INTELLIVISION POPIA TRUTH
Sign In Start Free →
PROTECTION OF PERSONAL INFORMATION ACT (POPIA)

Privacy Policy & Data Sovereignty

We believe the most secure data is the data that never leaves your building. Your operational records live locally in your browser's IndexedDB.

📁 1. Local Device Storage in IndexedDB

Your business data lives on your device, not our servers, until you choose Connected Mode. When you record sales, register products, or manage inventory in IntelliVision, all records are stored in your device browser's persistent IndexedDB database.

Zero Server Contact in Offline Mode: IntelliVision keeps selling with no internet. During till operations, no telemetry, customer names, or transaction amounts are transmitted to external servers.

🔑 2. Password Security & Cryptography

PBKDF2 Local Hashes: User passwords are never transmitted or stored in plain text. Passwords are saved only as salted PBKDF2 hashes and verified directly on your device.

Fail-Closed Role Access: Our role-based access control (RBAC) enforces strict authorization on-device. Cashier sessions can never view or open owner-restricted reports or settings.

👤 3. Staff Face-Photo Consent for Biometric Clock-In

IntelliVision includes optional biometric facial clock-in for staff attendance. In strict compliance with POPIA section 26 and 27 concerning special personal information:

  • On-Device Only: Staff facial verification templates are generated and processed entirely on the local device hardware. Facial biometric data is never transmitted to or stored on remote cloud servers.
  • Recorded Consent: Prior to registering any staff member, the application records affirmative, explicit employee consent.
  • Purpose Limitation: Biometric templates are used strictly and solely for local shift clock-in attendance records and never sold or shared with any third party.

☁️ 4. What Connected Mode Will Change

Connected Mode: cloud sync, multi-site and integrations Coming soon

Connected Mode is an upcoming, strictly opt-in capability. If and when you explicitly activate Connected Mode in the future:

  • You will be presented with a clear consent screen detailing what data will sync to encrypted cloud storage.
  • Multi-site consolidation will occur only across branches you explicitly link.
  • You retain the ability to disable Connected Mode and revert to standalone on-device operation at any time.

🌍 4b. Regional Auto-Detection

On your first visit we detect your country only (never your identity) to pre-set your currency, tax regime and language — your raw IP address is never stored, and any region or language you choose yourself always overrides and replaces the automatic guess.

📤 5. Data Export, Portability & Deletion Rights

In accordance with POPIA sections 23 and 24, you maintain complete ownership and control of your records:

  • Data Deletion: You can purge your local database at any moment directly through the platform reset tool or browser storage settings.
  • Export Out & Exit Freedom: Export everything and leave anytime - your data is yours Coming soon. We are engineering open-format export tools so you are never locked in.

⚖️ 6. Truthful Audit & Integrity

No Simulated Filings: We never simulate a payment, filing or approval — if it is not real, it says so. We do not claim third-party certifications we do not hold.

📮 Responsible party, Information Officer & complaints

Pending owner confirmation: the verified legal entity, registered address, Information Officer name and official contact are not yet published. This is a blocker for connected or paid commercial processing.

For the current offline beta, the merchant/business owner controls the operational records kept on the merchant’s device and must provide the notices, permissions and deletion process required for staff and customers. Face-photo clock-in is optional and consent-based; delete local photos when consent is withdrawn.

Use the local export, backup and reset tools for records on your device. The official IntelliVision support channel is pending verified owner details. Regional complaints should follow the regulator route applicable to the data subject’s country.