flex acts as Operator, the Customer is ordinarily responsible for identifying and maintaining the lawful ground for the relevant Processing.

9. Customer Content

Customer Content remains under the control of the Customer or the applicable rights holder.

Flex does not claim ownership of Customer Content merely because it is processed through the Flex Platform.

Flex processes Customer Content only:

  • to provide, maintain, secure and support the Flex Platform;
  • in accordance with the Customer’s documented instructions;
  • as authorised by the applicable agreement;
  • where required by law; or
  • in an aggregated or de-identified form that does not reasonably identify the Customer or an individual.

Platform Users may access only the Customer Content that the Customer has authorised them to access.

10. Artificial Intelligence and Automated Processing

The Flex Platform may include artificial intelligence or machine-assisted functionality intended to support productivity, administration, content creation, analysis, reporting, decision support or other platform functions.

Where these features process Personal Information:

  • the Processing remains subject to this Privacy Policy and applicable privacy legislation;
  • Personal Information will be processed only as necessary to provide the relevant functionality;
  • access will be governed by applicable permissions and security controls;
  • third-party AI service providers, where used, will be assessed and contractually managed as appropriate;
  • Flex will seek to minimise the Personal Information shared with external AI services;
  • Customer Content will not be used to train publicly available or general-purpose AI models without appropriate authorisation;
  • Platform Users should review AI-generated outputs before relying on them; and
  • Flex will not intentionally subject individuals to solely automated decisions producing legal or similarly significant effects unless the Processing is lawful, appropriately authorised and subject to required safeguards.

Further information is available in the Responsible AI Policy.

11. Cookies and Similar Technologies

The Website and Flex Platform may use cookies, local storage, pixels and similar technologies to:

  • provide essential functionality;
  • maintain sessions;
  • remember preferences;
  • support authentication and security;
  • analyse performance and usage; and
  • improve user experience.

Some cookies are necessary for the operation of the relevant service. Other cookies will be used only where permitted by applicable law and, where required, after consent has been obtained.

Further information is available in the Cookie Policy.

12. Sharing Personal Information

Flex does not sell Personal Information.

We may disclose Personal Information to the following recipients where necessary and lawful:

12.1 Customers

Where you use the Flex Platform, Personal Information and activity associated with your account may be accessible to the Customer and to Platform Users authorised by that Customer.

12.2 Service Providers and Sub-Operators

We may use carefully selected service providers to support:

  • cloud infrastructure and hosting;
  • communications and email delivery;
  • customer support;
  • security and monitoring;
  • analytics;
  • payment and billing administration;
  • software development and operations;
  • integrations; and
  • professional services.

These parties may process Personal Information only for authorised purposes and are subject to appropriate confidentiality, security and data-protection obligations.

12.3 Customer-Selected Integrations

A Customer may choose to connect the Flex Platform to a third-party application or service.

Where a Customer enables such an integration, Personal Information may be exchanged with that provider as required for the integration to operate. The Customer is responsible for authorising the integration and assessing the third party’s terms and privacy practices.

12.4 Professional Advisers

We may disclose Personal Information to auditors, attorneys, accountants, insurers and other professional advisers where reasonably necessary.

12.5 Corporate Transactions

Personal Information may be disclosed in connection with a merger, acquisition, financing, restructuring, sale of assets or similar corporate transaction, subject to appropriate confidentiality and legal safeguards.

12.6 Legal Requirements

We may disclose Personal Information where reasonably necessary to:

  • comply with applicable law;
  • respond to a court order, subpoena or lawful regulatory request;
  • protect legal rights;
  • investigate fraud, misuse or security incidents;
  • protect the safety or rights of individuals; or
  • enforce our agreements and policies.

13. International Customers and Applicable Laws

Flex is established in South Africa and POPIA is our primary privacy framework.

However, Customers and Platform Users may be located in other jurisdictions. Privacy laws outside South Africa may therefore apply to particular Processing activities.

Where required by applicable law or contractual commitments, Flex will take reasonable steps to comply with relevant obligations under laws such as:

  • the EU GDPR;
  • the UK GDPR; and
  • other applicable national or regional privacy legislation.

The applicability of a particular law depends on factors including:

  • the location and activities of the Customer;
  • the location of the relevant Data Subjects;
  • the nature of the services provided;
  • whether goods or services are offered to individuals in that jurisdiction;
  • whether individuals’ behaviour is monitored in that jurisdiction; and
  • Flex’s contractual role in the Processing.

