Privacy Policy
Last updated:
This policy explains how iKhaya (“we”, “us”) processes personal information of property owners, tenants, and contractors in line with the Protection of Personal Information Act, 2013 (POPIA).
1. Data controller
The responsible party (data controller) under POPIA is iKhaya. For access, correction, or deletion requests, contact the Information Officer at admin@ikhaya.online.
2. Notification of collection (POPIA s.18)
We collect personal information directly from you when you register an account, list a property, submit a maintenance request, or otherwise interact with the service. The categories we collect include: name, email address, phone number, ID number (where you choose to provide it for tenant onboarding), property and lease details, payment-related metadata, and message content you send through the platform.
The lawful basis for processing is performance of a contract (the property-management service you have signed up for) and our legitimate interest in operating and securing the service. Provision of identifying information is voluntary; without it, we may be unable to offer parts of the service such as tenant onboarding or contractor coordination.
3. How we use your information
- To deliver the property-management features of the service.
- To send transactional notifications about your account, leases, and maintenance threads.
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To comply with legal obligations under South African law, including POPIA, the Companies Act, and tax legislation.
- Where an organisation opts in to email finance ingestion, to process finance documents (levy, rates, insurance, and utility invoices) forwarded to that organisation's dedicated ingest address: scanning attachments for malware, rebuilding a clean rendition, and extracting vendor, amount, date, and category details to populate that organisation's expense ledger. This is automated processing only — we do not read or otherwise use the content of forwarded emails beyond what this automated pipeline requires, and we help with a specific email only if you ask us to. See Section 4 and Section 5 for how forwarded documents are handled and retained.
4. Operators (sub-processors) we share data with
We use a small number of operators to deliver the service. Each is contractually bound to process personal information only on our instructions and to maintain appropriate security safeguards.
- Resend — transactional email delivery (account notifications, password resets) and, for organisations that opt in to email finance ingestion, receiving the finance documents you forward to your dedicated ingest address. Forwarded emails and their attachments transit Resend's infrastructure and may be retained by Resend under their own platform policies after we have processed them — Resend does not offer a deletion API for received email, so we cannot instruct them to delete the source message on your behalf. We do not rely on Resend for retention control: our own working copies of a forwarded email are deleted once processing completes, and only your account data (the clean, malware- scanned rendition attached to the resulting expense) and the encrypted evidence archive described in Section 5 persist on our side.
- Telegram (Telegram Messenger Inc.) — opt-in message delivery for tenant and contractor coordination. Only users who connect Telegram themselves are reachable there.
- PayFast — payment processing for subscription billing only (we do not collect or store card numbers).
- Google Cloud Storage (GCS) — object storage for uploaded documents and images.
- Postgres database host — managed Postgres hosting in South Africa or the European Union for relational data.
5. Retention period
We retain personal information for as long as your account is active and for a further seven years after closure, to comply with South African tax and accounting record-keeping obligations. Backups containing closed-account data are pruned within 35 days of their creation cycle. Where you exercise a deletion right, we remove the underlying records within 30 days, retaining only what law obliges us to keep.
Tax pack exports are an exception with a defined lifespan: when you export a tax pack you confirm your inputs are accurate, and we keep an encrypted copy of that exact export together with a record of your confirmation (account identifier, IP address, timestamp, and a cryptographic fingerprint of the file) for five years as evidence in the event of a dispute, relying on POPIA section 14's provision for records retained for evidentiary purposes. These records survive account deletion under a restricted legal hold, are not used for any other purpose, and are deleted automatically when the five years elapse.
Email finance ingestion has a similar exception. Where you enable this feature, every forwarded email — whether it is logged, flagged for your review, or rejected outright — is written to an encrypted evidence archive (the original attachment bytes, the message metadata, and a record of the automated malware-scanning and extraction gates it passed through) for five years, relying on the same POPIA section 14 provision for records retained for evidentiary purposes described above. This archive lets us show, in the event of a dispute over what was logged to your books, what was actually forwarded and what our pipeline did with it. It survives account deletion under the same restricted legal hold as the tax pack archive, is not used for any other purpose, and is deleted automatically when the five years elapse. This is separate from, and does not extend, Resend's own retention of the forwarded email described in Section 4.
6. Your rights (POPIA s.23 and s.24)
You have the right under POPIA s.23 to request access to the personal information we hold about you, and under POPIA s.24 to request correction of inaccurate information or deletion of information we are no longer entitled to retain. Send requests to admin@ikhaya.online. We respond within 30 days.
You may also lodge a complaint with the Information Regulator of South Africa if you believe your rights under POPIA have been breached.
7. Cross-border transfers
Some operators (notably Resend, Telegram, GCS) may process data outside the Republic of South Africa. POPIA permits these transfers where the recipient is bound by laws or binding agreements that provide an adequate level of protection.
8. Security
We use TLS in transit, encryption at rest for the database and object storage, role-based access controls, and per-organisation tenancy isolation enforced at the application and database layer.
9. Updates to this policy
We update this policy when our processing practices change. The last-updated date at the top of this page reflects the most recent revision.