- About this Privacy Notice
This Privacy Notice includes general information applicable to all users, South Africa-specific information under the Protection of Personal Information Act 4 of 2013 (POPIA), and United Kingdom-specific information under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where EU/EEA processing is relevant, EU GDPR may also apply.
- Who we are and how to contact us
bountiXP (Proprietary) Limited is a South African limited liability company that provides a digital employee engagement platform supporting employee recognition, engagement, communication, rewards and reporting.
| Contact point | Details |
| General contact | contact@bountixp.com |
| Legal / privacy / data protection contact | legal@bountixp.com |
| Telephone | 021 700 2300 |
| South Africa address | 14 Stibitz Street, Westlake, Cape Town, South Africa, 7945 |
| United Kingdom address | Office 015, 30 Great Guildford Street, London, SE1 0HS |
- When this Privacy Notice applies
- Website visitors and marketing-site users who browse or interact with bountiXP online pages;
- Prospective customers and enquiry contacts who request information, demos or support;
- Business customer representatives and customer administrators who manage or configure the platform;
- Employees, participants and end users who use the bountiXP platform as part of an employer or customer programme;
- Support users, complainants and individuals who submit rights requests or data protection complaints.
- Our role under POPIA and UK GDPR
bountiXP’s role depends on the processing context. Where a customer or employer organisation decides why and how participant or employee data is processed in the platform, that customer/employer is generally the responsible party under POPIA and/or controller under UK GDPR. In that context, bountiXP generally acts as an operator under POPIA and/or processor under UK GDPR, processing data on the customer’s documented instructions.
bountiXP may act as responsible party/controller for processing that bountiXP determines itself, including website administration, business contact management, platform security, compliance records, legal obligations, complaints handling, service administration and operational communications.
- Personal information and personal data we process
| Context | Categories of information |
| Website and enquiry users | Name, surname, email address and information submitted through forms or enquiries. Other fields may depend on customer or campaign requirements, for example mobile number or identity number where required. |
| Platform users / participants | Name, surname, email address, organisation, programme information, profile details, reward activity and customer or employer supplied attributes. |
| Customer administrators and business contacts | Name, surname, work contact details, role, organisation, administrator actions and support interactions. |
| Rewards and engagement records | Recognition activity, reward balances, points, transaction history, redemptions, deductions, catalogue activity and programme-related information. |
| Technical and security data | IP address, browser/device data, authentication events, platform logs, cookies, analytics data and monitoring records. |
| Support, rights and complaints records | Contact details, correspondence, request details, complaint information, investigation records and outcome records. |
- How we collect information
Directly from users when users complete forms, interact with the website or platform, update profiles, submit requests or contact bountiXP;
From employer/customer organisations that configure programmes, upload users or provide participant data;
Automatically through cookies, platform logs, analytics, monitoring and security tools;
From service providers, integrations or third-party systems where the platform configuration or service delivery requires those connections.
- Purposes, lawful bases and lawful grounds
| Purpose | Information used | UK GDPR lawful basis | POPIA lawful ground / justification | bountiXP role |
| Provide and administer the website and platform | Account, profile, administrator, technical and customer data | Contract; legitimate interests; processor activity where customer-controlled | Consent where applicable; contract; legitimate interest; compliance with law; operator activity where customer-controlled | Controller/responsible party for own operations; processor/operator for customer programmes |
| Operate recognition, engagement and rewards programmes | Participant, reward, recognition, wallet and transaction data | Contract; legitimate interests; customer instructions | Contract; legitimate interest; customer instruction; consent where applicable | Usually processor/operator for customer programme data |
| Send service communications, platform notifications and support responses | Contact details, account data, communication preferences | Contract; legitimate interests; consent where required | Contract; legitimate interest; consent where required | Depends on context |
| Marketing and newsletters | Name, email, preferences and marketing interaction data | Consent or legitimate interests depending on channel and applicable rules | Consent and/or legitimate interest, subject to POPIA direct marketing requirements | Controller/responsible party |
| Analytics, performance monitoring and service improvement | Usage, technical, analytics and log data, preferably aggregated/anonymised where possible | Legitimate interests | Legitimate interest and operational necessity | Controller/responsible party |
| Security, fraud prevention and platform integrity | Security logs, account activity, IP addresses, authentication and monitoring data | Legitimate interests; legal obligation | Security safeguards; legitimate interest; compliance with law | Controller/responsible party |
| Legal, compliance, complaints, audit and governance | Requests, complaints, correspondence, legal and audit evidence | Legal obligation; legitimate interests | Compliance with law; legitimate interest; accountability | Controller/responsible party |
Where bountiXP relies on legitimate interests, those interests include platform security, preventing misuse, supporting customers, improving performance, maintaining audit evidence, handling complaints and enforcing platform integrity. bountiXP does not use platform data to build unrelated third-party advertising profiles.
