Privacy Policy
Last Updated: July 9, 2026
This privacy policy describes how your personal information is collected, used, and shared when you visit or make a purchase from our site.
1. Who We Are (Responsible Party Overview)
Plinth-Cloud (Pty) Ltd (operating as Plinth), hereinafter referred to as "Plinth", "we", "us", or "our", respects your digital privacy rights and is firmly committed to securing personal data. Plinth operates as a "Responsible Party" under the Protection of Personal Information Act, No. 4 of 2013 ("POPIA") with respect to our direct subscribers' credentials, and as an "Operator" when executing processing instructions over tenant records input by our subscribers. Our designated Information Officer can be reached directly at compliance@plinthcloud.com.
2. What Personal Information We Collect
- Subscriber Profiles: Full legal names, employment titles, professional email addresses, cellular contact details, and platform identity tokens.
- Corporate/Landlord Data: Company registration numbers, physical business addresses, trading names, tax/VAT certifications, and authorized executive signatures.
- Tenant Profiles: Full names, South African national ID numbers or passport parameters, email handles, phone vectors, lease parameters, deposit parameters, utility metrics, and maintenance request descriptions.
- Financial and Transactional Metadata: Bank routing variables, verification tokens from open banking layers, transaction numbers, invoice allocations, and masked banking summaries (e.g., "FNB Cheque ****1234"). We explicitly do NOT store tenant or landlord raw banking login credentials or unmasked account details.
- Screening Logs: Pass/Fail credit verification markers along with the verification date. We do not store the full credit bureau file report.
- Telemetry Logs: Internet Protocol (IP) addresses, browser cookie strings, system interaction timestamps, and consent record state logs.
3. Why We Collect It
- Executing SaaS subscription agreements and provisioning secure workspace profiles.
- Facilitating core real estate features: automated invoice distribution, automated rental matching via the 'Plinth Match' engine, utility calculation allocation, and tenant communications.
- Authenticating payment transactions via integration rails and confirming deposit structures. We do not store raw banking credentials or unmasked account numbers.
- Conducting credit background screening upon explicit separate data subject confirmation.
- Complying with statutory reporting requirements mandated by the South African Revenue Service (SARS) and financial monitoring frameworks (FICA).
4. How We Use It and Who We Share It With
Personal data is used exclusively within the platform's execution bounds. We do not rent, sell, or swap data with advertising brokers. Information is shared strictly with downstream Operators and technical clearing partners required to run the Service: cloud hosting environments, localized payment networks, registered credit bureaus for authorized screening, and automated SMS/Email delivery networks. All such third parties are contractually bound to rigorous data isolation standards under Section 21 of POPIA.
5. Section 69 POPIA Direct Marketing Strict Opt-In Framework
In strict compliance with Section 69 of POPIA, Plinth enforces a default double-opt-in protocol for all electronic direct marketing communications (including promotional emails, targeted platform system announcements, and SMS channels) directed at prospects or non-subscribers. Plinth will never process your personal information for direct marketing purposes unless you have explicitly granted affirmative consent, or unless you are an existing corporate subscriber who has previously engaged our commercial services. Every marketing transmission features an immediate, friction-free 'unsubscribe' option, which will permanently log an opt-out flag within our messaging distribution trees within forty-eight (48) operational hours.
6. Cross-Border Data Transfers
Plinth's primary production databases are hosted by Supabase. If certain specialized fallback delivery networks, distributed server load nodes, or technical sub-processors utilize cloud architecture across geographical borders, Plinth satisfies Section 72 of POPIA by confirming that such external regions enforce statutory protections that mirror or exceed POPIA's guidelines, or by embedding strict standard contractual clauses into the vendor master agreements.
7. Security, Safeguards, and Data Retention Limits
We enforce comprehensive technical, physical, and administrative safeguards (including Let's Encrypt TLS 1.3 transit encryption, storage-level AES-256 blocks, and row-level database policy locks). Data points are subject to strict, predefined retention cycles designed to minimize storage liabilities. Once a retention timeline expires, rows are permanently purged, de-identified, or securely anonymized in accordance with Section 14 of POPIA.
8. Your Rights Under POPIA
- Request free confirmation of whether Plinth stores their personal profile attributes (Section 23).
- Request the immediate correction, modification, or updating of out-of-date or distorted records (Section 24).
- Request the full deletion or destruction of personal data records where no statutory retention override exists.
- Opt out of automated payment matching loops or object to specific processing baselines.
- Lodge formal administrative complaints directly with the South South African Information Regulator via email at infoirsa@justice.gov.za.
9. How to Contact the Information Officer
For any formal data queries, right-assertion applications, or compliance verifications, please address our Information Officer via email at compliance@plinthcloud.com. Responses are managed autonomously or manually within standard statutory windows.
Ready to Simplify Property Management?
Join other South African landlords who've made the switch.
Built for South African landlords.
