Privacy Policy
Version 1.1 · Last updated: 21 July 2026
Plain English: we only collect the information we need to run KYC Pro, we never sell it, and we keep it secure. The client information you capture belongs to you and your clients — you decide what goes in, and we process it on your behalf and on your instructions. Some features send limited information to a trusted AI provider so we can offer help and drafting tools.
1. Who we are
This Privacy Policy explains how Know Your Clients (Pty) Ltd (registration number 2023/875399/07), trading as "KYC Pro" ("KYC Pro", "we", "us", "our") collects, uses, stores, shares and protects personal information when you use the KYC Pro platform, websites and applications (the "Service"). It is written to comply with the Protection of Personal Information Act 4 of 2013 ("POPIA"). It forms part of, and should be read with, our Terms of Service.
2. Our two roles under POPIA (important)
KYC Pro handles personal information in two different roles:
(a) As Responsible Party — for the information about you, our subscriber (your account, contact, firm and billing details, and how you use the Service). We decide how and why this information is processed, and this policy governs it.
(b) As Operator (processor) — for the information about your clients that you capture and store in the Service (client names, contact details, needs-analysis answers, financial information, documents, signatures, etc.). Here, you are the Responsible Party: you decide what to collect, you are responsible for having a lawful basis and any necessary consent, and we process it only on your behalf and on your instructions to provide the Service to you. You are responsible for your own privacy notice to your clients.
3. Information we collect
Account & profile information: your name, email address, phone number, firm/brokerage name, FSP number, professional details, profile settings and any signature or logo you upload.
Billing information: subscription plan, billing status and payment records. Card and bank details are collected and processed by our payment provider (PayFast) — we do not store your full card details on our systems.
Client information you enter: the personal information of your clients that you choose to capture, including names, contact details, ID/date-of-birth information, dependants, needs-analysis and risk-profile responses, product and financial details, uploaded documents (such as FICA documents), records of advice, quotations and electronic signatures.
Communications: messages you send us (support requests, contact forms, emails) and messages the Service sends on your behalf.
Technical & usage information: log data, device and browser information, IP address, approximate location derived from IP, pages and features used, timestamps, and audit-trail records of key actions (for security, compliance and product-improvement purposes).
Cookies: essential cookies and similar technologies needed to keep you logged in, keep the Service secure, and remember your preferences (see section 11).
4. How we collect it
We collect information directly from you when you register, subscribe, use the Service, upload content or contact us; automatically through your use of the Service (technical and usage data); and from you when you enter your clients' information. Where you enter another person's information, you confirm you are entitled to do so and have any required consent.
5. Why we process it and our lawful basis
We process personal information to: create and manage your account; provide, maintain, secure and improve the Service; process payments and manage your subscription; provide support and respond to you; send you service, security and (where permitted) product communications; enable the features you use, including AI-assisted features you choose to use; keep audit trails; prevent fraud and misuse; and comply with our legal obligations. Our lawful bases under POPIA include performance of our contract with you, our legitimate interests in running and securing the Service, your consent where required, and compliance with law. For client information we process as Operator, the lawful basis rests with you as the Responsible Party.
6. Artificial intelligence (AI) features
Some features of the Service use artificial intelligence provided by a third-party model provider (currently Anthropic) — for example, the in-app help assistant, AI-assisted summaries, and drafting or suggestion tools. When you use one of these features, the relevant text or information you submit for that task is sent to the AI provider to generate a response, and is then returned to you.
We only send what is needed for the requested feature, and we use providers that offer enterprise-grade privacy terms. We do not sell your information, and we do not use your or your clients' personal information to train our own or third parties' public AI models. AI features are optional tools — you control what you submit to them, and you should avoid submitting personal information that is not necessary for the task. AI output may be inaccurate and must be reviewed by you before use (see our Terms of Service).
