Version 2 · August 2026 · Effective date: 15 August 2026 · Applies to Office Vault EasySign, operated by Office Vault Technology (Pty) Ltd
Scope. This notice applies to Office Vault EasySign only. Other products in the Office Vault range, including the Office Vault document management platform, are covered by their own separate privacy policy and are hosted differently.
In short. We collect what we need to run a signing service: your account details, the documents you upload, and a record of who opened and signed them. Documents are stored in South Africa. We don't sell your data or use your documents to train AI models.
Office Vault Technology (Pty) Ltd (Reg. No. 2020/835556/07), of 56 Church Street, Olivedale, Johannesburg North, Randburg, 2188, South Africa, is the responsible party for personal information we collect about our own customers (your account details and how you use EasySign).
For the personal information inside documents you send — your signers' names, email addresses and signatures — you are the responsible party and we act as your operator under POPIA. We process that information on your instructions, to deliver the signing service.
Information Officer: Suniel Seejiram, Founder / Information Officer
Registered with the Information Regulator of South Africa — registration no. 2026-064465 (15 August 2026)
suniel@officevault.co.za · 010 500 1589 · 56 Church Street, Olivedale, Johannesburg North, Randburg, 2188
| Category | Examples | Why |
|---|---|---|
| Account information | Name, work email, company name, hashed password, plan | To create and secure your account and bill you |
| Document content | The PDFs you upload and the fields placed on them | To display, sign and seal the document |
| Signer information | Signer name, email address, signature image, and any details they type into fields | To deliver the document and record the signature |
| Billing information | Your plan, invoice history, and the last four digits and brand of the card used. Never the full card number | To take payment, issue invoices and keep proper accounting records |
| Signing evidence | IP address, timestamps, device information, and — only with the signer's permission — approximate location | To produce the audit trail and certificate that make a signature defensible |
| Usage information | Documents sent, feature use, error reports, feedback you submit | To operate, support and improve the Service |
We process personal information because it is necessary to perform our contract with you, to pursue our legitimate interest in operating and securing the Service, to comply with the law, and — for optional items such as location capture — with consent, which can be refused without preventing signing.
We are deliberately specific here, because "hosted in South Africa" is often used loosely:
| Sub-processor | Service provided | Location |
|---|---|---|
| Amazon Web Services, Inc. | Document storage (S3) | South Africa (af-south-1, Cape Town) |
| Amazon Web Services, Inc. | Application and database hosting (Lightsail) | Outside South Africa — see section 4 |
| Zoho Corporation (ZeptoMail) | Transactional email: signing invitations, reminders, completion notices | Outside South Africa |
| Paystack | Payment processing, card tokenisation and payment receipts for paid plans | Outside South Africa |
| Orange Dot Technology (Pty) Ltd | Customer support. Support staff may see your account details and document titles when responding to a request you raise | South Africa |
We never see your card. Card details are entered on Paystack's own payment page and are never sent to, processed by, or stored on our servers. We keep only the last four digits and the card brand, so you can recognise which card is on file.
Where a sub-processor is located outside South Africa, transfers are made subject to section 72 of POPIA, relying on Standard Contractual Clauses and equivalent contractual protections.
We do not sell personal information, we do not share it for advertising, and we do not use your documents to train artificial intelligence models.
We keep personal information only as long as necessary, aligned with the retention schedule of the Office Vault group:
| Category | Retention period |
|---|---|
| Documents, signatures and audit trails | For the duration of the subscription and 30 days after termination, after which data is securely deleted or returned on written request. A signed document's evidentiary value depends on its audit trail, so we do not prune it while the account is active. |
| User account records | Duration of the account plus 12 months, for audit and dispute resolution. |
| Financial and billing records | 7 years from the date of the transaction, as required by the Companies Act and tax legislation. |
| Feedback and support correspondence | 12 months from submission, unless an ongoing matter requires longer. |
Documents you delete move to Trash and can be restored. Permanently deleting a document removes it and its audit record, and cannot be undone.
You can close your account yourself in Settings. Closing signs everyone in the organisation out, stops your subscription and cancels anything still out for signature. Your signed documents and their audit trails are kept for 30 days from that point so you can ask us for copies, and are then permanently deleted. Financial and billing records are kept for the period in the table above, because tax legislation requires it.
Breach notification. In the event of a security compromise affecting personal information, we will notify affected parties and the Information Regulator in accordance with section 22 of POPIA, and within 72 hours of becoming aware of the breach.
We are in public beta and have not yet completed an independent penetration test or a formal certification such as ISO 27001. We will say so plainly here when that changes.
Under POPIA you may ask us to confirm what personal information we hold about you, to correct or delete it, to object to processing, or to complain. Write to suniel@officevault.co.za and we will respond within a reasonable time.
If you are a signer rather than an account holder, the company that sent you the document controls that information — please contact them first; we will assist them in responding.
If you hold an EasySign account, we may email you about the service itself — new features, changes to your plan, security notices, and occasional short surveys asking how we can improve. Section 69 of POPIA allows us to contact our own customers about our own similar products. Every one of these emails carries an unsubscribe link, and unsubscribing never affects your account or the documents you have signed.
We do not market to your signers. Someone who receives a document from you through EasySign is your contact, not ours. We will not add them to a mailing list, and we will not send them anything other than the emails needed to deliver and complete that document.
We never sell or rent personal information, and we do not share it with advertisers or data brokers. If we ever wanted to use your information for something outside this notice, we would ask you first.
If you take part in a survey or send us feedback, we may quote it anonymously to improve the product or on our website. We will not attach your name, your company or your email address to a public quote without asking you.
You may lodge a complaint with the Information Regulator of South Africa:
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 · inforeg@justice.gov.za · inforegulator.org.za
EasySign uses only what it needs to work: a session token to keep you signed in, and local storage for preferences. We do not use advertising or third-party tracking cookies.
EasySign is intended for use by businesses and by adults aged 18 and over. We do not knowingly collect personal information from children. If we learn that we have, we will delete it promptly.
We will update this notice as the Service changes, and will tell you about material changes by email or in the app.