WORKING DRAFT for a South African attorney to finalise. Not legal advice and not a substitute for an attorney. Do not publish until finalised and until every † item is true (see the README). Cherrystone Business Services intellectual property · © 2026 Cherrystone Business Services (Pty) Ltd.
Privacy Notice
This notice explains how Cherrystone collects, uses and protects personal information on cherrystone.co.za, on the Ipso platform and in our engagements. It is written to meet section 18 of the Protection of Personal Information Act, 2013 (POPIA).
1. Who is responsible
1.1 Responsible party. Cherrystone Business Services (Pty) Ltd, registration number [Company registration number], [physical address], Johannesburg. Email privacy@cherrystone.co.za. Telephone [telephone].
1.2 Information Officer. Zander Kirstein, registered with the Information Regulator on [date] under number [registration number]. [Deputy Information Officer: none designated.]
1.3 POPIA protects juristic persons as well as natural persons. We apply this notice to information about organisations too.
2. Our two roles
2.1 Responsible party. We decide how to process information for these purposes:
- accounts, sign-in and security;
- billing;
- enquiries and marketing;
- partners and certification.
2.2 Operator. We process the content of a client's workspace on that client's behalf. That content includes documents, parameters, actuals and findings, and the names of the client's people recorded in its model. Here the client is the responsible party, and our Data Processing Terms apply. If you are named in a client's material and want to use your rights, contact that client. We will help them.
3. What we collect
| Category | What it includes | Where it comes from | Must you give it? |
|---|---|---|---|
| Account | Email address; name (optional); account creation and last sign-in dates | You, or the colleague who invites you | Email: yes. Without it we cannot sign you in |
| Sign-in and sessions | Sign-in links and session tokens (we store only hashes of them); IP address; browser type; session expiry | Collected automatically | Yes. Needed to sign you in securely |
| Workspace access | Your role in each workspace; who invited you; the email address an invitation went to | The workspace owner | Yes, to give you access |
| Security records | An audit log of significant actions (sign-ins, account creation, changes) with IP address; rate-limit counters keyed to email address or IP address | Collected automatically | Yes |
| Billing | Billing contact; company legal name, address, VAT number and order number; invoices; Paystack subscription and payment references | You | Yes, for paid plans. Tax law requires invoice details |
| Card payment notifications | From Paystack: card type, issuing bank, first six and last four card digits, expiry month and year, and cardholder name where available. Never the full card number or security code | Paystack | Yes, if you pay by card |
| Enquiries | Name, email, company, role, phone (optional), message, how you heard of us, marketing choice | Website forms | Name and email: yes, so we can reply. The rest: no |
| Marketing choice | Whether you opted in, and when | You | No |
| Partners and certified collectors | Name, email, partner firm, certification number, status, issue and expiry dates, reason for any revocation | You and your firm | Yes, to certify you |
| Workspace content (as operator) | Uploaded documents and workbooks; the model and its parameters; names and roles of client staff recorded as stage owners, sources or observers; actuals, with who entered them and when; findings; receipts; package builds with the licensee's name | The client and its users | The client decides |
| Hosting logs | Technical request data (IP address, time, address requested, browser) kept by our hosting provider | Collected automatically | Yes, to deliver and protect the service |
4. Why we use it, and on what basis
| Purpose | Lawful basis (POPIA s11) |
|---|---|
| Create your account, sign you in and give you workspace access | Contract (s11(1)(b)) where you are our client. Otherwise, our legitimate interest and our client's in giving its users access (s11(1)(f)) |
| Keep Ipso secure: rate-limit sign-in, keep audit logs, prevent abuse | Legitimate interest (s11(1)(f)); our legal duty to secure information (ss11(1)(c), 19) |
| Deliver the services a client orders (Studio, Sprint, re-snaps), including extraction at build time | Contract (s11(1)(b)). As operator, we act on the client's instructions |
| Invoice, collect payment and keep tax records | Contract (s11(1)(b)); legal obligation (s11(1)(c)) |
| Answer enquiries and arrange sessions | Steps you asked for before a contract (s11(1)(b)); legitimate interest (s11(1)(f)) |
| Send marketing emails | Your consent (s11(1)(a), s69). [Option: for clients, our similar services under s69(3)] |
| Run partner certification and the public register | Contract (s11(1)(b)); legitimate interest in letting clients check a certificate (s11(1)(f)) |
| Comply with the law, answer regulators and defend claims | Legal obligation (s11(1)(c)); legitimate interest (s11(1)(f)) |
We do not sell personal information. We make no automated decisions with legal effect about you. No AI runs inside Ipso.