7. Sharing and operators (sub-processors)
We do not sell, rent or trade your personal information, and we do not share it for third-party marketing. We share information only as needed to run the Service, with trusted operators who process it on our behalf under contract and appropriate safeguards, including:
• Supabase — cloud database, authentication and document storage;
• Vercel — application hosting and delivery;
• PayFast — payment processing;
• Resend — sending transactional and service emails;
• SMSPortal — sending SMS messages, such as one-time codes for electronic signatures and links to application forms. This receives the recipient's mobile number and the message content;
• Sentry — error and performance monitoring, so we can find and fix faults. This receives technical diagnostic data (error messages, stack traces, browser and page information). It is configured not to send personal information, and where a session recording is captured after an error, all text and input is masked before it leaves your browser; and
• Anthropic — AI model provider for the AI features described above.
We may also disclose information where required by law, regulation, court order or a lawful request by a regulator, or to protect our rights, users or the security of the Service, or as part of a business reorganisation, merger or sale (subject to this policy).
8. Where your information is stored and cross-border transfers
Our primary database and document storage — which is where your clients' personal information, documents and records are held — are hosted on cloud infrastructure located in the European Union (data centre region: Frankfurt, Germany), which offers data-protection laws comparable to POPIA.
Some of the operators listed above process information outside South Africa and outside the European Union. In particular, our error-monitoring provider (Sentry) receives technical diagnostic data on servers in the United States, and our AI and email providers may process information in the United States or other jurisdictions. We limit what is sent to these providers to what the feature requires, and our error monitoring is configured not to transmit personal information.
Where personal information is transferred outside South Africa, we take reasonable steps to ensure it is protected by a comparable level of protection, binding contractual safeguards, or your or your clients' consent, as required by section 72 of POPIA.
9. How we protect it
We use reasonable, appropriate technical and organisational measures to protect personal information, including encryption in transit and at rest, row-level database security that isolates each advisor's data, two-factor authentication for advisor accounts, access controls and least-privilege access, private (non-public) document storage, audit logging, and regular review of our security posture. No system is completely secure, and we cannot guarantee absolute security, but we work to protect your information and to respond promptly to any incident.
10. How long we keep it
We keep account information for as long as your account is active and for a reasonable period afterwards to meet legal, accounting, audit and dispute-resolution requirements. Client information you enter is retained for as long as you keep it in your account; you can delete individual records at any time. When your account closes you may request a full export for at least 30 days afterwards, as set out in section 18 of our Terms of Service, after which we may delete it. Note that, as an FSP, you may have your own legal record-keeping obligations (for example under FAIS and FICA) that determine how long you must keep certain records. We may retain limited information where the law requires it or to establish, exercise or defend legal claims.
11. Cookies
We use strictly necessary cookies and similar technologies to keep you signed in, keep the Service secure, and remember essential preferences. These are required for the Service to work. We do not use the Service to run third-party advertising trackers. You can control cookies through your browser settings, but disabling essential cookies will prevent the Service from working.
12. Your rights (data subjects)
Subject to POPIA, you have the right to: be told what personal information we hold about you and to access it; request correction or deletion of inaccurate, irrelevant, excessive or unlawfully held information; object to certain processing; withdraw consent where processing is based on consent; and lodge a complaint with the Information Regulator. To exercise these rights in respect of your account information, contact us at info@kycpro.co.za. If you are a client of an advisor who uses KYC Pro and you want to exercise your rights in respect of the information that advisor holds, please contact that advisor directly, as they are the Responsible Party for that information; we will assist the advisor as their Operator where appropriate.
13. Children
The Service is intended for use by financial professionals and is not directed at children. Where information about a minor is captured as part of a client's financial needs (for example a dependant), the advisor is responsible for the lawful basis and any required consent of a competent person.
14. Data breaches
If a security compromise affecting personal information occurs, we will act to contain and investigate it and, where required by POPIA, notify the Information Regulator and affected parties as soon as reasonably possible. Where we act as your Operator, we will notify you so that you can meet your own notification obligations to your clients.
15. Changes to this policy
We may update this Privacy Policy from time to time. Where changes are material, we will give you reasonable notice, for example by email or an in-app notice. The "Last updated" date at the top shows when it was last revised. Continued use of the Service after changes take effect constitutes acceptance.
16. Contact and complaints
Questions, requests or complaints about how we handle personal information can be sent to our Information Officer at info@kycpro.co.za or via our contact page. You also have the right to complain to the Information Regulator (South Africa): inforegulator.org.za, complaints email POPIAComplaints@inforegulator.org.za.