About this policy
This Privacy Policy explains how SA-ArchPro collects, uses, shares, secures and retains personal information when you use the SA-ArchPro platform at sa-archpro.com (the “Service”). It is written primarily to meet the South African Protection of Personal Information Act, 2013 (POPIA), and — for users in the European Economic Area / United Kingdom — the equivalent principles of the GDPR/UK GDPR. It also contains the disclosures required by the Google API Services User Data Policy and by Intuit for QuickBooks Online.
01Who we are
The Service is operated by SA-ArchPro (Pty) Ltd (“SA-ArchPro”, “we”, “us”), a company registered in the Republic of South Africa with registration number 2026/049810/07 and registered address at Dana Bay, Mossel Bay, Western Cape, South Africa.
For the purposes of POPIA, our Information Officer can be reached at info@mail.sa-archpro.com. You may direct any privacy question, request or complaint to that address.
02Our role: Responsible Party and Operator
SA-ArchPro is a practice-management platform for South African architectural practices. It holds two different roles under POPIA depending on the data in question:
- Responsible Party — for the account and identity data of the professionals who sign in (for example your name, email, phone number, SACAP registration number and professional designation, and the practice’s subscription and billing records). We decide the purpose and means of processing this data.
- Operator — for the practice data that a subscribing firm loads into the Service about its own employees, clients, consultants, contractors and projects. Here the subscribing practice is the Responsible Party and instructs us; we process that data on the practice’s behalf, under this policy and our Terms, and only to provide the Service.
If you are an employee or client of a practice that uses SA-ArchPro and you want to know how your data is handled, or to exercise your rights over it, please contact that practice (the Responsible Party) in the first instance. We will assist them as their Operator.
03Personal information we collect
We collect the following categories of personal information:
- Account & profile — email address, password (stored only as a salted hash by Firebase Authentication, never in plain text), first/last name, phone number, SACAP registration number and category, professional role/designation, practice name, and — where you enable it — two-step verification (a phone number held by Firebase Authentication).
- Practice & team — firm details (name, VAT number, physical and postal address, contact email and phone, SACAP number, professional-indemnity insurance details), and employee records including role, contact details, SACAP number and remuneration data (hourly rate, hourly cost, monthly salary) that a firm chooses to capture.
- Clients, consultants & projects — client contact details and, where entered by the practice, VAT and identity (ID) numbers; consultant and contractor contacts and registration numbers; and project information such as briefs, property details (erf number, address, coordinates, zoning), budgets, documents and photographs you upload, timesheets and billing entries.
- Communications — where you link an email account, the content, subjects, recipients and attachments of messages you send and the messages the Service reads to associate them with projects (see the Google section below), and calendar events you sync. Where you connect a mailbox over IMAP, we store the mail-server address, your mailbox username and your mailbox password (encrypted at rest) solely to retrieve new messages from that mailbox on a schedule; if you choose a tidy-up option for a connected mailbox, the Service moves or deletes messages on your mail host only after they have been safely stored here, exactly as you configured. Disconnecting a mailbox deletes the stored credentials.
- Billing — subscription tier, plan, status, amounts (in ZAR), payment references and an opaque PayFast recurring-payment token. We do not store your card number — see “Payments” below.
- Signatures — if you choose to save one, an image of your signature (drawn or uploaded), held so it can be applied to documents you sign. It is private to you: nobody else in your practice can see or use it, and it is never sent to any AI feature. When a document is signed we also keep a record of who signed, when, the wording they agreed to, and a digest of the exact document signed. Where a client accepts a fee proposal through a signing link, that record additionally names the email address the link was sent to, and notes that a one-time code sent to that address was verified. We keep that address solely as evidence of the signature and for security investigation — it is not used for analytics, tracking, profiling or marketing.
- Technical & security — a hashed record of your last sign-in IP address, device/browser information and push-notification tokens for notifications, and security/audit logs (including, for team invitations, the IP address and user-agent recorded when an invitation link is opened or an account is claimed, and for signed documents, the IP address and user-agent recorded at the moment of signing).
04Special personal information
Some of the information above is special personal information or otherwise sensitive under POPIA, and some firms may capture data about their staff and clients that falls into these categories. In particular:
- Financial information — employee remuneration (hourly rate, cost, monthly salary), practice and client VAT numbers, project budgets and billing records.
- Identity numbers — South African ID numbers and property-owner identifiers that a practice may enter for a client or a property record.
Where SA-ArchPro acts as Operator, the subscribing practice is responsible for having a lawful basis (including any consent required under POPIA) to load this information and to instruct us to process it. When a practice invites a team member, the inviting administrator must confirm an explicit data-processing consent before an invitation is sent; the Service enforces this consent gate.
