Privacy Policy
Under POPIA · last updated 14 July 2026
1. Who we are & our two roles
VytlRx is an enterprise risk-management platform operated from South Africa. We are the responsible party for the account and usage data we collect to run the service, and the operator for the risk data your organisation uploads — for that data your organisation is the responsible party and we process it only on its instruction under our Data Processing Addendum.
2. What we collect
Account data (name, email, hashed credentials, 2FA settings, role); usage and technical logs needed to run and secure the service; and the risk-management data you enter, which may contain personal information if you include it. We do not sell your data or use it for advertising.
3. Purpose & lawful basis
We process data to create and secure accounts, provide and support the service, meter usage and (at GA) bill, and comply with the law — on the bases of performance of a contract, our legitimate interests in operating and securing the service, and legal obligation.
4. AI processing
To generate draft proposals, relevant data may be sent to our AI sub-processor (Anthropic, Claude API). Your data is never used to train any AI model. AI output is a draft for your review, not professional advice.
5. Where it is stored — SA residency
Application and database are hosted in Johannesburg, South Africa; file attachments and backups in AWS Cape Town (af-south-1). Data stays resident in South Africa, except the cross-border AI (Anthropic) and email (Resend) sub-processors, handled under POPIA §72.
6. How it is protected
Tenant isolation enforced at the database level by row-level security (with a production fail-closed self-check); HTTPS in transit and AES-256-GCM encryption of sensitive secrets at rest; an immutable audit log; optional / enforced two-factor authentication and a 15-minute idle timeout; and nightly encrypted backups.
7. Sub-processors & cross-border
We use Fly.io (hosting, SA), AWS S3 (storage/backups, SA), Anthropic (AI, US — §72), Resend (email, US/EU — §72) and Paystack (payments, at GA). No customer data is used for AI training. Full list on the legal page.
8. Your rights & retention
Under POPIA you may access, correct, delete or object to processing of your personal information — contact avin@hbdadvisory.com. We keep data only as long as needed or as the law requires (the immutable audit log is retained for 7 years); data is deleted on request or termination, subject to legal holds.
9. Complaints & Information Officer
Our Information Officer is Avi Naidoo (avin@hbdadvisory.com). You may complain to the Information Regulator (South Africa), Braamfontein, Johannesburg — enquiries@inforegulator.org.za. We use essential cookies only.