01
Scope and our role
This policy explains how autofinn processes personal information under South Africa’s Protection of Personal Information Act, 4 of 2013 (“POPIA”).
autofinn is the responsible party for information used to register, activate, bill, secure and support autofinn accounts. For personal information about a tenant’s customers, directors, team members and contacts entered into the workspace, the tenant generally determines why that information is processed and autofinn acts as its operator.
02
Information we collect
- Account information: names, email addresses, password hashes, roles, authentication and security records.
- Business registration information: business type, legal and trading names, registration and VAT numbers, contact details, addresses, ownership information and supporting documents such as identity, registration, address and banking evidence.
- Workspace information: customers, products, quotations, approvals, invoices, branding, banking details, team invitations, files and activity history.
- Payment information: subscription plan, status, amounts, payment references, Paystack customer, subscription and subaccount codes, settlement-related metadata and transaction status. autofinn does not store complete card details.
- Communications: contact enquiries, support tickets, replies and email-delivery events.
- Technical information: session identifiers, request data, IP address and device or browser information where needed for security, approvals, diagnostics and fraud prevention.
03
Where information comes from
We obtain information directly from applicants, account holders, team members and users; from businesses that enter their customer or staff information; from customer interactions with public quotations, invoices and payments; and from service providers such as Paystack, email providers, hosting services and security tools.
04
Why we process information
- register, review, activate and administer business accounts;
- provide quotations, invoices, document storage, payment records, branding, team access and support;
- process and verify subscriptions and customer payments;
- authenticate users, enforce tenant separation, prevent fraud and protect the platform;
- send requested service communications and maintain audit records;
- diagnose faults, improve performance and develop useful features;
- meet tax, accounting, regulatory, legal and dispute-resolution obligations; and
- establish, exercise or defend legal rights.
05
Lawful processing
Depending on the context, processing is necessary to perform our agreement with you, comply with law, protect a legitimate interest of autofinn or another person, or is based on consent. Where consent is required, it may be withdrawn, but withdrawal does not invalidate earlier lawful processing or information we must retain by law.
07
Cross-border processing
Some infrastructure or service providers may process information outside South Africa. Where POPIA applies, we use providers, contractual commitments and safeguards intended to provide an appropriate level of protection and limit processing to the service purpose.
08
Security
autofinn uses measures designed to protect information against loss, unauthorised access, alteration or disclosure. These include authentication, password hashing, tenant-scoped database access, private object storage, time-limited or session-protected document access, audit records and encrypted transport.
No online service can guarantee absolute security. Users must protect their credentials, restrict team permissions and report suspected compromise promptly.
09
Retention and deletion
We keep information only for as long as reasonably required to provide the service, maintain legitimate business and security records, resolve disputes and comply with legal, tax, payment and regulatory duties. Retention periods vary by record type. Information may remain in protected backups for a limited period after deletion and may be retained where law or a legal claim requires it.
10
Your POPIA rights
Subject to applicable law, you may ask whether we hold your personal information and request access, correction or deletion; object to certain processing; withdraw consent where processing relies on consent; or complain about our handling of information. We may need to verify identity before acting on a request.
Submit a request through the contact page or authenticated support portal. If the information belongs to a tenant’s customer record, we may refer the request to that tenant as the responsible party.
12
Children
autofinn is a business service and is not directed at children. Do not submit children’s personal information unless it is lawful, necessary for a legitimate business purpose and handled with the permissions and protections required by law.
13
Tenant privacy responsibilities
Each business using autofinn is responsible for its own privacy notices, lawful collection of customer and team information, responding to data-subject requests, configuring appropriate access and avoiding unnecessary or excessive information in documents, notes and support messages.
14
Questions, requests and complaints
Privacy questions and requests may be submitted through the autofinn contact page. Existing customers should use authenticated support so we can verify the relevant account.
You may also lodge a POPIA complaint with the South African Information Regulator through its complaints service or contact POPIAComplaints@inforegulator.org.za.
15
Policy updates
We may update this policy when the service, providers or legal requirements change. The effective date will be revised and material changes will be communicated where reasonably practical.