The JET Intranet is an internal staff portal for JET Education Services. It holds a small amount of personal information about every member of staff so that the directory, the notice board and the calendar work. This notice explains what is held, where it comes from, who can see it and how long it is kept, as required by the Protection of Personal Information Act, 2013 (POPIA).
The intranet never holds your year of birth, your identity number, your home address or your bank details. If you choose to share your birthday it is stored as a day and a month only, and even that can be switched off.
Who is responsible
JET Education Services is the responsible party for this information. Questions, corrections and complaints go to JET's Information Officer, or to the ICT Manager for anything technical. Both can be reached through the staff directory on the intranet itself.
What is held, and where it comes from
| Information | Where it comes from | Why |
|---|---|---|
| Name, work email address, profile photograph, whether your account is active | Your JET Google Workspace account, read automatically | To identify you, to sign you in, and to list you in the staff directory |
| Job title and department | Maintained by HR inside the intranet | To group the directory and to colour your avatar |
| Preferred name, mobile number, telephone extension | You, on your own profile page. All optional | So colleagues can reach you and the dashboard greets you properly |
| Birthday — day and month only | You, on your own profile page. Optional | The birthday widget on the dashboard |
| Notices you have opened, comments you post, application shortcuts you pin | Created as you use the portal | The unread badge, the discussion under a notice, and your own dashboard tiles |
| Today's entries from your own Google Calendar | Read from Google when you open the dashboard, and never stored | The "My Day" card. Only ever your own diary, never a colleague's |
| A record of administrative changes — who changed what, and when | Created automatically when an administrator acts | So that a change to a role, a profile or a notice can be accounted for |
| Sign-in times and the address you signed in from | Recorded at sign-in | Security. It is how unauthorised access would be noticed |
Much of this already exists in JET's Google Workspace, which the organisation uses for email and calendars. The intranet reads from it rather than keeping a second copy that would slowly go out of date.
On what basis
The intranet is part of running the organisation: an internal directory, announcements and a shared calendar are ordinary tools of employment. The information above is processed because it is necessary for JET's legitimate interests as your employer and for the performance of your employment contract. The two optional items — your birthday and whether it is displayed — are processed with your consent, which you give by filling them in and withdraw by clearing them.
Who can see it
Only JET staff who are signed in. There is no public page: every page, every interface and every uploaded file requires a JET account, and a request without one is refused rather than answered. Nothing on the intranet is shared with advertisers or sold, and there is no analytics or tracking of any kind.
Google processes the information JET already keeps in Google Workspace, under JET's existing agreement with them, which involves storage outside South Africa. The intranet adds no new third party to that arrangement.
Administrative access is limited by role. HR administrators can edit staff records, editors can publish notices, and system administrators can change roles and read the audit log. Nobody, of any role, can read another person's calendar through the intranet.
How long it is kept
- Your staff record — for the duration of your employment. When you leave, your account is deactivated rather than deleted: you disappear from the directory, the birthday widget and the colleague list immediately, and the record is kept for a further seven years to match JET's employment record retention, then removed.
- Notices and comments you wrote — kept, and still attributed to you. Removing them would leave replies answering nobody. A comment you delete yourself stops being visible to anyone immediately.
- The audit log — twenty-four months, which is long enough to investigate something noticed late and short enough that it does not become an archive in its own right.
- Sign-in records — twelve months.
- Your profile photograph — until you replace or remove it. It is deleted from the server when you remove it, not merely hidden.
- Calendar entries — never stored. They are read from Google when a page is opened, held in memory for two to three minutes so the page is not slow, and then gone.
Your rights, and how to use them
- See and correct what is held. Your profile page shows it and lets you edit the parts that are yours to edit. Your name, email address and photograph come from Google Workspace; ask ICT to change those. Your job title and department are maintained by HR.
- Keep your birthday to yourself. Leave it blank, or fill it in and switch off Show my birthday on your profile. With it off, no colleague sees it anywhere on the portal.
- Object, or ask for information to be deleted. Speak to the Information Officer. Some of it JET is obliged to keep as an employment record, and you will be told which.
- Complain. To the Information Officer first. If that does not resolve matters you may complain to the Information Regulator (South Africa) at inforegulator.org.za.
Cookies
Two, both necessary and neither used for tracking. One keeps you signed in and is cleared when you sign out. The other carries a security token that proves a request came from a page you were actually looking at. There are no analytics, advertising or third-party cookies.
How it is protected
Sign-in is through your JET Google account, so the intranet never sees or stores a password. Everything is behind that sign-in, including uploaded photographs and documents, which are stored outside the public web folder and released only to a signed-in request. Administrative changes are recorded. Server logs are written with email addresses, dates of birth and security tokens stripped out.