Our commitments under the Protection of Personal Information Act, 4 of 2013. Last updated 4 August 2026.
Dumaflow is built in South Africa for South African trade businesses, and the Protection of Personal Information Act ("POPIA") shapes how the product works — from role-based access to consent-aware sign-up. This statement explains who is responsible for what, how personal information is protected, and how to exercise your rights.
For the personal information of account holders (your name, email, billing details), Dumaflow is the responsible party. For the personal information your business stores in Dumaflow about its own clients and staff (contact details, site addresses, job history, technician locations), your business is the responsible party and Dumaflow acts as an operator under section 20 and 21 of POPIA — processing only on your instructions, under a duty of confidentiality and security.
We process personal information only for defined, legitimate purposes: providing the service, account administration and billing, security and fraud prevention, support, and legal compliance. We collect directly from you wherever possible, we don't collect more than the purpose requires, and we don't process special personal information.
We apply appropriate, reasonable technical and organisational measures: encrypted connections, a secured cloud database with continuous backups, role-based access inside the product (technicians never see pricing; organisations are isolated from one another), and least-privilege access for our own team. Our operators (hosting, email and payment providers) are bound by written agreements to equivalent standards.
Some infrastructure providers process data on servers outside South Africa. Where this happens, the transfer complies with section 72 of POPIA — the recipient is subject to a law or binding agreement providing an adequate level of protection substantially similar to POPIA's conditions.
If we have reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and affected parties as soon as reasonably possible, with enough information for you to take protective measures.
Under POPIA you may: request confirmation of whether we hold personal information about you and a description of it (section 23); request correction or deletion of information that is inaccurate, out of date, excessive or unlawfully obtained (section 24); object to processing (section 11(3)); and withdraw consent where processing is based on consent. To exercise any of these, email admin@dumaflow.com — we respond promptly and won't charge for reasonable requests.
If you believe we've interfered with the protection of your personal information, you may complain to the Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg; complaints.IR@justice.gov.za; enquiries: inforeg@justice.gov.za. We'd appreciate the chance to resolve it directly first.
Information officer contact for Dumaflow: admin@dumaflow.com, or write to us via the contact page.