Privacy & POPIA
Binteca (Pty) Ltd is the responsible party for personal information processed here, under the Protection of Personal Information Act 4 of 2013 (POPIA). This page describes what is actually implemented, not an intention.
What is collected
| Data | Why | Kept for |
|---|---|---|
| Email address | Identifies your account and appears in the signature | Until you delete the account |
| Password | Authentication | Stored only as a scrypt hash — never in plain text, never recoverable |
| Name (optional) | Appears in the signature if given | Until you delete the account |
| Signature / emblem images | Applied to your documents | Until you delete them |
| Uploaded documents | To sign them | 60 minutes after upload, then deleted |
| IP address & browser | Audit trail — this is what makes a signature evidentially useful | With the audit record |
That is the complete list. There is no analytics, no advertising identifier, no third-party tracker, and no profiling.
Document retention
Uploaded documents and their signed copies are deleted 60 minutes after upload. A background sweeper removes them, and every read path re-checks expiry independently, so an expired document is refused even in the gap between sweeps. What survives is the audit record — who signed, when, and the document's SHA-256 digest. It holds no document content.
Where the data goes
Nowhere. Documents are processed on Binteca infrastructure and are not sent to any third-party service for signing, storage, OCR or analysis. Signing happens in-process. Traffic is TLS-encrypted in transit; the application binds loopback and is reached only through the estate's reverse proxy.
Your rights
- Access & correction — everything held about you is on your dashboard.
- Deletion (POPIA s24, GDPR art.17) — “Delete my account” removes the account, its signatures and its documents, files first and then rows.
- Objection & complaint — you may complain to the Information Regulator (South Africa).