Legal
Privacy Policy
Last updated: 5 October 2026
This notice describes how GoLevi processes personal information when you request access, use a workspace, or pay an invoice a business sent through GoLevi. It distinguishes what we decide from what your business decides about its own clients.
Please read the risk clauses
The clauses on acceptable use and fraud, who holds client money, limitation of liability, and indemnity affect your risk. They are drawn to your attention here, and again before you request access or sign in, as the Consumer Protection Act requires where that Act applies.
1. Who this notice is about
This notice explains how GoLevi, the operator of https://golevi.app, processes personal information. It is written for the Protection of Personal Information Act, 2013 ("POPIA"), including the notice a responsible party gives under section 18. It is the privacy notice incorporated into our Terms of Service at https://golevi.app/terms.
Privacy requests go to privacy@golevi.app. That is the address for the person who handles POPIA requests for this service. We do not, on this page, claim that an Information Officer has been registered with the Information Regulator. You may still use the rights below, and you may complain to the Regulator.
2. Two roles
We are the responsible party for personal information about you as the person who requests access, owns a workspace, signs in, or pays us for the service, and for platform security logs. We decide why that information is used.
You are the responsible party for personal information of your clients and of other people you put into the workspace. We are the operator for that information. We process it on your instructions, which are these terms, this notice, and the settings you choose in the product. We step out of that operator role only where we must use the information to secure the service, to investigate fraud or abuse, or to obey the law. For that limited use we are the responsible party.
A separate data-processing addendum will be offered when we publish one. Until then this notice and the Terms are the operator terms. We will not sell your clients' information and we will not use the contents of your invoices for our own advertising.
3. What we collect
- Identity and account data: name, email address, the business name, the workspace address you request, currency, and sign-in identifiers from a code, a magic link, or Google or Microsoft if you choose those.
- Workspace content you or your users enter: clients, contacts, invoices, quotes, credit notes, statements, notes, files, and branding.
- Payment metadata. Online payments run on the provider you connect. We receive status such as paid, failed, or reversed. We do not store full card numbers. The provider receives what its own checkout collects, under your agreement with it.
- Security and usage data: address of the network, time, the page or API called, and logs needed to run, rate-limit, and protect the service.
- Support and legal mail you send to legal@golevi.app or privacy@golevi.app.
Please do not put special personal information (such as health, religion, or biometric data) into notes or document fields. We do not ask for it. If you do, you are responsible for having a lawful basis.
4. Where it comes from
We collect it from you and your users, from your clients when they open a portal, a document, or a pay link you sent them, from the payment provider you connected (status webhooks), and from the systems that host the service. We do not buy marketing lists.
5. Why we use it
POPIA section 11 needs a justification. We rely on these:
- To carry out the request or the contract you asked for: creating or reviewing a workspace, signing you in, sending documents, and operating a pay link.
- A legal obligation: tax and accounting records of fees you pay us, and a duty to answer a lawful demand.
- Our legitimate interests, and yours: keeping the service secure, enforcing rate limits, detecting fraud and abuse, and keeping a record of a waitlist decision. Where this is the basis, you may object, as section 6 describes.
- Consent, where we actually ask for it. We do not treat a request for early access as consent to unrelated marketing.
6. What you must provide
The business name, workspace address, currency, your name, and a working email address are required to request access. If you do not provide them, or you do not enter the email code, we cannot add the request or open a workspace. Client details are required only for the documents you choose to create. You may leave optional profile fields empty.
7. Who receives it
We do not sell personal information. We share it with these categories of recipient, and only as needed for the purpose:
- The provider that hosts the service and stores databases, files, and cache. Processing can take place in South Africa and in other countries where that provider runs.
- The provider that sends transactional email such as sign-in codes, document notices, and waitlist mail.
- Google or Microsoft, only if you choose that sign-in method. They receive the sign-in under their own terms.
- The payment provider you connect (PayFast, Paystack, Yoco, Ozow, or Stripe). They process your client's payment under your merchant agreement. We send them the checkout details the integration needs and we receive status back.
- Your own recipients: the clients you email, and the users you invite.
- Professional advisers bound to confidence, and a regulator, court, payment provider, bank, or law-enforcement authority when we must disclose or when the fraud clause in the Terms allows it.
8. Outside South Africa
Some of those providers process information outside the Republic. POPIA section 72 allows a transfer when the recipient is subject to a law, binding corporate rules, or a binding agreement that provides adequate protection, when you consent, or when the transfer is necessary for the contract you asked us to perform. Hosting, email delivery, optional Google or Microsoft sign-in, and an international payment provider such as Stripe are necessary for the features you use. By requesting those features you agree to that transfer. You may ask privacy@golevi.app which of these applies to a particular flow.
