Pricing is published — Personal is free, and Family is R99/month for a household of 5 (R79/month billed annually). Every price includes VAT. See pricing
Sign in Start free
Legal

Privacy & POPIA notice

What we collect, why we have it, where it lives, and exactly what you can make us do about it.

Last updated 4 August 2026 · Protection of Personal Information Act 4 of 2013 (POPIA)

In short
  • Your documents and account data are stored in South Africa, not routed offshore by default.
  • We don't sell personal information, and we don't use your documents to train AI models.
  • Identity verification collects the minimum needed to answer one question, and is never resold or reused for marketing.
  • You can ask for a copy, a correction or a deletion — and complain to the Information Regulator if we handle that badly.
  • The public timestamp is a fingerprint, never your document. A hash cannot be turned back into the file it came from.

There is no such thing as being "POPIA certified" — the Act doesn't work that way. Compliance is an ongoing practice enforced by South Africa's Information Regulator, not a badge a company earns once and hangs on a wall. So instead of a badge, here is the practice, in detail.

1What we collect

Grouped by why it exists rather than by how our database happens to be shaped.

Account information

Name, email address, password (stored hashed, never in readable form), and optionally a company name and role. This is what makes an account an account.

Document content and metadata

The files you upload, the fields you place on them, filenames, page counts, and the completed sealed output. Whatever is inside your documents is inside your documents — we neither choose it nor inspect it.

Signer information

The names and email addresses you give us for the people who need to sign, plus what they do with the request: opened, viewed, signed, declined, and when. This is the audit trail, and it is part of the proof rather than an analytics by-product.

Identity verification data

Only where an identity check is attached to a signature. Covered separately and in detail in section 4, because it deserves it.

Technical and usage data

IP address, browser and device type, timestamps, and error diagnostics. Used to keep the service running, secure and debuggable — not to build an advertising profile of you.

Billing information

Plan, invoices and VAT details. Card numbers are handled by the payment provider and never stored by us.

Support correspondence

What you write to us and what we write back, so the next person picking up the thread has the context.

2How we use it

  • To run the service — render your document, place fields, deliver the request to signers, and collect the signatures.
  • To seal and verify — apply the certification signature, compute the SHA-256 fingerprint, and anchor it with OpenTimestamps so anyone can check it later.
  • To keep the audit trail — a hash-chained record of who did what, when. Removing entries from it would destroy the thing that makes it evidence.
  • To support you when something breaks, and to answer what you ask us.
  • To bill you, where you're on a paid plan or have used a metered add-on.
  • To keep the platform secure — detecting abuse, fraud and attacks against the service.
  • To meet legal obligations, where the law genuinely requires it of us.

And what we don't do with it

  • We don't sell personal information. Not to data brokers, not to anyone.
  • We don't build advertising profiles or run ad-network trackers on this site.
  • We don't use the contents of your documents to train AI models — ours or anybody else's.
  • We don't read your documents. The exceptions are narrow and named: where you switch on an AI reading tool yourself, and where you ask us for support on a specific document and give us permission to look at it.

3Where it lives

Documents and account data are stored on infrastructure located in South Africa. They aren't routed offshore by default, which matters for leases, employment contracts and anything else with real legal weight attached to it.

Some supporting services necessarily operate across borders — outbound email delivery is the clearest example. Where a processor sits outside South Africa, the transfer conditions in section 72 of POPIA apply, and we'll name the category of processor in section 5 rather than hide it behind "our partners".

The public timestamp deserves its own paragraph

OpenTimestamps anchoring publishes a hash — a 64-character fingerprint derived from the completed file. It does not publish the document, any part of the document, or anyone's name. A SHA-256 hash is one-way: it cannot be reversed back into the file it came from. That's precisely why it's safe to make public, and why the resulting proof works even if we're not around to vouch for it.

4Identity verification data

Identity verification only happens where a customer attaches a check to a signature. It's the most sensitive data we touch, so the rules around it are the tightest we have: minimised, purpose-limited, and never resold.

Tier 1 — document and biometric verification

The signer photographs an identity document and takes a selfie. A specialist provider runs document authenticity checks and OCR, plus a liveness-checked one-to-one face match against the photo on the document. We keep the result and the minimum evidence needed to show the check took place.

We label this exactly as what it is: document and biometric verification. It is not a government registry check, and we won't describe it as one — it proves the person holds a genuine-looking document whose photo matches their face, which is a real thing but a different thing.

Tier 2 — official registry check (HANIS)

A live check against the Department of Home Affairs' National Population Register, run through a licensed provider. We keep the result and the reference — confirmation that the check ran and what it returned. We do not hold a copy of the register, and we do not retain more of the response than the customer's purpose requires.

The rules we hold ourselves to on this data

  • Never resold, never reused. Identity data is used for the check it was collected for and nothing else — no marketing, no enrichment, no secondary product.
  • Biometric data is special personal information under POPIA and is treated accordingly, including the consent requirements that come with that.
  • Criminal and credit screening needs written consent captured before the check runs, and purpose limited to what the role genuinely requires. Our onboarding flows capture that consent as a product feature, not a checkbox at the end.
  • The check result belongs to the customer who requested it and the signer it's about — not to us to aggregate.

5Sharing and processors

We use operators — POPIA's word for processors — to run parts of the service. Each one is bound by a written agreement to process personal information only on our instruction, and only for the purpose it was given to them.

