Kustomcode Logo
Statutory Compliance Architecture

Privacy Policy & Data Protection Notice

Statutory Compliance Notice under Protection of Personal Information Act (POPIA Act 4 of 2013), EU General Data Protection Regulation (GDPR 2016/679), and Electronic Communications and Transactions Act (ECTA 25 of 2002).

Effective Date: 1 January 2026Responsible Party: Zash Holdings Pty Ltd t/a KustomcodeReg No: FPB8/2026/435135

1. Responsible Party Identity & Scope

This Privacy Policy applies to all applications, websites, and APIs operated under Zash Holdings Pty Ltd t/a Kustomcode and related operational portfolio, including but not limited to kustomcode.xyz, fleet.kustomcode.xyz, zbot.kustomcode.xyz, Relay Ingress gateways, and OEM diagnostics software.

Under Section 1 of the Protection of Personal Information Act (POPIA Act 4 of 2013), Zash Holdings Pty Ltd t/a Kustomcode acts as the designated Responsible Party determining the purpose and means of processing Personal Identifiable Information (PII).

2. POPIA Section 18 Explicit PII Notice

Pursuant to POPIA Section 18, we provide explicit notice regarding the precise categories of data collected directly from data subjects during platform onboarding and interaction:

Identity & Contact Telemetry

Legal full name, verified email address, phone number for OTP authentication, hashed credentials, and device identifiers.

Geospatial Telemetry

Coarse and fine PostGIS spatial coordinates used exclusively for localized parcel tracking and fleet dispatching.

Payment & Transaction Tokens

Stripe and PayFast transaction IDs. Raw credit card numbers are processed directly via PCI-DSS Level 1 compliant gateways and are never stored on Kustomcode servers.

3. POPIA Section 57 Biometric Consent & Zero-Knowledge Burn

POPIA Section 57 requires prior authorization and explicit data subject consent for processing special personal information, specifically biometric data.

MediaPipe Facial Liveness & Zero-Knowledge Protocol

When undergoing verification (e.g. driver badge verification or selfie liveness checks), our client-side MediaPipe engine extracts facial geometry landmarks in client memory. Once verification is calculated:

  • Raw camera frames are immediately destroyed in memory (Zero-Knowledge Burn).
  • Only a boolean verification status flag (`isVerified: true`) and cryptographically signed verification token are stored in PostgreSQL.
  • No raw biometric imagery, facial depth maps, or facial feature templates are retained or shared with third parties.

4. ECTA Section 43 Disclosures & Section 44 Digital Waiver

In compliance with Section 43 of the Electronic Communications and Transactions Act (ECTA 25 of 2002), merchant details are disclosed below:

  • Merchant / Company Name: Zash Holdings Pty Ltd t/a Kustomcode
  • Website: https://kustomcode.xyz
  • Primary & Legal Email: contact@kustomcode.xyz
  • Physical Jurisdiction: Polokwane, Limpopo / Gauteng, Republic of South Africa
ECTA Section 44 Digital Performance Cooling-Off Waiver

By purchasing digital API keys, software licenses, or digital PDF publications, users acknowledge that digital content is delivered immediately upon transaction confirmation. Pursuant to ECTA Section 44(2), the standard 7-day cooling-off period does not apply to un-downloadable digital services or delivered digital assets once performance has commenced.

5. Right to Erasure & Tombstone Ledger Policy

Under POPIA Section 24 and GDPR Article 17, users possess the absolute statutory right to request erasure of their personal identifiable information.

Automated Erasure & Anonymization Pipeline

Upon submitting an Account Deletion request via settings or by emailing contact@kustomcode.xyz:

  1. All profile PII, telemetry records, and chat histories are permanently hard-deleted from live production databases within 72 hours.
  2. Financial transaction records mandated by South African Revenue Service (SARS) tax laws are anonymized into non-identifiable tombstone ledgers.

6. Contact Information Officer

For statutory privacy inquiries, POPIA Form 2 objection requests, or data protection officer communications, contact:

Information Officer: Kustomcode Data Protection Office
Email: contact@kustomcode.xyz
Regulatory Body: Information Regulator (South Africa) — inforeg@justice.gov.za