05How and why we use it, and our lawful basis
We use personal information for the following purposes:
| Purpose | Lawful basis (POPIA) |
|---|---|
| Create and manage your account and practice; authenticate you. | Performance of the contract; your consent. |
| Provide the project-management, timesheet, calendar, email and reporting features. | Performance of the contract with your practice. |
| Take payment and manage subscriptions, renewals and dunning. | Performance of the contract; compliance with law. |
| Secure the Service, prevent abuse, and keep audit/billing records. | Legitimate interests; compliance with a legal obligation. |
| Send you service, security and (where enabled) marketing communications. | Legitimate interests; your consent for marketing. |
| Provide optional AI-assisted analysis, drafting and reporting. | Performance of the contract; your consent. |
We do not sell your personal information, and we do not use it for automated decisions that have legal or similarly significant effects on you without a lawful basis and appropriate safeguards.
06Sub-processors and third parties
We rely on the following processors and third parties to run the Service. Each receives only the data needed for its function. Their locations are relevant to the cross-border section below.
| Provider | Purpose | Data shared | Region |
|---|---|---|---|
| Google Firebase / Google Cloud | Authentication, database, file storage, serverless functions, hosting, App Check. | All account, practice, project and technical data. | United States (us-central1, us-east4) |
| Google (OAuth APIs) | Calendar and Drive integration you opt into. | Events on the SA-ArchPro-created calendar, and the Drive files you pick — per the scopes you grant. | United States |
| Google Gemini API | Optional AI analysis, drafting, images and reports. | Only the minimal, feature-specific content described in the AI section (e.g. project title/brief, email subject and sender domain, redacted spreadsheet samples, or the text you type into Archie), plus any file or voice note you explicitly attach to an Archie message. Never employee records, identity numbers, banking details or financial records, and no stored document you have not chosen to attach. | United States |
| Intuit (QuickBooks Online) | Accounting sync you opt into. | Employee names/emails and bill rates, customer/client data, company (realm) identifier. | United States |
| PayFast | Subscription and recurring billing. | Amount (ZAR), item description, your email and firm identifiers, opaque recurring token. No card number reaches us. | South Africa |
| Resend | Transactional email delivery (invitations, notifications). | Recipient email address, name and message content. | United States / EU |
| BuildSphere | Optional accredited construction-governance integration. | Project metadata you elect to send, and your linked-account identity. Currently a synthetic sandbox environment. | africa-south1 |
We keep this list current as our processors change. We do not sell personal information to any of these parties or to anyone else.
07Google user data — Limited Use disclosure
If you connect a Google account, you may grant SA-ArchPro access to Google Calendar and Google Drive. The scopes we request, and only for the features you enable, are:
calendar.app.created— to create a dedicated “SA-ArchPro” calendar in your Google account and manage the events on it, so appointments planned in the Service appear on your own devices. This scope reaches only the calendar the Service creates — it cannot see, change or delete events on your personal or any other calendar.drive.file— to upload and reference practice documents you attach to projects and email. This scope reaches only the files you pick and the files the Service itself creates — never the rest of your Drive.userinfo.email— to confirm which Google account you linked.
Separately, if you sign in using Continue with Google, Firebase Authentication requests the standard sign-in scopes openid, email and profile to establish who you are. They identify your account only; no practice data is read through them.
We do not read your mailbox. Doing so needs a Google restricted scope, and SA-ArchPro no longer requests it — mailbox linking is shown in the Service as “coming soon”. If we introduce it, it will run as a separate Google application with its own verification and independent security assessment, and this policy will be updated before it is switched on. Mail you send from the Email hub goes through our own delivery provider, not through your Google account.
Limited Use commitment
SA-ArchPro’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained through the Calendar and Drive scopes is used only to provide and improve the user-facing features described above; is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition; is not used for advertising; and is not used to develop, improve or train generalised/non-personalised AI or machine-learning models. Humans do not read your Google data except with your explicit consent for support, for security or abuse investigation, to comply with law, or where the data has been aggregated and anonymised.
You can disconnect a linked Google account at any time from within the Service. When you unlink an email account, we also ask Google to revoke the stored token. You can review and revoke access directly at myaccount.google.com/permissions.
08QuickBooks / Intuit data
If you connect QuickBooks Online, SA-ArchPro uses the Intuit Accounting scope (com.intuit.quickbooks.accounting) to synchronise practice data. Depending on the features you use, this involves reading and writing your company (realm) identifier, employee names and emails and their bill rates, and customer/client records, so that timekeeping and billing stay aligned between the two systems.
