Privacy Notice

Last updated: 2026/09/15

1. Introduction

Larasoft (Pty) Ltd respects your privacy and is committed to protecting your personal information in accordance with the Protection of Personal Information Act (POPIA) and other applicable data protection laws.

This Privacy Notice explains how we collect, use, store, and protect your personal information when you use our cloud reporting and data integration services.

2. Information Officer

Our Information Officer is responsible for POPIA compliance:

Contact: hello@larasoft.global

Phone: +27 82 457 8390

Address: Larasoft (Pty) Ltd, South Africa

3. What Information We Collect

We collect and process various types of personal information depending on how you interact with our services:

Client Onboarding

Collecting client company information during signup

Data Categories

Business contact info, Company registration details

Purpose

To establish client relationship and provide services

Legal Basis

Contract performance

Retention Period

7 years after contract ends (tax law requirement)

Xero Integration - Financial Data Sync

Connecting to clients' Xero accounts to sync financial data

Data Categories

Financial transactions, Invoice data, Payment records, Account balances

Purpose

To provide accounting automation and financial reporting services

Legal Basis

Contract performance + Legitimate interest

Retention Period

Transactional data: 7 years (tax law)

CIN7 Integration - Inventory Data Sync

Syncing inventory and order data from CIN7

Data Categories

Inventory records, Sales orders, Purchase orders, Product data

Purpose

To provide inventory management automation

Legal Basis

Contract performance

Retention Period

3 years after order completion

FTP/SFTP File Transfers

Secure file transfer service for client document exchange

Data Categories

Business documents, Financial files, Reports

Purpose

To provide secure file transfer service

Legal Basis

Contract performance

Retention Period

Configurable per client (default: 90 days post-processing)

Application Logging and Monitoring

Logging user activity and system events for troubleshooting and security

Data Categories

Access logs, Error logs, API call logs

Purpose

Security monitoring + System troubleshooting + Legal compliance

Legal Basis

Legitimate interest

Retention Period

90 days (rolling)

For a complete list of processing activities, please see our Data Processing Register.

4. How We Use Your Information

We use your personal information for the following purposes:

  • To provide and maintain our cloud reporting services
  • To process and sync data from the applications you connect to our platform. The systems we currently integrate with are listed in full in our Data Processing Register.
  • To generate reports and analytics based on your business data
  • To provide customer support and respond to your inquiries
  • To send important service updates and notifications
  • To comply with legal and regulatory requirements
  • To improve and optimize our services

5. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

  • Encryption at rest and in transit (AES-256, TLS)
  • Secure cloud infrastructure hosted in South Africa (Azure South Africa North)
  • Access controls and authentication (including MFA)
  • Regular security audits and monitoring
  • Secure backup and disaster recovery procedures
  • Staff training on data protection and privacy

6. Third-Party Services

Third parties fall into two groups, and the distinction matters for who is accountable for your information.

Infrastructure we run our platform on

These providers process personal information on our instruction. We are accountable for them.

  • Microsoft Azure - cloud hosting and databases, South Africa North region
  • AWS S3 - secure file storage for our file transfer service, Cape Town (af-south-1)

Systems we connect to on our clients' instruction

When a client asks us to bring their data into their reporting warehouse, we read from the business systems they already use. We act as an operator on that client's documented instruction: the client remains the responsible party, and the client holds the relationship with each of these providers. The systems we currently read from are:

  • Accounting and ERP: Xero, PowerOffice Go, GAAP and GAAPUnity, and clients' own on-premise Informix systems
  • Inventory, retail and eCommerce: CIN7, Vend and Lightspeed, WooCommerce, and Wherehouse
  • CRM and sales: Salesforce, HubSpot, Zoho CRM, and Bitrix24
  • Marketing and advertising: Mailchimp, Google Ads, and Meta Ads
  • Project, work and time management: Asana, monday.com, Zoho Projects, and Harvest
  • Payroll and HR: PaySpace, Deel, and SimplePay
  • Healthcare: MedicalDirector Helix. This system carries health information, which is special personal information under POPIA. We process it only on the documented instruction of the healthcare provider that holds the patient relationship, and we assert no independent ground for processing it.
  • Clients' own databases, where no supported integration exists: MySQL databases, read only within the scope the client nominates

We also support, but do not currently read from on any client's behalf, Sage Business Cloud Accounting, Uniconta and generic OData endpoints. They are listed here because the capability exists and a client could ask us to enable it, not because data is flowing today.

The Data Processing Register is the authoritative record of this list. It sets out, for every activity, what data is processed, on what legal basis, where it is stored, how long it is kept, and whether it crosses a border. This section summarises that register; where the two differ, the register is correct.

We are working through data processing and operator agreements across this set. Where an agreement is not yet in place, that gap is recorded in our internal risk register rather than treated as closed.

7. Your Rights Under POPIA

You have the following rights regarding your personal information:

  • Right to Access: Request a copy of your personal information
  • Right to Correction: Request correction of inaccurate information
  • Right to Deletion: Request deletion of your personal information (subject to legal retention requirements)
  • Right to Object: Object to processing of your personal information
  • Right to Data Portability: Request your data in a portable format
  • Right to Lodge a Complaint: Complain to the Information Regulator

To exercise any of these rights, please contact our Information Officer at hello@larasoft.global.

8. International Data Transfers

We store and process data in South Africa. Our databases, file storage and application infrastructure are hosted in the Azure South Africa North region and in AWS Cape Town, and the reporting warehouse we build for a client is held here.

Data crosses a border in two different ways, and they are not the same thing in law or in practice. We separate them here because a single combined list obscures which transfers are ours to justify.

Reading in: data we bring into South Africa

Most of what we do is read a business system a client already uses and copy the data into their warehouse here. If that system is hosted abroad, the data moves into South Africa. The client chose to put their data in that system before we were involved, and that choice is theirs to account for; our step moves a copy closer to home rather than further away. The origins this currently involves are:

  • United States - Mailchimp, Google Ads, Meta Ads, Asana, Harvest, and the US regions of Salesforce, HubSpot, monday.com, Bitrix24 and Zoho
  • European Union - the EU regions of Salesforce, HubSpot, monday.com, Bitrix24, Zoho, Google Ads and Meta Ads
  • Australia - MedicalDirector Helix, and the Australian region of Xero. The Helix flow carries health information and is treated as our highest-sensitivity read.
  • Norway - PowerOffice Go
  • India - the Indian region of Zoho CRM and Zoho Projects
  • Canada - Lightspeed, for clients using Vend or Lightspeed point of sale
  • Varies by client - CIN7, WooCommerce stores, and clients' own databases and endpoints, whose location the client chooses

Writing out: data we send out of South Africa

Some clients ask us to post data from their warehouse back into an operational system, so the two agree. