Data Processing Register (ROPA)

Record of Processing Activities - Complete inventory of how Larasoft processes personal information

About This Register

This register documents all personal information processing activities at Larasoft, as required by the Protection of Personal Information Act (POPIA). It shows what data we collect, why we collect it, how we protect it, and how long we keep it.

Client Onboarding

PA-001

MEDIUM RISK

Collecting client company information during signup

Data Categories

Business contact info, Company registration details

Data Subjects

Business clients (companies)

Purpose of Processing

To establish client relationship and provide services

Legal Basis

Contract performance

Storage Location

Azure South Africa North

Retention Period

7 years after contract ends (tax law requirement)

Security Measures

Encryption at rest, Access controls, Backups

Transborder Transfers

None (SA only)

Data Recipients

Internal CRM/database

Owner

Sales/Ops

View Specific Data Fields

Company name, Registration number, VAT number, Contact person name, Email, Phone, Physical address, Billing address

Xero Integration - Financial Data Sync

PA-002

HIGH RISK

Connecting to clients' Xero accounts to sync financial data

Data Categories

Financial transactions, Invoice data, Payment records, Account balances

Data Subjects

Business clients and their end-customers

Purpose of Processing

To provide accounting automation and financial reporting services

Legal Basis

Contract performance + Legitimate interest

Storage Location

Xero (global - likely Australia/US), Our DB: Azure SA

Retention Period

Transactional data: 7 years (tax law)

Security Measures

Data encrypted in transit (TLS), Access logs

Transborder Transfers

Yes - Xero servers (Australia/US/EU depending on client's Xero region)

Data Recipients

Xero (processor) + Our application database

Owner

Tech Team

View Specific Data Fields

Transaction IDs, Amounts, Dates, Invoice numbers, Customer names (from client's customers), Payment methods, Bank account numbers (masked), GL codes

CIN7 Integration - Inventory Data Sync

PA-003

MEDIUM RISK

Syncing inventory and order data from CIN7

Data Categories

Inventory records, Sales orders, Purchase orders, Product data

Data Subjects

Business clients and their suppliers/customers

Purpose of Processing

To provide inventory management automation

Legal Basis

Contract performance

Storage Location

CIN7 servers (global), Our DB: Azure SA

Retention Period

3 years after order completion

Security Measures

TLS encryption, Access controls

Transborder Transfers

Yes - CIN7 servers (likely US/Australia)

Data Recipients

CIN7 (processor) + Our application database

Owner

Tech Team

View Specific Data Fields

Product SKUs, Quantities, Prices, Order numbers, Supplier names, Customer names (from client's customers), Timestamps

FTP/SFTP File Transfers

PA-004

HIGH RISK

Secure file transfer service for client document exchange

Data Categories

Business documents, Financial files, Reports

Data Subjects

Business clients

Purpose of Processing

To provide secure file transfer service

Legal Basis

Contract performance

Storage Location

AWS S3 Cape Town (af-south-1) + Azure South Africa North. Files written on the outbound leg land on the remote endpoint the client nominates.

Retention Period

Configurable per client (default: 90 days post-processing)

Security Measures

AES-256 encryption at rest, TLS in transit, SFTP authentication, Audit logs, Per-client isolation

Transborder Transfers

Yes, on the outbound leg. Inbound storage is AWS S3 Cape Town (South Africa) only, but this activity also WRITES files to client-nominated remote endpoints, some of which are outside South Africa, including one in Europe used for logistics document exchange. Each outbound destination needs its own POPIA section 72 ground. See PA-039.

Data Recipients

AWS S3 (processor) + Client-nominated remote file transfer endpoints (outbound leg)

Owner

Tech Team

View Specific Data Fields

File names, File contents (varies - invoices statements payroll etc), Upload/download timestamps, Client usernames, IP addresses

Application Logging and Monitoring

PA-005

LOW RISK

Logging user activity and system events for troubleshooting and security

Data Categories

Access logs, Error logs, API call logs

Data Subjects

Business clients (users of our platform)

Purpose of Processing

Security monitoring + System troubleshooting + Legal compliance

Legal Basis

Legitimate interest

Storage Location

Azure South Africa North

Retention Period

90 days (rolling)

Security Measures

Encrypted storage, Access restricted to tech team only

Transborder Transfers

Possibly (if using Azure Monitor global services)

