Privacy Policy
This Privacy Policy explains how Umbrella Communications Digital (PTY) LTD t/a Umbrella Digital (“we”, “us”, “our”), the operator of the iinventory.online platform, collects, uses, discloses, stores and protects personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA), the Electronic Communications and Transactions Act 25 of 2002 (ECTA) and the Consumer Protection Act 68 of 2008 (CPA), as applicable.
- Registered legal name
- Umbrella Communications Digital (PTY) LTD t/a Umbrella Digital
- Registration number
- 2019/199985/07
- Physical / business address
- Corner of Allandale Road and President Drive, 1st Floor Mushroom Farm Retail Centre, Kyalami Gardens, Midrand, 1685, South Africa
- Information Officer / contact
- privacy@iinventory.online
- Main platform
- https://iinventory.online
1. Scope of this Policy
This Policy applies to all visitors to iinventory.online, all organisations that register a workspace on the platform (“Subscribers”), all authorised users of a Subscriber workspace (including administrators, operators, supervisors and field crews), and any person who contacts us, subscribes to our newsletter or submits information through our web forms.
Where a Subscriber loads its own operational data (asset registers, custody events, staff records) onto the platform, that Subscriber is the responsible party in terms of POPIA and we act as its operator (processor). We process such data only on the documented instructions of the Subscriber and in accordance with this Policy.
2. Information Officer
In terms of section 55 of POPIA, our Information Officer is responsible for encouraging compliance with the conditions for the lawful processing of personal information, dealing with requests made to us under POPIA and the Promotion of Access to Information Act 2 of 2000 (PAIA), and working with the Information Regulator.
- Information Officer contact address: privacy@iinventory.online
- Postal / physical address: Corner of Allandale Road and President Drive, 1st Floor Mushroom Farm Retail Centre, Kyalami Gardens, Midrand, 1685, South Africa
- Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 — complaints may be lodged directly with the Regulator at any time.
3. Categories of Personal Information We Process
3.1 Account and identity information
- Full name, work email address and password credentials (stored only as a salted hash).
- Organisation name, trading industry, role assigned within the workspace.
- Field-crew access identifiers such as six-digit PINs and site access tokens.
3.2 Operational and asset information
- Asset registers, serialised item records, bulk stock counts and site allocations.
- Custody events, including the responsible person’s name, destination, condition notes, up to five photographs per event and a captured digital signature.
- Scanning activity, adjustment history and audit trails attributable to a named user.
3.3 Billing information
- Subscription tier, billing status, invoice history and amounts payable in ZAR (R).
- Payment gateway references and tokens. We never receive or store full card numbers, CVV codes or bank credentials.
3.4 Technical and usage information
- IP address, browser and device type, operating system and time-zone.
- Pages visited, features used, error and crash diagnostics.
- Cookie identifiers, as described in our Cookie Policy.
3.5 Marketing information
- Newsletter subscription email address, subscription status, source of the subscription and the date consent was given.
4. Purpose and Lawful Basis for Processing
We process personal information only where a lawful justification under section 11 of POPIA exists:
- Performance of a contract — to create and operate workspaces, authenticate users, deliver inventory, custody and audit functionality, and invoice subscription fees.
- Legal obligation — to retain tax and accounting records, respond to lawful requests and comply with statutory reporting duties.
- Legitimate interests — to secure the platform, prevent fraud, investigate abuse, maintain audit trails and improve service reliability.
- Consent — for optional analytics and marketing cookies, newsletter communications, and any processing not otherwise justified. Consent may be withdrawn at any time without affecting the lawfulness of processing before withdrawal.
5. Operators and Third-Party Processing
We appoint operators who process personal information on our behalf under written contracts requiring confidentiality and security measures in line with section 21 of POPIA.
5.1 Cloud database, authentication and storage (Supabase / PostgreSQL infrastructure)
Our managed cloud backend hosts the PostgreSQL database, authentication service and object storage used by the platform. It stores account credentials (hashed), workspace records, asset and custody data, uploaded photographs, proof-of-purchase documents and digital signatures. Access is controlled by row-level security policies that isolate each Subscriber’s tenant data. Data is encrypted in transit using TLS and encrypted at rest by the infrastructure provider.
