Privacy Policy

Last updated: August 3, 2026

1. Introduction

Welcome to Goodbooks ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal information.

This Privacy Policy describes how Goodbooks (Pty) Ltd collects, uses, processes, and discloses your information, including Special Personal Information, in conjunction with your access to and use of the Goodbooks Platform, including our CIPC filing services, Identity Verification, and Credit Reporting tools.

We act in accordance with the Protection of Personal Information Act (POPIA) and the Promotion of Access to Information Act (PAIA).

2. Definitions

  • "Responsible Party": The entity that determines the purpose of the processing.
    • If you are a Business Owner: You are the Responsible Party for your company data.
    • If you are an Accountant/Practitioner: You are the Responsible Party for your clients' data.
  • "Operator": Goodbooks acts as the Operator, processing data on your behalf.
  • "Personal Information": Information relating to an identifiable, living, natural person or existing juristic person (company).

3. Information We Collect

To provide our compliance services, we collect information that goes beyond basic contact details.

3.1 Information You Give Us

  • Identity Data: Names, ID numbers, Passport numbers of Directors and Shareholders.
  • Corporate Data: Enterprise numbers, registered addresses, financial year-ends, and shareholding structures.
  • Financial Data: Bank account details (for processing CIPC payments) and Xero/Accounting integration data (if connected).
  • Biometric Data: Facial images and "liveness" video clips used for identity verification.

3.2 Information We Collect Automatically

  • Usage Data: IP addresses, browser type, and device information.
  • Transaction Logs: Audit trails of every CIPC filing, document generation, and signature event (required for legal non-repudiation).

3.3 Information from Third Parties

We may receive information about your company or directors from:

  • CIPC Registry: To sync your company status and details.
  • Credit Bureaus: (TransUnion, Experian, XDS) When you request a credit report.
  • SARS: When you link your tax profile via our ISV integration.

4. How We Use Your Information

We use your data to perform the specific mandates you give us:

  1. Statutory Filing: Submitting Annual Returns, Director Changes, and Beneficial Ownership declarations to the CIPC.
  2. Identity Verification: Processing facial scans via our partner (Didit.me) to verify the identity of a director before allowing sensitive changes.
  3. Credit Monitoring: Retrieving credit data to display solvency and liquidity risks.
  4. Communication: Sending WhatsApp/SMS notifications for OTPs, signature requests, and compliance reminders.

5. Processing of Special Personal Information

By using our Identity Verification or Credit Reporting features, you explicitly consent to the processing of Special Personal Information:

  • Biometrics: You acknowledge that facial scans are processed to prevent fraud and identity theft. This data is encrypted and transmitted securely to our verification partner.
  • Credit History: You warrant that you have obtained the necessary consent from any Data Subject (Director or Company) before running a credit check on them via our platform.

6. Disclosure to Third Parties

We do not sell your data. We share it only to execute your instructions. Your data is shared with:

  • Government Registries: CIPC, SARS, and the Department of Labour (for filing purposes).
  • Verification Partners: Didit.me (for Biometric checks).
  • Credit Bureaus: TransUnion, Experian, and XDS (for credit reports).
  • Communication Providers: WhatsApp (Meta) and Postmark (Email) for notifications.
  • Payment Gateways: Peach Payments (for processing card/EFT transactions).

7. Data Retention

We retain your personal information only for as long as necessary.

  • Account Data: Retained while your account is active.
  • Statutory Records: In accordance with the Companies Act 71 of 2008, we retain company records (Resolutions, Minutes, Registers) for a minimum of 7 years.
  • Biometric Data: Retained only for the duration of the verification session, after which only the Verification Result (Pass/Fail) and the audit certificate are stored.

8. Security

We implement enterprise-grade security to protect your data, including:

  • Encryption: Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Access Control: Strict role-based access for our internal staff.
  • Audit Trails: We log every action taken on the platform to ensure accountability.

While we take every precaution, no transmission over the Internet is 100% secure. You are responsible for keeping your login credentials confidential.

9. Your Rights

Under POPIA, you have the right to:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request that we update or correct your information.
  • Deletion: Request deletion of your data (subject to our legal obligation to retain statutory records for CIPC/SARS).
  • Objection: Object to the processing of your personal information.

To exercise these rights, email our Information Officer at the address below.

10. International Transfers

Some of our service providers (e.g., Cloud Hosting) may be located outside South Africa. We ensure that these providers are subject to laws or binding agreements that provide an adequate level of protection for your personal information, consistent with POPIA.

11. Contact Us & Information Officer

If you have questions about this policy or wish to lodge a complaint, please contact our Information Officer:

If you are unsatisfied with our response, you have the right to complain to the Information Regulator of South Africa (https://inforegulator.org.za/).