Privacy Policy
Last updated: 2 August 2026
HTM LEDGR (“HTM LEDGR”, “the Services”, “we”, “us”) is a product of HTM Legacy (Pty) Ltd, a private company duly incorporated in the Republic of South Africa under registration number 2021/423883/07, of Pretoria, South Africa (“HTM Legacy”, the “Supplier”). This policy sets out, for purposes of compliance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), what personal information the Supplier collects through htmledgr.com and the HTM LEDGR application, the purposes for and grounds upon which it is processed, the parties to whom it may be disclosed, the periods for which it is retained, and the rights available to data subjects in respect thereof, together with the manner in which such rights are, as a matter of law and administrative process, to be exercised.
Where the Customer uses HTM LEDGR to generate documents addressed to its own clients, the Customer is the responsible party (in the terminology of POPIA, analogous to a “data controller”) in respect of the personal information of those clients, and the Supplier acts solely as the Customer’s operator (analogous to a “data processor”), processing such information exclusively on the Customer’s documented instructions and for no independent purpose of its own. This policy addresses both capacities: the Supplier’s processing of the Customer’s own account information as responsible party, and the Supplier’s processing of information on the Customer’s behalf as operator. To the extent any provision of this policy is inconsistent with the Customer’s obligations as responsible party under clause 5 of our Terms of Service, the Terms of Service shall prevail as between the Supplier and the Customer.
1. Information we process
1.1 Information provided directly
- Account details — name, email address, phone number, password (accounts created through a third-party sign-in provider do not give us a password), occupation, and a profile photo if you upload one.
- Business details — business or individual trading name, physical/postal address, VAT number, company registration (CIPC) number, financial year-end date, banking details displayed on your invoices (bank name, account holder, account number, branch code), and your logo.
- Client information you enter — the names, contact details, addresses and VAT numbers of the clients you save in your Clients Directory or type directly onto a quote, invoice, receipt or purchase order. The Customer warrants that it holds a lawful basis, within the meaning of section 11 of POPIA, for the processing of any such third-party personal information, in accordance with clause 5 of our Terms of Service.
- Financial records you create — line items, amounts, payment records, refunds, write-offs, expenses and the notes you attach to them. This is the core content of the Services; it is not analysed for any purpose other than operating the Customer’s account and calculating the totals and reports requested.
- Team information — names, emails, phone numbers, job titles and roles of people you invite to your workspace.
- Support correspondence — anything transmitted via the contact form, in-app support widget, or email.
1.2 Information collected automatically
- Device and sign-in security signals — when you sign in, we record a device identifier (so we can recognise browsers you’ve used before) and, if you enable it, alert you the first time your account is accessed from a new device. We keep a short list of your recent devices for this purpose only.
- Trial-abuse prevention signals — to stop the same business claiming a fresh free trial by deleting an account and signing up again, we derive irreversible one-way values from identifiers you have already supplied in the course of registering (including business registration, tax and banking identifiers) together with coarse, non-invasive characteristics of the browser used to sign up. Only these irreversible values are retained — never the underlying details, and they cannot be reversed to reveal your banking, tax or business information by us or by anyone else. We do not employ invasive device-fingerprinting techniques. They serve one purpose, at the point of signup: establishing whether a free trial has already been used. They are never used to identify or track you elsewhere, never disclosed to any third party, and never used to make any decision about your account thereafter. Your IP address is also recorded at signup for the same investigative purpose, but is never on its own a reason to refuse a signup, since South African mobile networks place many unrelated customers behind a single address.
- Local storage — your browser stores a small number of preference values on your own device (see our Cookie Policy for the full list) so things like your theme, font size, and remembered sign-in email persist between visits.
- Usage information — an internal activity log records who on your team performed key actions (created a document, recorded a payment, changed a role) and when, so you have an audit trail. This is visible to your own team, not to us, except as needed to provide support, investigate abuse, or comply with a legal obligation.