Data Recipients

Internal log storage + possibly Azure Monitor

Owner

Tech Team

View Specific Data Fields

Usernames, IP addresses, Timestamps, Actions performed, Error messages

Customer Support Communications

PA-006

LOW RISK

Email and support ticket correspondence

Data Categories

Support tickets, Email communications

Data Subjects

Business clients

Purpose of Processing

To provide customer support

Legal Basis

Contract performance

Storage Location

Local server or email provider (TBD - need to document)

Retention Period

2 years

Security Measures

Email encryption (TLS), Access controls

Transborder Transfers

Depends on email provider

Data Recipients

Internal ticketing system (or email)

Owner

Support Team

View Specific Data Fields

Client contact name, Email address, Phone (if provided), Issue descriptions, Resolution notes

Invoicing and Billing

PA-007

MEDIUM RISK

Generating invoices and processing payments via Xero

Data Categories

Billing information, Payment records

Data Subjects

Business clients

Purpose of Processing

To bill for services and maintain financial records

Legal Basis

Contract performance + Legal obligation (tax)

Storage Location

Xero servers (global)

Retention Period

7 years (tax law)

Security Measures

Xero's security controls, TLS for data sync

Transborder Transfers

Yes - Xero servers

Data Recipients

Xero (processor)

Owner

Finance

View Specific Data Fields

Company name, VAT number, Billing address, Invoice amounts, Payment status, Bank details (Xero holds these)

Employee/Contractor Information (Internal)

PA-008

MEDIUM RISK

Managing information about the 2 founders/team members

Data Categories

HR records, Payroll, Contact info

Data Subjects

Employees (the 2 founders)

Purpose of Processing

HR administration + Payroll + Tax compliance

Legal Basis

Legal obligation + Contract

Storage Location

Depends on payroll provider

Retention Period

6 years after employment ends (tax law)

Security Measures

Need to document security measures

Transborder Transfers

Depends on provider

Data Recipients

Payroll provider (TBD - need to document)

Owner

HR/Finance

View Specific Data Fields

Names, ID numbers, Tax numbers, Bank details, Contact details, Employment contracts

Website Analytics

PA-009

LOW RISK

Tracking website visitors for analytics

Data Categories

Website usage data, IP addresses, Browser info

Data Subjects

Website visitors

Purpose of Processing

To analyze website performance and improve user experience

Legal Basis

Legitimate interest

Storage Location

Google servers (global)

Retention Period

14 months (configurable)

Security Measures

Google's security + cookie consent

Transborder Transfers

Yes - Google servers (US/EU)

Data Recipients

Google Analytics or similar

Owner

Marketing

View Specific Data Fields

Page views, Session duration, Referrer URLs, Device type, Location (city level), IP addresses

Data Backups

PA-010

MEDIUM RISK

Backing up client data for disaster recovery

Data Categories

All data categories above

Data Subjects

All data subjects above

Purpose of Processing

Business continuity and disaster recovery

Legal Basis

Legitimate interest

Storage Location

TBD - need to document

Retention Period

30 days (daily backups)

Security Measures

Encrypted backups, Secure storage, Access controls

Transborder Transfers

Depends on backup location

Data Recipients

Backup storage provider (TBD - Azure Backup? Local?)

Owner

Tech Team

View Specific Data Fields

All fields from above activities

Excel Data Import/Export

PA-011

MEDIUM RISK

Processing client data via Excel spreadsheets for bulk operations

Data Categories

Financial data, Inventory data, Transaction records

Data Subjects

Business clients

Purpose of Processing

To facilitate bulk data operations and reporting

Legal Basis

Contract performance

Storage Location

Local devices + OneDrive/SharePoint (if Microsoft 365)

Retention Period

Transient processing (deleted after import) + Exports retained per client needs

Security Measures

File encryption if Microsoft 365, Local disk encryption, Access controls

Transborder Transfers

Possibly (if using Microsoft 365 cloud)

Data Recipients

Microsoft Excel (local/cloud) + Our application

Owner

Tech Team

View Specific Data Fields

Transaction details, Product info, Customer names, Amounts, Dates

SQL Database Operations

PA-012

HIGH RISK

Storing and querying all application data in Azure SQL

Data Categories

All client data categories

Data Subjects

All business clients

Purpose of Processing

Core application data storage and retrieval

Legal Basis

Contract performance

Storage Location

Azure South Africa North

Retention Period

Varies by data type (see retention policy)

