Privacy Policy
How Noetic Labs collects, uses, shares and protects personal data through Metlha — written plainly, and aligned with Botswana's Data Protection Act, 2024.
- Effective:
- 10 July 2026
- Last updated:
- 22 July 2026
1. Who we are
Metlha is operated by Noetic Labs (Pty) Ltd(“Noetic Labs”, “we”, “us”, “our”), a company registered in Botswana (registration number BW00009522091), with its registered office at Fairgrounds Mall, Unit G26, Stanbic Accelerate, Gaborone, Botswana. We are the data controller for the personal data described in this policy, except for the customer employee data we handle as a processor on our customers’ behalf (explained in Section 3).
For any question about this policy or your personal data, contact us at info@noeticlabs.africa or on WhatsApp at +267 73 461 650.
2. Who this policy applies to
This policy applies to:
- Visitors to our website, metlha.com.
- Customers and their staff who sign in to and use the Metlha app at app.metlha.com.
- Prospects who contact us or complete the free Compliance Check on our website.
It covers the marketing website and the Metlha application. It does not cover third-party services we link to, which have their own privacy policies.
3. The two roles we play (controller and processor)
Metlha handles two very different kinds of personal data, and the law treats our responsibility for each differently. It matters that you understand the split.
Data we control (we are the “data controller”)
This is data about our relationship with you as a customer or visitor: your account and login details, your billing information, your support messages, how you use the app, and prospect enquiries. We decide why and how this data is processed, so we are responsible for it, and this policy governs it in full.
Data we only process for you (we are the “data processor”)
When you use Metlha’s HR and Payroll features, you load in your own employees’ personal data — names, national identity (Omang) numbers, dates of birth, addresses, bank details, salaries, leave and related records. That data belongs to your business. You are the data controller for it; we are only the processor, handling it on your documented instructions so the service works. Your business is responsible for having a lawful basis to collect and use your employees’ data, and for telling your employees how their data is used. If one of your employees asks us about their data, we will direct them to you, their employer, as the controller.
4. What personal data we collect
Account and user data
- Your name, work email address, and profile photo if you add one.
- A secure identifier from our authentication provider (see Section 6). We never see or store your password.
- Your role and permissions, and your app preferences.
Billing data
- Your business name, the contact we invoice, your chosen plan and team size, and your payment records. Billing is by bank transfer (EFT) — we do not collect or store card numbers.
Prospect and enquiry data
- If you complete the Compliance Check or contact us, we collect your name, your WhatsApp number, your answers, and how you found us (including campaign tags in the link you clicked), so we can follow up and improve our marketing.
Usage and technical data
- Server logs — including your IP address, browser type, and the actions you take in the app — which we keep for security, troubleshooting, and to run the service.
Customer content, including employee HR & payroll data
This is the data you enter into Metlha to run your business. We process it for you as described in Section 3. It can include sensitive information, so we call it out honestly:
- Employee records — names, Omang numbers, dates of birth, gender, nationality, home addresses, contact details, job and employment history.
- Payroll and financial data — salaries, allowances, deductions, loans, court/garnishee orders, bank account details, tax and pension-fund numbers, payslips and EFT files.
- Leave and records — leave requests and balances, which can include reasons and attachments such as medical or maternity certificates, and so may reveal health information.
- Employment-process records — disciplinary, grievance, termination and related records, which can be sensitive and may name individuals.
- Projects, documents and meetings — any content you and your team type into projects, tasks, documents, comments and meeting notes.
5. Why we process it, and our lawful basis
Botswana’s Data Protection Act requires a lawful basis for every use of personal data. Ours are:
- To provide the service (performance of a contract). Running your account, processing your business’s data in the app, and giving you support.
- To bill you (contract and legal obligation). Issuing invoices, collecting payment, and keeping tax records the law requires.
- To keep the service secure and improve it (legitimate interests). Preventing abuse, fixing problems, and understanding how the product is used — balanced against your rights.
- To follow up on enquiries and market to you (consent or legitimate interests). Where you have contacted us or asked to hear from us. You can opt out at any time.
- For customer content, on your instructions. We process your employees’ data as your processor; your business is responsible for the lawful basis to use it.
6. Sign-in, passwords and where that data sits
Sign-in is handled by Metlha itself — we do not use a third-party identity provider. When you register or sign in, we process your email address, your name, and account metadata such as your last login time. Your password is cryptographically hashed (never stored in readable form, and never visible to our staff), and signing in issues a secure session token that expires and can be revoked.
All of this authentication data — your account record, the password hash, and your active sessions — lives in the same database as the rest of your business data, hosted in South Africa (see Section 8). Your sign-in information is not transferred to the United States or any other country outside the adequacy list.
