Skip to content
Legal

Privacy Policy

What LedgerAI collects, why, where it goes, and how to make us stop.

Effective 26 August 2026

Responsible party

Who is responsible

LedgerAI is operated from South Africa and processes personal information as a responsible party under the Protection of Personal Information Act 4 of 2013 (POPIA). Where we process personal information on behalf of a customer organisation - the compliance records they load into their workspace - we act as an operator for that organisation.

Questions about this policy, or any request concerning your personal information, go to vuyo@quantyx.co.za.

Categories

What we collect

Account information. Your email address and authentication identifiers. If you sign in with Apple or Google, we receive the identifier that provider returns; we never receive your password.

Organisation profile. Company name, website, industry, size, operating regions, role, and the business characteristics you supply during onboarding. This exists to determine which regulations apply to you - it is the input to the applicability engine, not marketing data.

Compliance content. The products, controls, obligations, evidence records and audit artefacts you create. This is your data. We process it to provide the service.

Correspondence. Anything you send through the contact form or an access request, including the name, email and message you provide.

Local browser storage. The application stores preferences and some working state in your browser’s local storage. This stays on your device and is not transmitted to us as a tracking signal.

POPIA

The eight conditions

POPIA sets eight conditions for lawful processing. Rather than assert compliance in the abstract, here is what each one means in our case.

Accountability
We take responsibility for the conditions below being met.
Processing limitation
We collect the minimum needed to operate the service, with your knowledge.
Purpose specification
We collect for the specific purposes set out on this page and no others.
Further processing limitation
We do not repurpose your data for something incompatible with why it was collected.
Information quality
We give you the means to keep your organisation profile accurate and current.
Openness
This document is that openness. It is written to be read, not to be survived.
Security safeguards
See the Security page for what we actually do, in technical terms.
Data subject participation
You may ask what we hold, correct it, or ask us to delete it.

Operators

Who else processes it

We use a small number of third-party processors. We do not sell personal information, and we do not share it with advertisers.

Google (Firebase)

Authentication and the Realtime Database that stores your organisation profile, controls, obligations and evidence metadata.

Google Cloud regions; may include processing outside South Africa.

Vercel

Hosting and delivery of the web application.

Global edge network; may include processing outside South Africa.

Email transport (SMTP)

Delivery of contact-form messages, access requests and notification email.

Depends on the configured provider.

Section 72 of POPIA restricts transfers of personal information outside South Africa. Our infrastructure providers operate globally, so your information may be processed outside the Republic under the contractual protections those providers offer. If your organisation requires data residency guarantees, raise it with us before you load regulated data.

Data subject participation

Your rights

Under POPIA you may:

  • ask whether we hold personal information about you, and ask for a copy;
  • ask us to correct or delete information that is inaccurate, irrelevant, excessive, misleading or obtained unlawfully;
  • object to processing on reasonable grounds;
  • withdraw consent where our processing relies on it;
  • complain to the Information Regulator.

Send any of these to vuyo@quantyx.co.za. We will respond within a reasonable period and will tell you if we need more information to identify the records you mean.

If you are not satisfied with our response, you may complain to the Information Regulator (South Africa).

Safeguards

Security and breaches

The technical detail of how the service is built is on the Security page, because it deserves more than a sentence here.

If personal information under our control is accessed or acquired by an unauthorised person, section 22 of POPIA requires us to notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering it. We will tell you what happened, what information was involved, and what we recommend you do.

Housekeeping

Retention, marketing, and changes

Retention. We keep your account and compliance records for as long as your account is active. Attestation and audit artefacts are designed to be durable evidence, so tell us explicitly if you want them destroyed. After closure we delete or de-identify what we are not required to keep.

Direct marketing. Section 69 of POPIA restricts unsolicited electronic marketing. We email you about the service you asked for. If we ever send anything else, it will carry a way to opt out, and opting out will work.

Changes. If we change this policy materially we will update the effective date and, where the change affects how we handle information you have already given us, tell you directly.