Security Measures

TDE encryption at rest, TLS in transit, Access controls, Automated backups, Row-level security

Transborder Transfers

No (SA only)

Data Recipients

Azure SQL Database

Owner

Tech Team

View Specific Data Fields

All application data fields (financial, inventory, transactions, user accounts)

CSV Data Processing

PA-013

MEDIUM RISK

Importing and exporting data via CSV files

Data Categories

Financial data, Inventory data, Transaction records

Data Subjects

Business clients

Purpose of Processing

To enable data portability and integration

Legal Basis

Contract performance

Storage Location

Temporary processing in memory + Azure SA storage

Retention Period

Transient (deleted after processing)

Security Measures

In-memory processing, Input validation, Access logs

Transborder Transfers

No (local processing)

Data Recipients

Our application (internal processing)

Owner

Tech Team

View Specific Data Fields

Varies by CSV type - transactions, products, customers, invoices

GAAP Integration - Hospitality and Retail Data Sync

PA-014

MEDIUM RISK

Syncing point-of-sale, stock and financial data from clients' GAAP systems

Data Categories

Sales transactions, Stock records, Financial transactions, Account balances

Data Subjects

Business clients and their end-customers

Purpose of Processing

To provide hospitality and retail operations reporting and accounting automation

Legal Basis

Contract performance

Storage Location

GAAP servers (South Africa), Our DB: Azure South Africa North

Retention Period

7 years (tax/audit requirement)

Security Measures

TLS in transit, Access controls, Audit logs

Transborder Transfers

No - GAAP servers are South African

Data Recipients

GAAP (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Transaction IDs, Sale amounts, Product and stock codes, Quantities, GL codes, Account balances, Period dates, Store/outlet identifiers, Timestamps

Vend / Lightspeed POS Integration

PA-015

HIGH RISK

Syncing point-of-sale and retail data from Vend (now Lightspeed Retail)

Data Categories

Sales transactions, Inventory, Customer purchase data

Data Subjects

Business clients and their retail customers

Purpose of Processing

To provide retail operations automation and reporting

Legal Basis

Contract performance

Storage Location

Lightspeed servers (Canada/US), Our DB: Azure SA

Retention Period

3 years after transaction

Security Measures

TLS encryption, Access controls, Audit logs

Transborder Transfers

Yes - Lightspeed servers (Canada/US)

Data Recipients

Lightspeed (processor) + Our application database

Owner

Tech Team

View Specific Data Fields

Transaction IDs, Sale amounts, Product SKUs, Customer names (from client's customers), Payment methods, Timestamps, Store locations

Zoho CRM Integration (Client Data)

PA-016

MEDIUM RISK

Syncing a client's Zoho CRM records into their reporting warehouse on their documented instruction

Data Categories

Contact information, Communication history, Deal pipeline, Notes

Data Subjects

The client's customers, prospects and staff (not Larasoft's)

Purpose of Processing

To replicate the client's CRM data into their reporting warehouse for analytics and reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

Zoho data centers (India/US/EU, per the client's own Zoho account region), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

Yes - read from Zoho servers (India/US/EU depending on the client's Zoho region); our copy is stored in South Africa

Data Recipients

Zoho (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Contact person names, Email addresses, Phone numbers, Company names (the client's own customers and prospects), Deal values, Deal stages, Activity and communication logs, Owner/assignee names, Timestamps

RETIRED - Deel Contractor Management (internal use ceased)

PA-017

HIGH RISK

RETIRED. This activity has ceased and is retained only as a historical record, which a Record of Processing Activities is required to keep. Larasoft no longer uses Deel to manage its own contractors. Historical records are held for the retention period stated below. The connector-side successor, where Larasoft reads a client's Deel payroll data on their instruction, is PA-018.

