POPIA & Data Protection Commitment
DeePay ("InvoiceFlow", "we", "us", or "our") is dedicated to safeguarding the personal and financial information entrusted to us by our users and their customers. We operate in full compliance with the Protection of Personal Information Act (POPIA) (Act 4 of 2013) of South Africa, ensuring lawful, transparent, and secure data processing across our platform.
1. Information We Collect
In providing cloud invoicing, quote generation, developer APIs, and payment integration services, we collect:
- Account Information: Your name, email address, company/workspace name, encrypted password hash, and member roles.
- Invoicing & Customer Data: Customer names, email addresses, billing addresses, phone numbers, tax IDs, invoice line items, banking details for payment instructions, and transaction totals.
- Developer & Technical Telemetry: SHA-256 hashed API keys, webhook delivery event logs, IP addresses, browser user-agents, and application error logs.
- Payment Records: Payment references, settlement timestamps, amounts, and transaction status callbacks from integrated gateways (e.g. Ozow).
2. Purpose of Data Processing
We process personal and financial information exclusively for lawful business purposes:
- Generating, delivering, and rendering PDF tax invoices and quotes.
- Providing client payment checkout portals and processing Ozow / EFT settlement status.
- Authenticating API requests and monitoring platform performance & telemetry.
- Sending transactional email notifications (e.g. invoice dispatched, payment received, password resets).
- Complying with South African Revenue Service (SARS) and statutory financial record retention requirements.
3. Data Security & Storage
We implement enterprise-grade technical and organizational security measures:
- Encryption in Transit: All web traffic, customer portals, and API calls are secured via 256-bit TLS/SSL encryption.
- Password Protection: Passwords are cryptographically hashed using industry-standard bcrypt with high work factors.
- API Key Protection: API keys are hashed and never stored in plain text after generation.
- Database Isolation: Multi-tenant workspace data is segmented with row-level workspace identifier scoping.
4. Third-Party Service Providers
We do not sell, rent, or trade personal information to third parties. We share data only with operators and infrastructure providers bound by strict confidentiality agreements:
- Payment Gateways: Ozow (for South African Instant EFT processing).
- Cloud & Database Hosting: Neon PostgreSQL (cloud database infrastructure) and cloud deployment providers.
- Transactional Email: SMTP dispatch servers for sending transactional invoice alerts and receipts.
5. Data Retention Period
We retain account and transaction records for the active duration of your workspace. In accordance with South African tax laws and SARS regulations, tax invoices and payment records are preserved for the statutory minimum of 5 years to ensure regulatory compliance for you and your clients.
6. Your Rights Under POPIA
As a data subject in South Africa, you have the right to:
- Request confirmation of whether we hold personal information about you.
- Request correction or deletion of inaccurate, irrelevant, or unlawful personal data.
- Object to the processing of your personal information on reasonable grounds.
- Lodge a complaint with the South African Information Regulator.
For privacy inquiries or to exercise your POPIA data rights, contact our Information Officer at privacy@deepay.dev