1.3 Organisation domain and business-name records
In addition to the signals described at clause 1.2, the Supplier maintains two further registries, distinct from the trial-abuse hashes, existing specifically to prevent one Organisation gaining unauthorised access to another’s workspace:
- Custom email domains. Where an Organisation’s owner signs up using an email address on a custom domain (that is, not a free consumer provider such as Gmail, Outlook, Yahoo, or similar SA webmail services), that domain is automatically recorded against the Organisation the first time it is used to onboard. This is not optional or hidden: it is what allows the Supplier to refuse a later, unrelated signup attempt on the same domain and direct that person to request an invitation instead, rather than allowing anyone who happens to share an employer’s email domain to create a second, unaffiliated Organisation and potentially confuse or defraud the first. An Organisation’s owner or administrator may add further domains it controls, or remove one previously recorded, from Settings → Team → Invitation Policy at any time; doing so does not affect any Organisation’s existing members.
- Business and trading names. The Organisation’s registered business or trading name is likewise recorded in a duplicate-checking registry at the time the Organisation is created, so that the Supplier can flag, and where appropriate decline, an attempt to register a second Organisation under a name already claimed by an existing one.
Both registries are processed on the Supplier’s legitimate interest, within the meaning of section 11(1)(f) of POPIA, in preventing unauthorised access to an Organisation’s workspace and in maintaining the integrity of the Organisation namespace within the Services; that interest is, the Supplier considers, not overridden by the interest or fundamental rights of the data subject, given the narrow and security-driven purpose to which the records are put and the fact that a domain or business name is not, of itself, sensitive personal information. Neither registry is accessible to any Organisation other than the one to which the record belongs, is used for marketing, is sold, or is disclosed to any third party save as described at clause 3.
1.4 Information from third parties
If you choose to sign in using a third-party sign-in provider rather than a password, that provider confirms your identity to us and supplies your name, email address and profile photo. We receive nothing further from it, and it receives nothing about your use of the Services. If you subscribe to a paid plan, our payment gateway provider tells us the outcome of the transaction (success, amount, plan) — we never receive or store your card number, expiry date or CVV; that information is captured directly by the payment gateway under its own terms.
2. Purposes and grounds of processing
Each category of personal information described at clause 1 is processed only for the purposes below, each of which is undertaken on one or more of the grounds set out in section 11(1) of POPIA (consent; necessity for the performance of a contract to which the data subject is party; compliance with a legal obligation; protection of a legitimate interest of the data subject; performance of a public duty; or the Supplier’s own or a third party’s legitimate interest, where not overridden by the data subject’s interests):
- To create and operate your account, workspace and team (contract necessity).
- To generate the quotes, invoices, receipts, purchase orders, statements and reports you create (contract necessity).
- To send transactional email (documents you send to clients, payment reminders, team invitations, receipts, verification and password-reset emails, service and outage notices, and — only where you’ve enabled them in Settings — payment/quote/team notifications) (contract necessity and, for optional notifications, consent).
- To bill your subscription via our payment gateway and keep your plan entitlements up to date (contract necessity).
- To detect and prevent fraud, trial abuse, duplicate-domain and duplicate-business-name registration, and unauthorised account access (see 1.2 and 1.3 above), and to give effect to any suspension or termination for breach as described in clause 8 of our Terms of Service (legitimate interest).
- To provide customer support when you contact us (contract necessity and legitimate interest).
- To meet our own legal, tax and accounting obligations, and to establish, exercise, or defend legal claims (legal obligation and legitimate interest).
- To send product updates or marketing email, but only if you’ve opted in (our newsletter signup is a separate, clearly-labelled action from creating an account) (consent).
We do not sell personal information, and we do not use your financial data to train any AI or machine-learning model. The Services do not make any decision, solely by automated means, that produces legal effects concerning a data subject or affects them to a similarly significant degree, within the meaning of section 71 of POPIA — every figure, reminder, or countdown the Services produce is, as set out in our Terms of Service, informational only and requires the Customer’s own judgment to act upon.
