Privacy Policy
Last updated: 06 August 2026
Munika is a product of HashData (Pty) Ltd, a South African company. This policy explains what personal information we process when your municipality or municipal entity uses Munika, why we process it, how we protect it, and the rights individuals have under the Protection of Personal Information Act (POPIA). Munika acts as an operator processing data on behalf of the municipality, which remains the responsible party.
Information we process
- Account data — the name, email, password (hashed), municipality, and role of each official granted access.
- Financial data — budgets, the mSCOA chart of accounts, ledger postings, invoices, bills, receipts, payment batches and journals captured by your officials.
- Consumer & supplier data — ratepayer and consumer account details, billing and debtor records, and supplier/creditor records you capture for billing and payment.
- Banking details — supplier and consumer banking information captured for payments and reconciliation (stored encrypted at rest, scoped to your municipality only).
- Employee data — payroll, leave and HR records for your establishment, including sensitive fields such as ID numbers, salaries and bank accounts (encrypted at rest).
- Integration credentials — service keys for payment and reporting providers (e.g. Netcash), encrypted at rest, used only to make API calls on your instruction.
- Usage data — server logs (IP, timestamps, requested URLs) retained for operational and security purposes, typically for 90 days.
How we use it
- To deliver the Munika service to your municipality and keep its records mSCOA-aligned.
- To facilitate payments to suppliers and salaries via your payment provider on your instruction.
- To produce the data strings, returns and statements you submit to National Treasury and the Auditor-General.
- To send transactional emails (password resets, account notifications, batch status updates).
- To diagnose issues and maintain platform security.
We do not sell your data, share it with advertisers, or use it to train external machine-learning models.
Third parties we share data with
Munika integrates with a small set of trusted providers, only to deliver functionality your municipality explicitly enables:
- Netcash — supplier and salary payment submission, account balance and status polling.
- National Treasury — when you generate and upload mSCOA data strings and returns to the Local Government database (initiated by your officials).
- Amazon Web Services — infrastructure hosting (af-south-1), email delivery (SES), and object storage (S3).
- Cloudflare — DNS and edge protection for selected domains.
Each transmission is the minimum data required to complete the action you requested.
Where your data lives
Operational data is stored in PostgreSQL hosted in AWS South Africa (af-south-1, Cape Town). File assets are stored in AWS S3 in the same region. Backups are encrypted at rest.
Your rights under POPIA
Individuals whose information we process have the right to:
- Access the personal information we hold about them.
- Correct or update inaccurate information.
- Request deletion (subject to legal retention requirements, including municipal records that must be retained under the MFMA and applicable archives legislation).
- Object to processing.
- Lodge a complaint with the Information Regulator (South Africa).
Requests relating to records held on behalf of a municipality are directed to that municipality as the responsible party; we assist it in giving effect to them.
Contact us
For privacy questions or to exercise any of the rights listed above:
HashData (Pty) Ltd — Information OfficerEmail: info@hashdata.co.za
Phone: +27 21 330 5784
Fairway Square — Office E001, 23 Fairway Close,
Parow Golf Course, Parow, Cape Town, 7500, South Africa.
Changes
We may update this policy from time to time. Material changes will be notified to your municipality's administrators by email at least 14 days before they take effect.