- QuickBooks data is used only to provide the accounting-sync feature you enabled.
- We do not sell QuickBooks data, and we do not use it for advertising.
- Access tokens are stored encrypted (see “How we protect information”) and are never exposed to your browser.
- You can disconnect QuickBooks at any time from the integration settings. On disconnect we make a best-effort call to Intuit’s token-revocation endpoint and remove the stored credentials. You can also disconnect from within your Intuit account.
09AI features (Google Gemini)
Several optional features use Google’s Gemini API to generate output — for example analysing a project brief, drafting reports and social content, classifying an email to a project, resolving an address, and mapping spreadsheet columns during import. AI features operate on a strict data-minimisation basis: each feature transmits only the specific, minimal content it needs — for example a project’s title, brief, complexity and a banded budget range (never the client’s name or the exact contract value); spreadsheet headers together with sample values that are first automatically redacted; an email’s subject line and the sender’s domain (never the message body, recipients or the sender’s address); or the photos and instruction you explicitly select when generating social content.
AI features have no access to your employee records, salaries or rates, identity numbers, banking details or practice financial records, and none of them reads your stored documents unless you explicitly attach a document to a request (see Archie below). Before transmission, text inputs are automatically screened. Patterns resembling South African ID numbers and bank account numbers are removed and are not restored. Email addresses, phone numbers, South African business identifiers (company registration, IBAN, SWIFT and bank branch codes) and the names of your own clients, contacts and staff are replaced with placeholders before the text is sent, and the real values are substituted back into the reply once it returns — so the AI provider does not receive them, while the answer still reads normally. Text we can read inside an attachment (Word, plain text, CSV, Markdown and HTML files) is screened the same way; the contents of PDFs, images and voice notes cannot be screened and are transmitted as you attached them.
Archie, the built-in AI advisor, cannot browse, list or search any practice, project, client, employee or financial data held in the Service, and it never selects a file on its own. The content sent to the Gemini API is the text you type (after the screening described above), any voice note you record, and the specific files you choose to attach to a message — attached files are transmitted in full, so you are shown a confirmation explaining this before you attach one for the first time in a session. Choose which model handles a message from the options your platform administrator has enabled; a daily per-person limit may apply to each. Recordings are transcribed and then discarded — the audio is not stored. Files Archie produces stay in your browser unless you choose to download them or save them to your practice storage. Your Archie conversations are stored in your own private, per-user history within the Service and can be deleted by you at any time.
Please avoid pasting information into free-text AI features that you do not wish to send to this processor. As noted in the Google section, data obtained from Google Workspace scopes (Calendar/Drive) is not used to train generalised AI models. Your use of the Gemini API is additionally subject to Google’s applicable terms.
10Payments (PayFast)
Subscription payments are processed by PayFast, a South African payment gateway. When you subscribe or change plans, we send PayFast the amount (in ZAR), an item description and identifiers for your practice and account. Your card or banking details are entered on PayFast’s secure pages and are handled by PayFast — SA-ArchPro never receives or stores your full card number. For recurring billing we store only an opaque token issued by PayFast, which cannot be used to reconstruct your card. Payment-outcome notifications from PayFast are validated (by signature, passphrase and source) before we act on them.
11Cross-border transfer of information (POPIA section 72)
Your data is processed outside South Africa
SA-ArchPro runs on Google Cloud infrastructure hosted in the United States (regions us-central1 and us-east4), and several of our sub-processors (Google, Intuit, Resend, and the Gemini API) also process data outside South Africa. This means your personal information is transferred across borders.
We rely on the conditions in section 72 of POPIA for these transfers, namely one or more of the following:
- the recipient is subject to a law, binding corporate rules or a binding agreement that upholds principles of lawful processing substantially similar to POPIA and that includes provisions substantially similar to POPIA’s own conditions for onward trans-border transfer (we contract with our processors on data-protection terms to this effect);
- the transfer is necessary for the performance of the contract between you (or your practice) and us, or to take steps at your request before entering into it; or
- you have consented to the transfer.
Where you are in the EEA or UK, we likewise rely on appropriate safeguards (such as the relevant standard contractual clauses) for transfers outside your region.
12How we protect information
We take the security of personal information seriously and apply technical and organisational safeguards, including:
- Encryption in transit using current TLS, and encryption of stored OAuth refresh tokens for Google Drive, QuickBooks and BuildSphere using AES via a key held in Google Secret Manager.
