Privacy Policy
Last Updated: February 2026
PRIVACY NOTICE AND POLICY: PROFORMAL PDF CONVERTER
Version: 1.2
Effective Date: June 12, 2026
Responsible Party: Pro Formal (PTY) LTD
1. INTRODUCTION AND SCOPE
ProFormal PDF Converter ("the Company," "we," "us," or "our") respects your privacy and is committed to protecting the personal information of our users ("Data Subjects"). This Privacy Notice explains how we collect, use, disclose, and safeguard your information when you use our PDF conversion platform, in accordance with the Protection of Personal Information Act, No. 4 of 2013 (POPIA).
1.1 Our Role (Responsible Party vs. Operator)
Account Data: When managing your subscription, billing, and direct interactions with us, ProFormal acts as the Responsible Party (Data Controller) determining the purpose and means of processing.
Uploaded Document Data: When you upload financial documents (such as bank statements) containing the personal information of third parties (e.g., your clients, employees, or vendors), you act as the Responsible Party. In this context, ProFormal acts strictly as an Operator (Data Processor). We process the content of these documents solely automatically, on your behalf, and strictly for the purpose of providing the conversion Service. You represent and warrant that you have the lawful right, consent, or legal basis to upload and process any third-party personal information contained within your documents.
2. DEFINITIONS
Personal Information: Information relating to an identifiable, living, natural person, or an identifiable, existing juristic person.
Processing: Any operation or activity concerning personal information, including collection, receipt, recording, storage, retrieval, and destruction.
Data Subject: The person (you or your organization) to whom the personal information relates.
Operator: A third party who processes personal information for a responsible party in terms of a contract (e.g., our payment processors or hosting providers).
3. INFORMATION WE COLLECT
We collect only the minimum information necessary to provide the Service.
3.1 Account and Billing Information
To manage your subscription and prepaid wallet, we process:
Full name of the primary user/admin.
Business email address.
Organization/Company name.
VAT registration number (where applicable).
Billing address and payment metadata (Note: We do not store full credit card numbers; these are processed by our PCI-DSS compliant Operators, Paystack).
3.2 Uploaded Financial Documents (Ephemeral Processing)
The PDF documents (e.g., bank statements, invoices) that you upload for conversion are processed in-memory or stored ephemerally. They are automatically and permanently purged from our active systems within 24 hours of processing. We do not use your financial documents to train AI models, nor do we harvest the financial data within them for our own business purposes.
3.3 Server Logs and IP Addresses (Security & Rate Limiting)
When you access the Service, our servers automatically record standard log data, including your IP address, browser type, and time of access. We temporarily store and process your IP address strictly to enforce our fair-use "Gatekeeper" limits for guest users, monitor server health, and prevent fraud or abuse of our computing resources.
4. USE OF COOKIES AND TRACKING TECHNOLOGIES
We use strictly necessary functional cookies to maintain secure login sessions, remember your preferences, and ensure the proper and secure operation of the Service.
Because ProFormal operates on a B2B SaaS model, we do not use third-party tracking cookies, we do not sell your browsing data to data brokers, and we do not participate in cross-site advertising networks. Any analytics used within the platform are strictly anonymized and used exclusively to monitor server health, performance vitals, and application errors.
5. DATA MINIMIZATION AND "EPHEMERAL PROCESSING"
Recognizing the sensitivity of financial documents, we adhere to a strict security protocol:
Automated Conversion: Files are processed by code; no human employee views the content of your uploaded files during the standard course of business.
Strict Retention Policy: Uploaded PDFs and the resulting converted data (CSV/Excel) are stored temporarily only for the purpose of download. All such files are purged from our active server environment within 60 minutes to 24 hours of processing. Exception: If you explicitly submit a file to our technical team via the "Report Issue" function to request a custom parser fix, you grant us permission to securely retain that specific document for up to thirty (30) days for debugging purposes, after which it is permanently destroyed.
No Secondary Use: Data extracted from your documents is never used for profiling, analytics, or any purpose other than providing you with the converted output.
