Data Processing Register (ROPA)
Record of Processing Activities - Complete inventory of how Larasoft processes personal information
About This Register
This register documents all personal information processing activities at Larasoft, as required by the Protection of Personal Information Act (POPIA). It shows what data we collect, why we collect it, how we protect it, and how long we keep it.
Client Onboarding
PA-001
Collecting client company information during signup
Data Categories
Business contact info, Company registration details
Data Subjects
Business clients (companies)
Purpose of Processing
To establish client relationship and provide services
Legal Basis
Contract performance
Storage Location
Azure South Africa North
Retention Period
7 years after contract ends (tax law requirement)
Security Measures
Encryption at rest, Access controls, Backups
Transborder Transfers
None (SA only)
Data Recipients
Internal CRM/database
Owner
Sales/Ops
View Specific Data Fields
Company name, Registration number, VAT number, Contact person name, Email, Phone, Physical address, Billing address
Xero Integration - Financial Data Sync
PA-002
Connecting to clients' Xero accounts to sync financial data
Data Categories
Financial transactions, Invoice data, Payment records, Account balances
Data Subjects
Business clients and their end-customers
Purpose of Processing
To provide accounting automation and financial reporting services
Legal Basis
Contract performance + Legitimate interest
Storage Location
Xero (global - likely Australia/US), Our DB: Azure SA
Retention Period
Transactional data: 7 years (tax law)
Security Measures
Data encrypted in transit (TLS), Access logs
Transborder Transfers
Yes - Xero servers (Australia/US/EU depending on client's Xero region)
Data Recipients
Xero (processor) + Our application database
Owner
Tech Team
View Specific Data Fields
Transaction IDs, Amounts, Dates, Invoice numbers, Customer names (from client's customers), Payment methods, Bank account numbers (masked), GL codes
CIN7 Integration - Inventory Data Sync
PA-003
Syncing inventory and order data from CIN7
Data Categories
Inventory records, Sales orders, Purchase orders, Product data
Data Subjects
Business clients and their suppliers/customers
Purpose of Processing
To provide inventory management automation
Legal Basis
Contract performance
Storage Location
CIN7 servers (global), Our DB: Azure SA
Retention Period
3 years after order completion
Security Measures
TLS encryption, Access controls
Transborder Transfers
Yes - CIN7 servers (likely US/Australia)
Data Recipients
CIN7 (processor) + Our application database
Owner
Tech Team
View Specific Data Fields
Product SKUs, Quantities, Prices, Order numbers, Supplier names, Customer names (from client's customers), Timestamps
FTP/SFTP File Transfers
PA-004
Secure file transfer service for client document exchange
Data Categories
Business documents, Financial files, Reports
Data Subjects
Business clients
Purpose of Processing
To provide secure file transfer service
Legal Basis
Contract performance
Storage Location
AWS S3 Cape Town (af-south-1) + Azure South Africa North. Files written on the outbound leg land on the remote endpoint the client nominates.
Retention Period
Configurable per client (default: 90 days post-processing)
Security Measures
AES-256 encryption at rest, TLS in transit, SFTP authentication, Audit logs, Per-client isolation
Transborder Transfers
Yes, on the outbound leg. Inbound storage is AWS S3 Cape Town (South Africa) only, but this activity also WRITES files to client-nominated remote endpoints, some of which are outside South Africa, including one in Europe used for logistics document exchange. Each outbound destination needs its own POPIA section 72 ground. See PA-039.
