Privacy Policy

How M2North collects, uses and protects personal information in South Africa and the United Kingdom.

Privacy Policy

Last updated: 24 September 2026

This policy explains how M2North collects, uses, shares and protects personal information when you use our website, www.m2north.com, and the M2North platform, platform.m2north.com (together, the "Services"). M2North is the trading name of two companies: IRJ Software (Pty) Ltd in South Africa and IRJ.IO LTD in the United Kingdom ("M2North", "we", "us").

We process personal information in line with the Protection of Personal Information Act 4 of 2013 ("POPIA") in South Africa, and the UK General Data Protection Regulation and the Data Protection Act 2018 (together, "UK data protection law") in the United Kingdom. Section 12 sets out what applies specifically if you are in the United Kingdom.

1. Who we are

South Africa

Responsible partyIRJ Software (Pty) Ltd, trading as M2North
Registration number2025/303685/07
VAT number4210183820
Physical addressUnit 4, 8 Osborne Lane, Bedfordview Ext 447, 2008, South Africa
Postal addressPostNet Suite 423, Private Bag X19, Gardenview, 2047, South Africa
Telephone+27 11 856 2000
Information OfficerBrett Misselhorn

United Kingdom

ControllerIRJ.IO LTD, trading as M2North
Company number09896416 (registered in England and Wales)
VAT numberGB230390835
Registered office203 West Street, Fareham, Hampshire, PO16 0EN, United Kingdom
Telephone+44 20 3322 3849

For any privacy question or request, in either country, email support@m2north.com.

2. What personal information we collect

M2North is a business-to-business network. Most of the information we handle is about companies. It becomes personal information where it identifies a person, such as a contact person, director, signatory or platform user.

2.1 When you use our website

  • Contact form: your name, email address, company name and phone number (both optional), the department you chose, your message, and whether you asked to receive our newsletter.
  • Free business analysis: your name, work email, job title and phone number; your company's registered name, country, registration number and address; your acceptance of our non-disclosure agreement (with the date, time, IP address and browser recorded as evidence); and your answers about your company's processes.
  • Meeting bookings: your name, email address and any details you enter when booking a call through our Google Calendar booking page.
  • Usage information: pages visited, links clicked, approximate location, device and browser type, and the website or advert that referred you, collected through cookies and similar technologies (see section 9).

2.2 When you use the M2North platform

  • Account information: name, email address, phone number, job title, role and permissions, login details, and activity logs (including which user approved or changed what, and when).
  • Company and verification information: company registration details, directors, VAT registration, B-BBEE certificates, tax clearance, insurance certificates, bank confirmation letters or statements, and bank account holder details.
  • Screening and risk information: results of company and director verification, sanctions screening and ongoing sanctions monitoring. For certain trust levels this also includes anti-money-laundering (AML), politically exposed person (PEP) and adverse media checks, commercial credit reports, and trading history.
  • Transaction documents: purchase orders, invoices, delivery documents and similar trade documents exchanged between buyers and suppliers. These may contain names and contact details of the people involved.
  • Profile content: information suppliers publish about themselves, such as catalogues, certifications, case studies, and reviews and ratings.

2.3 Where we get it

Mostly from you or from your organisation. We also collect information from:

  • public and official registries, such as the Companies and Intellectual Property Commission (CIPC) in South Africa and Companies House in the United Kingdom;
  • sanctions and watch-list sources;
  • verification, credit and risk data providers, such as credit bureaus and bank account verification services;
  • the other party to a transaction on the platform, for example a buyer sending a purchase order to a supplier.

