Office VaultEASYSIGN

Privacy & POPIA Notice

Version 2 · August 2026 · Effective date: 15 August 2026 · Applies to Office Vault EasySign, operated by Office Vault Technology (Pty) Ltd

Scope. This notice applies to Office Vault EasySign only. Other products in the Office Vault range, including the Office Vault document management platform, are covered by their own separate privacy policy and are hosted differently.

In short. We collect what we need to run a signing service: your account details, the documents you upload, and a record of who opened and signed them. Documents are stored in South Africa. We don't sell your data or use your documents to train AI models.

1. Who is responsible

Office Vault Technology (Pty) Ltd (Reg. No. 2020/835556/07), of 56 Church Street, Olivedale, Johannesburg North, Randburg, 2188, South Africa, is the responsible party for personal information we collect about our own customers (your account details and how you use EasySign).

For the personal information inside documents you send — your signers' names, email addresses and signatures — you are the responsible party and we act as your operator under POPIA. We process that information on your instructions, to deliver the signing service.

Information Officer: Suniel Seejiram, Founder / Information Officer
Registered with the Information Regulator of South Africa — registration no. 2026-064465 (15 August 2026)
suniel@officevault.co.za · 010 500 1589 · 56 Church Street, Olivedale, Johannesburg North, Randburg, 2188

2. What we collect

CategoryExamplesWhy
Account informationName, work email, company name, hashed password, planTo create and secure your account and bill you
Document contentThe PDFs you upload and the fields placed on themTo display, sign and seal the document
Signer informationSigner name, email address, signature image, and any details they type into fieldsTo deliver the document and record the signature
Billing informationYour plan, invoice history, and the last four digits and brand of the card used. Never the full card numberTo take payment, issue invoices and keep proper accounting records
Signing evidenceIP address, timestamps, device information, and — only with the signer's permission — approximate locationTo produce the audit trail and certificate that make a signature defensible
Usage informationDocuments sent, feature use, error reports, feedback you submitTo operate, support and improve the Service

3. Lawful basis

We process personal information because it is necessary to perform our contract with you, to pursue our legitimate interest in operating and securing the Service, to comply with the law, and — for optional items such as location capture — with consent, which can be refused without preventing signing.

4. Where your information is stored

We are deliberately specific here, because "hosted in South Africa" is often used loosely:

5. Who else processes it

Sub-processorService providedLocation
Amazon Web Services, Inc.Document storage (S3)South Africa (af-south-1, Cape Town)
Amazon Web Services, Inc.Application and database hostingOutside South Africa — see section 4
Zoho Corporation (ZeptoMail)Transactional email: signing invitations, reminders, completion noticesOutside South Africa
PaystackPayment processing, card tokenisation and payment receipts for paid plansOutside South Africa
Mistral AI SASOnly if you use the free contract check, or switch on AI features in your account. The text of the document you submit is sent to Mistral to be read, and the reading is sent back. Nothing else about your account is sentEuropean Union (France)
Orange Dot Technology (Pty) LtdCustomer support. Support staff may see your account details and document titles when responding to a request you raiseSouth Africa

Mistral is the only one of these that reads what a document says, and it is the only one you have to switch on. Every other sub-processor above handles your documents as files — storing them, delivering a link, taking a payment — without anything reading the words inside. If you never use the contract check, nothing is ever sent to Mistral.

Mistral keeps a copy for about 30 days. They retain what is sent to them, and what they send back, for roughly 30 days for abuse monitoring, and then delete it. Zero-retention is an arrangement offered on their highest plan and we do not have it, so we are not going to tell you your document is not stored there. We will say so here if that changes.

We never see your card. Card details are entered on Paystack's own payment page and are never sent to, processed by, or stored on our servers. We keep only the last four digits and the card brand, so you can recognise which card is on file.

Where a sub-processor is located outside South Africa, transfers are made subject to section 72 of POPIA, relying on Standard Contractual Clauses and equivalent contractual protections.

We do not sell personal information, and we do not share it for advertising.

Your documents are not used to train artificial intelligence models — not by us, and not by Mistral. Mistral’s terms for the API we use exclude API content from model training. Reading a document and training on it are different things, and only the first happens here.

6. How long we keep it

We keep personal information only as long as necessary, aligned with the retention schedule of the Office Vault group:

