How M2North collects, uses and protects personal information in South Africa and the United Kingdom.
Last updated: 24 September 2026
This policy explains how M2North collects, uses, shares and protects personal information when you use our website, www.m2north.com, and the M2North platform, platform.m2north.com (together, the "Services"). M2North is the trading name of two companies: IRJ Software (Pty) Ltd in South Africa and IRJ.IO LTD in the United Kingdom ("M2North", "we", "us").
We process personal information in line with the Protection of Personal Information Act 4 of 2013 ("POPIA") in South Africa, and the UK General Data Protection Regulation and the Data Protection Act 2018 (together, "UK data protection law") in the United Kingdom. Section 12 sets out what applies specifically if you are in the United Kingdom.
| Responsible party | IRJ Software (Pty) Ltd, trading as M2North |
|---|---|
| Registration number | 2025/303685/07 |
| VAT number | 4210183820 |
| Physical address | Unit 4, 8 Osborne Lane, Bedfordview Ext 447, 2008, South Africa |
| Postal address | PostNet Suite 423, Private Bag X19, Gardenview, 2047, South Africa |
| Telephone | +27 11 856 2000 |
| Information Officer | Brett Misselhorn |
| Controller | IRJ.IO LTD, trading as M2North |
|---|---|
| Company number | 09896416 (registered in England and Wales) |
| VAT number | GB230390835 |
| Registered office | 203 West Street, Fareham, Hampshire, PO16 0EN, United Kingdom |
| Telephone | +44 20 3322 3849 |
For any privacy question or request, in either country, email support@m2north.com.
M2North is a business-to-business network. Most of the information we handle is about companies. It becomes personal information where it identifies a person, such as a contact person, director, signatory or platform user.
Mostly from you or from your organisation. We also collect information from:
| Purpose | Lawful basis |
|---|---|
| Providing the Services and managing accounts | Performing our contract with you or your organisation |
| Verifying companies, directors and bank details, and assessing trading and credit risk | Our legitimate interests, and those of network members, in preventing fraud and trading safely; consent where the law requires it, for example for certain credit enquiries |
| Processing transaction documents, including automated extraction and matching | Performing the contract |
| Answering enquiries and preparing a business analysis you asked for | Taking steps at your request, and our legitimate interest in responding |
| Sending the Trust Update newsletter and product news | Your consent, which you can withdraw at any time, or, for existing customers, our legitimate interest in telling them about similar services |
| Measuring and improving the website and our adverts | Your consent where the law requires it (see section 9); otherwise our legitimate interests |
| Security, audit, and meeting legal and regulatory obligations | Legal obligation and legitimate interests |
We use information only for these purposes, or for a purpose compatible with them.
Automated processing. Invoices and trade documents are read and matched automatically, for example to extract VAT numbers, dates and PO references and to detect duplicate invoices. Trust levels and risk indicators are calculated from verification results. They describe companies, and we do not make decisions that have legal or similarly significant effects on a person based solely on automated processing. If you are affected by a trust level or risk indicator, you can ask for it to be reviewed by a person.
Parts of a company's profile are shown publicly on the website and in the supplier directory. These include:
Contact people, phone numbers, email addresses, physical addresses, compliance documents and banking details are not public. Only signed-in platform users with the necessary permissions can see them.
We do not sell personal information. We share it only:
M2North works across South Africa and the United Kingdom, so personal information passes between the two. Some of our operators also store or process information in other countries, including the European Union and the United States.
From South Africa, we transfer personal information across borders only in line with section 72 of POPIA: the recipient must be bound by law, binding corporate rules or an agreement that protects the information to a standard comparable to POPIA, or you must have consented, or the transfer must be needed to perform a contract with you.
From the United Kingdom, we transfer personal information only where UK data protection law allows it: to a country the UK recognises as providing adequate protection, or under safeguards approved for the purpose, such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Transfers between IRJ.IO LTD and IRJ Software (Pty) Ltd are covered by such an agreement. You can ask us for a copy of the safeguards that apply.
We keep personal information only as long as we need it for the purposes above, or as long as the law requires. In particular:
After that, we delete the information or de-identify it.
M2North's information security management system is certified to ISO/IEC 27001:2022 (certificate ZA10649E). In 2026 we achieved a CyberVadis Silver rating. Our measures include:
If we have reasonable grounds to believe your personal information has been compromised, we will notify you and the regulator as the law requires: the Information Regulator under section 22 of POPIA, and the Information Commissioner's Office under UK data protection law.
Our website uses:
| Cookie | Set by | Purpose | Type |
|---|---|---|---|
m2north-session, XSRF-TOKEN | M2North | Keep your session working and protect forms against forgery. Expire after 2 hours. | Essential |
__cf_bm, _cfuvid | Cloudflare, our hosting network | Bot protection and traffic management | Essential |
| A load-balancing cookie | Laravel Cloud, our hosting provider | Routing your requests to the right server | Essential |
m2n_business_analysis | M2North | Lets you return to an unfinished business analysis in the same browser. Kept for up to 90 days. | Essential |
_ga, _ga_* | Google Analytics | Shows us how the website is used. We configure it not to receive form contents, email addresses or phone numbers. | Analytics |
LinkedIn cookies (e.g. li_fat_id, bcookie, lidc) | LinkedIn Insight Tag | Tell us whether our LinkedIn adverts lead to enquiries | Advertising |
Visitors from the United Kingdom, the European Economic Area and Switzerland are asked first. Analytics and advertising cookies are set only after they accept, and they can change their choice at any time using "Cookie settings" at the foot of every page.
For visitors from elsewhere, including South Africa, analytics and advertising cookies are set when the page loads, as described above. You can block or delete them in your browser settings at any time; the site still works without the non-essential ones.
We send marketing email, such as the Trust Update newsletter, only if you have opted in or you are an existing customer. Every message has an unsubscribe link. You can also email support@m2north.com to opt out.
Under POPIA you may:
Send requests to our Information Officer at support@m2north.com. We may need to verify your identity first. Requests for records may also be made under our PAIA manual.
Information Regulator (South Africa): www.inforegulator.org.za, enquiries@inforegulator.org.za, Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191.
Who is responsible. IRJ.IO LTD is the controller of personal information about UK customers and prospects, including anyone who completes a business analysis for a company registered in the United Kingdom. For other UK visitors to our website, IRJ Software (Pty) Ltd is the controller and IRJ.IO LTD acts as its representative in the United Kingdom, under Article 27 of the UK GDPR. You can contact either company through support@m2north.com, or write to IRJ.IO LTD at its registered office.
Lawful bases. The bases in section 3 are the lawful bases we rely on under Article 6 of the UK GDPR. Where we rely on legitimate interests, we have weighed them against your rights, and you can ask us for details.
Your rights. Under UK data protection law you have the right to:
Email support@m2north.com to use any of these rights. There is normally no fee, and we will respond within one month. We may need to verify your identity first.
Complaints. We would like the chance to put things right first, but you have the right to complain to the Information Commissioner's Office: ico.org.uk, 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
The Services are for businesses, and are not intended for or directed at anyone under 18.
We may update this policy from time to time. The current version is always on this page, with its date. Where a change materially affects you, we will let you know.