Nothing in this Privacy Policy should be interpreted as a representation that every privacy law applies to every Flex service, Customer or Processing activity.

14. International Transfers

Flex may process or permit access to Personal Information in jurisdictions outside the country in which it was originally collected where this is necessary to provide, secure, support or improve the Website or Flex Platform.

International transfers may arise where:

  • a Customer or Platform User accesses the Flex Platform from another country;
  • Flex provides support from another jurisdiction;
  • a service provider or sub-Operator processes information internationally;
  • a Customer enables an international third-party integration; or
  • infrastructure, communications, security or support services involve more than one jurisdiction.

Where Personal Information is transferred outside South Africa, Flex will take reasonable steps to ensure that the transfer complies with POPIA, including by relying on one or more of the following where appropriate:

  • the recipient being subject to a law, binding corporate rules or binding agreement that provides an adequate level of protection;
  • an agreement requiring the recipient to protect the information in a manner substantially similar to POPIA;
  • the Data Subject’s consent;
  • necessity for the performance or conclusion of a contract;
  • the interests of the Data Subject; or
  • another lawful basis recognised under POPIA.

Where the EU GDPR or UK GDPR applies, Flex and the relevant Customer will implement an appropriate transfer mechanism where required. This may include:

  • an applicable adequacy decision or adequacy regulation;
  • approved standard contractual clauses;
  • a United Kingdom international data transfer agreement or addendum;
  • binding corporate rules;
  • another approved safeguard; or
  • a lawful derogation applicable to the specific transfer.

Flex may also implement supplementary technical, organisational or contractual safeguards where reasonably required.

15. Information Security

Flex implements appropriate and reasonable technical and organisational measures designed to protect Personal Information against:

  • loss or destruction;
  • unauthorised access;
  • unlawful Processing;
  • alteration;
  • disclosure; and
  • misuse.

Depending on the relevant system and risk, these measures may include:

  • identity and access management;
  • role-based permissions;
  • authentication controls;
  • encryption in transit and, where applicable, at rest;
  • secure software-development practices;
  • infrastructure and application monitoring;
  • logging and audit trails;
  • vulnerability and patch management;
  • backups and recovery procedures;
  • incident-response processes;
  • staff confidentiality obligations;
  • security awareness measures; and
  • contractual controls over service providers.

No system or internet transmission is completely secure. Platform Users and Customers must also take reasonable steps to protect credentials, devices, networks and account access.

Further information is available in our Security Overview and Information Security documentation.

16. Security Incidents

Flex maintains processes for identifying, investigating, containing and responding to suspected security incidents.

Where Flex becomes aware of a security compromise involving Personal Information:

  • we will take reasonable steps to contain and mitigate the incident;
  • where Flex acts as Operator, we will notify the affected Customer without undue delay in accordance with our contractual and legal obligations;
  • where Flex acts as Responsible Party, we will notify affected Data Subjects and the relevant regulator where required by applicable law; and
  • we will cooperate with Customers and competent authorities as reasonably required.

Platform Users should promptly report suspected unauthorised access, credential compromise or other security concerns using the contact details provided below.

17. Data Retention

Flex retains Personal Information only for as long as reasonably necessary to:

  • provide the Website and Flex Platform;
  • fulfil the purposes described in this Privacy Policy;
  • comply with contractual commitments;
  • meet legal, tax, accounting and regulatory obligations;
  • resolve disputes;
  • enforce agreements;
  • maintain security and audit records; and
  • establish, exercise or defend legal claims.

Retention periods vary according to:

  • the nature and sensitivity of the information;
  • the reason it was collected;
  • contractual requirements;
  • Customer instructions;
  • legal obligations;
  • security considerations; and
  • whether the information is contained in backups or archival systems.

Where Flex acts as Operator, the Customer generally determines the applicable retention period for Customer Content.

Following termination of a Customer’s services, Customer Content will be returned, deleted or otherwise handled in accordance with the applicable agreement, documented Customer instructions and legal requirements.

Residual copies may remain temporarily in secure backup systems until overwritten in the ordinary course of Flex’s backup and retention processes.

Flex may retain aggregated or de-identified information where it can no longer reasonably be linked to an identifiable person.