6. PURPOSE OF PROCESSING
We process your personal information for the following purposes:
To establish and maintain your user account and Prepaid Wallet balance.
To perform the document conversion services as requested.
To process payments and maintain VAT-compliant financial records for tax compliance (SARS).
To communicate critical system updates, security alerts, and billing notices.
Communication & Marketing: To send you updates about new processor engines or platform features. You may opt out of promotional communications at any time by clicking the "unsubscribe" link in our emails. However, we will continue to send you essential transactional notices (e.g., invoices, security alerts, and password resets).
7. DISCLOSURE TO THIRD PARTIES (OPERATORS)
We do not sell, rent, or trade personal information. We disclose information only to the following categories of Operators:
Payment Gateways: Paystack for secure transaction processing and card tokenization.
Cloud Infrastructure: DigitalOcean for secure data hosting.
Email Communication: Zoho Mail (via NodeMailer integration) for delivery of transactional emails and OTPs.
Legal and Regulatory Authorities: We may disclose your personal information or retained files if we are compelled to do so by law, subpoena, court order, or to protect the rights, property, or safety of ProFormal, our users, or others.
All Operators are vetted to ensure they maintain security standards equivalent to our own and are contractually bound to process data only for specified purposes.
8. CROSS-BORDER DATA TRANSFERS
Your information may be stored and processed in cloud infrastructure located outside of South Africa. In such cases, we ensure that the recipient is subject to a law, binding corporate rules, or a binding agreement which provide an adequate level of protection that effectively upholds principles for reasonable processing of the information that are substantially similar to the conditions for the lawful processing of personal information relating to a data subject who is a natural person and, where applicable, a juristic person.
9. SECURITY SAFEGUARDS
We implement appropriate, reasonable technical and organizational measures to prevent loss of, damage to, or unauthorized destruction of personal information. These include:
Encryption: All data in transit is encrypted using Transport Layer Security (TLS/SSL).
Access Control: Infrastructure access is restricted to essential personnel via multi-factor authentication.
Firewalls and Monitoring: Continuous monitoring for unauthorized access attempts.
9.1 Data Breach Notification Protocol
While we implement robust, industry-standard security measures, no system is entirely immune to risk. In the unlikely event of a verified data breach or unauthorized access to Personal Information, ProFormal will:
Notify the Information Regulator as soon as reasonably possible after the discovery of the compromise.
Notify the affected Data Subjects as soon as reasonably possible (and no later than 72 hours after becoming aware of the incident), unless the identity of such Data Subjects cannot be established.
Provide affected users with sufficient information to allow them to take protective measures against the potential consequences of the compromise, including a description of the possible consequences and the measures we are taking to mitigate the breach.
10. YOUR LEGAL RIGHTS
Under POPIA, you have the right to:
Access: Request a copy of the personal information we hold about you.
Correction: Request that we update or correct inaccurate information.
Deletion: Request that we delete your account information (subject to statutory record-keeping requirements, such as those imposed by SARS for a period of 5 years).
Objection: Object to the processing of your information for specific purposes.
Complaint: Lodge a complaint with the South African Information Regulator.
10.1 How to Request Account Deletion
If you wish to permanently delete your account and associated personal data, please email support@proformal.co.za with the subject line "Account Deletion Request" from your registered email address. We will verify your identity and purge your account data within 30 days. Please note that we may retain specific transaction and billing records as legally mandated by the South African Revenue Service (SARS).
11. INFORMATION OFFICER
In terms of POPIA, the Company has appointed an Information Officer responsible for overseeing compliance.
Information Officer: Anton Das
Email: admin@proformal.co.za
Deputy Information Officer: Tiaan Robinson
Email: support@proformal.co.za
Physical Address: 521A 15th Avenue, Rietfontein
Pretoria
0084
South Africa
Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: enquiries@inforegulator.org.za
12. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our technological practices or legal requirements. If we make material changes, we will notify you via the email address associated with your account. Upon your next login following a material change, you will be required to explicitly review and accept the revised Privacy Policy via our digital consent interceptor. Your continued use of the Service after such changes have been accepted constitutes your agreement to the updated terms.