Privacy & Cookie Policy
This policy explains how ClientFlow handles personal information in the South Africa market and how we use cookies and similar technologies across our websites and services.
This is a template policy and should be reviewed and adapted by qualified legal counsel before launch.
Last updated: 29 June 2026
1. Introduction
ClientFlow ("ClientFlow", "we", "us" or "our") provides a white-labelled client-management and business operating system (BOS) platform for debt, credit and legal-services firms. We take the privacy of the people whose information we process seriously and are committed to handling personal information lawfully, fairly and transparently in accordance with the Protection of Personal Information Act, 2013 (POPIA).
This policy applies to information we collect from visitors to our marketing websites and from the businesses (our "Customers") who use the platform. Where we process personal information on behalf of a Customer as part of the service, we act as a processor (or service provider) and that Customer is responsible as the controller for that data.
2. Information We Collect
Depending on how you interact with us, we may collect:
- Contact & account information — name, business name, email address, phone number and role, for example when you request a demo, contact us or create an account.
- Customer-provided data — the consumer and client records, communications, documents and payment details that our Customers upload to or generate within the platform, which may include sensitive financial and personal information.
- Usage data — log data, device and browser information, IP address and interactions with our websites and platform.
- Cookies & tracking data — as described in the Cookies & Tracking section below.
3. How We Use Information
We use personal information to:
- provide, operate, maintain and improve the platform and our websites;
- respond to enquiries, provide demos and offer customer support;
- manage accounts, billing and the contractual relationship with Customers;
- send service communications and, where permitted, relevant marketing;
- monitor performance, prevent fraud and secure our services; and
- comply with legal, regulatory and compliance obligations.
We process personal information only where we have a lawful basis to do so, such as the performance of a contract, our legitimate business interests, your consent, or compliance with a legal obligation.
4. Cookies & Tracking
We and our service providers use cookies and similar technologies to operate our websites, remember your preferences, understand how our sites are used and measure the effectiveness of our communications. We use:
- Essential cookies that are necessary for the site and platform to function;
- Analytics cookies that help us understand usage and improve our services; and
- Preference cookies that remember your settings, such as your selected region.
You can control or delete cookies through your browser settings. Disabling some cookies may affect the functionality of our sites.
5. Data Sharing & Processors
We do not sell personal information. We share information only as needed to run our business, including with:
- trusted sub-processors and service providers (such as hosting, email, SMS, analytics and payment providers) who act on our instructions under appropriate contractual safeguards;
- our Customers, in respect of the data they manage on the platform;
- professional advisers and authorities where required by law or to protect our rights; and
- a successor entity in connection with a merger, acquisition or sale of assets.
6. Data Security
We maintain appropriate technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse or alteration. These include encryption in transit, access controls, monitoring and regular review of our security practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Data Retention
We retain personal information for as long as necessary to fulfil the purposes set out in this policy, to provide our services, and to comply with legal, accounting and regulatory obligations. Customer-provided data is retained in accordance with our agreement with the relevant Customer and is deleted or returned on termination, subject to applicable law.
8. Your Rights
Subject to the Protection of Personal Information Act, 2013 (POPIA), you may have the right to access, correct, update or delete your personal information, to object to or restrict certain processing, to withdraw consent, and to lodge a complaint with a supervisory authority. In South Africa you may contact the Information Regulator, and we will respond to requests in line with POPIA. To exercise any right, please contact us using the details below. Where we act as a processor, we will direct such requests to the relevant Customer.
9. International Transfers
Personal information may be processed and stored in countries other than the one in which it was collected, including by our sub-processors. Where information is transferred across borders, we take steps to ensure it receives an adequate level of protection through appropriate safeguards consistent with the Protection of Personal Information Act, 2013 (POPIA).
10. Contact
If you have questions about this policy or how we handle personal information, please contact us at info@clientflow.co.za.