Digital Officeby Datova

Datova Technology (Pty) Ltd · Datova Digital Office

Privacy Policy

Version 2026-10-draft-1 · last updated 2026-10-10

Draft — not yet reviewed by a lawyer. Highlighted text is still to be confirmed by Datova. This draft describes how Digital Office works today and will be replaced by a reviewed version.

1. Two different roles

Datova Technology (Pty) Ltd ("Datova") is responsible for the personal information it uses to run its own business — for example the accounts of people who sign in, billing contacts and support requests.

Customer organisations use Digital Office to manage their own staff, clients, suppliers and work. For that information the customer organisation decides what is collected and why; Datova processes it on the organisation's behalf and instructions, under the Data Processing Agreement. Questions or requests about that information should go to the organisation first; Datova will help it respond.

2. What we hold

Account and profile: name, work email address, job title, organisation memberships and roles, profile picture (optional), signature image (optional, for approvals), notification preferences, and the time you last signed in. Passwords are handled by our authentication provider and are never visible to Datova.

Information your organisation puts into the service, which may include: employee records (contact details, position, department, manager, employment dates and type, work schedules, attendance, leave requests and balances, evidence such as medical certificates, performance reviews and HR cases, HR documents); client and supplier contacts and communication history; quotations, contracts, invoices, payments, expense claims and receipts; projects, tasks, meetings, messages, comments and documents; compliance, legal and risk records.

Security and audit information: a record of significant actions (who did what and when), sign-in activity and technical logs needed to run and protect the service. These records are kept even after the related item is removed, so that changes can be accounted for.

We do not use advertising, analytics or tracking tools in the service, and we do not sell personal information.

3. Why we use it

To provide the service your organisation subscribed to (sign-in, showing you the right information, sending notifications and the emails your organisation's users send through the service); to keep it secure and investigate problems; to provide support when your organisation asks for it; to bill and manage subscriptions; and to meet legal obligations.

TO CONFIRM with counsel: the legal bases for each purpose under the data-protection laws that apply (for example contract performance, legitimate interests and legal obligation), which laws apply — Namibia and the markets Datova serves (such as South Africa's POPIA or the EU/UK GDPR where relevant) — and whether any processing needs consent.

4. Who receives it (service providers)

Supabase — database, sign-in and file storage, hosted in the European Union (Ireland). Holds all service information and files.

Railway — runs the Digital Office application, in the European Union (Netherlands). Processes information while serving pages; keeps technical logs.

Resend — delivers the service's emails (notifications, invitations, password resets, quotations and invoices sent to clients), sending region European Union (Ireland). Receives the recipient's address and the email content.

Zoho — Datova's own business email (for example messages to support@ and admin@).

Cloudflare — the datovatechnology.com domain's DNS, and hosting of Datova's public website.

TO CONFIRM: each provider's data-processing terms and transfer safeguards; update this list whenever a provider changes. We also share information when the law requires it.

5. Where it is held and international transfers

Datova is based in Namibia; the service is hosted in the European Union as described above, so information is transferred outside Namibia. TO CONFIRM with counsel: transfer requirements and safeguards under the applicable laws.

6. How long we keep it

Account information is kept while you have access to an organisation and for TO CONFIRM: period afterwards. Your organisation's information is kept for the duration of its subscription and then returned or deleted as set out in the Subscription and Service Terms. Audit records are kept for TO CONFIRM: period.

Backups: TO CONFIRM — currently backups are taken manually before significant changes; describe automated backup frequency and retention once enabled.

7. Security

Each organisation's information is separated and access is enforced by the database for every request, according to each person's roles. Connections use encryption (HTTPS). Sensitive areas such as HR records, finance and confidential documents are limited to people with the right permissions. Datova staff can only see an organisation's information through support access the organisation grants, limits and can revoke, and which is recorded.

No system is perfectly secure. If a security incident affects your personal information we will inform the organisation and, where the law requires, the people affected and the authorities.

8. Your rights

Depending on the law that applies, you may have the right to ask for access to your personal information, have it corrected or deleted, object to or limit its use, or receive a copy. For information your organisation controls (for example HR records), contact your organisation; for your Datova account, contact us at admin@datovatechnology.com. We will verify the request and respond within TO CONFIRM: period.

You can correct your name and picture yourself under Account, and choose which notification emails you receive.

9. Cookies

The service uses only cookies and browser storage needed for it to work. See the Cookie Notice.

10. Changes and contact

We will publish changes here with a new version and date, and tell organisations about material changes. Privacy questions and requests: admin@datovatechnology.com.