1. Who we are and our privacy roles
EstateFlow operates the estate-readiness platform at estateflow.co.za. For direct individual and family accounts, billing, support, security and EstateFlow’s own business operations, EstateFlow acts as the responsible party under the Protection of Personal Information Act 4 of 2013 (“POPIA”).
Where a professional organisation uses EstateFlow to manage client records, the professional usually decides why the client information is collected, what is entered and who may access it. The professional is generally the responsible party and EstateFlow acts as its operator under a data-processing agreement. EstateFlow remains independently responsible for account administration, billing, fraud prevention, legal compliance, support and security records that it determines.
The current privacy contact and interim Information Officer channel is admin@estateflow.co.za, at 33 Silvertree, Jeffreys Bay, South Africa. The registered legal entity, complete postal code, telephone number, named Information Officer and registration reference must be added when confirmed. This Notice does not pretend that missing statutory particulars have already been completed.
2. Whose information we may process
- website visitors, account applicants, free users and paid subscribers;
- spouses, partners, children, dependants, guardians, beneficiaries, heirs, executors, trustees, creditors, employees and emergency contacts recorded by an authorised user;
- advisers, attorneys, accountants, fiduciary practitioners, tax practitioners, executor teams and authorised members of professional organisations;
- people who contact support, submit complaints, request demonstrations, report vulnerabilities or receive permitted service messages or marketing; and
- deceased persons where their records also identify living people or remain relevant to another legal or professional duty.
EstateFlow is not directed at children. A competent adult must control the account and provide lawful authority for a child’s information.
3. Categories of personal information
| Category | Examples |
|---|---|
| Account and contact | Name, email, phone, organisation, role, account status, preferences and authentication identifiers. EstateFlow does not receive your readable password. |
| Identity and family | Identity or passport number, date of birth, in- or out-of-community marital regime, accrual status, ANC or marriage-document references, spouse or partner information, dependants, guardians and relationships. |
| Estate and financial | Assets, liabilities, ownership, valuations, base costs, policies, account references, income, expenses, tax assumptions, gifts, bequests and liquidity information. |
| Legal and fiduciary | Will instructions, nominated executors, trustees, guardians, mandates, professional reviews, administration forms, status records and supporting instructions. |
| Sensitive information | Children’s information, identity-document copies, health or special-needs notes and other sensitive records an authorised user chooses to provide. |
| Regulated assets | Firearm descriptions, licence status and expiry data or details of other regulated assets. EstateFlow is not a licensing or transfer authority. |
| Vault content | Copies of wills, identity documents, marriage or divorce records, deeds, policies, statements, certificates, photographs and supporting records. |
| Payment and subscription | Plan, amount, billing status, transaction reference, mandate or token reference, payment method type and limited metadata supplied by the payment provider. |
| Technical and security | IP address, browser and device signals, authentication events, timestamps, activity logs, security tokens, error information and abuse-prevention results. |
| Communications | Support requests, emails, complaints, feedback, review notes and authorised collaboration messages. |
| AI feature data | User-selected prompts or estate facts, generated results, feedback and proportionate safety or audit records when an AI feature is knowingly used. |
Do not upload information merely because a field exists. Provide only information that is relevant, accurate and lawful for the planning or administration purpose.
4. Sources, purposes and lawful grounds
We collect information directly from you; from a person or professional you authorise; from a professional organisation managing a client record; from payment and communications providers; from devices and security logs; and, where lawful and necessary, from public records or authorities.
| Purpose | Typical POPIA justification |
|---|---|
| Create and administer accounts | Performing the user contract; legitimate interests in operating and securing the service. |
| Provide calculations, reports, vault, reminders and sharing | Contract, user instructions and consent where appropriate. |
| Process subscriptions, refunds and records | Contract, legal obligations, accounting and fraud-prevention interests. |
| Support, complaints and requests | Contract, legal obligations and legitimate service-quality interests. |
| Security, logging and abuse prevention | Legal duties and legitimate interests in protecting users and systems. |
| Professional client workflows | Documented instructions from the professional responsible party and its lawful basis. |
| Children’s or special personal information | Prior consent of a competent person or another specific lawful ground under POPIA. |
| Service measurement and improvement | Legitimate interests using minimised or de-identified information; consent where non-essential technologies require it. |
| Direct marketing | Specific consent or the limited existing-customer basis permitted by law, always with an opt-out. |
| Legal compliance and claims | Legal obligation or establishing, exercising or defending rights. |
Some information is necessary for authentication, billing or a requested function. If required information is not provided, that function may not work. Estate values, family information and vault uploads are generally voluntary, but reports may be incomplete without them.
5. Children, third-party information and special personal information
A user entering information about another person confirms that they have lawful authority, will provide any required privacy notice and will use the information only for the authorised estate-planning or administration purpose. EstateFlow records a confirmation before new beneficiary and dependant information is captured.
