Privacy notice
This is the South Africa version, written to meet the Protection of Personal Information Act 4 of 2013 (POPIA). Choose your country if this is not the right one.
Who we are
Jonathan Mills, trading as Bivetica Invoice, a sole trader established in the United Kingdom at 28 High Street, Nettlebed, Henley-on-Thames, Oxfordshire, RG9 5DD.
This notice explains how we handle personal information and is written to meet the Protection of Personal Information Act 4 of 2013.
If you have any question about how we handle information, the contact details are at the end of this notice.
The two roles we play
We act in two different capacities, and which one applies changes your rights and who you should approach.
When you open an account with us, we decide how your account, billing, support and security information is handled. For that information we are the one responsible, and you should come to us directly.
When you use the software to record your own customers, employees, contractors and suppliers, you decide what to enter and why. For that information you are responsible and we simply act on your instructions. If you are one of our customer's customers or employees and you want your information changed or removed, please contact that business rather than us. We will help them do it, but the decision is theirs.
What we collect
Account and billing information. Your name, email address, a securely hashed password, your business or trading name, your subscription plan and your payment status. We do not see or store your card number.
The business records you enter. Customers (name, company, contact name, email, phone, billing address and tax number), invoices, quotes, products, expenses, suppliers and payment records.
Employee and contractor information, if you use payroll. This can include name, email, phone, date of birth, gender, National Insurance number, tax code, National Insurance category, student loan plan, pension status and salary. This is sensitive identity information and we treat it accordingly. Contractor records may include a Unique Taxpayer Reference.
Photographs of receipts and invoices, if you use the scanning feature. The picture is stored with the expense as your record of it. Whatever is written on the paper is therefore held too, which may include a shop name, what was bought, and the last four digits of a payment card printed on the receipt.
Enquiries. If you use the contact form we keep your name, email, business name, what you asked about and your message. We store a one-way hash of your IP address to limit abuse of the form, not the address itself.
Technical and security information. Sign-in times, actions taken in the account for audit purposes, and error logs. We do not run analytics or advertising trackers.
Why we use it
To provide the service you have asked for: creating and sending invoices, recording payments, preparing reports and running payroll where you use it.
To take payment for your subscription and keep our own accounting records.
To keep accounts secure, investigate misuse and maintain an audit trail.
To answer your questions when you contact us.
To meet our own legal obligations, including tax and accounting record-keeping.
Where your data is stored
Your data is currently held on servers located in Dallas, Texas, in the United States, operated by our hosting provider Hawk Host Inc. We are planning to move to hosting in the United Kingdom or European Union, and we will tell account holders before that happens.
Separately, if you use the receipt scanning feature, that picture is sent to Anthropic in the United States to be read, and only at the moment you scan it.
We say this plainly because you are entitled to know where your records physically sit. We have never claimed to host in the United Kingdom and we will not.
Sending information outside South Africa
Our hosting is in the United States, so your personal information is transferred outside the Republic.
Section 72 of POPIA permits this only where a recognised condition applies — for example where the recipient is bound by binding corporate rules or an agreement providing an adequate level of protection, or where you consent, or where the transfer is necessary to perform a contract with you.
We will name the basis we rely on here once it is finalised with our hosting provider.
Who else sees it
Hosting. Hawk Host Inc., United States, stores the application and its databases.
Payment providers. Where you connect one, you authorise it on the provider's own website and your merchant account remains yours. Depending on what you enable this may include Stripe, PayPal, GoCardless or an open banking provider such as TrueLayer. Money settles to you, never to us. Payment connections currently run in test mode and go live only after the provider approves your account.
Email delivery. Invoices and notices are sent either from our own mail server or, if you have set it up, from your own business email account using credentials you supply. Those credentials are encrypted.
Reading scanned receipts. If you use the scanning feature, the picture of that receipt is sent to Anthropic, in the United States, which reads it and returns the supplier, date and amount so the expense form can be filled in for you. It is sent only at the moment you scan something. Anthropic does not use it to train its models, and neither do we. If you would rather nothing left the service, type the expense in by hand instead — everything works without scanning.
Accounting software. If you choose to export or connect to Xero, QuickBooks, Sage or Zoho, the data you export goes to them under their terms.
HMRC, for United Kingdom businesses that use the tax features. Live filing is not switched on yet.
Professional advisers and authorities, where we are legally required to disclose.
We do not sell your data. We do not share it for advertising. We do not use it to train artificial intelligence models.
How long we keep it
Account and business records are kept for as long as your account is open. If you close your account, you can export everything first, and you should, because you own it.
After an account closes we keep records for six years where we need them for our own tax and accounting obligations, then delete them.
Receipt photographs are kept with the expense they belong to, for the same six years, because they are the evidence behind the figure.
Enquiry messages are kept for two years.
Security and audit logs are kept for twelve months.
We do not keep data indefinitely without a reason.
How we protect it
Connections to the service use TLS encryption. Passwords are hashed and never stored in a readable form. Email credentials you give us for sending are encrypted individually.
Access inside an account is controlled by role, so a person only reaches the parts of the system their job needs. Employees using the payslip portal can see only their own payslips.
We never ask for card security codes or online banking passwords, and neither will any genuine message from us. If you receive one, it is not from us.
No system is perfectly secure. We tell you honestly what we do rather than promising what we cannot guarantee.
Your rights
POPIA gives you, as a data subject, the right to be told that we hold your personal information and to request a copy of it, under section 23.
You may ask us to correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, under section 24.
You may object to our processing on reasonable grounds, and you may object at any time to processing for direct marketing. We do not send direct marketing.
You may also submit a request for access to records under the Promotion of Access to Information Act 2 of 2000.
To make any of these requests, email the address at the bottom of this notice. We will respond within the time the law allows and will not charge you for it. We may need to confirm who you are first, so that we do not hand your information to somebody else.
Cookies
We use three cookies and none of them track you.
bivetica_invoice_session keeps you signed in. XSRF-TOKEN protects forms against a common attack. bv_region remembers which country's pricing you chose to look at.
The first two are strictly necessary for the service to work. The third only remembers a choice you made yourself. We run no analytics, no advertising pixels and no third-party trackers, so there is nothing here for you to opt out of.
Children
The service is for businesses. It is not intended for children and we do not knowingly collect information about them.
Changes to this notice
If we change this notice we will update the date at the top. If a change materially affects account holders — a new subprocessor, or a change of hosting country — we will tell them directly rather than relying on them to notice.
How to complain
Please raise the matter with our Information Officer first, using the contact details below.
You may also complain to the Information Regulator (South Africa) at inforegulator.org.za, which can investigate and enforce compliance with POPIA.
Where a security compromise puts your personal information at risk, section 22 requires us to notify both the Regulator and you as soon as reasonably possible after discovering it.
How to contact us
Email hello@bivetica.com and say what you would like us to do. If your question is about records held by a business that uses Bivetica Invoice — an invoice you received, or your payslip — please contact that business first, because they decide what happens to those records and we act on their instructions.
Our regulator for this version of the notice is the Information Regulator (South Africa).
This notice describes how the software actually works today, checked against the system on 27 August 2026. It has not yet been reviewed by a qualified adviser, and a small number of points — chiefly the legal safeguard covering our United States hosting — are still being put in place. Those are listed for our advisers and will be completed here rather than left vague.