7. Who we share data with
We do not sell your personal data. We share it only with the service providers (“sub-processors”) we rely on to run Metlha, and only as needed. Each is bound to protect it. Our key sub-processors are:
| Provider | What it does | Where |
|---|---|---|
| MongoDB Atlas (MongoDB, Inc.) | Primary database — stores your account and business records, including HR and payroll data. | Cape Town (AWS af-south-1), South Africa |
| Google Cloud Run (Google LLC) | Runs the Metlha application. This is stateless compute — it processes your requests but does not store your data at rest. | Johannesburg (africa-south1), South Africa |
| Google Cloud Storage (Google LLC) | Stores files you upload — attachments, payslip PDFs, and documents such as medical or maternity certificates. | Johannesburg (africa-south1), South Africa |
| Resend (Resend, Inc.) | Sends transactional and notification email (invites, billing notices, alerts). | Ireland (eu-west-1), European Union |
| Cloudflare, Inc. | Hosts and serves this marketing website (metlha.com), and provides privacy-friendly, cookieless visitor analytics across our website and app — it sets no cookies and collects no personal data. | Global content-delivery network |
| AI processing provider (Google Gemini or Anthropic Claude) | Generates meeting summaries and suggested action items from meeting and task content, when you use those features. | Outside Botswana |
We may also share data where the law requires it (for example, a valid court order or a lawful request from an authority), or to protect our rights, safety, or property. If we ever transfer the business, we will tell you before your data moves to a new owner.
Our staff. A small number of Noetic Labs staff can access customer data when it is genuinely needed to provide support, fix a problem, or run the platform. This access is limited to the people who need it and is used only for those purposes.
8. Sending data outside Botswana
Some of our providers store and process data outside Botswana. That is normal for cloud software, and the law allows it under safeguards. Here is where your data actually sits:
- Your main business data — your account, HR and payroll records — is stored in South Africa (MongoDB Atlas, Cape Town).
- Files you upload — attachments, payslips and certificates — are stored in South Africa (Google Cloud Storage, Johannesburg).
- Your sign-in / authentication data is stored in South Africa, alongside your business data (see Section 6).
- Our email is sent through a provider in Ireland (European Union).
South Africa and the European Union are among the countries the Information and Data Protection Commission of Botswana recognises as providing adequate protection. No personal data is processed in the United States. Where the law requires us to keep a copy of transferred data inside Botswana during processing, we will do so.
If you would like more detail on where a specific type of data is held, contact us at info@noeticlabs.africa.
9. How long we keep it
We keep personal data for as long as your account is active and you are a customer. After your account closes, we keep your data for up to 90 days so you can reactivate or export it, and then we delete it from our active systems, unless the law requires us to keep certain records (such as tax and invoicing records) for longer.
Please note two honest technical points. First, when you delete something in the app it is usually marked as deleted and hidden, and then removed on the schedule above rather than instantly erased. Second, residual copies may remain in our encrypted backups for a short period until those backups are overwritten in the normal cycle. If you need data permanently and immediately erased, contact us and we will action it as described in Section 10.
10. Your rights
Under Botswana’s Data Protection Act, you have the right to:
- Ask what personal data we hold about you and get a copy (access).
- Have inaccurate data corrected (rectification).
- Ask us to delete your data (cancellation/erasure), where the law allows.
- Object to certain processing, including direct marketing.
- Not be subject to a decision based solely on automated processing that significantly affects you.
To exercise any of these, email info@noeticlabs.africa. We will respond within the time the law requires. Please note: if the data is your employer’s employee record about you, we will pass your request to your employer, who is the controller of that data (see Section 3).
11. How we protect your data
We use appropriate technical and organisational measures, including:
- Encryption of data in transit (HTTPS) and at rest with our providers.
- Strict access controls and role-based permissions, so people only see what they should.
- Separation of each business’s data, so one customer cannot see another’s.
- Rate limiting and other protections against abuse.
- Regular backups of the database.
No system is perfectly secure, and we cannot guarantee absolute security. But we take protecting your data seriously, and because we are a local company you can always phone a real person about it.
12. If something goes wrong (data breaches)
If a data breach happens that is likely to put your rights at serious risk, we will act quickly. Where we act as processor for a customer’s data, we will notify that customer without undue delay so they can meet their own legal obligations. Where we are the controller, we will notify the Information and Data Protection Commission of Botswanaand, where required, the affected people, in line with the law’s timelines.
13. Complaints
If you are unhappy with how we handle your data, please contact us first at info@noeticlabs.africa — we would genuinely rather fix it directly. You also have the right to lodge a complaint with the Information and Data Protection Commission of Botswana.
14. Cookies and tracking
Both our marketing website (metlha.com) and the Metlha app (app.metlha.com) use Cloudflare Web Analytics, a privacy-friendly analytics tool, to understand how they are found and used so we can improve them. It does not set cookies, does not collect personal data, and does not track you across other websites. It counts visits and general, aggregated information such as the type of device and which pages are viewed.
Our marketing website (metlha.com) also keeps its own, first-party record of how visitors use the tools we build — for example, which steps of the 5-minute Compliance Check they reach — so we can see where a tool loses people and improve it. This uses a random, per-visit identifier stored in your browser’s session storage; it is not linked to your identity, sets no cookies, is not shared with any other company or website, and is cleared when you close the tab. The website remembers which link or campaign brought you (a “UTM” tag) in the same way.
The Metlha app (app.metlha.com) also uses browser storage that is strictly necessary to keep you signed in and to remember basic settings, such as which organisation you are viewing. This is separate from the analytics above, and it is not used to track you across other websites.
15. Children
Metlha is business software intended for use by adults. We do not knowingly collect personal data directly from children through the service. Where an employer records data about a young worker or an employee’s dependants as part of HR records, that data is handled under the employer’s responsibility as controller.
16. Changes to this policy
We may update this policy from time to time. When we make a significant change, we will update the date at the top and, where appropriate, let you know in the app or by email. The current version always lives at metlha.com/privacy.