Back to home

Legal

GDPR Compliance

How Fresh Stock supports GDPR compliance for customers and individuals in the European Economic Area and United Kingdom.

Last updated: 22 September 2025

1. Overview

Fresh Stock (Pty) Ltd ("Fresh Stock") is committed to respecting the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR where applicable. This page explains our approach to GDPR compliance when we process personal data relating to individuals in the European Economic Area (EEA) and the United Kingdom.

Fresh Stock is a business-to-business inventory management platform. In most cases, our customers act as data controllers for personal data relating to their employees, suppliers, and other contacts, and Fresh Stock acts as a data processor when handling that data on the customer's instructions.

2. Our Role as Controller and Processor

2.1 When Fresh Stock is a controller

We act as a data controller for personal data we collect for our own purposes, such as:

  • Website visitor and marketing contact information.
  • Account administrator and billing contact details.
  • Customer support communications.
  • Security, fraud prevention, and platform analytics relating to our operations.

2.2 When Fresh Stock is a processor

We act as a data processor when we store and process personal data contained in Customer Data on behalf of a customer organisation, such as employee names, user accounts, supplier contacts, or operational records entered into the Service.

In those cases, the customer organisation determines the purposes and means of processing and is responsible for providing appropriate notices and obtaining any required consents or legal bases.

3. Lawful Bases for Processing

Where Fresh Stock acts as controller, we rely on one or more of the following lawful bases under GDPR:

  • Contract: processing necessary to provide the Service or respond to your requests.
  • Legitimate interests: operating, securing, and improving our platform, provided those interests are not overridden by your rights.
  • Consent: where required for optional marketing or non-essential cookies.
  • Legal obligation: where processing is necessary to comply with applicable law.

4. Your Data Subject Rights

If you are located in the EEA or UK, you may have the following rights under GDPR, subject to conditions and exceptions in the law:

  • Right of access: obtain confirmation of whether we process your personal data and receive a copy.
  • Right to rectification: request correction of inaccurate or incomplete personal data.
  • Right to erasure: request deletion of personal data in certain circumstances.
  • Right to restriction: request that we limit processing in certain circumstances.
  • Right to data portability: receive personal data you provided in a structured, commonly used, machine-readable format where applicable.
  • Right to object: object to processing based on legitimate interests or for direct marketing.
  • Rights related to automated decision-making: where applicable, request human review of decisions based solely on automated processing with legal or similarly significant effects.

To submit a request, email info@freshstock.co.za. We will respond within one month, unless an extension is permitted. We may need to verify your identity before fulfilling a request.

If your personal data is processed by Fresh Stock on behalf of your employer or another organisation, we may direct your request to that organisation as the data controller.

5. International Data Transfers

Fresh Stock is based in South Africa and may use service providers in South Africa and other countries. Where personal data is transferred from the EEA or UK to a country that has not received an adequacy decision, we implement appropriate safeguards such as Standard Contractual Clauses and supplementary measures where required.

Customers requiring a Data Processing Agreement (DPA) or information about transfer mechanisms may contact us using the details below.

6. Security Measures

We implement technical and organisational measures designed to protect personal data, including access controls, encryption in transit, tenant isolation, role-based permissions, logging, and secure cloud infrastructure. Further details are available in our Privacy Policy.

7. Subprocessors

We use carefully selected subprocessors to help deliver the Service. These may include cloud hosting, authentication, email delivery, payment processing, and AI service providers. We require subprocessors to implement appropriate security and confidentiality obligations.

Representative categories of subprocessors include:

  • Cloud infrastructure and database hosting providers.
  • Authentication and identity providers.
  • Email and notification services.
  • Payment processors.
  • AI and document processing providers used for optional features.

Enterprise customers may request additional information about subprocessors relevant to their account.

8. Personal Data Breach Notification

We maintain procedures to detect, investigate, and respond to suspected personal data breaches. Where Fresh Stock acts as processor, we will notify the affected customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide reasonable assistance so the customer can meet its notification obligations where required.

9. Data Processing Agreement

Business customers subject to GDPR who require contractual processor terms may request a Data Processing Agreement from Fresh Stock. The DPA describes processing scope, security obligations, subprocessors, assistance with data subject requests, and breach notification commitments.

To request a DPA, contact info@freshstock.co.za.

10. Supervisory Authority

You have the right to lodge a complaint with a supervisory authority in the EU member state or UK country where you live or work, or where the alleged infringement occurred. We encourage you to contact us first so we can try to resolve your concern.

11. POPIA and Other Laws

Fresh Stock is also subject to South Africa's Protection of Personal Information Act, 2013 (POPIA). Customers and individuals in South Africa may have rights under POPIA in addition to, or instead of, GDPR rights depending on circumstances. Our Privacy Policy describes our broader privacy practices across jurisdictions.

12. Contact

For GDPR-related enquiries, data subject requests, or DPA requests, contact:

  • Fresh Stock — Data Protection Contact
  • Email: info@freshstock.co.za
  • Phone: +27 82 458 5816
  • Address: Ballito, KwaZulu-Natal, South Africa