A child’s information may be processed only when supplied or authorised by a competent person or where another POPIA ground permits it. We may ask for reasonable confirmation, restrict access or delete the information where authority is unclear.
Health, disability, special-needs and similar sensitive information should be limited to the specific support, dependency, guardian or trust-planning purpose. Do not upload full medical histories where a short, non-diagnostic note is sufficient.
7. Professional-account responsibilities
A professional organisation must establish the lawful basis and mandate for its client records, give required notices, limit access, remove departing users, respond to client rights requests and comply with professional retention and confidentiality requirements.
EstateFlow processes professional client information only on documented instructions embodied in the agreement, configured actions, support requests and data-processing addendum, unless law requires otherwise. We will reasonably assist with access, correction, deletion, objection, impact assessments, incidents and regulator enquiries, taking account of the processing and information available to us.
8. International processing and transfers
Some cloud, support, content-delivery or security infrastructure may be located outside South Africa or accessed by an authorised provider from another country. Before a cross-border transfer, EstateFlow must use a lawful POPIA section 72 ground, such as adequate protection under law or binding agreement, valid consent where appropriate, or necessity for the contract.
We assess the information categories, purpose, recipient, location, contractual protection, security and retention, and aim to minimise identifiable information transferred. Contact us for current material provider and transfer information relevant to your account.
9. AI features and automated processing
AI-enabled functions are optional and must identify themselves. The interface should tell you what selected information will be analysed. The default is to minimise identifiers and exclude full vault documents unless a feature genuinely requires a document and you knowingly start the analysis.
Where an external AI provider is used, EstateFlow will assess and document its purpose, information categories, retention and training settings, security and cross-border safeguard. Identifiable customer content will not be used to train a general-purpose model unless clear notice and a valid legal basis are established first.
EstateFlow does not intend to make decisions based solely on automated processing that produce legal or similarly significant effects. You may report an AI concern or request human review of a material output by emailing admin@estateflow.co.za.
10. Security safeguards and incidents
Safeguards are selected according to the sensitivity and risk and may include:
- unique accounts, authentication, background abuse protection and role-based access;
- encryption in transit and protective controls for stored information and secrets;
- permission-based vault sharing, time-limited document access and access logging;
- monitoring, backups, vulnerability management, incident response and service restoration;
- confidentiality obligations, least privilege, user offboarding and operator security requirements; and
- risk and impact assessments for high-risk functions.
No system is perfectly secure. Protect your devices and credentials, promptly revoke obsolete access and maintain independent copies of critical documents.
If there are reasonable grounds to believe personal information was accessed or acquired by an unauthorised person, we will investigate, contain the issue, preserve relevant evidence and make notifications required by POPIA, subject to any lawful delay requested by an authority.
11. Retention, account closure and deletion
We keep information only while needed for the stated purpose, the contract, legal retention, security, fraud prevention, a dispute or an authorised professional instruction. Retention differs by record:
- active account and estate records are kept for the account relationship and a controlled closure period;
- deleted vault items are removed from active access promptly and expire from protected rotating backups according to the documented backup cycle;
- billing, tax and transaction records are retained for applicable accounting and legal periods;
- support and complaint records are kept for service quality, audit and dispute purposes;
- routine authentication and security logs are kept for a proportionate security period, with incident evidence retained longer where necessary;
- professional client information is returned or deleted according to the professional organisation’s lawful instructions and data-processing agreement; and
- a minimal marketing-suppression record may be retained to ensure an opt-out is respected.
Exact operational targets will be published only after production databases, backups and all operators have been verified against them. Request current details for a specific record category from admin@estateflow.co.za.
12. Your POPIA rights and how to use them
Subject to POPIA and other applicable law, you may:
- ask whether we hold your personal information and request access;
- request correction, completion, deletion or destruction where the legal requirements are met;
- object to processing based on applicable grounds;
- withdraw consent without affecting processing that was lawful before withdrawal;
- opt out of direct marketing at any time;
- request information and make representations about a significant automated decision where POPIA requires safeguards; and
- complain to EstateFlow or the Information Regulator.
Email admin@estateflow.co.za with the subject “Privacy request”. Describe the request and the relevant account or relationship without sending unnecessary identity documents. We may verify identity and authority before disclosing or changing records. A request may be limited where law requires retention, another person’s rights must be protected or another lawful refusal ground applies.
Direct marketing
Marketing consent must be separate, specific and optional. Where EstateFlow relies on a lawful existing-customer basis for similar services, each message will identify EstateFlow and contain a working opt-out. A suppression record may be retained so that we do not contact you again.
Information Regulator
You may lodge a complaint with the Information Regulator (South Africa). Current channels and forms are available at inforegulator.org.za. The PAIA section explains requests for records needed to exercise or protect a right.
Changes to this Notice
We will update the version and effective date when this Notice changes. We will give prominent notice, and obtain fresh consent where required, before making a materially new use of sensitive information.