DAFNI
DAFNI / Privacy policy

Privacy policy

How DAFNI handles information about account users, business contacts and invoice communications.

Effective 27 September 2026

On this page

Who operates DAFNI

DAFNI is operated by Esteni Van Niekerk in a personal capacity. In this notice, “we” and “us” refer to that operator. Contact estenivn+dafni@gmail.com for privacy questions.

Correspondence address: 29 Margaret Maytom Avenue, Durban North, Durban, 4051, South Africa.

For account administration and enquiries addressed to us, we determine how information is used. For customer records managed by a business using DAFNI, that business generally determines the purpose of processing, and DAFNI handles the records on its instructions. Questions about an invoice or its accuracy should also be directed to the business that issued it.

Current development stage

Development and controlled testing

Development and controlled testing of DAFNI uses fictional invoice data; account details and authorised test communications may contain real personal information.

Direct Meta WhatsApp integration is under development and testing. Live synchronisation of invoice, payment and allocation information from the connected accounting platform, and live AI model calls, are not currently active. These capabilities must not be assumed to be available from this notice.

This notice covers the current development service and describes connected-service handling where a connection is enabled. We will update the notice before material changes to data use or a wider launch.

Information handled

  • Account information: name, email address, company membership, role, invitations and authentication records.
  • Business and invoice records: customer names and reference codes, contact details, invoice references, dates, amounts, balances, documents and payment or credit information supplied to the workspace.
  • Communications: outbound email recipients including To, CC and BCC, subject and message content, attachments, sending outcomes, and WhatsApp messages, recipient numbers, provider identifiers, replies and delivery information where received.
  • Workflow records: messaging permission evidence, recipient changes, follow-up notes, payment promises, instalment arrangements, exclusions, pauses and staff audit history.
  • Technical information: connection settings, protected integration credentials, session information and operational or security logs. Hosting and communication providers may also process IP addresses and device or request information.

Information comes from users and business administrators, contacts who communicate with a connected business, enabled providers, and the operation of the service. Please do not send passwords, payment-card details or unrelated sensitive information in messages or support requests.

Why information is used

We use information to provide account access, organise authorised invoice follow-ups, send requested documents and communications, record arrangements and permission choices, investigate errors, protect company data and respond to support or privacy requests.

The appropriate basis depends on the activity: providing a requested service, legitimate operational and security needs, legal obligations, or consent where required. An existing business relationship or a phone number in an accounting record is not automatically treated as WhatsApp messaging permission.

We do not sell personal information or use invoice messages for advertising.

The connected accounting platform remains the authoritative source of financial records. Financial transactions, payment allocations and corrections are processed there. DAFNI reads the relevant information to support invoice follow-ups and does not create or amend accounting transactions or independently determine outstanding balances. DAFNI does not make creditworthiness decisions. Staff handle disputes and uncertain cases.

Live AI processing is not enabled; its provider and data use would need to be disclosed before activation.

Service providers and access

Authorised members of a company can access its records according to their roles. DAFNI uses service providers to host the website and application, store information, manage sign-in, and deliver communications. Each provider receives information relevant to the service it performs. Depending on the features used, these include:

  • Supabase: application database, authentication, storage and backend functions.
  • Meta / WhatsApp: WhatsApp business messaging and message-status processing when connected.
  • The configured email provider: outbound messages and attachments.
  • Website hosting: the existing private development application is hosted through OpenAI Sites. Cloudflare hosts DAFNI’s public website.

Email services also support account invitations and privacy or support enquiries.

Customer replies to invoice emails go to the sending business’s configured mailbox or Reply-To address and are not imported into the DAFNI application. DAFNI’s privacy and support enquiries are handled separately through our contact email address. Recipients can retain or forward messages and attachments outside DAFNI.

We may disclose information where required by law or reasonably necessary to investigate misuse or protect rights. Provider handling is also subject to the relevant provider’s own terms and privacy notice.

Storage and protection

DAFNI’s current development database is hosted in Ireland. Other service providers may process information in additional countries, including through support services and subprocessors. Information is therefore not necessarily processed exclusively in Ireland or South Africa. Applicable provider terms and legal requirements govern these arrangements, including safeguards required for international transfers.

Controls include authenticated access, company and role restrictions, encrypted integration-secret storage and protected document access. No service can guarantee absolute security.

Retention and deletion

The following rules are agreed for the intended service. Retention and deletion operations still require implementation and verification; this notice does not claim that automatic cleanup is operating.