Pattern reports are written so that they contain no personal information. See the Terms of Service, clause 6.5.
5. Who we share it with
5.1 Operators. We use the following providers. Each processes personal information only on our instructions, under a written agreement.
| Operator | What it does for us | Where it processes | Safeguards |
|---|---|---|---|
| Vercel Inc. (USA) | Hosts the Ipso web application | Global edge network. App functions run in Frankfurt (fra1)†. Vercel's own systems and logs are mainly in the USA | Vercel Data Processing Addendum, with EU Standard Contractual Clauses; SOC 2 Type 2 |
| Supabase (Supabase Pte. Ltd, Singapore, on AWS infrastructure) | Database and file storage | Frankfurt, Germany (AWS eu-central-1). Account and support data may be processed elsewhere, including the USA | Supabase Data Processing Addendum, with EU Standard Contractual Clauses; encrypted at rest (AES-256); SOC 2 Type 2; ISO 27001 |
| Resend (Plus Five Five, Inc., USA) | Sends sign-in links, invitations and notices | Account data, email metadata and logs: USA. Sending region: [Ireland (eu-west-1)]† | Resend Data Processing Agreement, with EU Standard Contractual Clauses; EU-US Data Privacy Framework certification |
| Paystack South Africa (Pty) Ltd (a Stripe company) | Card subscriptions | Servers in Ireland (AWS). Transfers to the USA and possibly Nigeria | PCI DSS; ISO 27001 and 27701. Paystack processes payments for us and also has its own legal and card-scheme duties |
| Anthropic (Claude) | At build time only: AI-assisted extraction of parameters from documents clients supply for an engagement [and drafting support for the read — confirm]. Never inside the product | Data stored in the USA. Processing may run in other regions Anthropic uses unless we restrict it to the USA | Anthropic Commercial Terms, under which Anthropic may not train models on our content; Data Processing Addendum with EU Standard Contractual Clauses; retention as in section 7 |
| [Business email and file provider — complete] | Staff email and working files | [ ] | [ ] |
| [Accounting software — complete] | Bookkeeping and invoices | [ ] | [ ] |
5.2 Others.
- Our bank, for EFT payments.
- Our professional advisers and auditors.
- SARS and other authorities, where the law requires it.
- A certified partner, where your engagement names one. The partner sees only what that engagement needs.
6. Transfers outside South Africa (POPIA s72)
6.1 Most of our providers store or process information outside South Africa. They do so in the European Union (Germany and Ireland) and in the USA. Anthropic may also use other regions.
6.2 We transfer personal information only on one of the grounds s72 allows:
- s72(1)(a): a binding agreement. The recipient is bound by a written agreement that gives protection substantially similar to POPIA's conditions, including limits on onward transfer.
- s72(1)(c): our contract with you. The transfer is necessary to perform our contract with you, or to take steps you asked for.
- s72(1)(d): a contract in your interest. The transfer is necessary for a contract made in your interest.
6.3 South Africa has no official list of adequate countries. We rely on our providers' written agreements. The European Union locations are also subject to the GDPR. [Attorney: confirm that the GDPR-form agreements meet s72(1)(a).]
6.4 South-African-resident hosting. Clients who need their data held in South Africa can have it hosted in AWS Cape Town or Azure Johannesburg, by agreement. Even then, three things may still involve processing outside South Africa unless the agreement says otherwise: sign-in emails, card payments and AI-assisted extraction.
