DigitalFlyerGrowth

DigitalFlyer Personal Information Protection Policy

Effective Date: 2026/07/11

Last Updated: 11 July 2026

DigitalFlyer SA (“DigitalFlyer”, “we”, “us”) respects your privacy and is committed to protecting your personal information in line with the Protection of Personal Information Act (POPIA).

This policy explains what personal information we collect, how we use it, and your rights.

1. Who We Are

DigitalFlyer provides tools that help small and informal South African businesses build a professional online presence and generate leads. Our platform includes landing pages, lead capture forms, and (on the Growth tier) ad tracking tools.

2. What Personal Information We Collect

We collect information in two main ways:

From Business Owners (Clients):

  • Name, email address, phone number, and business details
  • Business address, description, logo, photos, and social media links
  • Payment information (processed securely by Paystack, and we do not store full card details)

From Leads (People who enquire through client pages):

  • Name, phone number, email address, suburb/town, and details about the service they need

We also collect technical information (IP address, browser type, device) when you visit our site or a client’s page.

3. How and Why We Use Your Information

We use your information to:

  • Provide and improve our service
  • Deliver leads to the correct business owner
  • Send important service updates and occasional news (you can opt out anytime)
  • Comply with legal obligations

We only collect and use the minimum information necessary.

4. Sharing Your Information

  • We share lead information only with the business owner whose page the enquiry came from.
  • We use trusted service providers (such as Supabase, Vercel, and Paystack) to run the platform. These providers are bound by contracts to protect your data.
  • We may share information if required by law.

We do not sell your personal information.

5. Security

We use reasonable technical and organisational measures to protect your information. While no system is 100% secure, we continuously work to improve our safeguards.

6. Your Rights Under POPIA

You have the right to:

  • Access the personal information we hold about you
  • Ask us to correct or delete your information
  • Object to processing for direct marketing
  • Lodge a complaint with the Information Regulator

To exercise these rights, contact us at the details below.

6a. Data Retention

We keep your personal information for as long as you remain a DigitalFlyer member. If you cancel your subscription, we retain your information for a further 12 months, after which it is deleted, except where we are required by law to keep it longer.

Deletion requests are actioned on our live systems as soon as we receive them. We also keep a weekly encrypted backup of our database for disaster recovery, retained on a rolling 90-day basis, after 90 days each backup is automatically deleted. Any personal information in a backup made before your deletion request will age out of that backup within 90 days.

6b. People Who Are Not Members

If you verify your email address to comment on, react to, or message a business through The Board, we store that email address, the name you choose to display, and whether you agreed to be sent a quote. We do not create an account for you, we never ask you for a password, and we do not build a profile of you. If you have no activity for 12 months, that information is deleted. You can ask us to delete it sooner at any time, using the contact details below.

Your email address is never shown publicly and is never given to a business unless you specifically agree to it when you write to them. Sharing a page does not require any of this, and we do not record who shares what.

7. Direct Marketing & Communication

By signing up or using our service, you agree that we may contact you occasionally with updates, news, and relevant information about DigitalFlyer. You can unsubscribe at any time by replying “STOP” or clicking the unsubscribe link in our emails.

8. International Transfers

We prefer to use services based in South Africa where possible. However, some of our service providers (such as Vercel and certain Supabase infrastructure) may process data outside South Africa. Where this happens, we use appropriate safeguards to protect your information.

8a. Cookies and Advertising Tracking

Our own pages, and some client pages, use a tracking cookie (Meta Pixel) to help measure advertising performance. This includes the DigitalFlyer and KatisoBiz marketing and signup pages. This cookie is never loaded automatically. It only loads after you actively choose “Accept” on the cookie banner shown on that page. Choosing “Reject”, or not choosing at all, means the cookie is never set, and the page works exactly the same either way.

9. Changes to This Policy

We may update this policy from time to time. The latest version will always be available on our website.

10. Contact Us

Digital Flyer (Pty) Ltd, registration number 2018/350974/07, trading as DigitalFlyer SA
609 Swart Street, Pretoria, 0044, South Africa
Email: info@digitalflyer.co.za
WhatsApp: +27723110570

Our Information Officer is Dewald Rosema, registered with the Information Regulator on 11 July 2026 under registration number 2026-061838. Information Officer requests go to info@digitalflyer.co.za.