3. Why we use it

PurposeLawful basis
Providing the Services and managing accountsPerforming our contract with you or your organisation
Verifying companies, directors and bank details, and assessing trading and credit riskOur legitimate interests, and those of network members, in preventing fraud and trading safely; consent where the law requires it, for example for certain credit enquiries
Processing transaction documents, including automated extraction and matchingPerforming the contract
Answering enquiries and preparing a business analysis you asked forTaking steps at your request, and our legitimate interest in responding
Sending the Trust Update newsletter and product newsYour consent, which you can withdraw at any time, or, for existing customers, our legitimate interest in telling them about similar services
Measuring and improving the website and our advertsYour consent where the law requires it (see section 9); otherwise our legitimate interests
Security, audit, and meeting legal and regulatory obligationsLegal obligation and legitimate interests

We use information only for these purposes, or for a purpose compatible with them.

Automated processing. Invoices and trade documents are read and matched automatically, for example to extract VAT numbers, dates and PO references and to detect duplicate invoices. Trust levels and risk indicators are calculated from verification results. They describe companies, and we do not make decisions that have legal or similarly significant effects on a person based solely on automated processing. If you are affected by a trust level or risk indicator, you can ask for it to be reviewed by a person.

4. What we make public

Parts of a company's profile are shown publicly on the website and in the supplier directory. These include:

  • business name, description and logo;
  • whether it buys or sells;
  • trust and verification badges;
  • industries, and B-BBEE level;
  • links, and related (parent or child) companies;
  • approximate map location.

Contact people, phone numbers, email addresses, physical addresses, compliance documents and banking details are not public. Only signed-in platform users with the necessary permissions can see them.

5. Who we share it with

We do not sell personal information. We share it only:

  • between IRJ Software (Pty) Ltd and IRJ.IO LTD, which together run the Services;
  • with other network members, as the Services require. For example, a buyer sees a supplier's verification status and the documents exchanged with that supplier;
  • with operators and processors who work for us, under written agreements that require them to keep it secure and confidential. They provide:
    • cloud hosting and infrastructure (Amazon Web Services, Laravel Cloud and Cloudflare);
    • email and customer messaging (Loops, and Mailchimp for the newsletter);
    • website analytics and advertising measurement (Google Analytics and the LinkedIn Insight Tag);
    • maps and fonts (Google);
    • application monitoring (Laravel Nightwatch);
    • meeting scheduling (Google Calendar);
    • company verification, sanctions screening and credit information;
    • document reading and data extraction;
  • with professional advisers, auditors, regulators, courts or law enforcement, where the law requires it or it is necessary to protect our rights.

6. Sending information to other countries

M2North works across South Africa and the United Kingdom, so personal information passes between the two. Some of our operators also store or process information in other countries, including the European Union and the United States.

From South Africa, we transfer personal information across borders only in line with section 72 of POPIA: the recipient must be bound by law, binding corporate rules or an agreement that protects the information to a standard comparable to POPIA, or you must have consented, or the transfer must be needed to perform a contract with you.

From the United Kingdom, we transfer personal information only where UK data protection law allows it: to a country the UK recognises as providing adequate protection, or under safeguards approved for the purpose, such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Transfers between IRJ.IO LTD and IRJ Software (Pty) Ltd are covered by such an agreement. You can ask us for a copy of the safeguards that apply.

7. How long we keep it

We keep personal information only as long as we need it for the purposes above, or as long as the law requires. In particular:

  • Unfinished business analyses are deleted automatically 90 days after they were last used. Submitted analyses, and the non-disclosure agreement recorded with them, are kept for three years after our last contact with you about them, in line with the agreement's confidentiality period.
  • Contact form enquiries are kept for three years after our last contact with you, unless you ask us to delete them sooner.
  • Newsletter records are kept until you unsubscribe. We then keep only a record that you unsubscribed, so we do not email you again.
  • Platform account, verification and transaction records are kept for as long as the account is active, and then for six years for tax, audit and legal purposes.
  • Security and audit logs are kept for up to 12 months, unless they are needed to investigate an incident.

After that, we delete the information or de-identify it.

