Privacy Policy
This Privacy Policy explains how Codist (Pty) Ltd (“Codist”, “we”, “us”) processes personal information when you use DeskFlow Board (“the Service”) at board.app.deskflow.co.za.
1. Role under POPIA
For personal information contained in your organisation’s board materials (director names, contact details, meeting records, etc.), your organisation is typically the responsible party and Codist acts as an operator processing data on documented instructions. For account billing and support contact details, Codist may act as responsible party.
2. Processing purpose
We process personal information to:
- Provide board pack, meeting, minutes, and resolution workflow software;
- Authenticate users and enforce role-based access within your organisation;
- Deliver notifications you configure (email, web push);
- Process subscription payments via our payment provider;
- Maintain security, audit logs, and service reliability;
- Comply with lawful requests and protect our legal rights.
3. Categories of data
- Identity & contact: name, email, display name, organisation affiliation;
- Account & billing: subscription status, Paystack customer references (not full card data);
- Usage & audit: access logs, pack read progress, meeting participation metadata;
- Content you upload: documents, minutes, resolutions — treated as confidential customer data.
4. Data location & cross-border transfer
Primary application and database infrastructure is hosted with Hetzner Online GmbH in the European Union (Germany/Finland data centres). Object storage for documents uses the same region. Cross-border transfer from South Africa is undertaken with appropriate safeguards (operator agreement, technical measures, and POPIA s72 considerations). Your organisation should record this in its PAIA/POPIA compliance documentation.
5. Retention
- Active subscription: data retained for the life of the subscription and as needed to provide the Service.
- After cancellation: a 90-day export window during which administrators may download data and audit export bundles. After 90 days, tenant data (documents, meetings, user content) is permanently deleted from production systems except where law requires longer retention (e.g. billing records).
- Backups: encrypted backups may persist up to 30 days after deletion before rolling off.
6. Security
We use encryption in transit (TLS), tenant isolation, role-based access, watermarked pack delivery, and append-only audit logs. No system is perfectly secure; report concerns to banda@codist.co.za.
7. Sub-processors
Infrastructure and payment sub-processors include (non-exhaustive):
- Hetzner (hosting, EU);
- Paystack (payments, Nigeria/South Africa operations);
- Email delivery provider configured for your deployment.
8. Your rights
Data subjects may request access, correction, or deletion via their organisation administrator or by contacting banda@codist.co.za. We will assist the responsible party within reasonable time. You may lodge a complaint with the Information Regulator (South Africa).
9. Cookies
The application uses essential cookies and local storage for authentication sessions. The marketing site (this domain) does not use analytics cookies by default.
10. Changes
We may update this policy. Material changes will be notified via the Service or email to organisation administrators.
11. Contact
Codist (Pty) Ltd
Email: banda@codist.co.za