VytlRxReturn to VytlRx

Privacy Policy

Under POPIA · last updated 14 July 2026

1. Who we are & our two roles

VytlRx is an enterprise risk-management platform operated from South Africa. We are the responsible party for the account and usage data we collect to run the service, and the operator for the risk data your organisation uploads — for that data your organisation is the responsible party and we process it only on its instruction under our Data Processing Addendum.

2. What we collect

Account data (name, email, hashed credentials, 2FA settings, role); usage and technical logs needed to run and secure the service; and the risk-management data you enter, which may contain personal information if you include it. We do not sell your data or use it for advertising.

3. Purpose & lawful basis

We process data to create and secure accounts, provide and support the service, meter usage and (at GA) bill, and comply with the law — on the bases of performance of a contract, our legitimate interests in operating and securing the service, and legal obligation.

4. AI processing

To generate draft proposals, relevant data may be sent to our AI sub-processor (Anthropic, Claude API). Your data is never used to train any AI model. AI output is a draft for your review, not professional advice.

5. Where it is stored — SA residency

Application and database are hosted in Johannesburg, South Africa; file attachments and backups in AWS Cape Town (af-south-1). Data stays resident in South Africa, except the cross-border AI (Anthropic) and email (Resend) sub-processors, handled under POPIA §72.

6. How it is protected

Tenant isolation enforced at the database level by row-level security (with a production fail-closed self-check); HTTPS in transit and AES-256-GCM encryption of sensitive secrets at rest; an immutable audit log; optional / enforced two-factor authentication and a 15-minute idle timeout; and nightly encrypted backups.

7. Sub-processors & cross-border

We use Fly.io (hosting, SA), AWS S3 (storage/backups, SA), Anthropic (AI, US — §72), Resend (email, US/EU — §72) and Paystack (payments, at GA). No customer data is used for AI training. Full list on the legal page.

8. Your rights & retention

Under POPIA you may access, correct, delete or object to processing of your personal information — contact avin@hbdadvisory.com. We keep data only as long as needed or as the law requires (the immutable audit log is retained for 7 years); data is deleted on request or termination, subject to legal holds.

9. Complaints & Information Officer

Our Information Officer is Avi Naidoo (avin@hbdadvisory.com). You may complain to the Information Regulator (South Africa), Braamfontein, Johannesburg — enquiries@inforegulator.org.za. We use essential cookies only.