AEGIS
AEGIS Intelligence Systems (Pty) Ltd Reg. 2026/521302/07
Republic of South Africa
info@aegis.org.za · aegis.org.za
Legal · Document 01

Privacy Policy

Issued 13 July 2026 · Version 1.0 · Governed by the Protection of Personal Information Act 4 of 2013 (POPIA)

AEGIS builds accounting and statutory-compliance software for professional practices. That work is only possible because firms trust us with their clients' financial and personal information. This policy sets out, plainly, what we hold, why we hold it, what we will never do with it, and how you get it back.

The short version

We hold your data to run the software you asked us to run. We do not sell it, we do not mine it, and we do not train models on your clients' books. You can export everything and leave at any time. If we are ever breached, we will tell you immediately — not when it is convenient.

1Who we are

ItemDetail
Legal entityAEGIS INTELLIGENCE SYSTEMS (Pty) Ltd
Company registration2026/521302/07
Registered addressSouth Africa, Republic of South Africa
Information Officerinfo@aegis.org.za
Information RegulatorRegistered. Complaints may be lodged directly with the Regulator (see §12).
General contactinfo@aegis.org.za · support@aegis.org.za
Websiteaegis.org.za · Application: app.aegis.org.za

2The two roles we play — this distinction matters

POPIA draws a line between the party who decides why personal information is processed (the responsible party) and the party who processes it on their instruction (the operator). AEGIS sits on both sides of that line, depending on whose information is involved. We keep them strictly apart.

Whose informationOur roleWhat that means
Your firm's own — your staff, your billing contacts, your users Responsible party We decide the purpose (running your account, billing you, supporting you) and we are directly accountable to you under POPIA.
Your clients' — the books, contacts, employees and documents you load into AEGIS Operator Your firm is the responsible party. We process only on your written instruction, for your purpose, and for no purpose of our own. This is governed by our Operator Agreement (Document 04).
What this means in practice

We do not decide what happens to your clients' data. You do. If you tell us to delete it, we delete it. If you tell us to export it, we export it. We will not use it for our own purposes, analytics, benchmarking or model training — not aggregated, not anonymised, not ever, unless you instruct us in writing.

3What we collect

3.1 Information you give us directly

3.2 Client information you load into the platform (we are the operator)

3.3 Information generated automatically

4Why we process it — and the lawful basis

PurposeLawful basis under POPIA
To provide the platform you have subscribed toPerformance of our contract with you (s11(1)(b))
To process your clients' books on your instructionOperator processing on the instruction of the responsible party (s20–21)
To bill you and collect paymentPerformance of contract; our legitimate interest (s11(1)(f))
To secure the platform, detect abuse, and maintain the audit trailLegal obligation and legitimate interest (s11(1)(c), (f))
To retain records where law requires itLegal obligation (s11(1)(c))
To send you service and security noticesPerformance of contract

We do not process your information for marketing without your consent, and where you consent you may withdraw it at any time without affecting the service you pay for.

5What we will never do

These are commitments, not aspirations. They are repeated in our Operator Agreement, where they are contractually binding.

  1. We will not sell your data, or your clients' data, to anyone. Ever.
  2. We will not train artificial-intelligence models on your clients' books — not raw, not aggregated, not anonymised — unless you instruct us to in writing, for your own purposes.
  3. We will not use your clients' financial data for benchmarking, market research, or any product of our own.
  4. We will not make it difficult for you to leave. Export is a function of the product, not a favour we grant.
  5. We will not process your clients' information for any purpose you have not instructed.

6Who we share it with

We share personal information only with the sub-operators strictly necessary to run the service. Each is bound by a written agreement no weaker than this policy, and we remain accountable to you for their conduct.

Sub-operatorPurposeLocation of processing
SupabaseDatabase and file storageEuropean Union (EU-West)
VercelApplication hostingEuropean Union / United States
PaystackPayment processing (card data held by them, never by us)South Africa / Nigeria
AnthropicDocument extraction and reasoning within the platformUnited States
Email delivery providerTransactional email (payslips, statements, notices)European Union / United States

We will otherwise disclose personal information only where the law compels us (a court order, a lawful SARS or regulatory demand). Where we are legally permitted to tell you that such a demand has been made, we will tell you, so that you can exercise your own rights before we respond.

7Cross-border transfer

Some of our sub-operators process personal information outside South Africa. POPIA (s72) permits this where the recipient is subject to a law, binding corporate rules or a binding agreement that upholds principles of protection substantially similar to POPIA. We rely on binding contractual terms with each sub-operator to achieve that, and our primary database and file storage are hosted in the European Union, under the GDPR — a regime the Information Regulator recognises as substantially similar.

8How we protect it

9If there is a breach

Section 22 of POPIA requires notification where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.

Where we act as your operator, we will notify your firm immediately on becoming aware — not after an internal investigation, not when we have a fix, and not when it is commercially comfortable. You are the responsible party; the duty to notify the Information Regulator and the affected data subjects is yours, and you cannot discharge it if we sit on the news. We will give you what you need to make that notification, and we will help you make it.

Where we act as responsible party (your firm's own account information), we will notify the Information Regulator and you, as required by s22.

10How long we keep it

CategoryRetention
Client accounting records (as operator)For as long as you instruct. On termination: exported and then deleted on your written instruction, or retained where you are legally required to retain them.
Your firm's account and billing recordsFive years after the end of the relationship — the period required by the Companies Act and the Tax Administration Act.
Audit trail and access logRetained for the life of the account. Append-only; not deletable.
Support correspondenceThree years.
Marketing consentsUntil withdrawn.

11Your rights

Under POPIA, a data subject may:

Route your request correctly. If you are a data subject whose information sits in a client book loaded by an accounting firm, that firm is the responsible party and you should approach them. If they route it to us, we will act on their instruction promptly. If you are a user of our own service, write to the Information Officer at info@aegis.org.za. We respond within 30 days. Requests are made under PAIA — see our PAIA Manual (Document 03) and the prescribed Form 2.

12Complaints

Raise it with our Information Officer first — we would rather fix it than be told about it by a regulator. But you are entitled to go straight to the regulator, and we will not obstruct you:

Information Regulator (South Africa)Detail
Complaints (POPIA)POPIAComplaints@inforegulator.org.za
Complaints (PAIA)PAIAComplaints@inforegulator.org.za
Generalenquiries@inforegulator.org.za
Websiteinforegulator.org.za

13Cookies and tracking

We use only what the service needs to work. A session cookie to keep you signed in, and a preference cookie to remember your settings. We do not run advertising trackers, we do not sell your browsing behaviour, and we do not embed third-party marketing pixels in the application. Where we use analytics on our public website, it is configured not to identify you personally.

14Children

AEGIS is a business tool sold to professional firms. We do not knowingly process the personal information of children (persons under 18) as data subjects of our own service. Where a client book you load contains information about a minor (for example a dependant on a payroll record), you are the responsible party for it and s35 of POPIA applies to your processing.

15Changes to this policy

We will post any change here and update the version and date above. Where a change materially affects your rights or how we process your clients' information, we will notify you by email before it takes effect — we will not change the terms of trust quietly.

AEGIS Intelligence Systems (Pty) Ltd · 2026/521302/07 Privacy Policy · v1.0 · 13 July 2026