Privacy Policy

Last updated:

This policy explains how iKhaya (“we”, “us”) processes personal information of property owners, tenants, and contractors in line with the Protection of Personal Information Act, 2013 (POPIA).

1. Data controller

The responsible party (data controller) under POPIA is iKhaya. For access, correction, or deletion requests, contact the Information Officer at admin@ikhaya.online.

2. Notification of collection (POPIA s.18)

We collect personal information directly from you when you register an account, list a property, submit a maintenance request, or otherwise interact with the service. The categories we collect include: name, email address, phone number, ID number (where you choose to provide it for tenant onboarding), property and lease details, payment-related metadata, and message content you send through the platform.

The lawful basis for processing is performance of a contract (the property-management service you have signed up for) and our legitimate interest in operating and securing the service. Provision of identifying information is voluntary; without it, we may be unable to offer parts of the service such as tenant onboarding or contractor coordination.

3. How we use your information

4. Operators (sub-processors) we share data with

We use a small number of operators to deliver the service. Each is contractually bound to process personal information only on our instructions and to maintain appropriate security safeguards.

5. Retention period

We retain personal information for as long as your account is active and for a further seven years after closure, to comply with South African tax and accounting record-keeping obligations. Backups containing closed-account data are pruned within 35 days of their creation cycle. Where you exercise a deletion right, we remove the underlying records within 30 days, retaining only what law obliges us to keep.

Tax pack exports are an exception with a defined lifespan: when you export a tax pack you confirm your inputs are accurate, and we keep an encrypted copy of that exact export together with a record of your confirmation (account identifier, IP address, timestamp, and a cryptographic fingerprint of the file) for five years as evidence in the event of a dispute, relying on POPIA section 14's provision for records retained for evidentiary purposes. These records survive account deletion under a restricted legal hold, are not used for any other purpose, and are deleted automatically when the five years elapse.

Email finance ingestion has a similar exception. Where you enable this feature, every forwarded email — whether it is logged, flagged for your review, or rejected outright — is written to an encrypted evidence archive (the original attachment bytes, the message metadata, and a record of the automated malware-scanning and extraction gates it passed through) for five years, relying on the same POPIA section 14 provision for records retained for evidentiary purposes described above. This archive lets us show, in the event of a dispute over what was logged to your books, what was actually forwarded and what our pipeline did with it. It survives account deletion under the same restricted legal hold as the tax pack archive, is not used for any other purpose, and is deleted automatically when the five years elapse. This is separate from, and does not extend, Resend's own retention of the forwarded email described in Section 4.

6. Your rights (POPIA s.23 and s.24)

You have the right under POPIA s.23 to request access to the personal information we hold about you, and under POPIA s.24 to request correction of inaccurate information or deletion of information we are no longer entitled to retain. Send requests to admin@ikhaya.online. We respond within 30 days.

You may also lodge a complaint with the Information Regulator of South Africa if you believe your rights under POPIA have been breached.

7. Cross-border transfers

Some operators (notably Resend, Telegram, GCS) may process data outside the Republic of South Africa. POPIA permits these transfers where the recipient is bound by laws or binding agreements that provide an adequate level of protection.

8. Security

We use TLS in transit, encryption at rest for the database and object storage, role-based access controls, and per-organisation tenancy isolation enforced at the application and database layer.

9. Updates to this policy

We update this policy when our processing practices change. The last-updated date at the top of this page reflects the most recent revision.

We use cookies to keep iKhaya secure and to understand how landlords use the product. Essential cookies are always on; analytics and marketing cookies are off until you choose. See our cookie policy and privacy policy.