Data Recipients
AWS S3 (processor) + Client-nominated remote file transfer endpoints (outbound leg)
Owner
Tech Team
View Specific Data Fields
File names, File contents (varies - invoices statements payroll etc), Upload/download timestamps, Client usernames, IP addresses
Application Logging and Monitoring
PA-005
Logging user activity and system events for troubleshooting and security
Data Categories
Access logs, Error logs, API call logs
Data Subjects
Business clients (users of our platform)
Purpose of Processing
Security monitoring + System troubleshooting + Legal compliance
Legal Basis
Legitimate interest
Storage Location
Azure South Africa North
Retention Period
90 days (rolling)
Security Measures
Encrypted storage, Access restricted to tech team only
Transborder Transfers
Possibly (if using Azure Monitor global services)
Data Recipients
Internal log storage + possibly Azure Monitor
Owner
Tech Team
View Specific Data Fields
Usernames, IP addresses, Timestamps, Actions performed, Error messages
Customer Support Communications
PA-006
Email and support ticket correspondence
Data Categories
Support tickets, Email communications
Data Subjects
Business clients
Purpose of Processing
To provide customer support
Legal Basis
Contract performance
Storage Location
Local server or email provider (TBD - need to document)
Retention Period
2 years
Security Measures
Email encryption (TLS), Access controls
Transborder Transfers
Depends on email provider
Data Recipients
Internal ticketing system (or email)
Owner
Support Team
View Specific Data Fields
Client contact name, Email address, Phone (if provided), Issue descriptions, Resolution notes
Invoicing and Billing
PA-007
Generating invoices and processing payments via Xero
Data Categories
Billing information, Payment records
Data Subjects
Business clients
Purpose of Processing
To bill for services and maintain financial records
Legal Basis
Contract performance + Legal obligation (tax)
Storage Location
Xero servers (global)
Retention Period
7 years (tax law)
Security Measures
Xero's security controls, TLS for data sync
Transborder Transfers
Yes - Xero servers
Data Recipients
Xero (processor)
Owner
Finance
View Specific Data Fields
Company name, VAT number, Billing address, Invoice amounts, Payment status, Bank details (Xero holds these)
Employee/Contractor Information (Internal)
PA-008
Managing information about the 2 founders/team members
Data Categories
HR records, Payroll, Contact info
Data Subjects
Employees (the 2 founders)
Purpose of Processing
HR administration + Payroll + Tax compliance
Legal Basis
Legal obligation + Contract
Storage Location
Depends on payroll provider
Retention Period
6 years after employment ends (tax law)
Security Measures
Need to document security measures
Transborder Transfers
Depends on provider
Data Recipients
Payroll provider (TBD - need to document)
Owner
HR/Finance
View Specific Data Fields
Names, ID numbers, Tax numbers, Bank details, Contact details, Employment contracts
Website Analytics
PA-009
Tracking website visitors for analytics
Data Categories
Website usage data, IP addresses, Browser info
Data Subjects
Website visitors
Purpose of Processing
To analyze website performance and improve user experience
Legal Basis
Legitimate interest
Storage Location
Google servers (global)
Retention Period
14 months (configurable)
Security Measures
Google's security + cookie consent
Transborder Transfers
Yes - Google servers (US/EU)
Data Recipients
Google Analytics or similar
Owner
Marketing
View Specific Data Fields
Page views, Session duration, Referrer URLs, Device type, Location (city level), IP addresses
Data Backups
PA-010
Backing up client data for disaster recovery
Data Categories
All data categories above
Data Subjects
All data subjects above
Purpose of Processing
Business continuity and disaster recovery
Legal Basis
Legitimate interest
Storage Location
TBD - need to document
Retention Period
30 days (daily backups)
Security Measures
Encrypted backups, Secure storage, Access controls
Transborder Transfers
Depends on backup location
Data Recipients
Backup storage provider (TBD - Azure Backup? Local?)
