Privacy Policy
What LedgerAI collects, why, where it goes, and how to make us stop.
Effective 26 August 2026
Responsible party
Who is responsible
LedgerAI is operated from South Africa and processes personal information as a responsible party under the Protection of Personal Information Act 4 of 2013 (POPIA). Where we process personal information on behalf of a customer organisation - the compliance records they load into their workspace - we act as an operator for that organisation.
Questions about this policy, or any request concerning your personal information, go to vuyo@quantyx.co.za.
Categories
What we collect
Account information. Your email address and authentication identifiers. If you sign in with Apple or Google, we receive the identifier that provider returns; we never receive your password.
Organisation profile. Company name, website, industry, size, operating regions, role, and the business characteristics you supply during onboarding. This exists to determine which regulations apply to you - it is the input to the applicability engine, not marketing data.
Compliance content. The products, controls, obligations, evidence records and audit artefacts you create. This is your data. We process it to provide the service.
Correspondence. Anything you send through the contact form or an access request, including the name, email and message you provide.
Local browser storage. The application stores preferences and some working state in your browser’s local storage. This stays on your device and is not transmitted to us as a tracking signal.
POPIA
The eight conditions
POPIA sets eight conditions for lawful processing. Rather than assert compliance in the abstract, here is what each one means in our case.
- Accountability
- We take responsibility for the conditions below being met.
- Processing limitation
- We collect the minimum needed to operate the service, with your knowledge.
- Purpose specification
- We collect for the specific purposes set out on this page and no others.
- Further processing limitation
- We do not repurpose your data for something incompatible with why it was collected.
- Information quality
- We give you the means to keep your organisation profile accurate and current.
- Openness
- This document is that openness. It is written to be read, not to be survived.
- Security safeguards
- See the Security page for what we actually do, in technical terms.
- Data subject participation
- You may ask what we hold, correct it, or ask us to delete it.
Operators
Who else processes it
We use a small number of third-party processors. We do not sell personal information, and we do not share it with advertisers.
Google (Firebase)
Authentication and the Realtime Database that stores your organisation profile, controls, obligations and evidence metadata.
Google Cloud regions; may include processing outside South Africa.
Vercel
Hosting and delivery of the web application.
Global edge network; may include processing outside South Africa.
Email transport (SMTP)
Delivery of contact-form messages, access requests and notification email.
Depends on the configured provider.
Data subject participation
Your rights
Under POPIA you may:
- ask whether we hold personal information about you, and ask for a copy;
- ask us to correct or delete information that is inaccurate, irrelevant, excessive, misleading or obtained unlawfully;
- object to processing on reasonable grounds;
- withdraw consent where our processing relies on it;
- complain to the Information Regulator.
Send any of these to vuyo@quantyx.co.za. We will respond within a reasonable period and will tell you if we need more information to identify the records you mean.
If you are not satisfied with our response, you may complain to the Information Regulator (South Africa).
Safeguards
Security and breaches
The technical detail of how the service is built is on the Security page, because it deserves more than a sentence here.
If personal information under our control is accessed or acquired by an unauthorised person, section 22 of POPIA requires us to notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering it. We will tell you what happened, what information was involved, and what we recommend you do.
Housekeeping
Retention, marketing, and changes
Retention. We keep your account and compliance records for as long as your account is active. Attestation and audit artefacts are designed to be durable evidence, so tell us explicitly if you want them destroyed. After closure we delete or de-identify what we are not required to keep.
Direct marketing. Section 69 of POPIA restricts unsolicited electronic marketing. We email you about the service you asked for. If we ever send anything else, it will carry a way to opt out, and opting out will work.
Changes. If we change this policy materially we will update the effective date and, where the change affects how we handle information you have already given us, tell you directly.