Legal
This policy covers the ReportingServices website, web application, and mobile application, and explains how we collect, use, and protect your information in accordance with South Africa's Protection of Personal Information Act, 2013 (POPIA).
Last updated: 7 August 2026
ReportingServices ("ReportingServices", "we", "us") operates the ReportingServices website, the web application accessible to signed-up organisations ("tenants"), and the ReportingServices mobile application (together, the "Service"). We are the responsible party for personal information processed through the Service, as defined under POPIA.
ReportingServices
South Africa
We collect different information depending on how you use the Service.
Name, email address, phone number, and password (stored as a salted hash, never in plain text) when you or your organisation sign up, are invited as a user, or are added as a platform administrator. Organisation billing details — legal name, VAT number, registration number, billing address, and billing email — when provided for invoicing.
Site, asset, and meter/gauge reading records your organisation captures through the web application, mobile application, or telemetry API — including numeric reading values, timestamps, and the identity of the user who captured each reading. Where you choose to attach evidence to a reading, this may include a photograph and the device's GPS coordinates at the time of capture. Photo and location capture on the mobile application only occurs with your device's camera/location permission, and only when you actively attach that evidence to a reading — the app does not track location in the background.
When you log in from the mobile application or a third-party integration, we issue an API access token scoped to your account and device. We record when a token is issued, last used, and revoked (e.g. on logout), but we do not collect a general device identifier, advertising ID, or contacts/media library access beyond the specific photo you choose to upload.
Subscription and invoice records. Card payment details are collected and processed directly by our payment processor, PayFast, on their own hosted, PCI-compliant pages — we never receive or store your full card number.
Standard web server logs (IP address, browser, timestamp) for the marketing website and application, and any information you submit through the public contact form.
We do not sell your personal information, and we do not use reading data, photos, or location data for advertising.
ReportingServices is multi-tenant: every organisation's sites, assets, readings, users, and files are logically isolated and only accessible to authenticated users of that same organisation, or to platform administrators acting in a support capacity (see section 6).
We share personal information only with the following categories of recipient, and only as needed to operate the Service:
ReportingServices platform administrators can, for legitimate support purposes, view tenant configuration and — where explicitly initiated — sign in as a tenant user to help diagnose an issue. Every such action is logged against the real administrator's identity in an audit trail, and is visible to your organisation via a persistent on-screen notice for the duration of the session.
We retain account and operational data for as long as your organisation's subscription is active, and for a reasonable period afterwards to meet accounting, tax, and legal record-keeping obligations. Deleted records (sites, assets, reading types, and readings) are held in a recoverable trash state before permanent removal, so your organisation can undo accidental deletions. API access tokens are revoked immediately on logout or account removal.
Subject to applicable law, you have the right to:
Your organisation's administrator can raise a data export or deletion request for your account directly within the application. You may also contact us using the details in section 12.
The ReportingServices mobile application may request the following device permissions. Each is optional to the extent the underlying feature is optional, and is only used for the stated purpose:
You can decline any of these permissions in your device settings; declining camera or location permission only disables the optional photo/GPS evidence fields, not the ability to capture a reading.
We use industry-standard measures to protect your information, including encryption of stored payment-gateway and integration credentials, hashed passwords, HMAC-signed webhook delivery, and role-based access control within each organisation. No system is completely secure, and we cannot guarantee absolute security of information transmitted over the internet.
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page. Continued use of the Service after a change constitutes acceptance of the updated policy.
For any question about this policy, or to exercise your rights under POPIA, contact us at support@reportingservices.co.za or via our contact form.