Data Categories

HR records, Contract data, Payment info, Tax documents

Data Subjects

Employees and contractors

Purpose of Processing

HR administration + Payroll + Compliance

Legal Basis

Legal obligation + Contract performance

Storage Location

Deel servers (US/EU multi-region)

Retention Period

7 years after contract ends (legal requirement)

Security Measures

Deel's security (ISO 27001 SOC 2), Encryption at rest/transit, Access controls

Transborder Transfers

Yes - Deel servers (US/EU)

Data Recipients

Deel platform

Owner

HR/Finance

View Specific Data Fields

Full names, ID/passport numbers, Addresses, Bank details, Tax numbers, Contract terms, Payment history, Visa/work permit info

PaySpace / Deel Payroll Integration (Client Data)

PA-018

HIGH RISK

Syncing a client's PaySpace and Deel payroll records into their reporting warehouse on their documented instruction

Data Categories

Payroll data, HR records, Tax information, Banking details

Data Subjects

The client's employees and contractors (not Larasoft's)

Purpose of Processing

To replicate the client's payroll data into their reporting warehouse for payroll cost analysis and reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client, who holds the employment relationship)

Storage Location

PaySpace: South Africa. Deel: US/EU multi-region. Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls restricted to named engineers, Audit logs

Transborder Transfers

Yes - read from Deel servers (US/EU). PaySpace is read from South Africa. Our copy is stored in South Africa

Data Recipients

PaySpace and Deel (client-side systems, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Employee full names, ID numbers, Tax reference numbers, Bank account details, Salary and wage amounts, Payslip line items, Leave balances, Cost centre and department codes, Employment start/end dates

SimplePay Payroll Integration (Client Data)

PA-019

HIGH RISK

Syncing a client's SimplePay payroll records into their reporting warehouse on their documented instruction

Data Categories

Payroll data, Tax information, Banking details

Data Subjects

The client's employees (not Larasoft's)

Purpose of Processing

To replicate the client's payroll data into their reporting warehouse for payroll cost analysis and reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client, who holds the employment relationship)

Storage Location

SimplePay South Africa data centre, Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls restricted to named engineers, Audit logs

Transborder Transfers

No - SimplePay and our warehouse are both in South Africa

Data Recipients

SimplePay (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Employee full names, ID numbers, Tax reference numbers, Bank account details, Salary and wage amounts, Payslip line items, Leave balances, SARS submission references

Harvest Time Tracking Integration (Client Data)

PA-020

MEDIUM RISK

Syncing a client's Harvest time-tracking and invoicing records into their reporting warehouse on their documented instruction

Data Categories

Time tracking data, Project information, Invoicing data

Data Subjects

The client's staff, contractors and their end-customers (not Larasoft's)

Purpose of Processing

To replicate the client's time and billing data into their reporting warehouse for utilisation and profitability reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

Harvest servers (United States), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

Yes - read from Harvest servers (United States); our copy is stored in South Africa

Data Recipients

Harvest, Forecasting LLC (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Staff and contractor names, Time entries (hours and dates), Project and client names, Task descriptions, Billable rates, Invoice numbers and amounts, Expense records

Wherehouse Marketplace Management

PA-021

HIGH RISK

Managing multi-channel eCommerce operations for clients

Data Categories

Order data, Customer information, Inventory records, Pricing data, Invoice data, Sales analytics

Data Subjects

Business clients and their end-customers

Purpose of Processing

To provide marketplace management automation across multiple sales channels

Legal Basis

Contract performance

Storage Location

Wherehouse servers (South Africa - verify location)

Retention Period

3 years after order completion

Security Measures

TLS encryption, API authentication, Access controls, Audit logs (verify Wherehouse security certifications)

Transborder Transfers

Yes - Multiple marketplace APIs (varies by marketplace)

Data Recipients

Wherehouse platform + Our integration services

Owner

Tech Team

View Specific Data Fields

Order IDs, Customer names, Delivery addresses, Email addresses, Phone numbers, Order amounts, Payment methods, Product SKUs, Inventory quantities, Prices, Invoice numbers, Marketplace transaction IDs, Sales metrics

PowerOffice Go Integration (Client Data)

PA-022

MEDIUM RISK

Syncing a client's PowerOffice Go accounting records into their reporting warehouse on their documented instruction

Data Categories

Financial transactions, Invoice data, Supplier and customer records, Account balances

Data Subjects

The client's customers, suppliers and staff (not Larasoft's)

Purpose of Processing

To replicate the client's accounting data into their reporting warehouse for financial reporting and consolidation

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

PowerOffice servers (Norway), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

Yes - read from PowerOffice servers (Norway); our copy is stored in South Africa

Data Recipients

PowerOffice (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Transaction IDs, Amounts, Dates, Invoice and credit note numbers, Customer and supplier names, Contact email addresses, Organisation numbers, Bank account references, GL codes, Project and department codes