- Server-only secret storage. Sensitive nodes — including private user data, OAuth state and integration tokens — are held in database locations that cannot be read or written by browsers at all; they are accessible only to our server-side functions.
- Access control. Role-based rules (owner / admin / member) restrict who in a practice can see or change data, enforced at the database layer.
- Abuse and bot protection via Google reCAPTCHA Enterprise and Firebase App Check, and optional two-step (phone) verification for sign-in.
- Minimised sensitive handling. Team-invitation links are stored only as SHA-256 hashes; passwords are hashed by Firebase Authentication; and security and billing audit logs are append-only.
No method of transmission or storage is perfectly secure. While we work to protect your information, we cannot guarantee absolute security. Some integration tokens (for example for Google Calendar) are held in server-only storage but are not additionally application-encrypted; we are continuing to strengthen our controls.
13How long we keep information
We keep personal information for as long as your account or your practice’s account is active and as needed to provide the Service, and thereafter as required by law or for legitimate business records:
- Financial, billing and audit records — written by our systems only, and not editable or deletable from within the Service, so they form a tamper-evident history of your billing. We keep them for as long as your practice’s account exists. This in-Service history is not archived independently of your account: if the practice is closed and the deletion period elapses, it is deleted along with the rest of the practice’s data. (The invoices we issued to you are a separate record that we must keep — see the next point.) You can export the full billing history as a CSV file at any time, and you should do so if you need to satisfy your own statutory record-keeping obligations.
- Invoices we issue to you, and our own accounting records — when your practice pays us for a subscription or an add-on, we issue an invoice in our own name (a tax invoice, once we are registered for VAT) and keep a copy, together with the corresponding entry in our own accounting records. We are obliged to retain these: the Companies Act, 2008 requires a company to keep its accounting records for seven years, and the Tax Administration Act, 2011 separately requires tax records to be kept for five years. We apply the longer period — seven years, the same period we already apply to the minimal record kept after a practice is purged — so we keep them even after your practice’s account has been deleted, and we cannot delete them at your request while that obligation runs. This is permitted under section 14 of POPIA, which allows us to retain records for longer where retention is required or authorised by law.
- What those records contain — only what an invoice must show and what our books must record: your practice’s name and address, its VAT number if it has given us one, what was bought, the amount and VAT, the date, and the payment reference. They are held separately from your practice’s working data in the Service, are used only for accounting, tax and audit purposes, and are not used to contact you, to build a profile, or for any form of analysis or marketing. Where we record these amounts in our own accounting software, individual practices are not identified to that provider — the entries are aggregated and carry only our own invoice number and the payment reference.
- Account, practice and project data — retained while the account is active; on termination it is exported or deleted as described in our Terms and below.
- Security and dispatch logs — retained for a period proportionate to the security, audit and abuse-prevention purpose for which they are kept.
14Your rights
Subject to POPIA (and, if applicable to you, the GDPR/UK GDPR), you have the right to request access to the personal information we hold about you; to have it corrected or updated; to have it deleted; to object to certain processing; to withdraw a consent you have given; and, in some cases, to data portability. You will not be unfairly discriminated against for exercising these rights.
The Service already provides several ways to exercise these rights directly:
- Correct your profile and practice details in the account settings.
- Remove a team member — a practice owner/admin can remove a member, which revokes their access to the practice across every layer.
- Disconnect integrations — unlink Google, QuickBooks or BuildSphere, which removes stored tokens and (for the email link and QuickBooks) asks the provider to revoke access.
- Export your billing history to CSV from the subscription area.
For any request we cannot fully action in-product — including access to, or deletion of, data held about you — contact info@mail.sa-archpro.com (or your practice, where it is the Responsible Party). If you are not satisfied with how we handle your request, you may lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za (or, if you are in the EEA/UK, with your local supervisory authority).
16Children's data
The Service is a professional tool intended for registered architectural professionals and their practices. It is not directed to children and we do not knowingly collect personal information from children. If you believe a child’s information has been provided to us, please contact us so we can address it.
17Changes to this policy, and how to contact us
We may update this Privacy Policy from time to time. When we make material changes we will update the effective date above and, where appropriate, notify you in the Service. Your continued use after an update means you accept the revised policy.
Questions, requests or complaints: info@mail.sa-archpro.com (Information Officer) · SA-ArchPro (Pty) Ltd, Dana Bay, Mossel Bay, Western Cape, South Africa.
Our manual in terms of section 51 of the Promotion of Access to Information Act, 2 of 2000, sets out the records we hold and how to request access to them. It is available free of charge: download the PAIA Manual (PDF).