Legal · Privacy Policy
Privacy Policy
This Privacy Policy explains how Provantis (Pty) Ltd
(registration number 2014/122780/07) collects, uses, shares and safeguards personal
information when you use the Platform. We are the “responsible party” as
defined in the Protection of Personal Information Act 4 of 2013 (“POPIA”).
Last updated: 1 April 2026
1. Information Officer
In line with POPIA section 55 read with section 1 (designation of the Information
Officer) and the Information Regulator’s Guidance Note on Information Officers,
Provantis has appointed an Information Officer who can be reached at
privacy@provantis.co.za. The Information Officer is registered with
the Information Regulator of South Africa.
2. What we collect
We collect only the personal information necessary to operate the Platform:
- Account information — full name, work email, employer, role.
- Scan inputs — brokerage name, work email, domain or URL submitted to the public scanners.
- Self-attestation responses — answers you record in the readiness, audit, cyber and load-shedding modules.
- Representative records — FAIS-related personnel data you load into the Human Risk module.
- Vendor and reputation data — manual entries in the Vendor Register and Reputation Dashboard.
- WhatsApp opt-in records — recipient phone numbers, severity floors and POPIA consent timestamps.
- Billing metadata — subscription plan, invoice references; full card details are processed by our payment processor and never stored by Provantis.
- Technical telemetry — IP address, user-agent and access timestamps for security and rate limiting.
3. Lawful basis for processing
We process personal information under the following POPIA section 11 grounds:
- Performance of a contract — to deliver the Platform you have subscribed to;
- Legitimate interest — to secure the Platform, prevent abuse, and improve the rule library;
- Consent — for free public scans, marketing communication, and WhatsApp alerts;
- Compliance with a legal obligation — tax, FICA and accounting record-keeping.
4. Purpose of processing
Personal information is used solely for:
- operating the readiness diagnostic, scoring engine and report generation;
- delivering executive PDF reports, dashboards and WhatsApp alerts;
- billing, invoicing and subscription management;
- account security, fraud prevention and rate limiting;
- responding to support enquiries and improving the Platform.
5. Operators and third-party processors
We share limited personal information with the following operators (POPIA section 21) who
process it strictly on our behalf, under written instruction, and bound by appropriate
safeguards:
- Anthropic PBC (United States) — AI processing for the SENTINEL compliance assistant (chat, drafting and remediation plans), the Regulatory Intelligence scanner, and the Document Scan feature, using Anthropic’s Claude models. SENTINEL inputs include your questions and relevant scan-finding and assessment context; Document Scan by its nature transmits the content of documents you choose to upload for analysis — do not upload documents containing personal information you do not want processed by this operator. Account credentials are never transmitted.
- OpenAI, L.L.C. (United States) — AI summarisation of scan findings and plain-English explanations using
gpt-4o-mini. Inputs are limited to scan-finding text; account credentials are not transmitted.
- Twilio Inc. (United States / Ireland) — outbound WhatsApp alerts to opted-in recipients.
- Replit Deployments and Neon (United States / EU) — managed application hosting and managed PostgreSQL data storage.
- Payment processor — subscription billing; full card data is held by the processor under PCI-DSS, never by Provantis.
6. Cross-border transfers
Some operators listed above are located outside South Africa — including Anthropic PBC
and OpenAI, L.L.C. (United States), Twilio Inc. (United States / Ireland) and our hosting
and database providers (United States / EU). In line with POPIA section 72,
Provantis relies on contractual safeguards (Data Processing Addenda incorporating EU Standard
Contractual Clauses where relevant) and on operators that are subject to laws and binding
corporate rules providing an adequate level of protection. By using the Platform you
understand that personal information may be transferred to and processed in jurisdictions
outside South Africa.
7. Retention
We retain personal information only for as long as is reasonably necessary to fulfil the
purpose for which it was collected, or as required by law (including the FICA seven-year
record-keeping rule where applicable). On termination of your account, scan history and
attestation records are retained for up to twelve (12) months for audit-trail purposes and
then deleted, unless a longer period is required by law.
8. Security safeguards (POPIA s.19)
Provantis maintains appropriate, reasonable technical and organisational measures, including:
- TLS encryption in transit and at-rest encryption of the managed database;
- Role-based access control with company-scoped data isolation;
- Werkzeug-based password hashing and enforced session security, including
inactivity timeouts (30 minutes, or 15 minutes for platform administrators)
and an 8-hour maximum authenticated-session lifetime;
- SSRF-hardened scan pipeline that refuses private and link-local targets;
- Audit logging of administrative and assessment-finalisation events;
- Routine vulnerability scanning of the Platform itself.
9. Your rights as a data subject
Under POPIA sections 23 to 25 you have the right to:
- request confirmation of whether we hold personal information about you;
- request access to that information;
- request correction or deletion of inaccurate, irrelevant or out-of-date information;
- object to processing on legitimate-interest grounds;
- withdraw consent (where consent is the lawful basis), without affecting prior processing.
Requests can be sent to privacy@provantis.co.za. We respond within
thirty (30) days and may verify your identity before disclosing information.
10. Cookies and analytics
The Platform sets only a session cookie required for authentication. We do not use
third-party advertising cookies or cross-site tracking pixels. Aggregate anonymous
access logs are kept for security purposes and rotated.
11. Complaints to the Information Regulator
If you believe your personal information has been mishandled, you may lodge a complaint
directly with the Information Regulator of South Africa under POPIA section 74:
Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein,
Johannesburg, 2001 — complaints.IR@justice.gov.za ·
inforegulator.org.za.
12. Updates to this Policy
Provantis may update this Policy from time to time. Material changes will be announced on
the Platform and, where reasonable, by email at least seven (7) days before they take
effect.