Mailchimp Integration (Client Data)

PA-023

MEDIUM RISK

Syncing a client's Mailchimp audience and campaign records into their reporting warehouse on their documented instruction

Data Categories

Marketing contact data, Campaign engagement data, Audience segmentation data

Data Subjects

The client's marketing subscribers and prospects (not Larasoft's)

Purpose of Processing

To replicate the client's email marketing data into their reporting warehouse for campaign performance reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

Mailchimp servers (United States), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

Yes - read from Mailchimp servers (United States); our copy is stored in South Africa

Data Recipients

Intuit Mailchimp (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Subscriber email addresses, First and last names, Subscription status, Signup source and timestamp, Signup IP address, Location (country and region), Tags and segment membership, Campaign opens, Clicks, Bounces, Unsubscribe events

Google Ads Integration (Client Data)

PA-024

LOW RISK

Syncing a client's Google Ads campaign performance data into their reporting warehouse on their documented instruction

Data Categories

Advertising performance data, Campaign metadata, Aggregated audience data

Data Subjects

Data is campaign-level and aggregated; individual end-users are not identified in the fields we ingest

Purpose of Processing

To replicate the client's paid media performance data into their reporting warehouse for marketing return-on-spend reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

Google servers (global, primarily United States and EU), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

Yes - read from Google servers (United States/EU); our copy is stored in South Africa

Data Recipients

Google (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Campaign, ad group and ad IDs and names, Impressions, Clicks, Cost, Conversions and conversion value, Keywords and search terms, Device and geographic breakdowns (aggregated), Date ranges

Salesforce Integration (Client Data)

PA-025

MEDIUM RISK

Syncing a client's Salesforce CRM records, including their custom objects, into their reporting warehouse on their documented instruction

Data Categories

Contact information, Account records, Opportunity pipeline, Case and activity history, Client-defined custom objects

Data Subjects

The client's customers, leads and staff (not Larasoft's)

Purpose of Processing

To replicate the client's CRM data into their reporting warehouse for pipeline and service analytics

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

Salesforce servers (per the client's own org region, typically United States or EU), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Client-selected object and field scope, Access controls, Audit logs

Transborder Transfers

Yes - read from Salesforce servers (United States/EU depending on the client's org region); our copy is stored in South Africa

Data Recipients

Salesforce (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Contact and lead names, Email addresses, Phone numbers, Mailing addresses, Account names, Opportunity values and stages, Case subjects and descriptions, Activity and task notes, Owner names, Timestamps, Any personal information the client holds in custom fields they elect to sync

Uniconta Integration (Client Data)

PA-026

MEDIUM RISK

Syncing a client's Uniconta ERP and accounting records into their reporting warehouse on their documented instruction. CONFIGURED BUT NOT IN CLIENT USE as at 2026-09-09: the only connector of this type belongs to a Larasoft internal or demonstration organisation, so no client's personal information is processed through it today. The row is retained because the capability is live and a client could be enabled on it. The supporting measurement is held in the internal risk register.

Data Categories

Financial transactions, Invoice data, Debtor and creditor records, Inventory records, Account balances

Data Subjects

The client's customers, suppliers and staff (not Larasoft's)

Purpose of Processing

To replicate the client's ERP data into their reporting warehouse for financial and operational reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

Uniconta servers (Denmark/EU), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

No client transfer today - the sole connector is a Larasoft internal test organisation. If a client is enabled: read from Uniconta servers (Denmark/EU); our copy is stored in South Africa

Data Recipients

Uniconta (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Transaction IDs, Amounts, Dates, Invoice numbers, Debtor and creditor names, Contact email addresses and phone numbers, Delivery and invoice addresses, VAT and company registration numbers, GL codes, Product codes and quantities

WooCommerce Integration (Client Data)

PA-027

MEDIUM RISK

Syncing a client's WooCommerce store orders, customers and products into their reporting warehouse on their documented instruction

Data Categories

Order data, Customer information, Product and inventory data

Data Subjects

The client's online shoppers (not Larasoft's)

Purpose of Processing

To replicate the client's eCommerce data into their reporting warehouse for sales and fulfilment reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

The client's own store hosting (location varies by client), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

Depends on where the client hosts their own store; our copy is stored in South Africa

