Privacy Policy
Effective date: [DATE] Last updated: [DATE]
1. Who we are
Underpeaks ("Underpeaks", "we", "us", "our") is a developer-first headless CMS platform operated by [LEGAL ENTITY NAME] [CONFIRM: iDigiSolWeb (Pty) Ltd, or the new Underpeaks entity], a company registered in South Africa with registration number [REG NO], with its registered address at [ADDRESS].
For the purposes of the Protection of Personal Information Act, 2013 ("POPIA") and the EU/UK General Data Protection Regulation ("GDPR"), we are the responsible party / data controller for the personal information described in this policy, except where stated otherwise in Section 4.
Information Officer / Data Protection contact: [NAME], [EMAIL]
[CONFIRM: POPIA requires a registered Information Officer. By default this is the CEO/head of the business unless another person is designated and registered with the Information Regulator.]
2. Scope
This policy explains how we handle personal information when you:
- visit our websites at underpeaks.com and studio.underpeaks.com
- create an account and use Underpeaks Studio (our hosted service)
- contact us, subscribe to updates, or interact with our support channels
This policy does not cover:
- Underpeaks Core, our open-source self-hosted software. When you run Core on your own infrastructure, you control that deployment and we do not receive your data, except for the licence validation described in Section 6.
- End-user data inside your projects. Where you use Underpeaks to build an application, the data your own users submit to that application is handled by you as controller and by us as processor. See Section 4 and our Data Processing Agreement.
3. Information we collect
3.1 Information you give us
| Category | Examples | Why we collect it |
|---|---|---|
| Account information | Name, email address, password (hashed) | To create and secure your account |
| Organisation information | Company name, subdomain/tenant name | To provision your workspace |
| Billing information | Billing name, address, country, VAT/tax ID | To process payments and meet tax obligations |
| Project content | Data models, schemas, page definitions, uploaded media | To provide the service |
| Support communications | Messages, attachments, correspondence | To respond to your queries |
We do not store full payment card details. Card data is captured and processed directly by our payment providers (Section 5).
3.2 Information we collect automatically
| Category | Examples | Why we collect it |
|---|---|---|
| Usage data | Pages viewed, features used, timestamps | To improve the product and diagnose issues |
| Device and connection data | IP address, browser type, operating system, referring URL | Security, fraud prevention, analytics |
| Approximate location | Country derived from IP address | To display prices in the correct currency and route payments to the correct provider |
| Error and diagnostic data | Stack traces, error events, session identifiers | To detect and fix faults |
| Cookies and similar technologies | Session cookies, consent preferences, analytics identifiers | See our Cookie Policy |
3.3 Information from third parties
If you sign in or connect a third-party service (for example GitHub, Slack, HubSpot or Mailchimp through our Integrations feature), we receive the information that service shares with us under the permissions you grant — typically an account identifier, email address and access tokens. We store integration credentials encrypted at rest.
3.4 Special categories
We do not intentionally collect special personal information (such as health, biometric, religious or political data) or information about children. Our service is not directed at persons under 18. If you believe a minor has provided us with personal information, contact us and we will delete it.
4. When you are the controller and we are the processor
Underpeaks is a platform on which you build applications. Where your application collects personal information from your own end users — for example customers signing up to an app you have built — you determine why and how that information is processed. In that relationship:
- You are the responsible party / controller
- We are the operator / processor, acting on your documented instructions
Our obligations in that role are set out in our Data Processing Agreement (DPA), which forms part of our Terms of Service. Among other things, we commit to process such data only on your instructions, keep it confidential, apply appropriate security measures, and assist you with data subject requests.
You are responsible for having a lawful basis for the data you collect through your applications, for providing your own privacy notice to your end users, and for responding to their requests.
5. Legal bases for processing
Where GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the service under our Terms | Performance of a contract |
| Billing, invoicing and tax records | Contract and legal obligation |
| Security, fraud prevention, abuse detection | Legitimate interests |
| Product analytics and improvement | Consent (where cookies are involved) or legitimate interests |
| Marketing emails to prospects | Consent |
| Service and transactional emails to customers | Contract and legitimate interests |
| Responding to legal requests | Legal obligation |
Where POPIA applies, we process personal information on the bases of consent, performance of a contract, compliance with a legal obligation, and our legitimate interests, as permitted under section 11 of POPIA.
You may withdraw consent at any time where processing is based on consent. This does not affect processing carried out before withdrawal.