Owner
Tech Team
View Specific Data Fields
All fields from above activities
Excel Data Import/Export
PA-011
Processing client data via Excel spreadsheets for bulk operations
Data Categories
Financial data, Inventory data, Transaction records
Data Subjects
Business clients
Purpose of Processing
To facilitate bulk data operations and reporting
Legal Basis
Contract performance
Storage Location
Local devices + OneDrive/SharePoint (if Microsoft 365)
Retention Period
Transient processing (deleted after import) + Exports retained per client needs
Security Measures
File encryption if Microsoft 365, Local disk encryption, Access controls
Transborder Transfers
Possibly (if using Microsoft 365 cloud)
Data Recipients
Microsoft Excel (local/cloud) + Our application
Owner
Tech Team
View Specific Data Fields
Transaction details, Product info, Customer names, Amounts, Dates
SQL Database Operations
PA-012
Storing and querying all application data in Azure SQL
Data Categories
All client data categories
Data Subjects
All business clients
Purpose of Processing
Core application data storage and retrieval
Legal Basis
Contract performance
Storage Location
Azure South Africa North
Retention Period
Varies by data type (see retention policy)
Security Measures
TDE encryption at rest, TLS in transit, Access controls, Automated backups, Row-level security
Transborder Transfers
No (SA only)
Data Recipients
Azure SQL Database
Owner
Tech Team
View Specific Data Fields
All application data fields (financial, inventory, transactions, user accounts)
CSV Data Processing
PA-013
Importing and exporting data via CSV files
Data Categories
Financial data, Inventory data, Transaction records
Data Subjects
Business clients
Purpose of Processing
To enable data portability and integration
Legal Basis
Contract performance
Storage Location
Temporary processing in memory + Azure SA storage
Retention Period
Transient (deleted after processing)
Security Measures
In-memory processing, Input validation, Access logs
Transborder Transfers
No (local processing)
Data Recipients
Our application (internal processing)
Owner
Tech Team
View Specific Data Fields
Varies by CSV type - transactions, products, customers, invoices
GAAP Integration - Hospitality and Retail Data Sync
PA-014
Syncing point-of-sale, stock and financial data from clients' GAAP systems
Data Categories
Sales transactions, Stock records, Financial transactions, Account balances
Data Subjects
Business clients and their end-customers
Purpose of Processing
To provide hospitality and retail operations reporting and accounting automation
Legal Basis
Contract performance
Storage Location
GAAP servers (South Africa), Our DB: Azure South Africa North
Retention Period
7 years (tax/audit requirement)
Security Measures
TLS in transit, Access controls, Audit logs
Transborder Transfers
No - GAAP servers are South African
Data Recipients
GAAP (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Transaction IDs, Sale amounts, Product and stock codes, Quantities, GL codes, Account balances, Period dates, Store/outlet identifiers, Timestamps
Vend / Lightspeed POS Integration
PA-015
Syncing point-of-sale and retail data from Vend (now Lightspeed Retail)
Data Categories
Sales transactions, Inventory, Customer purchase data
Data Subjects
Business clients and their retail customers
Purpose of Processing
To provide retail operations automation and reporting
Legal Basis
Contract performance
Storage Location
Lightspeed servers (Canada/US), Our DB: Azure SA
Retention Period
3 years after transaction
Security Measures
TLS encryption, Access controls, Audit logs
Transborder Transfers
Yes - Lightspeed servers (Canada/US)
Data Recipients
Lightspeed (processor) + Our application database
Owner
Tech Team
View Specific Data Fields
Transaction IDs, Sale amounts, Product SKUs, Customer names (from client's customers), Payment methods, Timestamps, Store locations
Zoho CRM Integration (Client Data)
PA-016
Syncing a client's Zoho CRM records into their reporting warehouse on their documented instruction
Data Categories
Contact information, Communication history, Deal pipeline, Notes
Data Subjects
The client's customers, prospects and staff (not Larasoft's)
Purpose of Processing
To replicate the client's CRM data into their reporting warehouse for analytics and reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
Zoho data centers (India/US/EU, per the client's own Zoho account region), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
Yes - read from Zoho servers (India/US/EU depending on the client's Zoho region); our copy is stored in South Africa
Data Recipients
Zoho (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Contact person names, Email addresses, Phone numbers, Company names (the client's own customers and prospects), Deal values, Deal stages, Activity and communication logs, Owner/assignee names, Timestamps
RETIRED - Deel Contractor Management (internal use ceased)
PA-017
RETIRED. This activity has ceased and is retained only as a historical record, which a Record of Processing Activities is required to keep. Larasoft no longer uses Deel to manage its own contractors. Historical records are held for the retention period stated below. The connector-side successor, where Larasoft reads a client's Deel payroll data on their instruction, is PA-018.