Data Recipients

The client's own WordPress/WooCommerce hosting (accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Order IDs and status, Customer first and last names, Email addresses, Phone numbers, Billing and shipping addresses, Order totals, Line items and quantities, Payment method (name only, no card data), Coupon codes, Order timestamps, Customer IP address where the store records it

GAAPUnity Integration (Client Data)

PA-028

MEDIUM RISK

Syncing a client's GAAPUnity hospitality and retail records into their reporting warehouse on their documented instruction

Data Categories

Sales transactions, Stock records, Financial transactions

Data Subjects

The client's staff and end-customers (not Larasoft's)

Purpose of Processing

To replicate the client's hospitality and retail data into their reporting warehouse for trading and stock reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

GAAPUnity servers (South Africa), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

No - GAAPUnity servers and our warehouse are both in South Africa

Data Recipients

GAAP (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Transaction IDs, Sale amounts, Product and stock codes, Quantities, Payment method (name only, no card data), Store/outlet identifiers, Cashier and operator identifiers, GL codes, Timestamps

Meta Ads Integration (Client Data)

PA-029

LOW RISK

Syncing a client's Meta (Facebook and Instagram) advertising performance data into their reporting warehouse on their documented instruction

Data Categories

Advertising performance data, Campaign metadata, Aggregated audience data

Data Subjects

Data is campaign-level and aggregated; individual end-users are not identified in the fields we ingest

Purpose of Processing

To replicate the client's paid social performance data into their reporting warehouse for marketing return-on-spend reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

Meta servers (global, primarily United States and EU), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

Yes - read from Meta servers (United States/EU); our copy is stored in South Africa

Data Recipients

Meta Platforms (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Campaign, ad set and ad IDs and names, Impressions, Reach, Clicks, Spend, Conversions and conversion value, Placement, Device and geographic breakdowns (aggregated), Date ranges

Asana Integration (Client Data)

PA-030

MEDIUM RISK

Syncing a client's Asana project and task records into their reporting warehouse on their documented instruction

Data Categories

Project management data, Task records, Assignment and time data

Data Subjects

The client's staff and collaborators (not Larasoft's)

Purpose of Processing

To replicate the client's project delivery data into their reporting warehouse for delivery and utilisation reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

Asana servers (United States), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

Yes - read from Asana servers (United States); our copy is stored in South Africa

Data Recipients

Asana (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Project and task names and descriptions, Assignee names and email addresses, Follower names, Due dates and completion timestamps, Custom field values, Comments and task notes, Section and tag names

Bitrix24 Integration (Client Data)

PA-031

MEDIUM RISK

Syncing a client's Bitrix24 CRM and activity records into their reporting warehouse on their documented instruction

Data Categories

Contact information, Deal pipeline, Company records, Activity history

Data Subjects

The client's customers, leads and staff (not Larasoft's)

Purpose of Processing

To replicate the client's CRM data into their reporting warehouse for pipeline and activity analytics

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

Bitrix24 servers (per the client's own account region, typically EU or United States), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

Yes - read from Bitrix24 servers (EU/United States depending on the client's account region); our copy is stored in South Africa

Data Recipients

Bitrix24 (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Contact and lead names, Email addresses, Phone numbers, Company names, Deal values and stages, Activity and call logs, Responsible-user names, Custom field values, Timestamps

HubSpot Integration (Client Data)

PA-032

MEDIUM RISK

Syncing a client's HubSpot CRM and marketing records into their reporting warehouse on their documented instruction

Data Categories

Contact information, Company records, Deal pipeline, Marketing engagement data

Data Subjects

The client's customers, leads and staff (not Larasoft's)

Purpose of Processing

To replicate the client's CRM and marketing data into their reporting warehouse for pipeline and campaign analytics

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

HubSpot servers (United States and EU), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

Yes - read from HubSpot servers (United States/EU); our copy is stored in South Africa

Data Recipients

HubSpot (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Contact first and last names, Email addresses, Phone numbers, Job titles, Company names and domains, Deal amounts and stages, Lifecycle stage, Email open and click events, Form submissions, Owner names, Timestamps

MedicalDirector Helix Integration (Client Data, Special Personal Information)

PA-033

HIGH RISK

Syncing a client healthcare provider's MedicalDirector Helix FHIR records into their reporting warehouse on their documented instruction. This activity processes health information, which is special personal information under POPIA section 26.