3. Operators and recipients of information
The Supplier engages a limited number of carefully selected service providers (“operators” as contemplated in POPIA) to perform defined functions in connection with the operation of the Services. Each is bound by written terms requiring it to process personal information only on the Supplier’s documented instructions, to apply appropriate security safeguards, and to treat the information as confidential. Each receives only such personal information as is reasonably necessary for the function it performs, and no more.
- Infrastructure and hosting — provides the secure environment in which your account, documents and files are stored and the Services are made available to you.
- Message delivery — transmits the documents you elect to send, together with reminders, invitations, verification messages and service notices, and, where you have opted in, our newsletter. It receives only the recipient address and the content of the message concerned.
- Payment processing — processes your subscription payment to the Supplier. Your card details are handled by that provider directly and are never received or stored by the Supplier; we are informed only of the outcome of a transaction.
- Your own team members — Authorized Users you invite to your workspace can see the information their role permits, exactly as described in the Services.
Your account records and documents are held in the Republic of South Africa. Certain limited processing incidental to the operation of the Services may be performed outside the Republic. Where that occurs, the Supplier ensures that the recipient is subject to a law, binding agreement or corporate rules affording a level of protection substantially similar to the conditions for lawful processing under POPIA, as required by section 72 of that Act.
The Supplier does not share personal information with data brokers or advertising networks, and does not sell personal information within the meaning of any applicable law. The Supplier may disclose information where required or permitted by law, pursuant to a valid order of a court or other competent authority, a lawful direction of the Information Regulator, a request made in terms of the Promotion of Access to Information Act 2 of 2000, or where the Supplier, in its reasonable discretion, considers disclosure necessary to establish, exercise, or defend a legal claim, or to protect the rights, property, or safety of HTM Legacy, its users, or the public.
4. Retention
- Financial documents (quotes, invoices, receipts, purchase orders) are retained for a period determined by the Customer’s subscription plan — currently 12 months on Starter, 24 months on Growth, and unlimited on Business — measured from each document’s creation date. We email a warning 30 days and again 7 days before a document is due to expire, and export functionality remains available, on the terms set out in clause 6 of our Terms of Service, at any time prior thereto.
- Trial-abuse hashes (clause 1.2) are kept indefinitely, because their entire purpose is to remain valid evidence even after an account is deleted. They cannot be reversed into the original email, VAT number or registration number.
- Domain and business-name records (clause 1.3) are kept for as long as the Organisation to which they belong remains registered, and, following closure or termination, for such further period as the Supplier considers reasonably necessary to prevent immediate re-registration of the same domain or name in circumstances that would defeat the purpose described at clause 1.3.
- Account and team information is kept for as long as the account is active, and for a reasonable period thereafter to meet legal and accounting obligations, or, where access has been terminated for breach under clause 8.2 of our Terms of Service, for such further period as the Supplier considers reasonably necessary for evidentiary, legal, or regulatory purposes.
- Support correspondence is kept for as long as reasonably needed to resolve the query and for a record of the interaction.
Personal information is not retained for longer than is necessary to achieve the purpose for which it was collected, as required by section 14 of POPIA, save where a longer period is required or permitted by law, or is reasonably necessary for the Supplier to establish, exercise, or defend a legal claim.
5. Security
The Supplier takes reasonable technical and organisational measures, as contemplated in section 19 of POPIA, to safeguard the integrity and confidentiality of personal information in its possession or under its control, including:
- All data in transit is encrypted (HTTPS/TLS); data at rest is encrypted at the storage layer by our cloud infrastructure provider.
- Every read and write to your data is authorised against access rules scoped to your organisation, independently verified by an automated test suite.
- Optional two-factor authentication for your account, using a standard authenticator app, with single-use backup codes stored in a form we cannot read.
- New-device sign-in alerts and a mandatory email-verification gate.
- Password quality requirements when an account is created, including screening the proposed password against credentials known to have appeared in third-party data breaches — carried out without your password, or anything that could identify it, leaving your browser.
