Like Magic
POPIA Compliance Policy
Last Updated: July 3, 2026
domain: likemagic.co.za/
Section 51 Manual
Like Magic is committed to safeguarding personal privacy in accordance with the Protection of Personal Information Act, No. 4 of 2013 ("POPIA") of South Africa. This policy describes our processing practices, technical security controls, and the measures we employ as an Operator to ensure the lawful collection of employee tracking metrics.
1. Designation of Information Officer
Under Section 51 of the Promotion of Access to Information Act ("PAIA") and in compliance with Section 55 of POPIA, Like Magic has designated the following individual as the Information Officer:
- Information Officer: the Like Magic team
- Position: Founder & Solo Developer of Like Magic
- Email: info@likemagic.co.za/
- Website: likemagic.co.za/
2. Lawful Processing Principles
We adhere to the 8 statutory conditions for the lawful processing of personal information:
- Principle 1: Accountability: Like Magic establishes measures to ensure compliance with POPIA, providing organizational and system security standards.
- Principle 2: Processing Limitation: We process data lawfully and in a non-intrusive manner. Keystroke logging is restricted strictly to volume statistics (key count) and does not capture text content. Screen capture is fully deactivated.
- Principle 3: Purpose Specification: Telemetry is captured solely to build workforce efficiency analytics dashboards on behalf of corporate clients.
- Principle 4: Further Processing Limitation: Personal information is not utilized for any auxiliary marketing or advertising purpose.
- Principle 5: Information Quality: Data is logged directly from operating system activity to maintain high records accuracy.
- Principle 6: Openness: This manual, our Privacy Policy, and our terms are publicly available to ensure absolute transparency.
- Principle 7: Security Safeguards: Session storage databases utilize multi-tenant isolation, data is encrypted in transit using SSL, and servers are hosted in secure compliance centers.
- Principle 8: Data Subject Participation: Corporate employees may request confirmation from their administrative officers regarding what telemetry is logged.
3. Operator Obligations
Where corporate clients use Like Magic to track employee activity, Like Magic acts as an Operator under Section 20 of POPIA. As an Operator, we:
- Process employee telemetry strictly under the instructions of the client (the Responsible Party).
- Ensure that employees of Like Magic (specifically the Like Magic team as the sole developer) maintain strict confidentiality regarding client data.
- Immediately notify the client if there are reasonable grounds to believe that a data subject's personal information has been accessed or acquired by an unauthorized person.
4. Incident Response & Breach Notifications
In accordance with Section 22 of POPIA, Like Magic maintains an active incident tracking protocol. In the event of a security breach involving personal information, we will notify the corporate client administrator and the South African Information Regulator immediately, detailing the nature of the breach, the exposed parameters, and the remedial steps taken.
5. Access to Records (PAIA Requests)
Data subjects may request access to their records or submit corrections/deletion requests by emailing the Information Officer. We will respond to all PAIA and POPIA requests within 30 days.