Skip to content
VumaBillExplore VumaBill

LEGAL INFORMATION · UPDATED 9 SEPTEMBER 2026

Privacy policy

How personal information is handled when you browse VumaBill, use a workspace or contact support.

1. Our roles under POPIA

The operator identified above determines the purposes of processing account, subscription, security and support information and acts as a responsible party for that processing. Businesses using VumaBill generally determine why their own customer and billing records are processed. VumaBill processes those records to provide the service on their instructions, acting as an operator where applicable. A customer-record request may need to be referred to the relevant business.

2. Information collected and its sources

We receive account names and email addresses, company and team details, business contact and banking information, customer records, quotes, invoices, payments, credits, attachments and support messages from users and workspace members. Service providers may supply authentication, delivery and payment status information. Hosting and security services receive technical data such as IP address, browser information, timestamps and security events. Google Fonts receives connection information when fonts load; Google Places receives address searches when that feature is used.

3. Purposes and lawful grounds

We process information to create accounts, deliver requested billing tools, send transactional messages, administer subscriptions, answer support requests and protect the service. Depending on the purpose, processing relies on steps to enter or perform a contract, a legal obligation, a legitimate interest assessed against your rights, or valid consent where required. Required fields are needed to perform the relevant task; without them it may not be possible to create an account, issue a document or process a request. Optional information can be omitted.

4. Sharing and service providers

Information is accessible to authorised workspace members and personnel who need it for service delivery or support. Google Firebase and Google Cloud provide authentication, hosting, database, file storage, security and AI infrastructure. Brevo supports transactional email. Payment providers process payment information when online payment services are used. Information may also be disclosed when lawfully required or to investigate misuse or resolve disputes. Do not assume a public invoice or document link is private from anyone who possesses that link.

5. AI features and conversations

Questions and recent conversation context submitted to the AI help tool are sent to Google’s AI service to generate a response. The help tool uses product guidance; it does not independently retrieve company financial records. For business AI features, submit only the records necessary for your request and for which you have authority. Do not include passwords, full card details or unnecessary sensitive personal information. An AI response is assistance for a person to review, not an instruction to make a legally significant decision about someone.

6. Processing outside South Africa

Service providers may process information outside South Africa. The application uses Google Cloud Functions in the United States and global AI services. Cross-border processing must meet section 72 of POPIA, including an applicable adequate-protection arrangement, binding agreement or another lawful ground. You may request information about the relevant providers and transfer safeguards using the privacy contact above.

7. Retention and deletion

Information is kept for as long as necessary for its stated purpose, applicable record-keeping duties, a dispute or another lawful retention requirement. Closing an account does not necessarily erase invoices another business must retain. Request deletion through the privacy contact; identity and authority may need to be verified. We will explain any lawful reason that prevents deletion. Deletion from active systems and expiry of backup copies may occur at different times.

8. Security and incidents

We use authentication, access restrictions and service-provider security controls to protect information. No online service can guarantee absolute security. Protect your login and report suspected unauthorised access promptly. Where a security compromise triggers POPIA notification obligations, the responsible party must notify the Information Regulator and affected data subjects as soon as reasonably possible, subject to lawful exceptions. An operator must notify the responsible party immediately on reasonable grounds of unauthorised access or acquisition.

9. Your rights and how to exercise them

You may request confirmation of processing and access to your information, ask for correction or deletion where justified, object to processing on grounds provided by POPIA, or withdraw consent for future consent-based processing. Withdrawal does not undo earlier lawful processing. Send your request to the privacy contact above, describing the information and the action requested. We may ask for proportionate identity verification. Access requests may also follow PAIA procedures, including any lawful fees and applicable exceptions.

10. Marketing and children

Transactional messages about your account, invoices and security are distinct from marketing. Electronic direct marketing requires a lawful basis under POPIA, including consent or the applicable existing-customer exception, and a way to object or unsubscribe. VumaBill is a business service and is not intended for children to create accounts independently. Do not submit children’s or special personal information without the necessary authority and safeguards.

11. Complaints and changes

You can raise concerns with our privacy contact and complain to South Africa’s Information Regulator. Visit https://inforegulator.org.za/popia-forms/ or contact enquiries@inforegulator.org.za. We will update this notice when material processing practices change and communicate changes where required.

Information Regulator: privacy requests and complaints