Data Categories
HR records, Contract data, Payment info, Tax documents
Data Subjects
Employees and contractors
Purpose of Processing
HR administration + Payroll + Compliance
Legal Basis
Legal obligation + Contract performance
Storage Location
Deel servers (US/EU multi-region)
Retention Period
7 years after contract ends (legal requirement)
Security Measures
Deel's security (ISO 27001 SOC 2), Encryption at rest/transit, Access controls
Transborder Transfers
Yes - Deel servers (US/EU)
Data Recipients
Deel platform
Owner
HR/Finance
View Specific Data Fields
Full names, ID/passport numbers, Addresses, Bank details, Tax numbers, Contract terms, Payment history, Visa/work permit info
PaySpace / Deel Payroll Integration (Client Data)
PA-018
Syncing a client's PaySpace and Deel payroll records into their reporting warehouse on their documented instruction
Data Categories
Payroll data, HR records, Tax information, Banking details
Data Subjects
The client's employees and contractors (not Larasoft's)
Purpose of Processing
To replicate the client's payroll data into their reporting warehouse for payroll cost analysis and reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client, who holds the employment relationship)
Storage Location
PaySpace: South Africa. Deel: US/EU multi-region. Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls restricted to named engineers, Audit logs
Transborder Transfers
Yes - read from Deel servers (US/EU). PaySpace is read from South Africa. Our copy is stored in South Africa
Data Recipients
PaySpace and Deel (client-side systems, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Employee full names, ID numbers, Tax reference numbers, Bank account details, Salary and wage amounts, Payslip line items, Leave balances, Cost centre and department codes, Employment start/end dates
SimplePay Payroll Integration (Client Data)
PA-019
Syncing a client's SimplePay payroll records into their reporting warehouse on their documented instruction
Data Categories
Payroll data, Tax information, Banking details
Data Subjects
The client's employees (not Larasoft's)
Purpose of Processing
To replicate the client's payroll data into their reporting warehouse for payroll cost analysis and reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client, who holds the employment relationship)
Storage Location
SimplePay South Africa data centre, Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls restricted to named engineers, Audit logs
Transborder Transfers
No - SimplePay and our warehouse are both in South Africa
Data Recipients
SimplePay (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Employee full names, ID numbers, Tax reference numbers, Bank account details, Salary and wage amounts, Payslip line items, Leave balances, SARS submission references
Harvest Time Tracking Integration (Client Data)
PA-020
Syncing a client's Harvest time-tracking and invoicing records into their reporting warehouse on their documented instruction
Data Categories
Time tracking data, Project information, Invoicing data
Data Subjects
The client's staff, contractors and their end-customers (not Larasoft's)
Purpose of Processing
To replicate the client's time and billing data into their reporting warehouse for utilisation and profitability reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
Harvest servers (United States), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
Yes - read from Harvest servers (United States); our copy is stored in South Africa
Data Recipients
Harvest, Forecasting LLC (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Staff and contractor names, Time entries (hours and dates), Project and client names, Task descriptions, Billable rates, Invoice numbers and amounts, Expense records
Wherehouse Marketplace Management
PA-021
Managing multi-channel eCommerce operations for clients
Data Categories
Order data, Customer information, Inventory records, Pricing data, Invoice data, Sales analytics
Data Subjects
Business clients and their end-customers
Purpose of Processing
To provide marketplace management automation across multiple sales channels
Legal Basis
Contract performance
Storage Location
Wherehouse servers (South Africa - verify location)
Retention Period
3 years after order completion
Security Measures
TLS encryption, API authentication, Access controls, Audit logs (verify Wherehouse security certifications)
Transborder Transfers
Yes - Multiple marketplace APIs (varies by marketplace)
Data Recipients
Wherehouse platform + Our integration services
Owner
Tech Team
View Specific Data Fields
Order IDs, Customer names, Delivery addresses, Email addresses, Phone numbers, Order amounts, Payment methods, Product SKUs, Inventory quantities, Prices, Invoice numbers, Marketplace transaction IDs, Sales metrics
PowerOffice Go Integration (Client Data)
PA-022
Syncing a client's PowerOffice Go accounting records into their reporting warehouse on their documented instruction
Data Categories
Financial transactions, Invoice data, Supplier and customer records, Account balances
Data Subjects
The client's customers, suppliers and staff (not Larasoft's)
Purpose of Processing
To replicate the client's accounting data into their reporting warehouse for financial reporting and consolidation
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
PowerOffice servers (Norway), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
Yes - read from PowerOffice servers (Norway); our copy is stored in South Africa
Data Recipients