18. Data Subject Rights

Subject to applicable law and any lawful limitations, you may have the right to:

  • request confirmation that Personal Information about you is being processed;
  • request access to your Personal Information;
  • request correction or updating of inaccurate or incomplete information;
  • request deletion or destruction of Personal Information;
  • object to certain Processing;
  • request restriction of Processing;
  • withdraw consent where Processing is based on consent;
  • object to direct marketing;
  • request portability of information where applicable;
  • request information about international-transfer safeguards where applicable;
  • object to certain automated decision-making; and
  • lodge a complaint with an appropriate supervisory authority.

18.1 Requests Relating to Customer-Controlled Information

Where Personal Information is processed through the Flex Platform on behalf of a Customer, you should ordinarily submit your request directly to that Customer.

Flex will provide reasonable assistance to the Customer in responding to valid requests, subject to applicable law and contractual arrangements.

Flex may refer a request to the relevant Customer where the Customer is the Responsible Party or controller.

18.2 Verification

Flex or the Customer may request sufficient information to verify your identity and authority before acting on a request.

This protects Personal Information against unauthorised access, alteration or deletion.

18.3 Fees and Timeframes

Requests will ordinarily be handled without charge, although a reasonable fee may be permitted where a request is manifestly unfounded, excessive or repetitive.

Requests will be addressed within the periods required by applicable law.

19. Children’s Personal Information

The Flex Platform may be used by Customers that provide services to children or other legally protected individuals.

Flex does not independently determine whether children should use a Customer’s implementation of the Flex Platform. The Customer is responsible for:

  • determining whether the Processing of children’s Personal Information is lawful;
  • obtaining authorisation from a competent person where required;
  • providing appropriate privacy notices;
  • applying appropriate permissions and safeguards; and
  • complying with applicable education, child-protection and privacy legislation.

Where Flex processes children’s Personal Information on behalf of a Customer, we do so as Operator and in accordance with the Customer’s lawful documented instructions, applicable agreements and legal requirements.

Flex does not knowingly use children’s Personal Information for its own direct marketing purposes.

20. Direct Marketing

Flex may send electronic marketing communications only where permitted by applicable law.

Where consent is required, we will seek that consent before sending the communication.

Each non-essential electronic marketing communication will include a reasonable method to unsubscribe or opt out.

Opting out of marketing does not prevent Flex from sending necessary contractual, transactional, security, support or service-related communications.

21. Links and Third-Party Services

The Website and Flex Platform may contain links to or integrations with services operated by third parties.

Flex is not responsible for the independent privacy practices of third parties that determine their own purposes and means of Processing.

You should review the privacy policies and terms of those providers before submitting Personal Information to them or enabling an integration.

22. Changes to this Privacy Policy

Flex may update this Privacy Policy from time to time to reflect:

  • changes to the Flex Platform or Website;
  • changes to our Processing activities;
  • legal or regulatory developments;
  • changes to service providers;
  • security requirements; or
  • operational improvements.

The latest version will be published with its effective date and version number.

Where changes are material, Flex will take reasonable steps to notify affected Customers or Platform Users through the Website, Flex Platform, email or another appropriate channel.

23. Governing Law

This Privacy Policy is governed primarily by the laws of the Republic of South Africa.

This does not limit any mandatory rights or remedies available to a Data Subject under another privacy law that validly applies to the relevant Processing activity.

24. Complaints

We encourage you to contact Flex first if you have a question or complaint regarding how we process Personal Information.

We will investigate privacy complaints and seek to resolve them reasonably and promptly.

You may also lodge a complaint with the appropriate privacy or data-protection authority.

In South Africa, complaints may be directed to:

Information Regulator (South Africa)
Website: www.inforegulator.org.za

Individuals in the European Economic Area or United Kingdom may also have the right to complain to the competent supervisory authority in the country in which they live, work or believe an infringement occurred.

25. Contact Us

Questions, requests or complaints concerning this Privacy Policy or Flex’s Processing of Personal Information may be directed to:

Flex Online (Pty) Ltd
Information Officer: D Viljoen - Executive Director
Email: trust@flexonline.io
Physical Address: 13 Umgazi Street, Menlo Park, Pretoria, South Africa, 0081
Website: www.flexonline.io

Where your request relates to Personal Information controlled by a Customer through the Flex Platform, please identify the relevant Customer and Flex Platform environment so that the request can be routed appropriately.