If you have concerns about how we handle your personal information, please contact us first. You may also approach the Information Regulator at inforegulator.org.za, by email at POPIAComplaints@inforegulator.org.za, or by post at P.O. Box 31533, Braamfontein, Johannesburg, 2017.

KatisoBiz: where we act as operator

This section applies to KatisoBiz, our quoting and invoicing product. It sits alongside everything above rather than replacing it.

B1. Your customers’ personal information

B1.1 To provide KatisoBiz, we store personal information about your customers: typically names, physical or postal addresses, telephone numbers, email addresses, and a record of the work or services you performed for them.

B1.2 We process this information solely as an operator under POPIA, on your instructions, and only to let you create, send and keep records of quotes, invoices, credit notes and payment status. We do not use it for our own marketing, analytics, profiling or any other purpose, and we do not sell or rent it.

B2. What DigitalFlyer staff can and cannot see

We would rather be accurate than impressive. This section describes what is actually true.

B2.1 Banking details are encrypted at rest and are decrypted only at the moment a document is generated. Every decryption is recorded in an access log.

B2.2 Your customer names and contact details are protected by database access controls and application-level permissions. Our support team works from screens that do not display your customer lists or banking details in the ordinary course of support.

B2.3 We do not claim zero-knowledge encryption. Your customer names and contact details are not encrypted at rest in the same way as banking details. A technical administrator with elevated database access could in principle read them, because that access is necessary to maintain the service and resolve faults. We control this through restricted access, logging, and internal policy rather than through encryption.

B2.4 We tell you this plainly because a privacy policy that overstates its protections is worse than one that describes them honestly.

B3. Where your information is stored

B3.1 KatisoBiz’s infrastructure is hosted outside South Africa, currently in the European Union (Frankfurt, Germany). The European Union has data protection laws substantially similar to POPIA.

B3.2 Your records remain accessible to you at all times from within South Africa through the KatisoBiz application, and can be exported in full at any time.

B3.3 You should be aware that where SARS requires records to be kept in a particular form or location, meeting that requirement remains your responsibility. If you need records held within South Africa, contact us.

B4. Retention of financial records

B4.1 Financial Records are retained for at least five years, and seven years for registered companies, to support your obligations under the Tax Administration Act, the VAT Act and the Companies Act. This overrides our standard 60-day post-cancellation deletion timeline.

B4.2 Personal information appearing ona tax invoice, such as your customer’s name and address, is a legally required component of that document. It therefore forms part of the Financial Record and cannot be separated, redacted or deleted early without destroying the validity of the record.

B4.3 Personal information that is not part of a Financial Record continues to follow our ordinary deletion timelines.

B4.4 If one of your customers asks you to delete their information, you should be aware that information already contained in an issued invoice cannot lawfully be removed. Contact us and we will help you respond.

B5. Sub-processors

B5.1 We use the following sub-processors for KatisoBiz:

Sub-processorPurpose
Supabase Inc.Database and backend hosting
Vercel Inc.Application hosting and delivery
Resend Inc.Transactional and notification email
Paystack Payments LimitedSubscription and topup payment processing

B5.2 PDF rendering. Our intention is to render documents within our own infrastructure so that banking details are not transmitted to a third-party rendering service. If we adopt an external rendering provider, it will be added to the table above and this policy updated before any of your data is sent to it.

B5.3 We will update this list before adding any new sub-processor that will process your customers’ personal information, and will notify Members by email of material changes.

B6. Security incidents

B6.1 If we become aware of unauthorised access to your customers’ personal information, we will notify you without undue delay, and will provide the information you need to meet your own notification obligations to the Information Regulator and to affected individuals under POPIA section 22.

B7. Information Officer and complaints

B7.1 DigitalFlyer’s Information Officer is Dewald Rosema, registered with the Information Regulator (South Africa) under registration number 2026-061838, dated 11 July 2026.

B7.2 The Information Officer can be reached at info@digitalflyer.co.za.

B7.3 If you believe we have not handled personal information in accordance with POPIA, you may lodge a complaint with our Information Officer, or directly with the Information Regulator (South Africa):

  • Website: inforegulator.org.za
  • POPIA complaints: POPIAComplaints@inforegulator.org.za
  • General POPIA compliance queries: POPIACompliance@inforegulator.org.za
  • Postal: P.O. Box 31533, Braamfontein, Johannesburg, 2017

B8. Access to our records under PAIA

B8.1 DigitalFlyer’s PAIA manual, setting out the records we hold and how to request access to them, is available on our website and at our principal place of business.