Privacy Policy

Version 1.1 · Effective September 2026

Template for review, confirm it matches your real data practices and have it checked by a professional before launch.

1. Who we are

Renvo (“we”, “us”) provides accounting and compliance software. This policy explains how we collect, use and protect personal information under the Protection of Personal Information Act, 2013 (POPIA).

2. Information we collect

Account information (name, email, company details), the financial and payroll data you enter to use the Service, and technical information such as log and device data needed to operate and secure the Service.

3. How we use it

To provide and improve the Service, process your subscription, secure your account, provide support, and meet legal obligations. We do not sell your personal information.

4. Legal basis & consent

We process personal information to perform our contract with you, to comply with the law, and on the basis of your consent where required. You may withdraw consent or object to certain processing, subject to the effect on the Service.

5. Sharing & sub-processors

We share information only with the service providers listed below, who help us run the Service under agreements requiring them to protect it. We do not sell your personal information or share it for advertising.

Vercel Inc. (United States) hosts the application. Neon Inc. (European Union) hosts the database in which your financial data is stored. Google LLC (United States) reads documents you upload or forward, such as supplier invoices and bank statements, so that the Service can extract the amounts and descriptions from them. Resend (United States) sends email on our behalf, including notifications and invitations. Paystack (South Africa and Nigeria) processes subscription payments; card details are handled by Paystack and are never stored by us.

Several of these providers are outside South Africa, so operating the Service involves transferring personal information across borders. We do so on the basis permitted by section 72 of POPIA, under contracts requiring a level of protection substantially similar to POPIA's conditions for lawful processing.

We will give notice before adding a sub-processor that materially changes how your information is handled.

6. Documents read automatically

When you upload or forward a document, its contents are sent to Google's Gemini service to be read, and the amounts, dates and descriptions found in it are returned to the Service. Those documents commonly contain personal information about third parties, such as your own clients, employees and suppliers.

The document is used to extract that information and for no other purpose. It is not used to train anybody's models. If you would prefer no document to leave the Service this way, capture bills by entering them yourself rather than uploading or forwarding them.

7. When we act for an accounting practice

Where a practice uses the Service to keep books for its own clients, the practice is the responsible party for that client information and Renvo is an operator processing it on the practice's behalf, as those terms are used in POPIA.

As operator we process client information only on the practice's documented instructions, which its use of the Service constitutes; we keep it confidential and impose the same duty on anyone we allow near it; we apply the security safeguards described in this policy; and we notify the practice without undue delay where we reasonably believe client information has been accessed by an unauthorised person, so that the practice can meet its own obligations under section 22.

The practice remains responsible for having a lawful basis to process its clients' information and for responding to those clients' requests.

8. Security

We apply reasonable technical and organisational safeguards, including access controls and encryption in transit, and isolate each company's data so that one customer cannot reach another's.

No system is perfectly secure. Where we have reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected people as soon as reasonably possible after discovering it, as section 22 of POPIA requires, describing what happened and what can be done to reduce the harm.

9. Retention

We keep personal information for as long as your account is active and as needed to comply with legal, tax and accounting obligations, after which it is deleted or anonymised.

10. Your rights

Under POPIA you may request access to, correction of, or deletion of your personal information, and may lodge a complaint with the Information Regulator. Contact us to exercise these rights.

11. Information Officer

POPIA requires every responsible party to appoint an Information Officer, registered with the Information Regulator, who is accountable for compliance and is the point of contact for access requests and complaints.

Our Information Officer is [NAME], reachable at [EMAIL] and at [POSTAL ADDRESS].

You may also complain directly to the Information Regulator of South Africa: JD House, 27 Stiemens Street, Braamfontein, Johannesburg 2001, or complaints.IR@justice.gov.za.

12. Contact

For privacy questions or requests, contact our Information Officer at the details above, or reach us via the contact page.

See also our Terms of Service.