Voca Learning Solutions

Privacy Policy

Voca Learning Solutions — Learner Management System

Last updated: July 2026

1. Introduction

Voca Learning Solutions ("we", "us", "our") is committed to protecting the personal information of learners, bursary beneficiaries, staff, and all individuals whose data is processed through this Learner Management System ("LMS"). This policy explains what data we collect, how we use it, where it is stored, and your rights under the Protection of Personal Information Act, 2013 (POPIA).

2. What Personal Information We Collect

Learners

  • Full name, ID number, date of birth, gender, race, nationality, home language
  • Citizenship/residency status, socio-economic status, and disability status
  • Contact details (email, phone, physical and postal address)
  • Employment and learnership information (employer, contract dates, stipend)
  • Banking details (for stipend payments)
  • Educational records (attendance, competency assessments, PoE submissions, monthly workplace registers)
  • EISA and qualification records
  • Disciplinary records, including any evidence attached to them
  • POPI Act consent status and date

Bursary beneficiaries

Where we administer a bursary rather than a learnership, we process the beneficiary's name, ID number, date of birth, gender, race, and contact details; the institution, programme and year of study; and the value and dates of each bursary. We also store the supporting documents the bursary requires — a certified copy of the ID, bank confirmation letter, bank statement, proof of registration, confirmation of registration, the signed bursary agreement, proof of payment, and DHET registration certificates. A beneficiary may hold more than one bursary; the identity and banking documents are stored once against the person, while the remaining documents are stored per bursary.

Staff who use the system

  • Name, email address, role, and a securely hashed password
  • An optional profile photo. It is supplied by the staff member themselves, is visible only to colleagues signed in to this system, and can be removed at any time from the Staff page. It is never published, never shared outside the organisation, and is deleted with the account.

Records of activity in the system

  • Who signed in and what records they created, changed, deleted or exported
  • For an edit, the previous and the new value of each field that changed — which may itself contain personal information (for example, a corrected ID number or bank account)
  • The IP address the change was made from, and the date and time

3. Why We Collect This Information

  • To manage learner enrolment and progress on SETA learnerships
  • To administer bursaries and to account to the funding client for how the money was spent
  • To process stipend payments and payroll submissions
  • To report to SETAs, the QCTO and the DHET as required by law
  • To generate attendance registers and competency reports
  • To comply with ETQA and Skills Development Act requirements
  • To keep an audit trail, so that changes to a person's record can be traced to the staff member who made them — a requirement of SETA audits and a safeguard for the individuals concerned

4. Where Your Data is Stored

This system and all associated personal information are hosted on Microsoft Azure cloud infrastructure located within South Africa, in the South Africa North region (Johannesburg):

  • Application hosting — Azure Container Apps, South Africa North
  • Database — Azure Database for PostgreSQL, South Africa North
  • Uploaded documents (ID copies, certificates, supporting files) — Azure Blob Storage, South Africa North

Database backups are retained for 30 days and geo-replicated to the South Africa West region (Cape Town) for disaster recovery. Microsoft Azure operates under data processing agreements aligned with POPIA and international data protection standards.

5. Backups Sent by Email

So that we hold a copy of the records independently of the cloud platform, the system sends an automated weekly backup email to a nominated Voca Learning Solutions mailbox. You should be aware of what this involves:

  • A spreadsheet containing the system's data tables — including learner personal, contact and banking details — is attached to that email.
  • The email also contains a time-limited download link to a ZIP archive of every uploaded document. The link expires after 7 days, but for as long as it is valid anyone holding the link can download the archive without signing in.
  • The email is sent over an encrypted (STARTTLS) connection via Microsoft Office 365. Because mail is delivered through Microsoft's global mail infrastructure, we cannot guarantee that it is routed and stored only within South Africa.

The backup mailbox is treated as confidential and is accessible only to the Information Officer and authorised administrators. Backup emails and their links should not be forwarded.

6. Data Sharing

We do not sell your personal information, and we do not share it with third parties except:

  • With the relevant SETA, the QCTO or the DHET as required for learnership and bursary reporting
  • With your employer (host or client company) for training coordination
  • With the client funding your bursary, for reporting on how their allocation has been spent
  • With the educational institution at which you are registered, to confirm registration and to pay fees
  • With our payment processor (FNB/SimplePay) for stipend disbursement
  • With Microsoft, as the operator of the cloud and email infrastructure described above
  • As required by law or court order

7. Automated Reading of Documents

When an accreditation certificate is uploaded for an educational institution, the system may read the text of that document automatically in order to suggest the list of programmes it covers. This processing happens entirely within our own hosting environment — the document is not sent to any third-party or artificial-intelligence service — and the result is always reviewed and confirmed by a person before anything is saved. No decision affecting any individual is made by automated means.

8. Data Security

  • All data is transmitted over HTTPS (encrypted in transit)
  • Data is encrypted at rest on Microsoft Azure infrastructure
  • Access is restricted to authorised staff via individual, password-protected accounts
  • Passwords are stored only as a one-way cryptographic hash, never in readable form
  • Each staff member has a role that determines which parts of the system they may open. Learner records — including ID numbers and banking details — are visible to staff holding the Administrator or Learner Management role, who need them to enrol learners and pay stipends. Facilitators, assessors, moderators and client managers cannot open learner records.
  • A staff member holding the Backup Operator role cannot browse learner records in the system, but can download the full backup, which contains them. This role is granted only to the person responsible for safeguarding the data.
  • An audit log records every change made to a record, including who made it, when, from what IP address, and what the value was before and after
  • Sensitive actions (terminating or completing an enrolment) require a separate permission

9. Your Rights Under POPIA

You have the right to:

  • Request access to the personal information we hold about you
  • Request correction of inaccurate information
  • Object to the processing of your information in certain circumstances
  • Request deletion of your information where retention is no longer justified
  • Lodge a complaint with the Information Regulator of South Africa

Please note that where information is corrected, the audit log retains a record of the previous value, and where information is deleted, it may persist in backups until those backups expire (see Section 10). We keep these records because we are legally obliged to be able to demonstrate the integrity of learner records to a SETA auditor. They are not used for any other purpose.

10. Retention

  • Learner and bursary records — retained for a minimum of 5 years after the conclusion of a learnership or bursary, as required by the Skills Development Act and SETA audit requirements.
  • Banking details — deleted once no longer required for payment purposes.
  • Database backups — retained for 30 days, then automatically discarded.
  • Backup download links — expire 7 days after the email is sent.
  • The audit log — retained for the life of the system, as an audit trail is only meaningful if it cannot be pruned.

11. Changes to This Policy

We update this policy when the system changes in a way that affects how personal information is handled. The date at the top of this page shows when it was last revised.

12. Contact

For any privacy-related queries or to exercise your rights, please contact:
Information Officer — Voca Learning Solutions
Email: operations@amalgatraining.co.za

You may also lodge a complaint directly with the Information Regulator of South Africa at enquiries@inforegulator.org.za.