6.5 We do not transfer special personal information or children's personal information outside South Africa.
7. How long we keep it
| Information | How long we keep it |
|---|---|
| Account | While you have access to any workspace. Deleted [24] months after your last sign-in if you have none, or sooner if you ask |
| Sign-in links (hashes and IP address) | Expire after 20 minutes. Deleted after 2 days† |
| Sessions (hash, IP address, browser) | Expire after 30 days. Deleted when they expire, or at once when you sign out† |
| Rate-limit counters | 24 hours† |
| Audit log | 24 months†, except the record that an invoice was applied, which is kept with the invoice |
| Workspace content (as operator) | For the life of the workspace, plus [90] days after a paid plan ends. Studio workspaces are closed after 12 months without activity. Then deleted |
| Raw documents | Until extraction is done and the engagement closes, or sooner on request. The receipt keeps only the file's name, size and fingerprint |
| Invoices and payment records | [Seven] years, for tax and company law |
| Paystack payment notifications | 90 days†, stored without card details. After that we keep only the reference, amount and status |
| Enquiries | [24] months after last contact, unless you become a client |
| Marketing opt-out record | Your email address and the opt-out date, kept for as long as we send marketing, so that we never contact you again |
| Certification register | The certification period plus [5] years |
| Database backups | Roll off within 7 days [on our current Supabase plan]. Stored files are not part of these backups |
| Anthropic (AI-assisted extraction) | Deleted within 30 days by default. Up to 2 years if Anthropic's safety systems flag a request. [Not stored once a response is returned, if a zero-data-retention arrangement is in place] |
| Provider logs (Vercel, Resend) | As each provider's settings determine [confirm] |
† Drafting note: these items are not yet true in the platform (README, "Make these true before issue"). Delete this note once they are.
8. How we protect it (POPIA s19)
8.1 Technical measures.
- Sign-in. You sign in with a single-use link that expires in 20 minutes. There are no passwords to steal. We store only hashes of sign-in links and session tokens.
- Session cookie. It is HttpOnly and Secure, and the browser does not send it with most requests made from other sites.
- Changes. Any change must come from our own site and carry a per-session anti-forgery token.
- Rate limits. Sign-in requests are rate-limited, by email address and by IP address. [Confirm: uploads and forms.]
- Roles. Each workspace has owners, editors, viewers and collectors. Cherrystone staff access is limited to named staff accounts.
- Encryption. Data is encrypted in transit (TLS) to the app and the database. The database and file storage are encrypted at rest.
- Files. Uploads and downloads go straight to storage through signed links that expire within minutes. Upload size is limited.
- Package text. Text entered into a model is cleaned so that it cannot run as code inside a package.
- Audit log. Significant actions are logged.
8.2 By design.
- Derived, never stored. Figures are computed in your browser from parameters. We hold the inputs, not a database of results.
- Documents. Raw documents are deleted after extraction. What persists is the extraction.
- Offline packages. A package can run offline. Observations entered in an offline package stay in that browser on your device, and we never receive them.
8.3 Organisational measures.
- Providers. Our providers hold independent security assurance (SOC 2, ISO 27001 or PCI DSS).
- Reviews. We review risks and safeguards at least once a year, and after any incident or significant change.
- Incidents. If we suspect a security compromise, we notify the Information Regulator through its eServices portal, and affected people, as soon as reasonably possible (s22). Clients hear from us under the Data Processing Terms.
9. Cookies and browser storage
9.1 One cookie. Ipso sets one cookie, ipso_session. It is strictly necessary: it keeps you signed in. It is HttpOnly and Secure, and it expires after 30 days or when you sign out.
9.2 No tracking. We use no analytics cookies, advertising cookies or tracking pixels. [Confirm this for cherrystone.co.za before publishing.]
9.3 Share links. A share link carries parameters after the "#" in its address. Browsers do not send that part to any server.
9.4 Offline packages. An offline package keeps your observations in your browser's local storage, on your device only.
10. Marketing
10.1 We send marketing emails only to people who opt in by ticking an unticked box. [Option: clients may also receive news of our similar services under s69(3), with an opt-out offered when we collect their details and in every message.]
10.2 We ask for consent once only.
10.3 Every marketing email identifies Cherrystone and carries a free, one-click opt-out. We honour opt-outs promptly and keep a suppression record so we do not contact you again.
