Asset Assistant: POPIA Notice (South Africa)

Read together with the Privacy Policy.

This notice explains how personal information is processed under South Africa's Protection of Personal Information Act, 2013 (POPIA).

1. Responsible party & Information Officer

2. Our processing is minimal

Asset Assistant is device-first: your asset records, photos, GPS and backups are stored only on the register owner's device, under that owner's control - your own device on a Solo plan or as a team owner. In team mode, a field device's captures are transferred to the organization owner's device, end-to-end encrypted through a relay that cannot read them; the owner (your employer or principal) is the responsible party for the organization's register. We do not collect or store your records, and we operate no user accounts or database of your information. We are therefore not holding a personal-information store about you.

The only personal-information processing we perform is: 1. Transient AI processing: when you choose to use an AI feature, your photo/document and minimal text hints pass through our service to our AI provider for processing and are returned to you. They are not stored by us; our AI provider may retain them for up to 30 days for abuse monitoring and then deletes them (see §4). Photographs are sent inline with the request. A PDF invoice must be uploaded to the provider's file storage to be read; we set those uploads to expire one hour after upload. 2. Usage logging: per-request log entries (see Privacy Policy §4) used to operate, cost and improve the service. We hold no user accounts, so these are not linked to you or to any account or device. They include the asset category processed, and, only where you have separately given consent in the app's Terms & Privacy screen, off by default, the invoice vendor/supplier name. A vendor name can in some cases constitute personal information about a business or person; we therefore treat it as personal information for the purposes of this notice, gate it behind explicit consent, retain it for a limited period (§8), and use it only in aggregate for analytics. 3. Purchase verification: when you subscribe or renew, Google Play issues your device an opaque purchase token. Our service sends that token to Google's Play Developer API to confirm the purchase is genuine and to obtain its expiry date. A purchase token identifies a transaction, not a person: it carries no name, contact detail, payment detail or device identifier, and it is returned only to Google, who issued it. We consider this minimal processing necessary to provide the paid service and to prevent unauthorised use. 4. Team-mode relay (user-directed, ciphertext only): when an organization owner connects team devices, capture data travels between those devices through our relay end-to-end encrypted on the devices. We cannot read, decrypt, or access the content; the relay holds only ciphertext (auto-deleted, at most 60 days), pseudonymous device tokens, and device labels typed by the owner. The relay runs entirely in South Africa: it involves no cross-border transfer. This processing happens only at the organization owner's instruction; the register itself remains on the owner's device. The owner can delete all relay content in-app at any time.

  1. Accounting system connection (user-directed, device to provider): if you connect your accounting system (currently Xero), the app sends the asset records you choose directly from your device to your own accounting organisation, and reads your fixed-asset list back. The connection is authorised by you on the provider's login page and its tokens are stored on your device. Our service does not receive, store or forward that data. The provider processes it under its own privacy policy and may host it outside South Africa (see §4).

  2. Technical request logs: whenever a device or browser contacts our service, Google Cloud records the time, the address requested, the response status, the IP address and the app or browser identifier. We use these logs to keep the service secure, to detect and stop abuse and to trace faults. An IP address can in some cases identify a person, so we treat these logs as personal information. They are stored in South Africa and deleted after 90 days (Privacy Policy §4A).

Organizations: who is responsible for what

Where an organization owner invites team devices, the owner decides what is captured and why, and is the responsible party for that information as between them and their workers (for example, under an employment arrangement). We act only as a conduit: the relay carries ciphertext we cannot read, and we hold no register. If a worker leaves or is revoked, the organization's assets and photos are erased from that worker's device; the worker keeps only their own record of what they captured and delivered.

3. Purpose & lawful basis

4. Cross-border transfer (Section 72)

Our own service, the AI proxy that handles your request, and the storage that holds retained usage logs and technical request logs, run inside South Africa, on Google Cloud. The cross-border transfers we perform are: - AI processing (OpenAI, United States). Your photo/document and minimal hints are sent to OpenAI in the US for processing and the result is returned. OpenAI encrypts data at rest (AES‑256) and in transit (TLS 1.2+), retains inputs/outputs for up to 30 days for abuse monitoring and then deletes them, and holds SOC 2 Type 2 and ISO/IEC 27001 certifications. OpenAI processes this data under its API terms with us, which bind it not to use the content to train its models. - Google Play checks. Purchase verification and app verification (Play Integrity) send opaque tokens to Google's global services, under Google's own terms. They carry no name, contact or payment details.

A second transfer can happen at your own instruction and not through us: if you connect an accounting system (currently Xero), your device sends the asset records you choose to your own accounting organisation, and that provider may host them outside South Africa under its own privacy policy. You authorise that connection yourself and can revoke it in the app at any time.

The AI transfer is made because it is necessary to provide the feature you asked for (POPIA section 72(1)(c)), and under OpenAI's binding API terms with us, which require it to protect the data, not to train on it and to delete it within the stated period (section 72(1)(a)). It is limited to the photo/document and minimal hints needed for that single request. We may change providers or hosting arrangements in future; this notice will be updated if we do.

5. Your rights as a data subject

Under POPIA you may: - Access the personal information we hold about you (note: we hold only the usage-log entries described in §2, which carry no account or identity link, plus your own on-device data, which you control); - Correct or delete personal information; - Object to processing and withdraw consent to AI processing (you can simply stop using AI features; capturing assets does not require AI); - Complain to the Information Regulator.

To exercise these, contact the Information Officer above. A formal request for access to records may be made using the prescribed PAIA Form 2 (Request for Access to Record), https://inforegulator.org.za/wp-content/uploads/2020/07/InfoRegSA-PAIA-Form02-Reg7.pdf, submitted to the Information Officer as described in our PAIA Manual. Most of your data lives on your device, so you can edit or delete it directly, and uninstalling the app erases all local data.

6. Information Regulator

Information Regulator (South Africa). POPIA complaints: POPIAComplaints@inforegulator.org.za · https://inforegulator.org.za

7. Security

8. Retention

We retain technical request logs (including IP addresses) for 90 days, after which they are deleted. We retain usage-log entries (asset category, and vendor name only where consented, as described above) for 12 months, after which they are deleted; we may keep aggregated, non-identifying statistics for longer. Images/documents sent for AI processing are not retained by us, and are deleted by our AI provider within up to 30 days. Support correspondence you send us (including any support report you chose to share) is kept for as long as reasonably necessary for the matter and for proper business records, including the establishment or defence of legal claims, and then deleted. We hold no other personal information about app users.