  • Company workspace: necessary records remain while the business uses DAFNI, subject to the record-specific rules below. A workspace does not expire simply because it is five years old.
  • Invoice conversations and follow-up history: five years after settlement or final resolution, with documented exceptions for disputes, investigations or applicable obligations. Open invoices and arrangements remain while needed. This is an operational default, not a claim that every message is a statutory financial record or that this period alone satisfies tax-record requirements.
  • Customer profiles: retain necessary details while the business relationship continues. After five years without meaningful business activity, review the record for deletion or de-identification. Genuine work, invoices, payments or customer interactions count as activity; a background synchronisation does not restart the clock. Unpaid invoices, retention obligations and documented exceptions must be considered. Unanswered reviews must not allow indefinite retention without justification.
  • Messaging permissions: preserve relevant permission evidence, recipient, number, scope, date and withdrawals independently of individual invoice cleanup. Changes of number, recipient or scope require appropriate review; permission is not automatically transferred. Keep only the information needed to honour an opt-out and demonstrate relevant choices.
  • Temporary PDF copies: 30 days for replaceable copies that can reliably be obtained again. Proof of payment, disputed documents and other important evidence follow the relevant longer record-retention rule.
  • Routine diagnostic logs: intended retention of 30 days for technical troubleshooting, such as failed requests or timeouts. Provider-managed logs may have different availability. Business audit records follow their associated record requirements; security incidents require a separately justified period. Logs should exclude credentials and unnecessary message content.

A conversation may concern several invoices. The expiry of one invoice’s retention period does not automatically delete messages still needed for another invoice, an active arrangement or relevant permission evidence. Retain only the parts that remain necessary, with a documented purpose and review point; do not retain an entire conversation indefinitely merely because it contains a newer message.

Where deletion is appropriate, remove or irreversibly de-identify the relevant data. Retention exceptions must have a recorded purpose and review point. Deleting DAFNI records does not cancel debts or delete source accounting records or recipients’ copies.

When a business leaves DAFNI

The agreed account-closure policy provides a 30-day export period from closure for a departing business to obtain its information before eligible operational records are removed. The agreed initial approach is an export supplied on request to an authorised company administrator, after verifying their authority and arranging secure delivery. This export process still requires implementation and verification; it is not yet an operational commitment. This period does not guarantee account reactivation.

Specific lawful retention requirements or unresolved disputes may require limited, restricted records to remain. Privacy requests are assessed individually; the export period is not an automatic reason to delay a deletion that must occur sooner.

Backups and recovery

The intended setup keeps protected recovery copies for a rolling 30-day backup recovery window. This is separate from the 30-day account-closure export period and from five-year invoice history. Recovery is limited to available successful backup points; it does not offer a customer-controlled rewind to every moment.

The pilot’s internal recovery targets are no more than one hour of recent work lost and restoration within one business day. These are unverified design targets, not a service guarantee. Database records and important stored files need coverage, alongside recoverable application configuration and secure credential-recovery arrangements.

Company-specific recovery should use an isolated restoration and careful extraction of the affected records to avoid undoing another company’s work. Sending must be paused and reconciled during recovery to avoid duplicate communications.

After eligible records are deleted from the active system, residual protected backup copies may remain until their recovery window expires. Consequently, copies can remain beyond 30 days after a company leaves. Backups are for disaster recovery, not extended customer access. Completed deletions must be reapplied if an older backup is restored.

Development review note — not yet an operational commitment

The backup arrangements and recovery targets above describe the intended setup. They have not yet been fully implemented or verified. Backup coverage, scheduled operation, failure alerts, restoration and handling of previously deleted records must be tested before these arrangements are presented as operational commitments in the published policy.

Your choices and requests

You may contact us to request access to or correction of your information, deletion where applicable, withdrawal of consent, or objection to relevant processing.

Privacy requests are currently handled manually. After verifying your identity and authority, we identify and review the relevant records and arrange an appropriate export, correction or deletion, subject to applicable retention requirements. Requests involving a company’s records may require authorisation from that company.

For records held on a business’s behalf, we may refer the request to that business or coordinate with it. To stop WhatsApp invoice messages, tell the sending business or contact us, identifying the business and the number receiving messages. Opting out of WhatsApp does not itself remove an outstanding invoice or prevent other lawful communication.

Esteni Van Niekerk will monitor privacy requests. We aim to acknowledge requests within five business days and resolve straightforward requests within 30 calendar days, subject to applicable requirements. If verification, coordination or complexity affects completion, we will explain the reason and expected next steps. These targets do not replace applicable legal deadlines.

See the data-deletion instructions for the request process. You may also raise a privacy complaint with South Africa’s Information Regulator or another competent authority.

Website and notice changes

This website contains no advertising trackers, analytics scripts, external fonts or embedded social widgets. The application uses browser storage for sign-in and workspace operation. Hosting providers may process technical request information to deliver and protect this website. We will update this notice if the website’s tracking or cookie use changes.

DAFNI is intended for business use, not for services directed at children. Material privacy changes will be reflected here with an updated date and, where appropriate, brought to affected users’ attention.