Hosting and storage

Infrastructure located in South Africa, holding documents and account data.

Identity verification providers

Specialist providers performing Tier 1 document and biometric checks, and licensed providers performing Tier 2 Home Affairs checks. They receive only what the check needs.

Payment processing

Our payment provider handles card details directly. We receive confirmation and invoice data, never a card number.

Email and messaging delivery

Outbound mail — signature requests, reminders, password resets and completed documents — is sent through Resend, which processes those messages in the United States. Recipients you name, and the content of the message, go to Resend for delivery. Incoming mail to info@, hello@, support@ and privacy@ stays on Google Workspace in this organisation.

Error monitoring and product analytics

Used to find and fix faults and understand which features get used. Not advertising, and not sold on.

AI model providers, where you switch them on

Clause extraction, summarisation and question answering can run against a hosted provider. This is opt-in per account, disclosed here, and can be switched off. Where it's off, no document text leaves our systems for this purpose.

We also share where we're legally compelled to — a valid court order, a lawful regulatory demand. Where we're permitted to tell you that it happened, we will.

6Retention

  • Account data — kept while your account is open, and for a reasonable period afterwards for billing, tax and dispute purposes.
  • Documents — kept until you delete them, or until your account closes and the export window passes.
  • The audit trail — retained for as long as the document it belongs to. It isn't metadata we could quietly prune; it's part of the proof.
  • Verification documents — the ID or company documents you upload to have your KuduDoc portal opened. Deleted as soon as your profile is approved. If your profile is turned down they stay until you replace them, so you can see what needs fixing, and closing your account deletes them with it.
  • Identity check results — retained for the period the requesting customer's own regulatory obligation requires (FICA and employment records being the common cases), and no longer than that by default.
  • Support correspondence — kept while it's useful for context, then removed.
  • The public timestamp — permanent and irreversible by design. It contains a hash, never content, and it is the one thing on this list nobody can delete, including us.

7Your POPIA rights

POPIA gives you rights over your personal information. Exercising them is free, and you don't need a reason.

Access

Ask what personal information we hold about you and get a copy of it.

Correction

Ask us to fix information that's inaccurate, misleading or out of date.

Deletion

Ask us to delete information we no longer have a lawful basis to keep, or that we've held past its purpose.

Objection

Object to processing based on legitimate interests, and withdraw consent where consent is what we relied on.

Complaint to the Information Regulator

If you think we've handled your information badly — or handled your request badly — you can complain directly to South Africa's Information Regulator. You don't need our agreement, our cooperation, or to come through us first.

We may need to confirm who you are before actioning a request, precisely so that nobody can use a data request to get at somebody else's information. We'll respond within a reasonable period and tell you plainly if we can't do what you've asked and why.

Two honest limits on deletion

  • We cannot recall a document already delivered to a signer. Once someone has downloaded their copy, it's theirs and it's out of our reach — which is true of every e-signature platform, and worth stating instead of implying otherwise.
  • We cannot unpublish a timestamp. It's a hash committed to a public, independent standard. It reveals nothing about the document's contents, and it cannot be withdrawn — by you, by us, or by anyone.

8Cookies

  • Strictly necessary — keeping you signed in, protecting forms against cross-site request forgery, and holding the state of a signing session together. Without these, the service doesn't function.
  • Preference — remembering your language choice and which notices you've dismissed, so the site stops asking.
  • Product analytics — where used, to understand which features people actually use. Disclosed here, and declinable.

There is no advertising network on this site. No ad cookies, no cross-site tracking pixels, no retargeting. That's not a hard promise to keep, because we don't sell advertising — but it's the kind of thing worth being specific about rather than vague.

9Security practices

  • Encryption in transit and at rest for documents and account data.
  • Access on a need-to-know basis, limited to what's required to operate and support the service.
  • A hash-chained audit trail, where each event is chained to the one before it, so entries can't be quietly reordered or removed.
  • Destructive redaction — our redaction destroys the underlying content rather than drawing a black rectangle over it, and it's backed by attack-reproduction tests.
  • Responsible disclosure welcomed, and credited publicly if you'd like the credit. We don't run a paid bug bounty yet and won't imply we do.

What we don't hold, and won't imply we hold

No ISO 27001. No SOC 2. No GDPR certification — KuduDoc is built around POPIA rather than GDPR. And no "bank-level security", which is a phrase with no fixed standard behind it. Our certification signature is also still self-signed, which the security page explains in full. If any of that changes we'll link the actual certificate here, not just use the word.

10Contact the Information Officer

POPIA requires every responsible party to appoint an Information Officer, who is accountable for how personal information is handled and for responding to your requests. For KuduDoc, privacy requests, access requests, objections and complaints all go to the same place:

KuduDoc Information Officer

We haven't published an Information Officer registration reference on this page, because we're not going to print one that isn't issued. It'll appear here when it exists.

If you're not satisfied with how we handle a request, you can take it to the Information Regulator (South Africa) directly. They are the enforcement body for POPIA, and complaining to them is your right — not a favour we grant.

This is not legal advice.

This notice describes our practices and cites POPIA as it stood on the date at the top of the page. It isn't advice about your obligations as a responsible party, or about what a specific document or process requires of you. Confirm that with an admitted attorney before you rely on it commercially.

Last updated 4 August 2026 Read the Terms of Use

Want the proof story rather than the policy?

The security page shows all three proofs, and everything we don't claim yet.