- Automated measures limiting repeated attempts against sign-in, password-reset and enquiry functions.
- Browser-level controls restricting where the application may load code from and where it may transmit information.
- Monitoring and alerting on security events of consequence.
- Role-based access control inside your own workspace, so team members only see what their role allows.
- An immutable, append-only audit trail on financial transactions and administrative changes of consequence, so a record cannot be silently altered after the fact.
No system of technical or organisational safeguards can be guaranteed to be perfectly secure, and the Supplier makes no warranty, express or implied, to that effect. In the event the Supplier becomes aware of a security compromise affecting personal information for which it is responsible, it will notify affected data subjects and the Information Regulator to the extent, and within the timeframes, required by POPIA, and will take such steps as it considers reasonable to contain and remediate the compromise.
6. Your rights, and how they are exercised
Subject to the limitations, exemptions, and verification requirements provided for under POPIA, a data subject has the right to:
- request confirmation of, and access to, the personal information the Supplier holds concerning them;
- request correction of inaccurate, outdated, incomplete, or misleadingly recorded information, most of which can be amended directly in Settings;
- request the deletion or destruction of a record of personal information that the Supplier is no longer authorised to retain, subject always to the Supplier’s legal, tax, accounting, and evidentiary retention obligations, including those described in clause 4 above;
- object, on reasonable grounds, to the processing of personal information relating to them, including processing carried out for purposes of direct marketing, and to opt out of marketing communications at any time via the unsubscribe mechanism provided;
- where processing is based on consent, withdraw that consent at any time, without affecting the lawfulness of processing carried out before the withdrawal; and
- lodge a complaint with the Information Regulator (inforegulator.org.za) if they consider that the Supplier has processed their personal information otherwise than in accordance with POPIA.
A request to exercise any of the foregoing rights must be submitted in writing to support@htmledgr.com. The Supplier aims to acknowledge a request within a reasonable time and to respond substantively without undue delay, and reserves the right to require such proof of identity as it reasonably considers necessary before acting on the request, to decline a request to the extent permitted by section 23, 25, or any other applicable provision of POPIA, and to levy such fee as may be prescribed for the provision of a copy of a record. Nothing in this clause 6 entitles a data subject to make use of the Services’ self-service functionality otherwise than in accordance with the Customer’s subscription and account status, nor overrides clause 8.2 of our Terms of Service in respect of an account terminated for breach.
7. Children’s privacy
HTM LEDGR is a business tool intended for use exclusively by persons of at least 18 years of age, and is not directed at, marketed to, or knowingly used by children. The Supplier does not knowingly collect personal information relating to a child, as defined in POPIA, and reserves the right to terminate any account it reasonably believes to be held by, or predominantly used by, a person under the age of 18.
8. Relationship to our other policies
This policy should be read together with our Terms of Service, our Cookie Policy (which addresses browser-stored information specifically), and our Service Level Agreement. Where this policy addresses the treatment of personal information and any of those documents addresses a related but distinct matter (for example, the consequences of account termination), both apply, each to the extent of its own subject matter.
9. Changes to this policy
The Supplier may update this policy from time to time as the Services evolve. Material changes will be flagged in-app or by email; the “Last updated” date at the top of this page reflects the version currently in force, which shall apply to the exclusion of any prior version.
10. Contact us / Information Officer
For any privacy-related query or request, including a request to exercise a right described in clause 6, email support@htmledgr.com or use our contact page.
The Supplier’s Information Officer, as contemplated in section 1 read with sections 55 and 56 of POPIA, is Hope T. Madike, Chief Executive Officer of HTM Legacy (Pty) Ltd, who may be reached through the contact details set out above. A data subject who is dissatisfied with the outcome of a request or complaint dealt with by the Information Officer retains the right, in terms of section 74 of POPIA, to lodge a complaint directly with the Information Regulator, whose particulars appear in clause 6.
Questions about any of this? Reach us here: