Questions? Talk to us: 💬 WhatsApp 079 199 6369 ✉️ accountants@booksxperts.co.za 📞 087 012 6784

Privacy Policy

Effective date: 17 July 2026 — POPIA §1 & §71 Compliance

1. INTRODUCTION

This Privacy Policy outlines how THE ACCOUNTANTS, operated by Books Xperts (Pty) Ltd, collects, uses, stores, and protects your personal information in accordance with the Protection of Personal Information Act, 2013 ("POPIA").

2. WHAT PERSONAL DATA WE COLLECT

When you use THE ACCOUNTANTS, you may provide or we may collect:

  • Firm Data: Firm name, registration number (CIPC), email, phone, physical address, proprietor/partner names
  • User Data: Accountant name, email, password hash, login history, 2FA settings
  • Client Data: Client names, ID/passport numbers, email, phone, company registration details (entered for AFS compilation)
  • Financial Data: Trial balance uploads, journal entries, asset details, income/expense classifications (used solely for AFS generation)
  • Usage Data: Pages visited, reports generated, time spent, IP address, browser type (anonymised logs where possible)
  • Payment Data: Subscription tier, payment method (credit card / EFT), billing address, transaction history
3. HOW WE COLLECT YOUR DATA
  • Directly from you: Registration, firm setup, client input, trial balance uploads, AFS configuration
  • Automatically: Cookies, usage logs, IP address, browser fingerprint (for security + analytics)
  • From third parties: Payment processors (billing data), email service providers (delivery logs)
4. WHY WE COLLECT YOUR DATA (PURPOSE & LAWFUL BASIS)

Purposes:

  • Create and manage your firm account + user access
  • Generate compliant AFS reports + engagement letters
  • Process subscription billing and payment collection
  • Send transactional emails (password reset, report ready, billing notifications)
  • Comply with South African law (SARS, CIPC, tax regulations)
  • Prevent fraud and maintain platform security
  • Improve the Service (analytics, feature requests, bug reports)

Lawful Basis:

  • Contract: To perform services you've requested (AFS compilation, report generation)
  • Legal Obligation: To comply with South African law (SARS, CIPC, tax audit requirements)
  • Legitimate Interest: To prevent fraud, maintain platform security, improve user experience
  • Your Consent: If you opt-in to marketing communications or service updates
5. DATA RETENTION

We retain your data for:

  • Active firm accounts: As long as you use the platform
  • Closed accounts: 7 years (for tax, audit, and legal compliance under South African law)
  • Client data in your account: Until you delete it or your account is closed; then 7 years for compliance
  • Payment records: 7 years (SARS requirement for business records)
  • Usage logs: 90 days (anonymised after that)

After the retention period, your data is securely deleted or anonymised where legally permissible.

6. WHO WE SHARE YOUR DATA WITH

We do NOT sell or share your data with third parties for marketing purposes.

We may share data with:

  • Sub-processors (data handlers): Railway (hosting), DigitalOcean Spaces (storage), SendGrid (email)
  • Legal authorities: If required by law (SARS audit, court order, police investigation)
  • Payment processors: Your billing data (credit card, EFT details) is processed by [Payment Processor] under their terms

All sub-processors comply with POPIA §72 (lawful transfer of data outside South Africa) and maintain security standards (ISO 27001, SOC 2).

7. DATA SECURITY

We implement industry-standard security safeguards:

  • Encryption: Data in transit (HTTPS/TLS) and at rest (AES-256)
  • Access controls: Role-based access; only authorised staff view sensitive data
  • Authentication: Secure login with password encryption; optional MFA
  • Audit logging: All data access is logged and monitored
  • Data segregation: Your firm's data is isolated from other firms
  • Regular backups: Automated backups to prevent data loss
  • Security testing: Regular penetration testing and vulnerability scanning

Your Responsibility: Keep your password confidential. Log out of shared computers. Notify us immediately of any suspected unauthorized access.

8. YOUR DATA RIGHTS (POPIA §23)

You have the right to:

8.1 Right of Access (POPIA §23(1)(c))

You can request a copy of your personal data. To exercise this right:

  • Click Settings → Privacy & Data → Download My Data in THE ACCOUNTANTS, or
  • Email [DATA-PROTECTION-EMAIL] with subject "Data Access Request"
  • We will provide your data within 30 days in a machine-readable format (CSV/JSON)
8.2 Right of Correction (POPIA §23(1)(b))

You can correct inaccurate or incomplete data:

  • Edit your firm profile in THE ACCOUNTANTS (Settings → Firm Profile), or
  • Email [DATA-PROTECTION-EMAIL] with details of what needs correction
  • We will update your data within 10 business days
8.3 Right of Deletion (POPIA §23(1)(d))

You can request deletion of your data (subject to legal exceptions):

  • Click Settings → Account → Delete My Account, or
  • Email [DATA-PROTECTION-EMAIL] with subject "Data Deletion Request"
  • Exception: AFS records and financial data must be retained for 7 years (SARS requirement)
  • We will delete your personal data (except legally required records) within 30 days
8.4 Right to Object (POPIA §23(1)(e))

You can object to processing of your data for direct marketing:

  • Click Settings → Communications → Opt Out of Marketing, or
  • Email [DATA-PROTECTION-EMAIL] with subject "Opt Out"
  • We will stop sending marketing emails within 5 business days
8.5 Right to Lodge a Complaint

If you believe THE ACCOUNTANTS is mishandling your data, you can:

  • Contact us first: [DATA-PROTECTION-EMAIL]
  • If unresolved, lodge a complaint with the Information Regulator (South Africa's data protection authority)
  • Information Regulator: www.justice.gov.za/inforeg/
9. CROSS-BORDER DATA TRANSFERS

Your data may be transferred to the USA for processing by sub-processors (Railway, DigitalOcean, SendGrid, Anthropic). This transfer is lawful under POPIA §72 because these sub-processors comply with international data protection standards (ISO 27001, SOC 2).

If you object to your data being processed outside South Africa, please notify us at [DATA-PROTECTION-EMAIL].

10. DATA BREACH NOTIFICATION

If we discover that your personal information has been compromised (unauthorized access, theft, loss), we will:

  • ✅ Notify you within 30 days (per POPIA §22)
  • ✅ Provide details of what data was affected
  • ✅ Explain the steps we're taking to secure your data
  • ✅ Recommend actions you should take (password change, monitor accounts, etc.)

We will also notify the Information Regulator if the breach poses a significant risk.

11. COOKIES & TRACKING

THE ACCOUNTANTS uses cookies and similar tracking technologies for:

  • Session management: Keeping you logged in securely
  • Analytics: Understanding how users interact with the platform (anonymised)
  • Security: Detecting and preventing unauthorized access

You can manage cookie settings in your browser, though this may affect platform functionality.

12. CHILDREN'S DATA

THE ACCOUNTANTS is not intended for users under 18. We do not knowingly collect personal data from children. If we discover that we have collected data from a child, we will delete it promptly.

13. UPDATES TO THIS POLICY

We may update this Privacy Policy as laws change or our practices improve. Material changes will be notified via email at least 30 days before taking effect. Your continued use of the platform constitutes acceptance of the updated Privacy Policy.

14. CONTACT US

If you have questions about this Privacy Policy or your data, contact:

  • Data Protection Officer: [DPO-NAME]
  • Email: [DATA-PROTECTION-EMAIL]
  • Mailing Address: [PHYSICAL ADDRESS]

Response time: within 10 business days.

15. GOVERNING LAW

This Privacy Policy is governed by the laws of South Africa (Western Cape). Any disputes shall be subject to the jurisdiction of the South African courts.

Version: 1.0
Effective Date: 17 July 2026
Last Updated: 17 July 2026