WORKING DRAFT for a South African attorney to finalise. Not legal advice and not a substitute for an attorney. Cherrystone Business Services intellectual property · © 2026 Cherrystone Business Services (Pty) Ltd.
| Issue record | |
|---|---|
| Issue | [n], issued with proposal [ref] to [client] on [date] |
| AI tooling statement | Verified on 4 October 2026 by [name]. Re-verify before every issue of this standard |
| Signed | Zander Kirstein, Founder and Information Officer |
How your information is handled
This standard is written for the sceptical reader. Every statement in it should be checkable. If any statement turns out not to be true of your engagement, we have broken the standard. Tell us.
1. The short version
- Your information stays in your workspace.
- Only one thing ever leaves it for our own use: a sanitised pattern report. It contains no names, no figures and no documents. We tell you in writing whenever we file one.
- No AI runs inside Ipso. At build time we may use Claude, under Anthropic's commercial terms, to read documents you give us. Anthropic may not train its models on them.
- We keep what we extract from your documents. The raw documents are deleted when the engagement closes, or sooner if you ask.
- Your package derives every figure itself, and it runs offline in your hands.
2. The client wall
What stays in your workspace:
- documents and workbooks you upload;
- your parameters and structure, saved as versions, each with its parameter hash;
- observed actuals, with who entered them, how and when;
- reads: verbs, each with its written reason, issued by a named reader;
- receipts;
- the register of your package builds.
What is stored nowhere: derived figures. Every figure is computed from your parameters each time a package opens.
What leaves your workspace. Only a sanitised pattern report: what the engagement taught us about the method, such as a new kind of view, intake friction, objections or timing. It contains:
- no names of you, your people or your systems;
- no figures and no parameter values;
- no documents and no extracts.
We tell you in writing, with the date, each time we file one.
What never happens to your information:
- it is never used to build another client's package;
- it never appears in a demonstration (our demos use synthetic data only);
- it is never used to train any AI model.
Who can see your workspace:
- your own users, according to the role each one has;
- named Cherrystone staff working on your account;
- a certified partner collector, but only if your Statement of Work names them.
3. The Intake Room and its receipts
Every intake, whether an upload or a workbook, produces a numbered receipt in four parts:
| Part | What it records |
|---|---|
| Received | Each file: its name, size and SHA-256 fingerprint, who uploaded it, and when |
| Extracted | The parameters, stages, systems and levers taken from the file, each with its source reference and evidence grade, and how it was extracted (by hand, or with Claude) |
| Crossed the wall | Anything that left your workspace because of this intake. Normally nothing. Never a document, never a figure |
| Discarded | What we deleted, and when |
A receipt keeps a file's name and fingerprint, never its contents. Name your files without personal details.
Where your sources disagree with each other, we log the disagreement. We never quietly fix it. The disagreement log is part of what you receive.
4. AI tooling statement
Verified on 4 October 2026. Re-verify before every issue of this standard.
Which tool. Claude, made by Anthropic, used through [the Anthropic API under Anthropic's Commercial Terms of Service] [or: a Claude Team or Enterprise plan]. It is always a commercial account, never a consumer one (Free, Pro or Max).
Under what terms. Anthropic's Commercial Terms, effective 17 June 2025, state: "Anthropic may not train models on Customer Content from Services." Under the same terms, the customer keeps its rights in what it submits, and Anthropic's Data Processing Addendum applies. That addendum commits Anthropic to notify security breaches within 48 hours.
When it is used. Only at build time: during a Studio session, a Sprint or a re-snap. In each case Cherrystone staff extract parameters from documents you supplied. [Founder to confirm: whether Claude also helps build your package or draft the read from your parameters. If it does, say so here. Verbs and written reasons are always reviewed and issued by a named Cherrystone reader, who is accountable for them.]
What it sees. The document, or the relevant part of it. Before a document goes to the tool, we remove the identifiers the extraction does not need, wherever the format allows. It does not see the rest of your workspace.
What persists at Anthropic:
- Default retention. Anthropic deletes API inputs and outputs within 30 days.
- Zero-data-retention. [Cherrystone has / has not] arranged zero-data-retention with Anthropic. [If it has: prompts and outputs are not stored once the response is returned.]
- Flagged content. If Anthropic's automated safety systems flag a request, Anthropic may keep its inputs and outputs for up to two years.
- Location. Data is stored in the USA. Processing may run in other regions Anthropic uses, unless we restrict it to the USA.
- [If a Team or Enterprise plan is used instead of the API: chats are kept until they are deleted, then removed from Anthropic's systems within 30 days. Zero-data-retention does not apply to those interfaces.]
