Privacy policy

POPIA · South Africa

ArrayTrace (Pty) Ltd is the responsible party for personal information processed through ArrayTrace. This policy says what we hold, why we hold it, how long we keep it, who else sees it and what you can make us do about it. It is read with our terms of use.

Questions, requests and complaints go to info@arraytrace.co.za.

1. What we hold

What you give us directly. Your name and email address, the team you belong to and your role in it, and your password stored only as a hash. If your firm subscribes, the billing records that follow from that - never your card number, which is held by the payment provider and never reaches us.

What you put into the product. Sites and their coordinates, the client name and contact details you record against a project, designs, weather selections, simulations, financial models and the proposals you generate. This is your firm's working material and we process it to run the service.

What the service records as it runs. An audit trail of who changed what and when, application logs, and sign-in attempts including ones that fail.

What you send us about the product. If you use the feedback button, the message you write, the page you were on, and any screenshot you chose to attach.

2. Why we are allowed to

  • To perform our contract with you - creating your account, storing your designs, running simulations, producing documents, taking payment.
  • Because we have a legitimate interest - keeping accounts secure, detecting abuse, and diagnosing faults. The ground we rely on for security processing is section 11(1)(d) of POPIA.
  • Because the law requires it - keeping financial records for the periods tax legislation sets, and answering lawful requests.

We do not sell personal information, and we do not use your projects, designs or client data to train any model.

3. Site coordinates are treated as sensitive

A site coordinate identifies both a person's home and a customer's commercial pipeline, so it is handled as sensitive throughout. Application logs record a project by its identifier and never by address or coordinate, and the audit trail carries the same restriction. Passwords, tokens, identity numbers and banking details are never written to a log in any form. The same rule applies to feedback: an item is logged by its reference and the page path, never by what somebody wrote.

4. Sign-in records

Sign-in, registration, password-reset and email-verification events record the address that was tried, including attempts that fail. This is necessary to detect credential-stuffing and brute-force attacks against your account, and it is the one deliberate exception to the rule above that email addresses are not written to logs. It relies on the legitimate-interest ground in section 11(1)(d) of POPIA. Passwords are never recorded, in any form, on any code path.

5. How long we keep it

Account and project data
While your team is active. Erasing the team removes it.
Audit trail
For as long as the team exists. It is what answers "who changed this figure", so it deliberately outlives the record it describes.
Application logs
Rolled daily and kept for as long as the deployment's retention allows. They carry identifiers, not addresses or coordinates.
Financial records
For the period the applicable tax legislation requires, which outlasts an account being closed.
Feedback
Until the defect it describes is resolved and the item is closed. It is not attached to your team's estate, and erasing a team leaves the reports that team made standing.

6. Who else sees it

Your own team. A project belongs to the team, not to the person who made it, so everybody in your team can see it. That is the product working, and it is worth knowing before a personal note goes into a project field.

Anybody you share a project with. A share link is view-only and shows the site and the proposals you generated. Anybody holding the link can open it, so withdraw a share when it is no longer wanted; that takes effect immediately.

Our own staff. Whoever operates this deployment can see accounts, teams and settings in order to support them. Those screens are restricted to named administrators and every role change is written to the audit trail with a reason.

Service providers. The payment provider configured for this deployment, the mail service that sends our messages, and the map and weather services the product queries. A weather fetch is snapped to a grid cell before it leaves us precisely so your exact site coordinate is not what goes to a third party.

Authorities, where we are legally compelled.

7. Where it is kept

Project data is hosted in this deployment's own region and processed under the privacy law that applies there.

Some of what the product queries is served from outside that boundary - map imagery, the open-data geocoder and the public irradiance service among them. Those calls carry a location or a search term and never your name, your account or your client's details.

8. What you can make us do

  • See it. Your team's whole estate exports as JSON from Your data. Your own account data exports from your profile.
  • Correct it. Your own details from your profile; your firm's from the team screens.
  • Erase it. A team's owner can erase the whole team from Your data. It is the one operation in the product that deletes rather than archives, it takes the projects, designs, simulations and documents with it, and it cannot be undone.
  • Object, or withdraw consent, where we relied on either.
  • Complain - to us first, and to the Information Regulator of South Africa if our answer does not satisfy you.

Where erasing something would break a record we are obliged to keep, we will say so and say exactly what is retained and why, rather than quietly keeping it.

9. Security

Traffic is encrypted in transit. Passwords are hashed, never stored or recoverable. Third-party credentials in the administration console are encrypted at rest against the deployment's own key ring. Every team's data is separated by a filter applied at the database query itself rather than by each screen remembering to ask, which is what makes a URL from another team's account resolve to nothing rather than to their pipeline.

10. Changes

We may change this policy. A material change is notified to the email address on your account before it takes effect; a correction of wording is simply made. Because the text is held in source control, what changed and when is a matter of record.

Something went wrong. Reloading the page usually fixes it. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.