PowerOffice (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Transaction IDs, Amounts, Dates, Invoice and credit note numbers, Customer and supplier names, Contact email addresses, Organisation numbers, Bank account references, GL codes, Project and department codes
Mailchimp Integration (Client Data)
PA-023
Syncing a client's Mailchimp audience and campaign records into their reporting warehouse on their documented instruction
Data Categories
Marketing contact data, Campaign engagement data, Audience segmentation data
Data Subjects
The client's marketing subscribers and prospects (not Larasoft's)
Purpose of Processing
To replicate the client's email marketing data into their reporting warehouse for campaign performance reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
Mailchimp servers (United States), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
Yes - read from Mailchimp servers (United States); our copy is stored in South Africa
Data Recipients
Intuit Mailchimp (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Subscriber email addresses, First and last names, Subscription status, Signup source and timestamp, Signup IP address, Location (country and region), Tags and segment membership, Campaign opens, Clicks, Bounces, Unsubscribe events
Google Ads Integration (Client Data)
PA-024
Syncing a client's Google Ads campaign performance data into their reporting warehouse on their documented instruction
Data Categories
Advertising performance data, Campaign metadata, Aggregated audience data
Data Subjects
Data is campaign-level and aggregated; individual end-users are not identified in the fields we ingest
Purpose of Processing
To replicate the client's paid media performance data into their reporting warehouse for marketing return-on-spend reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
Google servers (global, primarily United States and EU), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
Yes - read from Google servers (United States/EU); our copy is stored in South Africa
Data Recipients
Google (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Campaign, ad group and ad IDs and names, Impressions, Clicks, Cost, Conversions and conversion value, Keywords and search terms, Device and geographic breakdowns (aggregated), Date ranges
Salesforce Integration (Client Data)
PA-025
Syncing a client's Salesforce CRM records, including their custom objects, into their reporting warehouse on their documented instruction
Data Categories
Contact information, Account records, Opportunity pipeline, Case and activity history, Client-defined custom objects
Data Subjects
The client's customers, leads and staff (not Larasoft's)
Purpose of Processing
To replicate the client's CRM data into their reporting warehouse for pipeline and service analytics
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
Salesforce servers (per the client's own org region, typically United States or EU), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Client-selected object and field scope, Access controls, Audit logs
Transborder Transfers
Yes - read from Salesforce servers (United States/EU depending on the client's org region); our copy is stored in South Africa
Data Recipients
Salesforce (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Contact and lead names, Email addresses, Phone numbers, Mailing addresses, Account names, Opportunity values and stages, Case subjects and descriptions, Activity and task notes, Owner names, Timestamps, Any personal information the client holds in custom fields they elect to sync
Uniconta Integration (Client Data)
PA-026
Syncing a client's Uniconta ERP and accounting records into their reporting warehouse on their documented instruction. CONFIGURED BUT NOT IN CLIENT USE as at 2026-09-09: the only connector of this type belongs to a Larasoft internal or demonstration organisation, so no client's personal information is processed through it today. The row is retained because the capability is live and a client could be enabled on it. The supporting measurement is held in the internal risk register.
Data Categories
Financial transactions, Invoice data, Debtor and creditor records, Inventory records, Account balances
Data Subjects
The client's customers, suppliers and staff (not Larasoft's)
Purpose of Processing
To replicate the client's ERP data into their reporting warehouse for financial and operational reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
Uniconta servers (Denmark/EU), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
No client transfer today - the sole connector is a Larasoft internal test organisation. If a client is enabled: read from Uniconta servers (Denmark/EU); our copy is stored in South Africa
Data Recipients
Uniconta (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Transaction IDs, Amounts, Dates, Invoice numbers, Debtor and creditor names, Contact email addresses and phone numbers, Delivery and invoice addresses, VAT and company registration numbers, GL codes, Product codes and quantities
WooCommerce Integration (Client Data)
PA-027
Syncing a client's WooCommerce store orders, customers and products into their reporting warehouse on their documented instruction
Data Categories
Order data, Customer information, Product and inventory data
Data Subjects
The client's online shoppers (not Larasoft's)
Purpose of Processing
To replicate the client's eCommerce data into their reporting warehouse for sales and fulfilment reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
The client's own store hosting (location varies by client), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
Depends on where the client hosts their own store; our copy is stored in South Africa
