Legal · Privacy Policy

Privacy Policy

This Privacy Policy explains how Provantis (Pty) Ltd (registration number 2014/122780/07) collects, uses, shares and safeguards personal information when you use the Platform. We are the “responsible party” as defined in the Protection of Personal Information Act 4 of 2013 (“POPIA”).

Last updated: 1 April 2026

1. Information Officer

In line with POPIA section 55 read with section 1 (designation of the Information Officer) and the Information Regulator’s Guidance Note on Information Officers, Provantis has appointed an Information Officer who can be reached at privacy@provantis.co.za. The Information Officer is registered with the Information Regulator of South Africa.

2. What we collect

We collect only the personal information necessary to operate the Platform:

  • Account information — full name, work email, employer, role.
  • Scan inputs — brokerage name, work email, domain or URL submitted to the public scanners.
  • Self-attestation responses — answers you record in the readiness, audit, cyber and load-shedding modules.
  • Representative records — FAIS-related personnel data you load into the Human Risk module.
  • Vendor and reputation data — manual entries in the Vendor Register and Reputation Dashboard.
  • WhatsApp opt-in records — recipient phone numbers, severity floors and POPIA consent timestamps.
  • Billing metadata — subscription plan, invoice references; full card details are processed by our payment processor and never stored by Provantis.
  • Technical telemetry — IP address, user-agent and access timestamps for security and rate limiting.

3. Lawful basis for processing

We process personal information under the following POPIA section 11 grounds:

  • Performance of a contract — to deliver the Platform you have subscribed to;
  • Legitimate interest — to secure the Platform, prevent abuse, and improve the rule library;
  • Consent — for free public scans, marketing communication, and WhatsApp alerts;
  • Compliance with a legal obligation — tax, FICA and accounting record-keeping.

4. Purpose of processing

Personal information is used solely for:

  • operating the readiness diagnostic, scoring engine and report generation;
  • delivering executive PDF reports, dashboards and WhatsApp alerts;
  • billing, invoicing and subscription management;
  • account security, fraud prevention and rate limiting;
  • responding to support enquiries and improving the Platform.

5. Operators and third-party processors

We share limited personal information with the following operators (POPIA section 21) who process it strictly on our behalf, under written instruction, and bound by appropriate safeguards:

  • Anthropic PBC (United States) — AI processing for the SENTINEL compliance assistant (chat, drafting and remediation plans), the Regulatory Intelligence scanner, and the Document Scan feature, using Anthropic’s Claude models. SENTINEL inputs include your questions and relevant scan-finding and assessment context; Document Scan by its nature transmits the content of documents you choose to upload for analysis — do not upload documents containing personal information you do not want processed by this operator. Account credentials are never transmitted.
  • OpenAI, L.L.C. (United States) — AI summarisation of scan findings and plain-English explanations using gpt-4o-mini. Inputs are limited to scan-finding text; account credentials are not transmitted.
  • Twilio Inc. (United States / Ireland) — outbound WhatsApp alerts to opted-in recipients.
  • Replit Deployments and Neon (United States / EU) — managed application hosting and managed PostgreSQL data storage.
  • Payment processor — subscription billing; full card data is held by the processor under PCI-DSS, never by Provantis.

6. Cross-border transfers

Some operators listed above are located outside South Africa — including Anthropic PBC and OpenAI, L.L.C. (United States), Twilio Inc. (United States / Ireland) and our hosting and database providers (United States / EU). In line with POPIA section 72, Provantis relies on contractual safeguards (Data Processing Addenda incorporating EU Standard Contractual Clauses where relevant) and on operators that are subject to laws and binding corporate rules providing an adequate level of protection. By using the Platform you understand that personal information may be transferred to and processed in jurisdictions outside South Africa.

7. Retention

We retain personal information only for as long as is reasonably necessary to fulfil the purpose for which it was collected, or as required by law (including the FICA seven-year record-keeping rule where applicable). On termination of your account, scan history and attestation records are retained for up to twelve (12) months for audit-trail purposes and then deleted, unless a longer period is required by law.

8. Security safeguards (POPIA s.19)

Provantis maintains appropriate, reasonable technical and organisational measures, including:

  • TLS encryption in transit and at-rest encryption of the managed database;
  • Role-based access control with company-scoped data isolation;
  • Werkzeug-based password hashing and enforced session security, including inactivity timeouts (30 minutes, or 15 minutes for platform administrators) and an 8-hour maximum authenticated-session lifetime;
  • SSRF-hardened scan pipeline that refuses private and link-local targets;
  • Audit logging of administrative and assessment-finalisation events;
  • Routine vulnerability scanning of the Platform itself.

9. Your rights as a data subject

Under POPIA sections 23 to 25 you have the right to:

  • request confirmation of whether we hold personal information about you;
  • request access to that information;
  • request correction or deletion of inaccurate, irrelevant or out-of-date information;
  • object to processing on legitimate-interest grounds;
  • withdraw consent (where consent is the lawful basis), without affecting prior processing.

Requests can be sent to privacy@provantis.co.za. We respond within thirty (30) days and may verify your identity before disclosing information.

10. Cookies and analytics

The Platform sets only a session cookie required for authentication. We do not use third-party advertising cookies or cross-site tracking pixels. Aggregate anonymous access logs are kept for security purposes and rotated.

11. Complaints to the Information Regulator

If you believe your personal information has been mishandled, you may lodge a complaint directly with the Information Regulator of South Africa under POPIA section 74:

Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 — complaints.IR@justice.gov.za · inforegulator.org.za.

12. Updates to this Policy

Provantis may update this Policy from time to time. Material changes will be announced on the Platform and, where reasonable, by email at least seven (7) days before they take effect.