legal hub/privacy-policy
POPIA ACT 4 OF 2013 COMPLIANT
/ data protection & privacy framework

Privacy Policy

Compliance Posture under the Protection of Personal Information Act (POPIA, Act 4 of 2013)

Information Officer Appointment & POPIA Commitment

Dubstrata is committed to protecting data privacy in full compliance with the Protection of Personal Information Act (Act 4 of 2013). Dubstrata has appointed an Information Officer registered with the Information Regulator of South Africa.

1. The 8 Lawful Processing Conditions under POPIA

Dubstrata implements strict technical and organizational measures across all 8 processing conditions:

POPIA ConditionDubstrata Architectural ControlsStatus
1. AccountabilityRegistered Information Officer oversees all data practices.Full Compliance
2. Processing LimitationProcesses strictly public corporate & macroeconomic data.Full Compliance
3. Purpose SpecificationSolely for quantitative market sentiment graph construction.Full Compliance
4. Further ProcessingNo secondary sale or monetization of client query telemetry.Full Compliance
5. Information QualityMulti-referee consensus validation & factuality scoring.Full Compliance
6. OpennessComplete transparent schema published in Data Dictionary.Full Compliance
7. Security SafeguardsAES-256 at rest, TLS 1.3 in transit, mTLS API verification.Full Compliance
8. Data Subject AccessMechanism for entities to challenge claims via referee queries.Full Compliance

2. Public Blockchain Wallet Address Pseudonymity (Section 1 POPIA)

Under Section 1 of POPIA, information is personal if it can be directly or reasonably linked to an identifiable living natural or juristic person:

Non-Identifiable Pseudonymous Processing

Public blockchain wallet hashes (e.g. 0x71C...) stored in market participant graph nodes represent public ledger hashes. Dubstrata collects and stores zero off-chain identity mappings (no real names, physical addresses, phone numbers, or IP addresses). Wallets are analyzed strictly as mathematical capital clusters.

3. Cross-Border Data Transfers (Section 72 POPIA) & Tenant Isolation

Dubstrata utilizes enterprise cloud infrastructure (AWS Africa Cape Town region, Google Cloud, Confluent Cloud).

  • Section 72 POPIA Compliance: International transfers are protected by standard Institutional Data Processing Agreements (DPAs) incorporating EU Standard Contractual Clauses (SCCs).
  • Private Tenant Overlays: Customer graph queries and private extractions are strictly segregated into isolated tenant namespaces. Private customer data is never mixed with the public graph or used to train global models.

4. Contacting the Information Officer

For formal POPIA access requests, Information Regulator compliance inquiries, or Data Processing Agreements (DPAs), contact:

Dubstrata Information Officeprivacy@dubstrata.io