Data Recipients
The client's own WordPress/WooCommerce hosting (accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Order IDs and status, Customer first and last names, Email addresses, Phone numbers, Billing and shipping addresses, Order totals, Line items and quantities, Payment method (name only, no card data), Coupon codes, Order timestamps, Customer IP address where the store records it
GAAPUnity Integration (Client Data)
PA-028
Syncing a client's GAAPUnity hospitality and retail records into their reporting warehouse on their documented instruction
Data Categories
Sales transactions, Stock records, Financial transactions
Data Subjects
The client's staff and end-customers (not Larasoft's)
Purpose of Processing
To replicate the client's hospitality and retail data into their reporting warehouse for trading and stock reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
GAAPUnity servers (South Africa), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
No - GAAPUnity servers and our warehouse are both in South Africa
Data Recipients
GAAP (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Transaction IDs, Sale amounts, Product and stock codes, Quantities, Payment method (name only, no card data), Store/outlet identifiers, Cashier and operator identifiers, GL codes, Timestamps
Meta Ads Integration (Client Data)
PA-029
Syncing a client's Meta (Facebook and Instagram) advertising performance data into their reporting warehouse on their documented instruction
Data Categories
Advertising performance data, Campaign metadata, Aggregated audience data
Data Subjects
Data is campaign-level and aggregated; individual end-users are not identified in the fields we ingest
Purpose of Processing
To replicate the client's paid social performance data into their reporting warehouse for marketing return-on-spend reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
Meta servers (global, primarily United States and EU), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
Yes - read from Meta servers (United States/EU); our copy is stored in South Africa
Data Recipients
Meta Platforms (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Campaign, ad set and ad IDs and names, Impressions, Reach, Clicks, Spend, Conversions and conversion value, Placement, Device and geographic breakdowns (aggregated), Date ranges
Asana Integration (Client Data)
PA-030
Syncing a client's Asana project and task records into their reporting warehouse on their documented instruction
Data Categories
Project management data, Task records, Assignment and time data
Data Subjects
The client's staff and collaborators (not Larasoft's)
Purpose of Processing
To replicate the client's project delivery data into their reporting warehouse for delivery and utilisation reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
Asana servers (United States), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
Yes - read from Asana servers (United States); our copy is stored in South Africa
Data Recipients
Asana (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Project and task names and descriptions, Assignee names and email addresses, Follower names, Due dates and completion timestamps, Custom field values, Comments and task notes, Section and tag names
Bitrix24 Integration (Client Data)
PA-031
Syncing a client's Bitrix24 CRM and activity records into their reporting warehouse on their documented instruction
Data Categories
Contact information, Deal pipeline, Company records, Activity history
Data Subjects
The client's customers, leads and staff (not Larasoft's)
Purpose of Processing
To replicate the client's CRM data into their reporting warehouse for pipeline and activity analytics
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
Bitrix24 servers (per the client's own account region, typically EU or United States), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
Yes - read from Bitrix24 servers (EU/United States depending on the client's account region); our copy is stored in South Africa
Data Recipients
Bitrix24 (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Contact and lead names, Email addresses, Phone numbers, Company names, Deal values and stages, Activity and call logs, Responsible-user names, Custom field values, Timestamps
HubSpot Integration (Client Data)
PA-032
Syncing a client's HubSpot CRM and marketing records into their reporting warehouse on their documented instruction
Data Categories
Contact information, Company records, Deal pipeline, Marketing engagement data
Data Subjects
The client's customers, leads and staff (not Larasoft's)
Purpose of Processing
To replicate the client's CRM and marketing data into their reporting warehouse for pipeline and campaign analytics
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
HubSpot servers (United States and EU), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
Yes - read from HubSpot servers (United States/EU); our copy is stored in South Africa
Data Recipients
HubSpot (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Contact first and last names, Email addresses, Phone numbers, Job titles, Company names and domains, Deal amounts and stages, Lifecycle stage, Email open and click events, Form submissions, Owner names, Timestamps
MedicalDirector Helix Integration (Client Data, Special Personal Information)
PA-033
Syncing a client healthcare provider's MedicalDirector Helix FHIR records into their reporting warehouse on their documented instruction. This activity processes health information, which is special personal information under POPIA section 26.
