Skip to main content
Compliance

POPIA Compliance

Last reviewed: 30 March 2026

1. Compliance Statement

Billdog is committed to full compliance with the Protection of Personal Information Act (No. 4 of 2013) (“POPIA”). We process personal information lawfully, fairly, and transparently in accordance with all eight conditions for lawful processing as set out in POPIA.

2. Information Officer

Name: Jason Thwaits

Email: privacy@billdog.co.za

Organisation: Billdog (Pty Ltd registration pending)

Address: Cape Town, Western Cape, South Africa

Billdog is in the process of registering its Information Officer with the Information Regulator as required by POPIA Section 55.

3. Data Processing Register

The following summarises what personal information we process, why, and for how long:

CategoryLawful BasisRetention
Identity (name, email)Contract performanceUntil account deletion
Municipal account detailsContract performanceUntil account deletion
Bill documentsContract performanceDeleted after case closure
Dispute case dataContract performance5 years after resolution
Payment tokenContract performanceUntil account deletion
Transaction recordsLegal obligation (SARS)7 years
Security logs (IP)Legitimate interest12 months
Marketing preferencesConsentUntil withdrawal

4. Data Processors

We share personal information with the following processors who act on our instructions:

ProcessorData CategoryPurposeLocation
AnthropicBill text, account detailsAI analysisUS
SupabaseAll dataDatabase & storageEU-West-1
ResendEmail, nameEmail deliveryUS
PayFastPayment tokenPaymentsSouth Africa
Voyage AIAnonymised textLegislation searchUS
RailwayHostingInfrastructureUS-East
CloudflareDNS, IPDNS & securityGlobal

5. Security Measures

  • End-to-end encryption (HTTPS/TLS) for all data in transit
  • Row Level Security on all database tables
  • Private file storage with time-limited signed URLs
  • Payment card tokenisation via PayFast — no card numbers stored
  • Secure, HttpOnly authentication cookies
  • Server-side API key management — secrets never exposed to browsers
  • Regular dependency auditing

6. How to Request Your Data

You can request a copy of all data Billdog holds about you:

  1. Log in to your Billdog account
  2. Go to Settings
  3. Click Download My Data
  4. Your data will be exported as a JSON file

Alternatively, email privacy@billdog.co.za and we will respond within 30 days as required by POPIA.

7. How to Delete Your Data

You can request permanent deletion of all your personal data:

  1. Log in to your Billdog account
  2. Go to Settings
  3. Click Delete My Account
  4. Confirm deletion in the confirmation dialog
  5. You will receive an email confirming that deletion is scheduled
  6. After 30 days, all personal data is permanently deleted
  7. To cancel, simply log back in before the 30-day period ends

Note: SARS requires us to retain anonymised transaction records (fee amounts and dates only, with all personal information removed) for 7 years.

8. PAIA Manual Reference

The Promotion of Access to Information Act (No. 2 of 2000) (“PAIA”) requires that we make available a manual detailing the types of records held and how to request access. Billdog's PAIA manual is available upon request from privacy@billdog.co.za.

9. Information Regulator

Information Regulator (South Africa)

Website: inforegulator.org.za

Email: inforeg@justice.gov.za

Telephone: 010 023 5200

Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg

POPIA Compliance Statement — Last reviewed 30 March 2026