8. How we protect it

M2North's information security management system is certified to ISO/IEC 27001:2022 (certificate ZA10649E). In 2026 we achieved a CyberVadis Silver rating. Our measures include:

  • encryption in transit and at rest;
  • role-based access controls;
  • activity logging;
  • additional encryption of especially sensitive records, such as business analysis answers.

If we have reasonable grounds to believe your personal information has been compromised, we will notify you and the regulator as the law requires: the Information Regulator under section 22 of POPIA, and the Information Commissioner's Office under UK data protection law.

9. Cookies and similar technologies

Our website uses:

CookieSet byPurposeType
m2north-session, XSRF-TOKENM2NorthKeep your session working and protect forms against forgery. Expire after 2 hours.Essential
__cf_bm, _cfuvidCloudflare, our hosting networkBot protection and traffic managementEssential
A load-balancing cookieLaravel Cloud, our hosting providerRouting your requests to the right serverEssential
m2n_business_analysisM2NorthLets you return to an unfinished business analysis in the same browser. Kept for up to 90 days.Essential
_ga, _ga_*Google AnalyticsShows us how the website is used. We configure it not to receive form contents, email addresses or phone numbers.Analytics
LinkedIn cookies (e.g. li_fat_id, bcookie, lidc)LinkedIn Insight TagTell us whether our LinkedIn adverts lead to enquiriesAdvertising

Visitors from the United Kingdom, the European Economic Area and Switzerland are asked first. Analytics and advertising cookies are set only after they accept, and they can change their choice at any time using "Cookie settings" at the foot of every page.

For visitors from elsewhere, including South Africa, analytics and advertising cookies are set when the page loads, as described above. You can block or delete them in your browser settings at any time; the site still works without the non-essential ones.

10. Direct marketing

We send marketing email, such as the Trust Update newsletter, only if you have opted in or you are an existing customer. Every message has an unsubscribe link. You can also email support@m2north.com to opt out.

11. Your rights in South Africa

Under POPIA you may:

  • ask whether we hold personal information about you, and request a copy;
  • ask us to correct, update or delete it;
  • object to processing on reasonable grounds, and object to direct marketing at any time;
  • withdraw consent you have given (this does not affect processing that already took place);
  • complain to the Information Regulator.

Send requests to our Information Officer at support@m2north.com. We may need to verify your identity first. Requests for records may also be made under our PAIA manual.

Information Regulator (South Africa): www.inforegulator.org.za, enquiries@inforegulator.org.za, Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191.

12. If you are in the United Kingdom

Who is responsible. IRJ.IO LTD is the controller of personal information about UK customers and prospects, including anyone who completes a business analysis for a company registered in the United Kingdom. For other UK visitors to our website, IRJ Software (Pty) Ltd is the controller and IRJ.IO LTD acts as its representative in the United Kingdom, under Article 27 of the UK GDPR. You can contact either company through support@m2north.com, or write to IRJ.IO LTD at its registered office.

Lawful bases. The bases in section 3 are the lawful bases we rely on under Article 6 of the UK GDPR. Where we rely on legitimate interests, we have weighed them against your rights, and you can ask us for details.

Your rights. Under UK data protection law you have the right to:

  • be informed about how we use your personal information;
  • access it, and receive a copy;
  • have it corrected if it is wrong or incomplete;
  • have it erased, in some circumstances;
  • restrict how we use it, in some circumstances;
  • receive it in a portable format, where we process it by automated means on the basis of consent or a contract;
  • object to processing based on legitimate interests, and object to direct marketing at any time;
  • not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you;
  • withdraw consent at any time, where we rely on it.

Email support@m2north.com to use any of these rights. There is normally no fee, and we will respond within one month. We may need to verify your identity first.

Complaints. We would like the chance to put things right first, but you have the right to complain to the Information Commissioner's Office: ico.org.uk, 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

13. Children

The Services are for businesses, and are not intended for or directed at anyone under 18.

14. Changes to this policy

We may update this policy from time to time. The current version is always on this page, with its date. Where a change materially affects you, we will let you know.