Privacy notice
What we collect, where it lives, and which section of POPIA each answer belongs to.
This is a plain-language notice, not legal advice and not the agreement itself. Where this page and the signed agreement differ, the agreement governs.
Last updated 17 September 2026 · legal@vumasign.com
You are the responsible party. We are the operator.
Your documents carry your customers’ personal information, and the decisions about that information are yours: what to collect, why, and for how long. We process it on your instruction. That relationship is what POPIA s21 describes, and it is why there is a written agreement rather than an assurance.
What we collect about you
Account details — names, work email addresses, the organisation you belong to. Billing records. And the audit events the service exists to produce: who opened an envelope, when, from what address, and how they were identified.
No advertising trackers. No third-party analytics reading your document content. The sealed document and the answers in it are not a data set we look at.
Where it lives — and why s72 does not arise
Application, database, document storage and sealing all run in Google Cloud’s Johannesburg region, on every plan. There is no replica elsewhere and no region to fall back to.
POPIA s72 governs transferring personal information out of South Africa. A transfer that does not happen needs no justification, no adequacy finding, and no clause in a contract nobody will read.
How it is protected — s19
Row-level isolation in the database itself, so one organisation cannot read another’s rows even from a query nobody has written yet. An append-only audit trail that cannot be edited, by us either. Encryption in transit and at rest. Access to production data limited to the people who operate the system, for the purpose of operating it.
There is no support tool that opens your document to help with a ticket.
If something goes wrong — s22
If personal information is accessed by somebody who should not have it, we notify you and the Information Regulator. That is a duty with no discretion in it, and we will tell you what we know while we still know little rather than waiting for a tidy account.
Requests from the people in your documents — s23 and s24
A person whose information is in a document you sent asks you, not us, because you are the responsible party. We give you what you need to answer them, including the audit trail.
Requests about a Vumasign account itself — yours — go to privacy@vumasign.com. The law allows 30 days; we aim for five.
How long we keep it
For as long as the account is open. We do not expire a sealed document, because the reason to keep one is that somebody may need it in five years, and a retention policy that quietly deletes evidence is worse than no policy at all.
When an account closes, the data goes with it.