AEGIS builds accounting and statutory-compliance software for professional practices. That work is only possible because firms trust us with their clients' financial and personal information. This policy sets out, plainly, what we hold, why we hold it, what we will never do with it, and how you get it back.
We hold your data to run the software you asked us to run. We do not sell it, we do not mine it, and we do not train models on your clients' books. You can export everything and leave at any time. If we are ever breached, we will tell you immediately — not when it is convenient.
| Item | Detail |
|---|---|
| Legal entity | AEGIS INTELLIGENCE SYSTEMS (Pty) Ltd |
| Company registration | 2026/521302/07 |
| Registered address | South Africa, Republic of South Africa |
| Information Officer | info@aegis.org.za |
| Information Regulator | Registered. Complaints may be lodged directly with the Regulator (see §12). |
| General contact | info@aegis.org.za · support@aegis.org.za |
| Website | aegis.org.za · Application: app.aegis.org.za |
POPIA draws a line between the party who decides why personal information is processed (the responsible party) and the party who processes it on their instruction (the operator). AEGIS sits on both sides of that line, depending on whose information is involved. We keep them strictly apart.
| Whose information | Our role | What that means |
|---|---|---|
| Your firm's own — your staff, your billing contacts, your users | Responsible party | We decide the purpose (running your account, billing you, supporting you) and we are directly accountable to you under POPIA. |
| Your clients' — the books, contacts, employees and documents you load into AEGIS | Operator | Your firm is the responsible party. We process only on your written instruction, for your purpose, and for no purpose of our own. This is governed by our Operator Agreement (Document 04). |
We do not decide what happens to your clients' data. You do. If you tell us to delete it, we delete it. If you tell us to export it, we export it. We will not use it for our own purposes, analytics, benchmarking or model training — not aggregated, not anonymised, not ever, unless you instruct us in writing.
| Purpose | Lawful basis under POPIA |
|---|---|
| To provide the platform you have subscribed to | Performance of our contract with you (s11(1)(b)) |
| To process your clients' books on your instruction | Operator processing on the instruction of the responsible party (s20–21) |
| To bill you and collect payment | Performance of contract; our legitimate interest (s11(1)(f)) |
| To secure the platform, detect abuse, and maintain the audit trail | Legal obligation and legitimate interest (s11(1)(c), (f)) |
| To retain records where law requires it | Legal obligation (s11(1)(c)) |
| To send you service and security notices | Performance of contract |
We do not process your information for marketing without your consent, and where you consent you may withdraw it at any time without affecting the service you pay for.
These are commitments, not aspirations. They are repeated in our Operator Agreement, where they are contractually binding.
We share personal information only with the sub-operators strictly necessary to run the service. Each is bound by a written agreement no weaker than this policy, and we remain accountable to you for their conduct.
| Sub-operator | Purpose | Location of processing |
|---|---|---|
| Supabase | Database and file storage | European Union (EU-West) |
| Vercel | Application hosting | European Union / United States |
| Paystack | Payment processing (card data held by them, never by us) | South Africa / Nigeria |
| Anthropic | Document extraction and reasoning within the platform | United States |
| Email delivery provider | Transactional email (payslips, statements, notices) | European Union / United States |
We will otherwise disclose personal information only where the law compels us (a court order, a lawful SARS or regulatory demand). Where we are legally permitted to tell you that such a demand has been made, we will tell you, so that you can exercise your own rights before we respond.
Some of our sub-operators process personal information outside South Africa. POPIA (s72) permits this where the recipient is subject to a law, binding corporate rules or a binding agreement that upholds principles of protection substantially similar to POPIA. We rely on binding contractual terms with each sub-operator to achieve that, and our primary database and file storage are hosted in the European Union, under the GDPR — a regime the Information Regulator recognises as substantially similar.
Section 22 of POPIA requires notification where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.
Where we act as your operator, we will notify your firm immediately on becoming aware — not after an internal investigation, not when we have a fix, and not when it is commercially comfortable. You are the responsible party; the duty to notify the Information Regulator and the affected data subjects is yours, and you cannot discharge it if we sit on the news. We will give you what you need to make that notification, and we will help you make it.
Where we act as responsible party (your firm's own account information), we will notify the Information Regulator and you, as required by s22.
| Category | Retention |
|---|---|
| Client accounting records (as operator) | For as long as you instruct. On termination: exported and then deleted on your written instruction, or retained where you are legally required to retain them. |
| Your firm's account and billing records | Five years after the end of the relationship — the period required by the Companies Act and the Tax Administration Act. |
| Audit trail and access log | Retained for the life of the account. Append-only; not deletable. |
| Support correspondence | Three years. |
| Marketing consents | Until withdrawn. |
Under POPIA, a data subject may:
Route your request correctly. If you are a data subject whose information sits in a client book loaded by an accounting firm, that firm is the responsible party and you should approach them. If they route it to us, we will act on their instruction promptly. If you are a user of our own service, write to the Information Officer at info@aegis.org.za. We respond within 30 days. Requests are made under PAIA — see our PAIA Manual (Document 03) and the prescribed Form 2.
Raise it with our Information Officer first — we would rather fix it than be told about it by a regulator. But you are entitled to go straight to the regulator, and we will not obstruct you:
| Information Regulator (South Africa) | Detail |
|---|---|
| Complaints (POPIA) | POPIAComplaints@inforegulator.org.za |
| Complaints (PAIA) | PAIAComplaints@inforegulator.org.za |
| General | enquiries@inforegulator.org.za |
| Website | inforegulator.org.za |
We use only what the service needs to work. A session cookie to keep you signed in, and a preference cookie to remember your settings. We do not run advertising trackers, we do not sell your browsing behaviour, and we do not embed third-party marketing pixels in the application. Where we use analytics on our public website, it is configured not to identify you personally.
AEGIS is a business tool sold to professional firms. We do not knowingly process the personal information of children (persons under 18) as data subjects of our own service. Where a client book you load contains information about a minor (for example a dependant on a payroll record), you are the responsible party for it and s35 of POPIA applies to your processing.
We will post any change here and update the version and date above. Where a change materially affects your rights or how we process your clients' information, we will notify you by email before it takes effect — we will not change the terms of trust quietly.