Privacy

Purpose, minimisation, provenance, redress.

Privacy at PONALO is a set of enforced behaviours, described here in the same language the product uses.

Plain language

How we handle information.

What PONALO holds

A verified identity record, the relationships associated with it, the provenance and status of each relationship, the consents that permit access, the authority records that evidence someone acting for another, and the event history of everything that happened.

What PONALO does not do

PONALO does not copy institutional databases wholesale, does not sell personal information, does not build advertising profiles, and does not permit population-level queries by any party, including government.

Purpose limitation

Every access is bound to a stated purpose. A consent granted for one purpose does not authorise another. Purposes are recorded, versioned and visible to the person in their Passport.

Minimisation

Each participant receives the least information necessary. An institution party to one relationship does not receive the person's wider relationship map.

Your rights

You can review what is held, challenge anything that is wrong, withdraw a consent, see every access that has occurred, and export the record. A challenge opens a case with a tracked lifecycle rather than disappearing into an inbox.

Retention

Relationship records and their event history are retained for as long as they are lawfully required, then removed. Withdrawal of consent stops future access immediately; the audit record of past access is retained because removing it would defeat accountability.

Jurisdiction

Privacy rules, residency requirements and redress paths are carried by the Country Pack for the jurisdiction concerned. South Africa is Country Pack #1.

This environment

This is a demonstration environment. Every person, institution, relationship and document shown is fictional sandbox data created for illustration, and no real institutional integration is implied.