Data Categories
Health information (SPECIAL PERSONAL INFORMATION under POPIA s26), Patient demographic data, Clinical encounter data, Practitioner records
Data Subjects
Patients of the client healthcare provider, and the provider's practitioners and staff (not Larasoft's)
Purpose of Processing
To replicate the client healthcare provider's clinical and operational data into their reporting warehouse for the provider's own clinical operations and practice reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction). The responsible party is the client healthcare provider, and the POPIA section 32 ground for processing health information is held by that provider under its own patient relationship and professional duty of confidentiality. Larasoft asserts no independent ground and processes only on instruction.
Storage Location
MedicalDirector Helix servers (Australia), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation with no cross-client querying, Access restricted to named engineers on a documented need, Audit logs of all access, Data minimisation to the FHIR resources the client scopes
Transborder Transfers
Yes - read from MedicalDirector Helix servers (Australia); our copy is stored in South Africa. This transborder flow carries special personal information and is the subject of risk R-043.
Data Recipients
MedicalDirector, a Telstra Health company (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Patient names, Dates of birth, Sex, Contact details, Patient and medical record identifiers, Medicare/health fund identifiers, Conditions and diagnoses, Medications and prescriptions, Allergies and intolerances, Observations and clinical measurements, Encounter and appointment dates, Practitioner and organisation identifiers
Monday.com Integration (Client Data)
PA-034
Syncing a client's Monday.com board and item records into their reporting warehouse on their documented instruction
Data Categories
Project management data, Board and item records, Assignment data
Data Subjects
The client's staff and collaborators (not Larasoft's)
Purpose of Processing
To replicate the client's work management data into their reporting warehouse for delivery and workload reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
monday.com servers (United States and EU), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
Yes - read from monday.com servers (United States/EU); our copy is stored in South Africa
Data Recipients
monday.com (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Board and item names, Column values including free-text notes, Assignee and subscriber names and email addresses, Status and timeline values, Update and comment text, Creation and completion timestamps
Zoho Projects Integration (Client Data)
PA-035
Syncing a client's Zoho Projects project, task and timesheet records into their reporting warehouse on their documented instruction
Data Categories
Project management data, Task records, Timesheet data
Data Subjects
The client's staff and contractors (not Larasoft's)
Purpose of Processing
To replicate the client's project and time data into their reporting warehouse for delivery and utilisation reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
Zoho data centers (India/US/EU, per the client's own Zoho account region), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
Yes - read from Zoho servers (India/US/EU depending on the client's Zoho region); our copy is stored in South Africa
Data Recipients
Zoho (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Project and task names and descriptions, Assignee and owner names and email addresses, Task status and priority, Start, due and completion dates, Timesheet entries (hours, dates, notes), Milestone names, Comments
Sage One SA Integration (Client Data)
PA-036
Syncing a client's Sage Business Cloud Accounting (South Africa) records into their reporting warehouse on their documented instruction. CONFIGURED BUT NOT IN CLIENT USE as at 2026-09-09: the only connector of this type belongs to a Larasoft internal or demonstration organisation, so no client's personal information is processed through it today. The row is retained because the capability is live and a client could be enabled on it. The supporting measurement is held in the internal risk register.
