Doc-Assure
Privacy Policy
Last updated: 26 June 2026
Doc-Assure (“we”, “us”, or “our”), a product of Manergy Consulting (Pty) Ltd (reg 2015/246879/07), registered at 25 Casablanca Van Heerden Rd, Halfway House, 1685, South Africa, operates the Doc-Assure platform at doc-assure.africa and doc-assure.app, including the Doc-Assure mobile application for iOS and Android (collectively, the “Service”). This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights as a data subject.
We comply with the Protection of Personal Information Act, 2013 (POPIA) of South Africa and, where applicable, the General Data Protection Regulation (GDPR) for users in the European Economic Area.
1. Information we collect
1.1 Information you provide
- Account information — name, email address, username, password (stored hashed), and role within your organisation.
- Files and documents — any documents, images, or files you upload, scan, or create using the Service.
- Signatures — drawn or uploaded images of your signature that you save in the signature library.
- Consent records — details of consents you grant or revoke for document sharing (purpose, access level, expiry).
- Workflow data — comments and decisions you make on workflow approval tasks.
- AI chat queries — the text of questions you ask about your documents through the AI chat feature.
- Support communications — any information you provide when contacting support.
- Purchase data — subscription and in-app-purchase status. Card details are handled by our payment providers and the app stores; we do not receive or store your full card number.
1.2 Information collected automatically
- Device information — device type, operating-system version, app version, and unique device identifiers (for push notifications only).
- Usage data — how you interact with the Service, to improve the product.
- Diagnostic data — crash reports and performance metrics.
- Log data — IP address, timestamps, and endpoint accessed when you call our APIs.
1.3 Information the mobile app accesses on your device
The app requests these permissions, each used only for the stated purpose and only after you grant consent:
- Camera — only for scanning documents in the Scan tab; captured images stay local until you upload them.
- Photo library — to let you pick existing photos to upload as documents or signature images. We do not otherwise read, index, or scan your photo library.
- Face ID / Touch ID / Fingerprint — for the optional biometric app lock. Biometric templates never leave your device; we only receive a pass/fail result.
- Push notifications — to alert you to shared-file views, shares, workflow approvals, and storage warnings.
- Local storage — to cache starred files for offline access and to queue uploads while offline, using app-sandbox isolation.
2. How we use your information
We use your information to:
- Provide, maintain, and improve the Service.
- Authenticate you and secure your account.
- Store, index, search, and preview your documents.
- Apply e-signatures to documents at your request.
- Route workflow tasks and approvals to the correct people.
- Respond to your AI chat queries (which may involve large-language-model providers acting as data processors under contract).
- Process subscriptions and in-app purchases and provide support.
- Send you transactional notifications.
- Detect and prevent abuse, fraud, and security incidents, and comply with legal obligations.
We do not use your personal information, documents, or AI chat queries to train any machine-learning model. We do not sell your personal information.
3. Legal basis for processing (POPIA / GDPR)
- Consent — where you have given clear consent (e.g. a POPIA consent for a specific sharing purpose).
- Contract — where processing is necessary to provide the Service you signed up for.
- Legal obligation — where processing is necessary to comply with applicable law.
- Legitimate interests — e.g. securing the Service and preventing abuse, balanced against your rights.
4. Who we share your information with
We do not sell your personal information. We share information only in these circumstances:
4.1 Within your organisation
Your documents and workflow activity are visible to other members of your tenant according to the permissions set by your administrator.
4.2 With people you explicitly share with
When you create a share link or grant a consent, the recipients you specify get access subject to the conditions you set (password, expiry, download limit).
4.3 With our service providers (subprocessors)
| Subprocessor | Purpose | Location |
|---|---|---|
| Our cloud infrastructure provider | Hosting and encrypted storage | South Africa and/or EU |
| Our AI model provider | AI chat query processing | Per signed DPA |
| Apple App Store / Google Play | In-app purchase & subscription billing | United States |
| Our payment processors | Web subscription & card processing | Per signed DPA |
| RevenueCat | In-app purchase validation & entitlements | United States |
| Expo, Apple & Google push services | Push notification delivery | United States |
A current list of subprocessors is available on request at support@doc-assure.app.
4.4 For legal reasons
We may disclose information if required by law, court order, or legitimate request from a relevant authority.
5. Data retention
- Active account data — retained while your account is active.
- Documents — retained until you delete them; trashed items are permanently deleted after 30 days unless restored.
- Audit logs — retained for a minimum of 7 years for compliance.
- Backup copies — retained for up to 90 days in encrypted backup storage.
- Account closure — on request we delete your account and associated personal information within 30 days, except where retention is legally required.
6. Your rights
Under POPIA and the GDPR you have the right to access, correct, delete, object to processing of, and receive a portable copy of your personal information, and to withdraw consent or lodge a complaint with a supervisory authority. You can delete your account and associated data directly in the app (Account → Delete Account), or contact us at privacy@doc-assure.app. We respond within 30 days.
7. Data security
- Encryption in transit — all network traffic uses TLS 1.2 or higher.
- Encryption at rest — files are stored in encrypted object storage using AES-256.
- Authentication — passwords are stored as salted hashes; session tokens are short-lived and stored in your device’s secure keystore.
- Access controls — role-based permissions at every API endpoint, with strict tenant isolation across our data stores.
- Monitoring & response — automated intrusion detection and audit logging; we notify affected users of any personal-information breach within 72 hours of becoming aware, as required by POPIA.
No system is perfectly secure. If you suspect your account has been compromised, contact support@doc-assure.app immediately.
8. International data transfers
Your data is primarily stored and processed in South Africa. Some subprocessors may process data in other jurisdictions; where data is transferred outside South Africa, we rely on Standard Contractual Clauses or equivalent safeguards to ensure an adequate level of protection.
9. Children’s privacy
Doc-Assure is designed for business use and is not directed at children under 18. We do not knowingly collect personal information from anyone under 18.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised “Last updated” date.
11. Contact us
Information Officer · privacy@doc-assure.app
Support · support@doc-assure.app
For complaints about how we handle your personal information, you can also contact the Information Regulator (South Africa) — inforegulator.org.za.