10.4 Sign-in links, invitations, invoices and notices about your account or our service are not marketing.
10.5 [Attorney: registration with the National Consumer Commission opt-out registry under the CPA Amendment Regulations, 2026 — README checklist B4.]
11. Your rights
11.1 You may do any of the following:
- Access (s23). Ask whether we hold information about you. That is free. Ask for a copy or description of it, including who has received it.
- Correction or deletion (s24). Ask us to correct or delete inaccurate, out-of-date or unlawfully held information. That is free.
- Objection (s11(3)). Object to processing we base on legitimate interest. You may object to direct marketing at any time. That is free.
- Withdraw consent. You may withdraw consent at any time. Earlier processing is not affected.
- Complain. Lodge a complaint with the Information Regulator (section 12).
11.2 How to ask. Use any of these channels:
- email privacy@cherrystone.co.za;
- post or hand-deliver to [physical address];
- SMS or WhatsApp [number].
You may use the Regulator's forms, but you do not have to. If you object by telephone, we record the call and give you the recording free of charge on request.
11.3 How we respond. We confirm your identity before acting, and we respond within 30 days. If we cannot do what you ask, we tell you why. We do not charge for copies at present. [Attorney: confirm the fee position.]
12. Complaints to the Information Regulator
Information Regulator (South Africa). Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191. P.O. Box 31533, Braamfontein, Johannesburg, 2017. Telephone 010 023 5200 or 0800 017 160 (toll-free). Email enquiries@inforegulator.org.za. Lodge complaints through the eServices portal (eservices.inforegulator.org.za) or by any other means listed on inforegulator.org.za.
We would welcome the chance to put things right first. Write to privacy@cherrystone.co.za.
13. Children
Ipso is not for anyone under 18. We do not knowingly collect children's personal information. Clients must not upload it unless we have agreed in writing.
14. Changes to this notice
The version and date of this notice appear at the top. We update it whenever our processing changes. We email account holders about material changes before they take effect.
Sources checked (all on 4 October 2026)
- POPIA ss11, 18, 19, 20, 21, 22, 23, 55, 69 and 72, as published at popia.co.za (e.g. popia.co.za/section-18-notification-to-data-subject-when-collecting-personal-information/; …/section-72-transfers-of-personal-information-outside-republic/).
- Amendments to the POPIA Regulations: GN 6126, GG 52523, 17 April 2025 (justice.gov.za), as summarised by Baker McKenzie (connectontech.bakermckenzie.com). The Regulator's consolidated PDF could not be retrieved, so the regulation text is to be confirmed.
- Breach reporting through the eServices portal, mandatory since 1 April 2025: imalimatters.co.za (the Regulator's statement); Werksmans, 5 May 2026 (werksmans.com).
- Regulator contact details: eservices.inforegulator.org.za/contact.aspx; inforegulator.org.za/contact-us/; Regulator media statement of 21 April 2026; inforegulator.org.za/complaints/.
- CPA Amendment Regulations, 2026 (NCC opt-out registry): Bowmans, ENS and Cliffe Dekker Hofmeyr summaries.
- Vercel: vercel.com/legal/dpa; vercel.com/docs/regions; vercel.com/docs/functions/configuring-functions/region (default region iad1).
- Supabase: supabase.com/legal/customer-resources/data-processing-addendum; Supabase transfer impact assessment (14 March 2025); supabase.com/security; supabase.com/docs/guides/platform/backups.
- Resend: resend.com/legal/dpa; resend.com/docs/dashboard/domains/regions.
- Paystack: paystack.com/za/terms; paystack.com/za/privacy/merchant; paystack.com/docs/api/transaction/.
- Anthropic: anthropic.com/legal/commercial-terms (effective 17 June 2025); anthropic.com/legal/data-processing-addendum (effective 24 February 2025); privacy.claude.com article 7996866 (updated 1 July 2026); platform.claude.com/docs/en/manage-claude/api-and-data-retention; platform.claude.com/docs/en/manage-claude/data-residency.
- Platform facts: the Ipso source (
src/lib/db/schema.ts,auth.ts,storage.ts,ratelimit.ts,engine/runtime/*), read on 4 October 2026.