Data Categories

Health information (SPECIAL PERSONAL INFORMATION under POPIA s26), Patient demographic data, Clinical encounter data, Practitioner records

Data Subjects

Patients of the client healthcare provider, and the provider's practitioners and staff (not Larasoft's)

Purpose of Processing

To replicate the client healthcare provider's clinical and operational data into their reporting warehouse for the provider's own clinical operations and practice reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction). The responsible party is the client healthcare provider, and the POPIA section 32 ground for processing health information is held by that provider under its own patient relationship and professional duty of confidentiality. Larasoft asserts no independent ground and processes only on instruction.

Storage Location

MedicalDirector Helix servers (Australia), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation with no cross-client querying, Access restricted to named engineers on a documented need, Audit logs of all access, Data minimisation to the FHIR resources the client scopes

Transborder Transfers

Yes - read from MedicalDirector Helix servers (Australia); our copy is stored in South Africa. This transborder flow carries special personal information and is the subject of risk R-043.

Data Recipients

MedicalDirector, a Telstra Health company (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Patient names, Dates of birth, Sex, Contact details, Patient and medical record identifiers, Medicare/health fund identifiers, Conditions and diagnoses, Medications and prescriptions, Allergies and intolerances, Observations and clinical measurements, Encounter and appointment dates, Practitioner and organisation identifiers

Monday.com Integration (Client Data)

PA-034

MEDIUM RISK

Syncing a client's Monday.com board and item records into their reporting warehouse on their documented instruction

Data Categories

Project management data, Board and item records, Assignment data

Data Subjects

The client's staff and collaborators (not Larasoft's)

Purpose of Processing

To replicate the client's work management data into their reporting warehouse for delivery and workload reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

monday.com servers (United States and EU), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

Yes - read from monday.com servers (United States/EU); our copy is stored in South Africa

Data Recipients

monday.com (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Board and item names, Column values including free-text notes, Assignee and subscriber names and email addresses, Status and timeline values, Update and comment text, Creation and completion timestamps

Zoho Projects Integration (Client Data)

PA-035

MEDIUM RISK

Syncing a client's Zoho Projects project, task and timesheet records into their reporting warehouse on their documented instruction

Data Categories

Project management data, Task records, Timesheet data

Data Subjects

The client's staff and contractors (not Larasoft's)

Purpose of Processing

To replicate the client's project and time data into their reporting warehouse for delivery and utilisation reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

Zoho data centers (India/US/EU, per the client's own Zoho account region), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

Yes - read from Zoho servers (India/US/EU depending on the client's Zoho region); our copy is stored in South Africa

Data Recipients

Zoho (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Project and task names and descriptions, Assignee and owner names and email addresses, Task status and priority, Start, due and completion dates, Timesheet entries (hours, dates, notes), Milestone names, Comments

Sage One SA Integration (Client Data)

PA-036

MEDIUM RISK

Syncing a client's Sage Business Cloud Accounting (South Africa) records into their reporting warehouse on their documented instruction. CONFIGURED BUT NOT IN CLIENT USE as at 2026-09-09: the only connector of this type belongs to a Larasoft internal or demonstration organisation, so no client's personal information is processed through it today. The row is retained because the capability is live and a client could be enabled on it. The supporting measurement is held in the internal risk register.

Data Categories

Financial transactions, Invoice data, Customer and supplier records, Account balances

Data Subjects

The client's customers, suppliers and staff (not Larasoft's)

Purpose of Processing

To replicate the client's accounting data into their reporting warehouse for financial reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

Sage South Africa servers, Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

No - Sage One SA and our warehouse are both in South Africa

Data Recipients

Sage (client-side system, accessed on client instruction) + Our application database

Owner

Tech Team

View Specific Data Fields

Transaction IDs, Amounts, Dates, Invoice and credit note numbers, Customer and supplier names, Contact email addresses and phone numbers, Billing and delivery addresses, VAT numbers, GL codes, Bank account references

Informix ERP Integration via Larasoft ODBC Agent (Client Data)

PA-037

MEDIUM RISK

Syncing a client's on-premise Informix ERP records into their reporting warehouse on their documented instruction, using the Larasoft ODBC Agent installed inside the client's own network

Data Categories

ERP transactional data, Customer and supplier records, Inventory and order data, Financial transactions

Data Subjects

The client's customers, suppliers and staff (not Larasoft's)

Purpose of Processing

To replicate the client's on-premise ERP data into their reporting warehouse for operational and financial reporting

