Residents
- Collected:
- Name, mobile number (optional), home ward, water requests and missed-tanker reports.
- Purpose:
- To route your ward's water request to the correct depot and to show you only your ward's status.
- Lawful basis:
- Consent, given at sign-up, plus the public-interest performance of a municipal service.
Drivers
- Collected:
- Name, municipal employee number, contractor, GPS coordinates at check-in, litres offloaded, evidence photos.
- Purpose:
- To prove a delivery took place at the correct tank at the correct time.
- Lawful basis:
- Employment / contractor obligation to the municipality.
Command staff
- Collected:
- Name, employee number, municipality, depot scope, approval decisions.
- Purpose:
- To control who may dispatch jobs and approve staff, and to keep an audit trail of those decisions.
- Lawful basis:
- Employment obligation and legitimate municipal interest.
Councillors
- Collected:
- Name, ward, party, office and private contact details.
- Purpose:
- Contact details are held for automated escalation messages only. They are never sent to a browser and never shown to residents or drivers.
- Lawful basis:
- Public office information plus legitimate interest in service escalation.
1. Accountability. The municipality's Information Officer remains accountable. STERNMARK processes only on documented instruction.
2. Processing limitation. We collect the minimum needed to dispatch and prove a water delivery. Residents are never asked for an ID number, address or income.
3. Purpose specification. Data is used for water dispatch, delivery verification and service reporting — nothing else. It is not sold, profiled or used for political communication.
4. Further processing limitation. Aggregated, de-identified statistics (litres per ward, response times) may be used in service reports. Individual records may not.
5. Information quality. Residents and staff can correct their own profile at any time; employee numbers are validated against the municipal staff register.
6. Openness. This page is the processing notice, linked from sign-up and from every resident page.
7. Security safeguards. See the controls below. Any compromise is reported to the Information Regulator and affected data subjects as required by section 22.
8. Data subject participation. You may request access to, correction of, or deletion of your personal information.
Row-level security on every table
The database itself enforces who may read each row. Residents can only read their own ward, drivers only what they are dispatched to, command only their municipality or depot.
No live tracking shown to the public
Residents never see a driver's live coordinates. They see coarse status bands only (approaching, active nearby, completed).
Contact details held server-side
Councillor phone numbers and e-mail addresses are readable only by the escalation engine and by an administrator making an explicit, logged lookup.
Audit trail
Staff approvals, tank verifications, job acceptances and check-ins are timestamped and exportable as CSV for the municipality's own records.
Operational records (requests, jobs, check-ins, litres): 5 years, for audit.
Evidence photographs: 12 months, then deleted.
Resident accounts: deleted on request, or 12 months after the last sign-in. Deleting an account removes the name and contact details; the ward-level delivery statistics remain in de-identified form.
Escalation messages and their recipients: 3 years.
Access. Ask for a copy of everything held about you (POPIA section 23, Form 2 of PAIA).
Correction. Fix your name, phone number or ward directly in your profile, or ask us to do it.
Deletion / objection. Withdraw consent and have your account removed. Water requests you backed stay as anonymous counts.
Complain. To the municipality's Information Officer first, then to the Information Regulator (South Africa), enquiries@inforegulator.org.za.
Data requests for a pilot deployment go to the municipality's Information Officer, copied to STERNMARK Technologies at the address in your pilot agreement. We respond within 30 days.
Data is stored in a managed PostgreSQL database with encryption in transit and at rest, and daily backups. Section 72 of POPIA permits trans-border storage where the receiving jurisdiction offers comparable protection; a municipality that requires in-country residency can be provisioned on a South African region at the start of a contract, and this page will be updated to state the region in use.
No third-party advertising, analytics or tracking scripts are embedded in AquaSure.
Last reviewed September 2026 · Read the 90-day pilot proposal