9. Security
We use measures appropriate to a multi-tenant billing service: access control, tenant isolation, encryption in transit, encryption of the payment keys you store with us, and secrets held in a secrets store rather than in the page. No measure is perfect. Please keep your own codes and keys safe, and tell us at privacy@golevi.app if you believe an account was misused.
10. How long we keep it
- A waitlist request: while it is open, and afterwards for as long as we need to show the decision and to block repeat abuse. You may ask us to delete it. We may keep a short record of the email address and the decision where security requires that.
- Workspace content: while the workspace is open. After you ask us to close it, we delete or anonymise that content within a reasonable time, except the records in the next items. Export CSV and documents the product makes available before you ask us to close.
- Our own invoices and accounting records for fees you pay us: for the period the Tax Administration Act requires.
- Security logs and fraud-investigation files: for as long as we need them to protect the service, to answer a claim, or to meet a legal duty, and no longer.
- Backups: until they age out of the normal backup cycle. They are not used as a live workspace.
11. Fraud and abuse
We process account data, content needed for the investigation, and security logs to detect fraudulent signups, false invoices, unauthorised payments, and attacks on the platform. The legal bases are the contract, our legitimate interest in protecting tenants and payment providers, and any legal duty to report. We may suspend access while we look, and we may share the information as the Terms describe. A delay in giving you a copy is only for as long as disclosure would help the fraud or destroy evidence. It is not a refusal of a right that POPIA says we must honour.
12. Your rights
Subject to POPIA, you may ask us to confirm whether we hold personal information about you, to give you a copy, to correct it, or to delete it. You may object to processing that we justify on legitimate interest, and you may lodge a complaint. Where the information is your client's, ask the business that holds the workspace first. We help that business answer, because they are the responsible party. We answer requests about the account itself.
Write to privacy@golevi.app. We may need to confirm you control the email address before we disclose. We aim to answer within the time POPIA allows. You may complain to the Information Regulator (South Africa) at https://inforegulator.org.za and POPIAComplaints@inforegulator.org.za. The Regulator publishes its current physical address.
13. Your duties for client data
If you are the responsible party, you must tell your clients that you use GoLevi, give them the notice POPIA requires, and honour their rights. You must not use the portal or email tools to process information you have no lawful basis for. If a client writes to us about information you control, we will usually refer them to you and help you respond.
14. Children
The service is for businesses and for people who are 18 or older. We do not knowingly collect personal information from a child in order to open a workspace. If you put a child's information into a client record, you must have a lawful basis for that, and you remain the responsible party.
15. Cookies and similar tools
The sign-in cookie is named __Host-golevi-session. It is strictly necessary, and it is set as Secure, HttpOnly, and SameSite. We use it to know that you are signed in. We do not set advertising cookies and we do not sell cookie data. A short-lived cookie may remember which company or which sign-in return you chose. Those are part of operating the service, not of tracking you across other sites.
16. Direct marketing
Mail about a code, a waitlist decision, a document you asked us to send, a security event, or a change to these terms is part of the service. It is not unsolicited marketing. POPIA section 69 restricts direct marketing by electronic communication. We do not send that marketing unless a basis in section 69 applies, and every such message will tell you how to opt out. You may also write to privacy@golevi.app.
17. Automated limits
A daily cap may refuse another signup code from the same email address or network. That limit is automatic and lasts for the day. A person still decides whether a waitlist request is approved. If a cap or a fraud hold blocks you and you believe that is wrong, write to privacy@golevi.app and a person will review it. This is the approach POPIA section 71 expects where an automated step has a legal effect.
18. Breaches
If we have reasonable grounds to believe personal information we are responsible for has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected people as POPIA requires. Where the information is client data for which you are the responsible party, we will tell you without undue delay so that you can meet your own duty, and we will help you with what we know about what happened.
19. Changes
We may update this notice by posting a new version on this page with a new date. If a change materially affects how we use account information, we will email the workspace address we have, or the address on an open waitlist request, before the change takes effect where that is practical. The Terms explain how a change to the agreement works.
20. Contact
Privacy: privacy@golevi.app. Terms: legal@golevi.app. Website: https://golevi.app. Information Regulator: https://inforegulator.org.za and POPIAComplaints@inforegulator.org.za.
See also Terms of Service.