What persists at Cherrystone. The extraction persists in your workspace: parameters, each with its source and grade. Local working copies and tool transcripts are deleted once the extraction is done.
What we never do:
- put your material into a consumer AI account;
- send your material to any AI provider as feedback or as a bug report;
- let a partner put your material into their own AI tools.
At runtime there is no AI. Your package is a single HTML file. It contains no AI, no tracking and no outside connections. It makes no network calls when you open it offline. Observations you enter offline stay in that browser, on that device, and we cannot see them.
[Option: if you prefer that no AI tool sees your documents, tell us before intake. We will extract by hand and agree any change to the timetable.]
5. Identifiers stripped
The parameters we keep are rates, counts, durations and capacities. They are not records about people.
Your model holds a person's name only where you choose to record one: a stage owner, a source, or the person who observed a value.
We remove identifiers before material goes to any AI tool. Where a format makes that impractical, such as a scanned diagram, the receipt says so.
6. Raw documents
- We process raw documents to extract parameters. The extraction is what persists.
- We delete raw documents when the engagement they were supplied for closes (the findings meeting), or sooner if you ask.
- To keep a document in your workspace as evidence, ask us in writing.
- Every deletion is recorded in the receipt.
7. Where your data is hosted
| What | Who | Where |
|---|---|---|
| The application | Vercel | Global edge network; application functions in Frankfurt [confirm] |
| Database and files | Supabase, on AWS | Frankfurt, Germany (eu-central-1); encrypted at rest |
| Email (sign-in links, invitations) | Resend | USA; emails sent from [Ireland] |
| Card payments | Paystack South Africa (a Stripe company) | Servers in Ireland. We never receive full card numbers |
| EFT payments | Our bank | South Africa |
| AI-assisted extraction | Anthropic | USA (see section 4) |
South African residency. If you need your data held in South Africa, we can host your database and files in AWS Cape Town or Azure Johannesburg, quoted separately. Your Statement of Work will then state exactly what still leaves South Africa: typically sign-in email and any AI-assisted extraction.
8. Retention
| What | How long |
|---|---|
| Raw documents | Until the engagement closes, or sooner on request |
| Workspace content | For the life of your subscription, plus a [90]-day export window. Then deleted. Backups roll off within 7 days |
| Receipts | With your workspace |
| Invoices | [Seven] years, as tax and company law require |
| AI provider | 30 days by default. None, under zero-data-retention. Up to two years if flagged (section 4) |
9. The incident rule
If we have reasonable grounds to believe that your information has been accessed or acquired without authority, we will:
- Tell you immediately: without undue delay, and in any event within 72 hours of becoming aware. We share what we know, and update you as we learn more.
- Contain the incident and preserve the evidence.
- Help you notify the Information Regulator, through its eServices portal, and the people affected, as section 22 of POPIA requires.
- Write up what happened and what we changed, and give you a copy.
10. Questions
Ask the person who sent you this standard, or our Information Officer:
- Information Officer: Zander Kirstein
- Email: privacy@cherrystone.co.za
- Telephone: [telephone]
We answer in writing. The Data Processing Terms and the Privacy Notice set out the detail behind this standard.
Sources checked (all on 4 October 2026)
- Anthropic Commercial Terms of Service (anthropic.com/legal/commercial-terms, effective 17 June 2025).
- Anthropic Data Processing Addendum (anthropic.com/legal/data-processing-addendum, effective 24 February 2025).
- "How long do you store my organization's data?" (privacy.claude.com/en/articles/7996866, updated 1 July 2026): API inputs and outputs deleted within 30 days; flagged content kept up to 2 years.
- "API and data retention" (platform.claude.com/docs/en/manage-claude/api-and-data-retention): zero-data-retention is arranged per organisation, does not cover consumer, Team or Enterprise interfaces, and excludes certain models and features.
- "Data residency" (platform.claude.com/docs/en/manage-claude/data-residency): storage in the USA; inference "global" by default, or restricted to the USA.
- Consumer retention, for contrast (privacy.claude.com/en/articles/10023548, updated 1 July 2026): consumer accounts may be used for training if the user allows it, with retention of up to 5 years. This is why consumer accounts are excluded.
- Hosting: vercel.com/docs/regions; Supabase DPA and security pages; resend.com/docs/dashboard/domains/regions; paystack.com/za/terms.
- POPIA ss21(2) and 22 (popia.co.za); eServices breach reporting, mandatory since 1 April 2025 (werksmans.com).