MBOS

Compliance & data protection

This page summarises how the MBOS Communications Portal handles personal information, for banks, insurers, auditors and anyone completing a supplier review. It is written to sit alongside our privacy notice (version 2026-08-25) and terms of use (version 2026-08-25), which remain the binding documents. Portal release v2.5.0, 2026-08-27,

Document version
Current

Published 2026-08-25 with portal release v2.4.0, This is the wording in force today.

Terms of use

  • Says plainly that you may invite more people than you have rewards for, and that rewards go to the first people to finish, up to the limit you set.
  • Confirms that the reward limit is enforced by the system itself, even when many people finish at the same moment.
  • Adds that SMS charges are shown before you send and recorded against each message.

Privacy notice

  • Explains which roles may see names, mobile numbers, message wording and link clicks, owner, campaign managers and reward managers only.
  • Confirms live dashboard updates carry counts and statuses only, never names, numbers or message wording.
  • Describes read-only developer keys receiving partly hidden mobile numbers and never a redeemable reward code.
  • Describes the answer-quality measurements taken during a survey, and what is deliberately not recorded.

API & developer docs

  • Reward codes are masked for read-only keys.
  • Keys can be given an expiry date and every call is logged.
  • Delivery receipts and reply webhooks require a per-workspace security header.
What personal information we hold

For each campaign we hold the name and mobile number your team loads, the survey answers given, delivery results from the messaging network, and the reward code sent out. For portal users we hold a name, work email, profile picture and the workspace they belong to.

Why we hold it

Only to run the campaign you set up: to send the survey, record the answer, work out who qualifies for a reward, deliver that reward, and report on the outcome. We do not sell personal information and we do not use it for anything else.

Who can see it

Access is limited to the workspace the information belongs to. Every request, from the portal, from a key issued to another tool, or from a webhook, is checked against the workspace and the person's role before any data is returned. Mobile numbers are partly hidden for anyone without permission to see them in full.

How long we keep it

Each workspace sets its own periods for names and numbers, survey answers and the activity log, and records the reason. Survey links expire after the number of days the workspace chooses, so an old link cannot be reused.

Rights of the people we contact

A recipient may ask for their name and number to be removed; the anonymous answer stays so reporting totals remain correct. A portal user may download everything we hold about them, or ask for their account and details to be deleted. Every such request is written to a register with the date and who handled it.

How access is enforced

Permission is checked twice, in two independent places: once by the endpoint being called, and again by the database itself through row-level rules. Names, mobile numbers, message wording and link clicks are readable only by the workspace owner, campaign managers and reward managers; other roles receive counts and reports only. Live dashboard updates carry counts and statuses, never personal details. Each of these rules has an automated test that runs on every change.

Keys issued to other systems

A key belongs to one workspace and cannot reach another. Read-only keys receive mobile numbers partly hidden and never receive a redeemable reward code. Keys are stored only as a one-way fingerprint, can carry an expiry date, and stop working immediately when removed.

Record keeping

We log who changed what in the workspace, every attempt to reach data without permission, every call made with a developer key, and every delivery receipt we accept or reject.

Documents you can download

Use your browser's print or “save as PDF” option on any of these pages to keep a dated copy for your records.

Who to contact

Questions about personal information, or a request to download or delete data, go to our information officer at privacy@mbos.co.za. Portal users can do both themselves under Privacy & data once signed in.

We only publish claims we can support. Where a certification or audit report is required for your review, please ask us directly rather than assuming it from this page.