Privacy Policy

Effective date: 2026-05-25 — Operated by CDSoft (Pty) Ltd, South Africa

This policy explains how we handle personal information on this Platform (talent.smorg.co.za and jobs.smorg.co.za). We try to collect as little as necessary and be clear about what we do with what we keep.

1. Who we are

CDSoft (Pty) Ltd is a South African company. We operate this Platform and are the responsible party under the Protection of Personal Information Act 4 of 2013 (POPIA).

Contact us

2. What we collect

For candidates:

For employers:

For all users:

3. What we don’t collect

4. Why we collect it

DataPurpose
Email addressAccount authentication, platform notifications
Profile contentDisplay to employers browsing the Platform
CV fileExtract and populate profile fields (you review before anything is published)
Usage logsDebugging, platform reliability
Session dataKeep you logged in securely

We do not sell personal information. We do not use profile content for advertising.

5. Profile visibility and how your data reaches employers

Visibility settings

Every candidate profile has three settings that control who can see it and who can contact you. All three are on by default when your profile is created, and you can change any of them at any time from your account:

Profile visibility — when on, your profile is a public web page that employers and anyone with the link can view. When off (hidden), it is not surfaced in searches, though job applications you submit are unaffected.

Members of Smorg — when on, registered members of the platform can see your profile and contact you.

Members of Smorg — when on, organisations using the Smorg recruitment system (smorg.co.za), also operated by CDSoft (Pty) Ltd, can see your profile and contact you about roles they are hiring for.

Switching a setting off takes effect immediately, but does not recall information already accessed while it was on — an employer or organisation that viewed your profile before then may retain what they saw, as an independent responsible party under POPIA.

Passive discovery (employer browses the database)

If your profile is visible, an employer may find it while searching the candidate database and view or download your information. At that point the employer becomes an independent responsible party under POPIA for how they handle your data. We are not responsible for what employers do with information once they have accessed it.

Active application (you apply to a listing)

When you apply to a job listing, your profile and any material you include are transmitted to the employer who posted that role. This is a deliberate action on your part and constitutes consent to that transfer. Once the employer has received your application data, they hold it under their own POPIA obligations.

6. Who we share data with

We use a small number of infrastructure providers to operate the Platform:

We do not share your data with recruiters, employers, or third parties beyond what you choose to publish on your profile, what your visibility settings allow (see section 5), or what you submit in a job application.

7. Cross-border transfers

Cloudflare and Anthropic operate globally. Your data may be processed outside South Africa. Cross-border transfers are governed by POPIA Section 72, which we rely on through binding agreements with these providers. Where special personal information is involved, Section 57 may add a further requirement — which is why we ask you not to include it in the first place

8. How long we keep your data

DataRetention
Active accountHeld while your account is active
Deleted accountProfile and CV removed within 30 days of deletion
Usage logs90 days rolling
Payment records5 years (SARS compliance)

If your account has been inactive for 12 months, we will email you before deleting it.

9. Your rights under POPIA

You have the right to:

To exercise any of these rights, contact us. We will respond within 30 days.

For how to request access to records CDSoft holds — including the applicable PAIA forms and fees — see our PAIA Manual.

10. Security

Connections to the Platform are encrypted (HTTPS). Data at rest is encrypted by Cloudflare’s storage infrastructure. Access to production systems is restricted to authorised personnel.

No system is completely immune to breach. If a breach occurs that poses a material risk to your rights, we will notify you and the Information Regulator as required by POPIA.

11. Children

The Platform is not directed at anyone under 18. We do not knowingly collect information from minors.

12. Changes to this policy

If we make material changes to how we handle your personal information, we will notify active users by email at least 14 days before the change takes effect.

Information Officer: Brent Greeff — contact us