Privacy & POPIA
Binteca (Pty) Ltd is the responsible party for personal information processed here, under the Protection of Personal Information Act 4 of 2013 (POPIA). This page describes what is actually implemented, not an intention.
What is collected
| Data | Why | Kept for |
|---|---|---|
| Email address | Identifies your account and appears in the signature | Until you delete the account |
| Password | Authentication | Stored only as a scrypt hash β never in plain text, never recoverable |
| Name (optional) | Appears in the signature if given | Until you delete the account |
| Signature / emblem images | Applied to your documents | Until you delete them |
| Uploaded documents | To sign them | 60 minutes after upload, then deleted |
| IP address & browser | Audit trail β this is what makes a signature evidentially useful | With the audit record |
That is the complete list. There is no analytics, no advertising identifier, no third-party tracker, and no profiling.
Document retention
Uploaded documents and their signed copies are deleted 60 minutes after upload. A background sweeper removes them, and every read path re-checks expiry independently, so an expired document is refused even in the gap between sweeps. What survives is the audit record β who signed, when, and the document's SHA-256 digest. It holds no document content.
Where the data goes
Nowhere. Documents are processed on Binteca infrastructure and are not sent to any third-party service for signing, storage, OCR or analysis. Signing happens in-process. Traffic is TLS-encrypted in transit; the application binds loopback and is reached only through the estate's reverse proxy.
Your rights
- Access & correction β everything held about you is on your dashboard.
- Deletion (POPIA s24, GDPR art.17) β βDelete my accountβ removes the account, its signatures and its documents, files first and then rows.
- Objection & complaint β you may complain to the Information Regulator (South Africa).