- Sharing information
| Recipient category | Purpose |
| Customer / employer organisation | Programme administration, user management, reporting and customer-controlled processing. |
| Hosting and infrastructure providers | Amazon Web Services (AWS), including hosting and infrastructure services in the EU region (Ireland), plus services such as S3, EC2, Elastic Beanstalk, Aurora Serverless, API Gateway, Lambda, CloudFront, Route 53, SES, SNS and CloudWatch. |
| Rewards and fulfilment providers | Achievement Awards Group and other approved rewards suppliers where required for a customer programme. |
| Communications, notifications and support providers | Platform communications, alerts, support and operational notices. |
| Client and external integrations | Integrations configured by customers or required for platform functionality. |
| Professional advisers, regulators and authorities | Legal advice, audit, compliance, dispute handling, regulatory reporting or legal obligations. |
- International transfers
bountiXP infrastructure and applications are hosted in the AWS EU region in Ireland, while AWS CloudFront may deliver web application assets through edge computing and caching.
For UK-originating restricted transfers, bountiXP will use an appropriate UK transfer safeguard where required, such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the European Commission Standard Contractual Clauses, an adequacy regulation, or another lawful UK transfer mechanism.
Where South African personal information is transferred outside South Africa, bountiXP will apply an appropriate basis under POPIA Section 72 where required. This may include suitable contractual protections, transfer necessary for contract performance, consent where appropriate, or another lawful safeguard.
- Retention
bountiXP keeps personal information only for as long as necessary for the purposes described in this Privacy Notice, the relevant customer programme, applicable contracts, legal obligations, audit requirements, security needs and legitimate business purposes.
| Category | Retention period / criteria |
| Platform log data | 12 months, unless a longer period is required for investigation, legal, audit or security purposes. |
| Daily backups | Kept on a two-week cycle. |
| Weekly backups | Kept on a four-month cycle. |
| Monthly backups | Kept on a one-year cycle. |
| Profile/account information | Retained in line with customer instructions, programme rules, applicable contracts, deletion requests and legal/audit requirements. |
| Complaints and rights requests | Retained for five years from final resolution or closure, unless a shorter or longer lawful period is approved and documented. |
| Customer programme data | Retained for the duration of the customer programme or applicable customer agreement and normally for up to five years after final closure where required for accountability, audit, contractual, dispute-resolution or legal purposes, unless a shorter or longer period is required by the customer agreement or applicable law. |
The Retention of Records Procedure is implemented through the Retention of Records Register. The register records the applicable record type, retention duration, retention start date, retention justification, format and destruction method for relevant regulatory, operational and accountability records. When records reach the end of their approved retention period, bountiXP completes secure destruction within 30 days where no lawful basis for continued retention applies, and records the destruction so that it is documented and auditable. Deletion requests may still be limited by legal, audit, security, contractual, backup and regulatory obligations.
- Security
bountiXP uses technical and organisational measures to protect personal information against unauthorised access, loss, misuse, alteration or disclosure. These include encryption, access controls, secure hosting, monitoring and logging, infrastructure security, security review and controlled supplier access.
bountiXP maintains a high-level Security Overview on its website. Detailed architecture documentation is available upon request and is not included in this public Privacy Notice.