5.2 Payment processing (Paystack)
Subscription payments in South African Rand are processed by Paystack, a licensed payment service provider. When you subscribe or upgrade, you are directed to Paystack’s secure checkout. Paystack collects and processes your card or bank details directly and returns only a transaction reference, masked identifiers and a payment result to us. Paystack acts as an independent responsible party for card data and applies PCI-DSS controls. We store only the customer reference, transaction reference, amount in ZAR, tier and payment status.
5.3 Transactional and notification email
Authentication, billing and service emails are delivered through our transactional email infrastructure operating from the notify.iinventory.online sending domain. Delivery metadata (recipient address, message identifier, delivery status and bounce reasons) is logged for deliverability and dispute purposes.
5.4 Analytics
Where you consent to Performance & Analytics cookies, aggregated usage statistics are collected via Google Analytics. Analytics scripts are blocked entirely until consent is given, and are disabled again immediately if consent is withdrawn.
6. Cross-Border Transfers
Certain operators host infrastructure outside the Republic of South Africa. Where personal information is transferred cross-border, we rely on section 72 of POPIA and ensure that the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection substantially similar to POPIA, including onward-transfer restrictions. A description of the safeguards in place is available on request from the Information Officer.
7. Security Safeguards
- TLS encryption for all data in transit and encryption at rest for stored data.
- Row-level security policies enforcing strict tenant isolation so that one organisation can never read another organisation’s records.
- Role-based access control separating owners, administrators, operators, field crews and internal staff, with least-privilege defaults.
- Password hashing, session expiry, and time-limited internal session tokens.
- Immutable activity logs and custody audit trails.
- Regular reviews of access rights, dependencies and security policies.
Should a security compromise occur where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and affected data subjects as soon as reasonably possible, in terms of section 22 of POPIA.
8. Retention Periods
- Active workspace data — retained for the duration of the subscription.
- After cancellation — retained for 30 calendar days to allow reactivation and data export, after which production records are permanently deleted.
- Financial and tax records — retained for five years from the end of the relevant tax period, as required by the Tax Administration Act and the Companies Act.
- Newsletter subscriptions — retained until you unsubscribe, plus a suppression record kept indefinitely so we do not contact you again.
- Security and audit logs — retained for up to 12 months.
- Backups — encrypted backups may retain deleted records for up to 35 days before rotation overwrites them.
9. Your Rights as a Data Subject
Under POPIA you have the right to:
- Be notified that your personal information is being collected, or that it has been accessed by an unauthorised person (sections 18 and 22).
- Request confirmation, free of charge, of whether we hold personal information about you, and to request a record or description of that information (section 23).
- Request the correction, destruction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained (section 24).
- Object, on reasonable grounds, to the processing of your personal information (section 11(3)).
- Object at any time to processing for purposes of direct marketing (section 11(3)(b)).
- Not be subject to a decision based solely on automated processing that results in legal consequences for you (section 71).
- Withdraw consent where processing is based on consent.
- Submit a complaint to the Information Regulator, or institute civil proceedings.
Requests must be submitted to privacy@iinventory.online. We may require proof of identity before acting on a request, and will respond within a reasonable period and in any event within 30 days. Where you are an authorised user of a Subscriber workspace, we may refer your request to that Subscriber as the responsible party.
10. Direct Marketing
We send commercial newsletters only to persons who have explicitly opted in and ticked the POPIA consent checkbox. Every marketing email contains a functional unsubscribe link. Service, billing, security and authentication emails are operational messages that form part of the service and are not direct marketing.
11. Children’s Information
iinventory.online is a business-to-business platform intended for use by persons aged 18 and older acting in a commercial capacity. We do not knowingly process the personal information of children. If we become aware that a child’s information has been submitted without the consent of a competent person, we will delete it.
12. Cookies
Details of the cookies we set, their purpose, duration and how to control them are provided in the Cookie Policy. You may reopen the Cookie Preferences panel at any time using the “Cookie Preferences” link in the footer of every public page.
13. Changes to this Policy
We may amend this Policy from time to time. The effective date at the top of this page will be updated, and material changes will be communicated to Subscriber administrators by email or in-platform notice at least 14 days before taking effect.
14. Contact
Queries, complaints, access requests and objections may be addressed to the Information Officer at privacy@iinventory.online or by post to the registered address listed above.
