PolicyPrivacy and Data Handling
How Deis Technologies collects, uses, stores, and protects personal information across its products and workflow services.
This page covers the legal basis, privacy principles, product-specific processing, and data-subject rights that apply when Deis handles personal information.
Legal framework
This Privacy Policy explains how Deis Technologies (Pty) Ltd collects, uses, stores, and protects personal data across its products and services.
We process personal information in accordance with the Protection of Personal Information Act (POPIA), the GDPR where applicable, and other relevant data protection obligations where they apply.
This policy applies to all Deis Technologies services, APIs, and platforms.
Prescribed purpose and usage notice
OCR services and document-processing APIs are provided solely for lawful document-processing purposes as determined by the customer.
Customers are responsible for ensuring they have the necessary rights, lawful basis, and consent to submit documents containing personal information for processing.
Customers remain responsible for obtaining appropriate consent from data subjects before submitting their information through Deis services, and Deis Technologies accepts no liability for customer misuse of the APIs or processing performed without lawful authority.
- The Protection of Personal Information Act (POPIA).
- The National Credit Act where credit-related information is processed.
- The Financial Intelligence Centre Act for identity-verification purposes.
- Any other applicable data-protection or industry-specific regulations.
Privacy principles
- Customer data is protected using industry-standard encryption in transit and at rest.
- Personal data is processed only for the specific purposes for which it was collected.
- Access to customer data is restricted to authorised systems and personnel only.
- We collect and retain only the data necessary to deliver the agreed workflow service.
Information we collect
- Document data, including documents, images, and files submitted for OCR processing, verification, or analysis, such as identity documents, financial statements, and business records.
- Personal information such as names, identity numbers, contact details, and other identifiers needed for service delivery, identity verification, and KYC compliance.
- Technical and usage information including API logs, IP addresses, system interactions, and operational telemetry used for security monitoring, service improvement, and troubleshooting.
Product-specific privacy practices
- OCR Platform and APIs process documents solely to extract structured information, do not use customer data for advertising or profiling, and do not use customer documents for model training without explicit consent.
- Document tampering detection services analyse uploaded documents solely for tampering and fraud detection, generate heatmaps and risk scores in real time, and do not share or reuse customer documents for training.
- Identity verification and KYC services process identity information solely for verification and regulatory-compliance purposes, with data shared only where necessary with authorised government and credit-bureau sources.
- Lending technology services handle bank statements, payslips, and financial records solely for affordability assessment and lending decisions, and do not use customer financial information for marketing or resale.
- ComplyHub and compliance services process screening data only for regulatory purposes, do not share results beyond the scope of compliance verification, and maintain secure audit trails and logs.
- Municipal indigent-management services process citizen data solely for eligibility verification, programme administration, fraud prevention, and service-delivery purposes.
- SecureCode processes verification data solely to confirm document authenticity, retains cryptographic signatures and logs according to customer policy, and secures private keys and sensitive cryptographic data.
- Smart Data Gateway processes payloads solely for routing and transformation, does not inspect or analyse payload data beyond what is required for delivery, and retains only request logs and transaction metadata for operational monitoring.
Data subject rights
- Right to access personal data held by Deis Technologies, subject to lawful process.
- Right to rectify inaccurate or incomplete information.
- Right to request deletion where retention is not required by law or contract.
- Right to object to certain processing and to withdraw consent where consent is the basis for processing.
- Right to portability where applicable.
- Right to withdraw consent at any time where consent is the lawful basis for processing.
Security measures
- Encryption in transit using TLS 1.2 or later.
- Encryption at rest using industry-standard controls, including AES-256 where applicable.
- Role-based access controls, staff security training, and regular security assessments.
- Intrusion-detection and incident-response procedures with regular policy reviews.
Contact us about privacy
If you have questions about this privacy policy, wish to exercise your data rights, or want to request deletion of data, contact [email protected].