- Your privacy rights
Depending on the applicable law and processing context, you may have the following privacy rights. These rights are not absolute and may be subject to lawful limitations, including where bountiXP acts on behalf of a customer/employer as processor or operator.
12.1 Your rights
- Right to be informed: You have the right to be told how your personal information or personal data is collected, used, shared, retained and protected.
- Right of access: You may ask whether bountiXP processes personal information or personal data about you and may request access to that information, subject to lawful limits.
- Right to correction or rectification: You may ask for inaccurate or incomplete personal information or personal data to be corrected, updated or completed.
- Right to deletion or erasure: You may ask for personal information or personal data to be deleted where a lawful basis for deletion exists. Deletion may be limited by legal, audit, security, contractual, backup or regulatory obligations.
- Right to object: You may object to certain processing, including direct marketing and, where applicable, processing based on legitimate interests.
- Right to restrict processing: Where UK GDPR applies, you may ask bountiXP to restrict processing in certain circumstances.
- Right to data portability: Where UK GDPR applies and the legal conditions are met, you may request certain personal data in a structured, commonly used and machine-readable format.
- Right to withdraw consent: Where processing is based on consent, you may withdraw that consent. Withdrawal does not affect processing that occurred before withdrawal or processing based on another lawful ground.
- Rights relating to automated decision-making and profiling: Where applicable law gives you rights in relation to solely automated decisions that produce legal or similarly significant effects, you may exercise those rights. bountiXP does not currently use high-stakes automated decision-making that significantly affects users.
- Right to complain: You may complain to bountiXP and may also complain to the relevant supervisory authority, including the Information Regulator of South Africa or the UK Information Commissioner’s Office where applicable.
12.2 How to exercise your rights
Rights requests should be sent to legal@bountixp.com. General enquiries may be sent to contact@bountixp.com. bountiXP may ask for information needed to verify your identity, understand the request and locate the relevant information.
Where bountiXP acts as an operator under POPIA or processor under UK GDPR, bountiXP may need to refer the request to the relevant customer/employer responsible party or controller, or act on that organisation’s documented instructions. bountiXP aims to respond to rights requests without undue delay and within applicable legal timeframes. Some requests may be refused, limited or delayed where a lawful reason applies.
- Complaints
If you have a concern about how bountiXP handles personal information, contact bountiXP using legal@bountixp.com. General enquiries may be sent to contact@bountixp.com. bountiXP’s Complaints Procedure provides that data protection complaints are received, logged, investigated and managed by the Data Protection Officer / GDPR Owner or relevant privacy contact. bountiXP aims to acknowledge data protection complaints within 5 working days and resolve complaints within 30 calendar days of receipt where possible. If a matter is complex or requires additional information, bountiXP will keep the complainant informed as appropriate. Appeals may be submitted in writing. Individuals may also complain to the relevant supervisory authority.
UK Information Commissioner’s Office: https://ico.org.uk/make-a-complaint/
Information Regulator of South Africa: https://inforegulator.org.za/complaints/
- Cookies and tracking technologies
bountiXP uses cookies and similar technologies for website and platform functionality, security, performance monitoring and analytics where applicable. bountiXP uses a cookie banner or consent management mechanism where required for non-essential cookies and similar technologies.
Cookie information is currently available at https://www.bountixp.com/privacy-policy. If bountiXP publishes a dedicated Cookie Policy page, it may be available at https://www.bountixp.com/cookie-policy or another link published by bountiXP. Users can manage cookie preferences using the available cookie banner or preference tool where available.
- Automated decision-making, profiling and system-generated outputs
The platform does not currently use automated decision-making, scoring or high-stakes profiling that significantly affects users. The platform may produce system-generated outputs such as dashboards, leaderboards, rankings, recognitions, notifications or transaction histories based on programme configuration and available data.
If bountiXP introduces significant automated decision-making, profiling or recommendation logic in the future, bountiXP will update this Privacy Notice and implement appropriate transparency and safeguards before the new processing begins.
- Updates to this Privacy Notice
bountiXP may update this Privacy Notice from time to time. The latest version will be available through the shared Privacy Notice link used by the website and platform.
Last updated: 4 August 2026.