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

Client's own premises (Australia), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

Larasoft ODBC Agent as outbound-only transport: the agent opens an outbound connection and polls for work, so no inbound port is exposed on the client network and no credential leaves the client's premises. TLS in transit, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

Yes - data is read on the client's premises in Australia and stored in South Africa

Data Recipients

Larasoft ODBC Agent (our own software, running on client-controlled infrastructure) + Our application database

Owner

Tech Team

View Specific Data Fields

Order and transaction IDs, Amounts, Dates, Customer and supplier names, Contact details and delivery addresses held in the client's ERP, Product codes and quantities, Employee or operator identifiers recorded against transactions, GL codes

Client-Hosted Database and Protocol Sources (MySQL, OData)

PA-038

MEDIUM RISK

Reading directly from a client's own MySQL database or OData endpoint into their reporting warehouse on their documented instruction, where the client has no supported SaaS API. The MySQL leg is in client use (one client connector). The OData leg is NOT in client use as at 2026-09-09: its only connector belongs to a Larasoft internal organisation.

Data Categories

Varies entirely by the client's own schema. Typically transactional records, customer or contact records, and operational data

Data Subjects

The client's customers, suppliers and staff, as recorded in the client's own database (not Larasoft's)

Purpose of Processing

To replicate a client's own database or protocol-exposed data into their reporting warehouse where no supported SaaS API exists

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction; the responsible party is the client)

Storage Location

The client's own database or endpoint (location varies by client), Our DB: Azure South Africa North

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit where the client's endpoint supports it, Client-scoped table/view/entity allowlist so we read only what the client nominates, Per-client data isolation, Access controls, Audit logs

Transborder Transfers

Depends on where the client hosts their own database or endpoint; our copy is stored in South Africa

Data Recipients

No third party is involved: we read the client's own system directly into our application database

Owner

Tech Team

View Specific Data Fields

Determined by the tables, views or entity sets the client scopes for the connector. May include names, email addresses, phone numbers, addresses, identifiers and free-text notes held in the client's own systems

Write-Back to Client Business Systems (Outbound Transfer)

PA-039

HIGH RISK

Writing data from a client's reporting warehouse in South Africa OUT to a business system they nominate. This is the only direction in which Larasoft itself transfers personal information out of the Republic, and it is therefore the activity to which POPIA section 72 applies to us rather than to the client.

Data Categories

Financial transactions, Invoice and bill data, Contact records, Project and task records

Data Subjects

The client's customers, suppliers and staff (not Larasoft's)

Purpose of Processing

To post data the client has assembled or corrected in their warehouse back into the operational system of record, so the two agree

Legal Basis

Contract performance (Larasoft acts as operator on the responsible party's documented instruction). Larasoft is the party effecting the transfer out of the Republic, so a POPIA section 72 ground must be held FOR EACH DESTINATION. WHICH ground applies is not settled and is deliberately not asserted here: the data subjects are the client's customers rather than the client itself, so the contract-necessity grounds do not map cleanly onto the Larasoft-to-client contract. This requires legal determination per destination and is tracked as risk R-044. No ground is currently recorded as held.

Storage Location

Written FROM Azure South Africa North TO the destination system's own servers

Retention Period

Retained in the client's warehouse for the life of the client contract, and deleted on termination of that contract in line with the client agreement

Security Measures

TLS in transit, Per-client data isolation, Write scope limited to the records the client nominates, Idempotency keys on the write-record path so a replayed run does not duplicate a posted record, Access controls, Audit logs of every write

Transborder Transfers

Yes, OUTBOUND. This is the only activity in this register in which Larasoft itself transfers personal information out of South Africa. Destinations are the client's own accounting system (Australia, the United States or the EU depending on their account region), a project management system in the United States, and client-nominated file transfer endpoints including one in Europe. A POPIA section 72 ground is required per destination and none is currently recorded as held.

Data Recipients

Accounting, project management and file transfer systems the client nominates

Owner

Tech Team

View Specific Data Fields

Invoice and bill numbers, Line items and amounts, Dates, Contact and customer names, Email addresses and billing addresses where the destination record requires them, Account and tax codes, Project and task names, Assignee names

Questions About Data Processing?

If you have questions about how we process your personal information, please contact our Information Officer:

hello@larasoft.global | +27 82 457 8390