Data Categories
Financial transactions, Invoice data, Customer and supplier records, Account balances
Data Subjects
The client's customers, suppliers and staff (not Larasoft's)
Purpose of Processing
To replicate the client's accounting data into their reporting warehouse for financial reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
Sage South Africa servers, Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
No - Sage One SA and our warehouse are both in South Africa
Data Recipients
Sage (client-side system, accessed on client instruction) + Our application database
Owner
Tech Team
View Specific Data Fields
Transaction IDs, Amounts, Dates, Invoice and credit note numbers, Customer and supplier names, Contact email addresses and phone numbers, Billing and delivery addresses, VAT numbers, GL codes, Bank account references
Informix ERP Integration via Larasoft ODBC Agent (Client Data)
PA-037
Syncing a client's on-premise Informix ERP records into their reporting warehouse on their documented instruction, using the Larasoft ODBC Agent installed inside the client's own network
Data Categories
ERP transactional data, Customer and supplier records, Inventory and order data, Financial transactions
Data Subjects
The client's customers, suppliers and staff (not Larasoft's)
Purpose of Processing
To replicate the client's on-premise ERP data into their reporting warehouse for operational and financial reporting
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
Client's own premises (Australia), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
Larasoft ODBC Agent as outbound-only transport: the agent opens an outbound connection and polls for work, so no inbound port is exposed on the client network and no credential leaves the client's premises. TLS in transit, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
Yes - data is read on the client's premises in Australia and stored in South Africa
Data Recipients
Larasoft ODBC Agent (our own software, running on client-controlled infrastructure) + Our application database
Owner
Tech Team
View Specific Data Fields
Order and transaction IDs, Amounts, Dates, Customer and supplier names, Contact details and delivery addresses held in the client's ERP, Product codes and quantities, Employee or operator identifiers recorded against transactions, GL codes
Client-Hosted Database and Protocol Sources (MySQL, OData)
PA-038
Reading directly from a client's own MySQL database or OData endpoint into their reporting warehouse on their documented instruction, where the client has no supported SaaS API. The MySQL leg is in client use (one client connector). The OData leg is NOT in client use as at 2026-09-09: its only connector belongs to a Larasoft internal organisation.
Data Categories
Varies entirely by the client's own schema. Typically transactional records, customer or contact records, and operational data
Data Subjects
The client's customers, suppliers and staff, as recorded in the client's own database (not Larasoft's)
Purpose of Processing
To replicate a client's own database or protocol-exposed data into their reporting warehouse where no supported SaaS API exists
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)
Storage Location
The client's own database or endpoint (location varies by client), Our DB: Azure South Africa North
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit where the client's endpoint supports it, Client-scoped table/view/entity allowlist so we read only what the client nominates, Per-client data isolation, Access controls, Audit logs
Transborder Transfers
Depends on where the client hosts their own database or endpoint; our copy is stored in South Africa
Data Recipients
No third party is involved: we read the client's own system directly into our application database
Owner
Tech Team
View Specific Data Fields
Determined by the tables, views or entity sets the client scopes for the connector. May include names, email addresses, phone numbers, addresses, identifiers and free-text notes held in the client's own systems
Write-Back to Client Business Systems (Outbound Transfer)
PA-039
Writing data from a client's reporting warehouse in South Africa OUT to a business system they nominate. This is the only direction in which Larasoft itself transfers personal information out of the Republic, and it is therefore the activity to which POPIA section 72 applies to us rather than to the client.
Data Categories
Financial transactions, Invoice and bill data, Contact records, Project and task records
Data Subjects
The client's customers, suppliers and staff (not Larasoft's)
Purpose of Processing
To post data the client has assembled or corrected in their warehouse back into the operational system of record, so the two agree
Legal Basis
Contract performance (Larasoft acts as operator on the responsible party's documented instruction). Larasoft is the party effecting the transfer out of the Republic, so a POPIA section 72 ground must be held FOR EACH DESTINATION. WHICH ground applies is not settled and is deliberately not asserted here: the data subjects are the client's customers rather than the client itself, so the contract-necessity grounds do not map cleanly onto the Larasoft-to-client contract. This requires legal determination per destination and is tracked as risk R-044. No ground is currently recorded as held.
Storage Location
Written FROM Azure South Africa North TO the destination system's own servers
Retention Period
Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement
Security Measures
TLS in transit, Per-client data isolation, Write scope limited to the records the client nominates, Idempotency keys on the write-record path so a replayed run does not duplicate a posted record, Access controls, Audit logs of every write
Transborder Transfers
Yes, OUTBOUND. This is the only activity in this register in which Larasoft itself transfers personal information out of South Africa. Destinations are the client's own accounting system (Australia, the United States or the EU depending on their account region), a project management system in the United States, and client-nominated file transfer endpoints including one in Europe. A POPIA section 72 ground is required per destination and none is currently recorded as held.
Data Recipients
Accounting, project management and file transfer systems the client nominates
Owner
Tech Team
View Specific Data Fields
Invoice and bill numbers, Line items and amounts, Dates, Contact and customer names, Email addresses and billing addresses where the destination record requires them, Account and tax codes, Project and task names, Assignee names
Questions About Data Processing?
If you have questions about how we process your personal information, please contact our Information Officer:
hello@larasoft.global | +27 82 457 8390