Privacy Policy
Version 2026-04-22. In force from 22 April 2026.
1. Who we are
This policy is published by Appventure (Pty) Ltd("Appventure", "we", "our"), registered in South Africa. We are the responsible party in terms of the Protection of Personal Information Act, 2013 ("POPIA") for all personal information we process through the Appventure One application.
2. Information we collect
We collect only what we need to deliver the service:
- Identity: name, email, SA ID number (optional, for age-based tax rebates).
- Entity information: company name, registration number, tax number, VAT number.
- Financial: bank statements you upload, transactions, invoices, fixed-asset records.
- Employment (if you use payroll): employee names, ID numbers, tax numbers, dates of birth, salary data. Encrypted at rest.
- Documents: files you upload (payslips, IRP5s, invoices).
- Behavioural: IP address, browser type, and audit log entries for your actions in the app.
3. Why we collect it (purpose)
We process personal information to provide the Appventure One service: parse your bank statements, classify transactions, generate management reports and tax returns, track compliance deadlines, and bill your subscription. We do not use your personal information for any other purpose without your further consent.
4. Lawful basis
We rely on the following lawful bases per POPIA s11:
- Contract — most processing is necessary to deliver the service you subscribed to.
- Law — tax and compliance records are processed pursuant to the Tax Administration Act, Companies Act, and related legislation.
- Legitimate interest — security logs (IP, user-agent) are processed to protect the platform and detect fraud.
- Consent — explicit, revocable consent is required for cross-border transfer to Anthropic (Claude API) for AI classification.
5. Who we share with
We share personal information only with the processors listed below, under written data-processing agreements:
| Processor | Purpose | Location |
|---|---|---|
| Anthropic (Claude API) | AI classification of bank transaction descriptions | USA (GDPR SCCs) |
| Paystack | Subscription billing and payments | South Africa |
| Neon | Database hosting | South Africa (primary) + Ireland (standby) |
| Resend | Transactional email delivery | USA (GDPR SCCs) |
| Upstash | Rate limiting + AI cost tracking (no PII) | Ireland |
| Vercel | Application hosting | Global edge |
| Sentry | Error monitoring (with aggressive PII scrubbing) | Germany |
| Cloudflare | DNS + CDN + DDoS mitigation | Global edge |
| AWS S3 | Document storage | South Africa (primary) + Ireland (replica) |
We do not sell personal information. We do not use personal information for targeted advertising.
6. Cross-border transfers
Some of our processors are located outside South Africa. Where the destination is not deemed "adequate" by the Information Regulator, we rely on the processor's Standard Contractual Clauses (SCCs) and, for Claude API classification specifically, your explicit consent recorded at onboarding. You may revoke cross-border consent at any time in your privacy settings; classification will fall back to keyword rules.
7. Retention
We retain information only as long as needed:
- SARS notices, assessments, and correspondence: 5 year(s) from date of the communication. Basis: Tax Administration Act s29 (5 years).
- Bank statements + parsed bank transactions: 7 year(s) from statement date. Basis: Companies Act s24 (7 years).
- Identity + address verification data: 5 year(s) from account closure date. Basis: FICA s42 (5 years after termination) — applied conservatively.
- System audit trail: 7 year(s) from entry creation date. Basis: POPIA + Companies Act s24 — 7 years.
- Paystack charge events + subscription history: 7 year(s) from event creation date. Basis: VAT Act + Companies Act — 7 years.
- Claude API classification cache + cost ledger: 0 year(s) from last access (entity soft-delete or ledger flush). Basis: Operational retention — minimise per POPIA Condition 5.
- User-uploaded documents (payslips, IRP5s, invoices): 7 year(s) from upload date (for supporting records). Basis: Companies Act s24 / Tax Admin Act — 7 years.
8. Your rights (POPIA Condition 8)
- Access — request a copy of all personal information we hold about you.
- Correction — request correction of inaccurate information.
- Deletion — request deletion of your personal information (subject to legal retention requirements for tax and financial records).
- Objection to AI processing — switch off Claude API classification; the classifier falls back to keyword rules.
- Complaint — lodge a complaint with the Information Regulator (inforegulator.org.za).
Exercise these rights in Settings → Privacy, or by emailing privacy@appventure.tech. We respond within 30 days per POPIA s23.
9. Security
We apply technical and organisational measures of a standard appropriate to the risk: row-level tenant isolation, AES-256-GCM encryption of PII at rest, TLS in transit, AES-256-GCM envelope encryption on data exports, HMAC-signed audit chains, principle-of-least-privilege access for all staff, penetration testing, and an incident response runbook aligned with POPIA s22 notification obligations.
10. Information Officer
Josh van Buuren Information Officer privacy@appventure.tech Appventure (Pty) Ltd, Cape Town, Western Cape, South Africa
11. Changes
We revise this policy as our processing evolves. Material changes trigger a notification email + in-app banner for at least 30 days, and may require fresh consent before you continue using the service.