6. How we use your information
- To create, maintain and secure your account
- To provide, operate and improve Underpeaks Studio
- To generate application code from your project definitions
- To validate licences for Underpeaks Core installations (a self-hosted Core instance periodically transmits its licence key and installation identifier to us so we can confirm the licence is valid and active)
- To process payments and issue invoices
- To send service messages, security alerts and product updates
- To provide customer support
- To detect, investigate and prevent fraud, abuse and security incidents
- To comply with legal obligations and enforce our Terms
7. Sub-processors and third parties
We use the following service providers. Each processes personal information on our behalf under contractual safeguards.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | [CONFIRM REGION] |
| Vercel | Application hosting and content delivery | Global edge network |
| Paddle | Payment processing for customers outside South Africa (Paddle acts as merchant of record and is a separate controller for payment data) | Global |
| PayFast | Payment processing for South African customers | South Africa |
| [SMTP PROVIDER] | Transactional email delivery | [CONFIRM] |
| Sentry | Error monitoring and diagnostics | [CONFIRM REGION] |
| Google reCAPTCHA | Spam and abuse prevention on forms | Global |
| [ANALYTICS PROVIDER, if used] | Product and website analytics | [CONFIRM] |
[CONFIRM: add or remove providers to match your actual stack. A current sub-processor list should be maintained and published, as enterprise customers will ask for it and the DPA commits you to notifying changes.]
We also disclose information where required by law, to enforce our agreements, to protect our rights or the safety of others, or in connection with a merger, acquisition or sale of assets (in which case we will notify you).
We do not sell personal information, and we do not display third-party advertising in the product.
8. International transfers
We are based in South Africa and our providers operate internationally, so your personal information may be transferred to and processed in countries other than your own, including the United States and the European Union.
Where personal information is transferred out of the EEA or UK, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where required.
Where personal information is transferred out of South Africa, we do so in accordance with section 72 of POPIA, on the basis of contractual protections that provide an adequate level of protection.
9. How long we keep information
| Data | Retention |
|---|---|
| Account and profile data | For the life of your account, then deleted or anonymised within [90] days of closure |
| Project content and customer data | For the life of your account; deleted within [30] days of account closure [CONFIRM your actual deletion window] |
| Billing and tax records | [5] years, as required by South African tax law |
| Support correspondence | [3] years from last contact |
| Security and access logs | [12] months |
| Backups | Deleted data persists in encrypted backups for up to [35] days before being overwritten |
We may retain information for longer where required by law or where necessary to establish, exercise or defend legal claims.
10. Security
We apply technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit using TLS
- Encryption of sensitive credentials at rest using AES-256-GCM
- Password hashing using bcrypt
- Session tokens stored in httpOnly cookies
- Role-based access controls within the application
- Row-level security and tenant isolation in the database
- Access to production systems restricted to authorised personnel
- Logging and monitoring of security-relevant events
No system is completely secure. If we become aware of a compromise of personal information, we will notify the Information Regulator and affected data subjects as required by section 22 of POPIA, and supervisory authorities and data subjects as required by Articles 33 and 34 of GDPR.
11. Your rights
Subject to the conditions in applicable law, you have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate or incomplete
- Delete your information where we no longer have grounds to keep it
- Object to processing based on legitimate interests
- Restrict processing in certain circumstances
- Portability — receive your data in a structured, machine-readable format
- Withdraw consent where processing is based on consent
- Not be subject to automated decision-making with legal or similarly significant effects (we do not carry out such decision-making)
- Complain to a supervisory authority
To exercise any of these rights, contact us at [PRIVACY EMAIL]. We will respond within the timeframes required by law — generally 30 days.
South Africa: You may complain to the Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001. Email: complaints.IR@justice.gov.za
EU/UK: You may complain to your local data protection authority.
[CONFIRM: POPIA also requires you to make available the prescribed Form 2 for access requests and Form 3 for objections. Consider linking these.]
12. Cookies
We use cookies and similar technologies. Our cookie banner allows you to accept or reject non-essential categories. See our Cookie Policy for the full list and how to change your preferences.
13. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or through the service before the changes take effect. The "last updated" date at the top indicates when this policy was last revised.
14. Contact us
[LEGAL ENTITY NAME] [ADDRESS] Email: [PRIVACY EMAIL] Information Officer: [NAME], [EMAIL]