CategoryRetention period
Documents, signatures and audit trailsFor as long as the account exists. Cancelling a subscription does not delete anything — it stops new documents being sent, and everything already signed stays available to view, download and verify. If the account is closed, we keep them for a further 30 days and then securely delete them, or return them on written request. A signed document's evidentiary value depends on its audit trail, so we never prune it.
User account recordsDuration of the account plus 12 months, for audit and dispute resolution.
Financial and billing records7 years from the date of the transaction, as required by the Companies Act and tax legislation.
Security records of refused sign-ins90 days. When a sign-in is refused — a wrong password, a locked-out address, a rate limit — we record the time, the IP address it came from and the email address that was tried. It is how we tell a customer who cannot get into their own account apart from somebody working through a list of addresses. It is deleted automatically after 90 days, and sooner if the account it relates to is closed.
Documents read by the free contract checkWe keep nothing. The text is read and discarded — it is not written to our storage, our database, or any file on our servers. Mistral holds its own copy for about 30 days, as described in section 5, and that clock is theirs and not ours.
Documents read by AI features in your accountThis one we do keep, and only while your account is open. When somebody in your account asks a question about a document, we extract that document’s text and store it so the same document never has to be read twice. We also keep the questions people asked and the page and quotation each answer relied on. We do not keep the answers. All of it is deleted with the rest of your documents 30 days after your account closes, and it is only ever created for documents somebody has actually asked about — if you never use AI features, none of it exists.
Feedback and support correspondence12 months from submission, unless an ongoing matter requires longer.

Documents you delete move to Trash and can be restored. Permanently deleting a document removes it and its audit record, and cannot be undone.

You can close your account yourself in Settings. Closing signs everyone in the organisation out, stops your subscription and cancels anything still out for signature. Your signed documents and their audit trails are kept for 30 days from that point so you can ask us for copies, and are then permanently deleted. Financial and billing records are kept for the period in the table above, because tax legislation requires it.

7. How we protect it

Breach notification. In the event of a security compromise affecting personal information, we will notify affected parties and the Information Regulator in accordance with section 22 of POPIA, and within 72 hours of becoming aware of the breach.

We are in public beta and have not yet completed an independent penetration test or a formal certification such as ISO 27001. We will say so plainly here when that changes.

8. Your rights

Under POPIA you may ask us to confirm what personal information we hold about you, to correct or delete it, to object to processing, or to complain. Write to support@orangedot.co.za and we will respond within a reasonable time.

If you are a signer rather than an account holder, the company that sent you the document controls that information — please contact them first; we will assist them in responding.

9. Marketing and product feedback

If you hold an EasySign account, we may email you about the service itself — new features, changes to your plan, security notices, and occasional short surveys asking how we can improve. Section 69 of POPIA allows us to contact our own customers about our own similar products. Every one of these emails carries an unsubscribe link, and unsubscribing never affects your account or the documents you have signed.

We do not market to your signers. Someone who receives a document from you through EasySign is your contact, not ours. We will not add them to a mailing list, and we will not send them anything other than the emails needed to deliver and complete that document.

We never sell or rent personal information, and we do not share it with advertisers or data brokers. If we ever wanted to use your information for something outside this notice, we would ask you first.

If you take part in a survey or send us feedback, we may quote it anonymously to improve the product or on our website. We will not attach your name, your company or your email address to a public quote without asking you.

10. Complaints to the Regulator

You may lodge a complaint with the Information Regulator of South Africa:
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 · inforeg@justice.gov.za · inforegulator.org.za

11. Cookies

EasySign uses only what it needs to work: a session token to keep you signed in, and local storage for preferences. We do not use advertising or third-party tracking cookies.

12. Children’s information

Nobody under 18 may open an EasySign account or sign a document as a signer. Our account holders and signers are adults.

A document one of our customers sends may nevertheless contain information about a child — a school indemnity naming a pupil, a medical aid form listing a dependant, a beneficiary nomination. Section 34 of POPIA prohibits the processing of a child’s personal information unless one of the grounds in section 35 applies. The ground that applies here is section 35(1)(a): the prior consent of a competent person, usually a parent or guardian.

Obtaining that consent is the customer’s responsibility, not ours. The organisation sending the document is the responsible party. It decides what the document contains, who receives it, and whether a competent person has consented. We are its operator under section 21: we process the document on its instruction, we do not read it for our own purposes, and we do not use anything in it to build a profile, train a model or market to anyone.

Practically, that means we cannot tell you whether a particular document holds a child’s information. Unless the contract check has been used on it, nothing reads what a document says — the file is stored encrypted and its contents are not inspected. So we do not apply a separate retention rule to it. It is kept, and deleted, exactly as section 6 describes for the account that sent it, and the customer can delete it at any time.

The contract check is the one exception, and it never happens by itself. Somebody has to upload a document to it and tick a box saying they understand it will be read outside South Africa. If that is done, the text of that document is read — by Mistral, to answer the question asked of it, and by nobody at Orange Dot. It is still not used to build a profile, train a model or market to anyone. Do not put a document through it if you are not free to share what is in it.

If you are a parent or guardian who has signed something through EasySign and you want to know what is held about your child, ask the school, employer or organisation that sent it to you. They hold the record and they can act on it. If they need us to act, we will act on their instruction. If you cannot get a response from them, contact us at support@orangedot.co.za and we will help you reach the right person.

If a child has opened an account or signed as a signer in their own right, that is outside what this service is for. Tell us and we will remove it.

13. Changes

We will update this notice as the Service changes, and will tell you about material changes by email or in the app.