Privacy Policy

Last updated: 22 May 2026

1. Who We Are

Origami Books is operated by Origami Consulting Group (Pty) Ltd (Reg 2022/887986/07, VAT 4810315038), Johannesburg, South Africa (“we”, “us”, “Origami Books”).

Under the Protection of Personal Information Act 4 of 2013 (“POPIA”) we are the responsible party for personal information collected directly from our users (data subjects). Where a customer organisation uses Origami Books to process the financial records of their own business, that customer organisation is the responsible party and we act as their operator in terms of sections 20–21 of POPIA, processing personal information only on their documented instructions.

2. Information Officer

Our POPIA Information Officer is the director of Origami Consulting Group (Pty) Ltd, reachable at origamiconsultinggroup@gmail.com.

3. Personal Information We Process

We process the following categories of personal information:

  • Account details: your name, email address, and password hash, collected when you sign up.
  • Financial records: bank transactions, amounts, counterparty names, receipt images, invoice data, and payroll figures that you import or upload into the service. These records may contain personal information about third parties (e.g. employee names on payroll, supplier names on invoices).
  • Usage logs: IP addresses, browser/device type, pages visited, and in-app actions, collected automatically by our hosting infrastructure.
  • Communications: emails or messages you send us, including support requests.

We do not knowingly collect the personal information of children under 18.

4. Purpose and Lawful Basis for Processing

We process personal information only for the following purposes:

  • Service delivery: creating and managing your account, storing and displaying your financial records, generating reports and exports.
  • AI features: sending transaction descriptions and receipt images to Anthropic's API for categorisation suggestions and OCR (see section 6).
  • SARS compliance: calculating tax obligations, generating deadline reminders, and producing accountant-ready documents.
  • Billing: processing subscription payments via PayFast.
  • Communications: sending transactional emails (receipts, deadline reminders, account notices) via Resend.
  • Security and abuse prevention: monitoring for unauthorised access, maintaining audit logs.
  • Legal compliance: retaining records as required by South African law (Tax Administration Act, POPIA).

The lawful bases for processing are: performance of our contract with you; compliance with a legal obligation; and our legitimate interests in operating a secure, reliable service.

5. Cookies

We use only essential session cookies required to keep you logged in and to protect against CSRF attacks. We do not use advertising, tracking, or analytics cookies. You cannot opt out of essential cookies without logging out of the service.

6. Operators (Sub-processors)

We share personal information only with the following vetted operators, strictly for the purposes described:

OperatorPurposeLocation
SupabaseDatabase, authentication, and file storage (receipts, AFS drafts)EU (Frankfurt)
VercelApplication hosting and serverless computeUSA
AnthropicAI categorisation and receipt OCR. Only transaction descriptions and receipt images are sent. Data is retained per Anthropic's API policy and is not used to train AI models.USA
GoogleOptional Gmail integration — pulling trusted-vendor receipts from your inbox. Scope-limited; only used if you explicitly connect Gmail.USA / EU
PayFastSubscription payment processing. We never store your card numbers; PayFast handles all payment card data under PCI-DSS.South Africa
ResendTransactional email (receipts, reminders, account notices)USA

We do not sell personal information to any third party.

7. Cross-Border Transfers

In terms of section 72 of POPIA, personal information is transferred to recipients in the European Union and the United States of America. These transfers are necessary to provide the service and are protected by contractual safeguards (including standard contractual clauses and data processing agreements) with each operator listed in section 6 above.

8. Retention

We retain personal information for as long as necessary for the purposes described, subject to the following:

  • Account data (name, email) is retained for the life of your account and deleted within 30 days of verified account closure, unless legal duties require longer retention.
  • Financial records are retained for a minimum of 5 years from the end of the tax year to which they relate, in accordance with section 29 of the Tax Administration Act 28 of 2011. We may retain them for up to 7 years where required by other applicable law.
  • Usage logs are retained for up to 12 months for security and debugging purposes.
  • Deletion on request is honoured subject to these legal retention duties — see section 9 below.

9. Your Rights as a Data Subject

Under POPIA you have the right to:

  • Access the personal information we hold about you (POPIA s23).
  • Correct inaccurate, incomplete, or outdated personal information (POPIA s24).
  • Delete your personal information, subject to our legal retention duties (POPIA s24).
  • Object to the processing of your personal information on reasonable grounds (POPIA s11(3)).
  • Complain to the Information Regulator if you believe we have infringed your rights under POPIA.

To exercise any of these rights, email our Information Officer at origamiconsultinggroup@gmail.com. We will respond within 30 days.

Information Regulator (South Africa)
Email: complaints.IR@inforegulator.org.za
Website: www.inforegulator.org.za

10. Security Measures

We implement appropriate technical and organisational measures to protect personal information, including:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
  • Row-level security on the database — each organisation's data is logically isolated at the database level.
  • Role-based access controls limiting which users can access which data.
  • Audit logs recording all mutating operations performed via the service or API.
  • Automatic session expiry and re-authentication requirements.

No method of transmission over the internet is 100% secure. In the event of a personal information breach we will notify affected data subjects and the Information Regulator as required by POPIA.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email before they take effect. Continued use of the service constitutes acceptance of the updated policy.

12. Contact

Questions or complaints about this policy:

Origami Consulting Group (Pty) Ltd
Johannesburg, South Africa
origamiconsultinggroup@gmail.com

Also read our Terms of Service.