ReportingServices ReportingServices

Legal

Privacy Policy

This policy covers the ReportingServices website, web application, and mobile application, and explains how we collect, use, and protect your information in accordance with South Africa's Protection of Personal Information Act, 2013 (POPIA).

Last updated: 7 August 2026

1. Who we are

ReportingServices ("ReportingServices", "we", "us") operates the ReportingServices website, the web application accessible to signed-up organisations ("tenants"), and the ReportingServices mobile application (together, the "Service"). We are the responsible party for personal information processed through the Service, as defined under POPIA.

ReportingServices
South Africa

2. Information we collect

We collect different information depending on how you use the Service.

2.1 Account and organisation information

Name, email address, phone number, and password (stored as a salted hash, never in plain text) when you or your organisation sign up, are invited as a user, or are added as a platform administrator. Organisation billing details — legal name, VAT number, registration number, billing address, and billing email — when provided for invoicing.

2.2 Operational and reading data

Site, asset, and meter/gauge reading records your organisation captures through the web application, mobile application, or telemetry API — including numeric reading values, timestamps, and the identity of the user who captured each reading. Where you choose to attach evidence to a reading, this may include a photograph and the device's GPS coordinates at the time of capture. Photo and location capture on the mobile application only occurs with your device's camera/location permission, and only when you actively attach that evidence to a reading — the app does not track location in the background.

2.3 Device and authentication data

When you log in from the mobile application or a third-party integration, we issue an API access token scoped to your account and device. We record when a token is issued, last used, and revoked (e.g. on logout), but we do not collect a general device identifier, advertising ID, or contacts/media library access beyond the specific photo you choose to upload.

2.4 Billing information

Subscription and invoice records. Card payment details are collected and processed directly by our payment processor, PayFast, on their own hosted, PCI-compliant pages — we never receive or store your full card number.

2.5 Website usage

Standard web server logs (IP address, browser, timestamp) for the marketing website and application, and any information you submit through the public contact form.

3. How we use your information

  • To provide the Service — authenticating you, storing and displaying readings, generating reports, and running scheduled/threshold/reconciliation checks your organisation configures.
  • To operate your subscription — billing, invoicing, and payment processing via PayFast.
  • To communicate with you — service notifications, scheduled report emails, replies to support/contact requests, and essential account or billing notices.
  • To maintain an audit trail — every reading and record change is attributed to the user and timestamp that made it, for accountability within your organisation.
  • To keep the Service secure and reliable — detecting abuse, rate-limiting, and diagnosing faults from error logs.

We do not sell your personal information, and we do not use reading data, photos, or location data for advertising.

4. Multi-tenant data isolation

ReportingServices is multi-tenant: every organisation's sites, assets, readings, users, and files are logically isolated and only accessible to authenticated users of that same organisation, or to platform administrators acting in a support capacity (see section 6).

5. Sharing your information

We share personal information only with the following categories of recipient, and only as needed to operate the Service:

  • PayFast — our payment processor, to process subscription payments.
  • Your organisation's own configured integrations — if your organisation enables outbound webhooks to its own third-party systems, reading data is sent to the destinations your organisation's administrators configure. We are not responsible for how your organisation's own destination system handles that data.
  • Infrastructure and hosting providers — who host our servers and database under contractual confidentiality obligations, strictly to operate the Service.
  • Legal and regulatory bodies — where required by law.

6. Platform administrator access

ReportingServices platform administrators can, for legitimate support purposes, view tenant configuration and — where explicitly initiated — sign in as a tenant user to help diagnose an issue. Every such action is logged against the real administrator's identity in an audit trail, and is visible to your organisation via a persistent on-screen notice for the duration of the session.

7. Data retention

We retain account and operational data for as long as your organisation's subscription is active, and for a reasonable period afterwards to meet accounting, tax, and legal record-keeping obligations. Deleted records (sites, assets, reading types, and readings) are held in a recoverable trash state before permanent removal, so your organisation can undo accidental deletions. API access tokens are revoked immediately on logout or account removal.

8. Your rights under POPIA

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate or outdated personal information.
  • Request deletion of your personal information, subject to our legal and legitimate business retention needs (e.g. financial records).
  • Object to processing of your personal information in certain circumstances.
  • Withdraw consent, where processing is based on consent, without affecting processing already carried out.
  • Lodge a complaint with the Information Regulator (South Africa) if you believe your rights have been infringed.

Your organisation's administrator can raise a data export or deletion request for your account directly within the application. You may also contact us using the details in section 12.

9. Mobile application permissions

The ReportingServices mobile application may request the following device permissions. Each is optional to the extent the underlying feature is optional, and is only used for the stated purpose:

  • Camera / photo library — to attach a photo to a reading you are capturing. Used only when you choose to attach a photo.
  • Location — to record the GPS coordinates of a reading at the moment you capture it. Used only at the point of capture, never tracked continuously in the background.
  • Network access — required to sign in and sync readings with your organisation's account.

You can decline any of these permissions in your device settings; declining camera or location permission only disables the optional photo/GPS evidence fields, not the ability to capture a reading.

10. Security

We use industry-standard measures to protect your information, including encryption of stored payment-gateway and integration credentials, hashed passwords, HMAC-signed webhook delivery, and role-based access control within each organisation. No system is completely secure, and we cannot guarantee absolute security of information transmitted over the internet.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page. Continued use of the Service after a change constitutes acceptance of the updated policy.

12. Contact us

For any question about this policy, or to exercise your rights under POPIA, contact us at support@reportingservices.co.za or via our contact form.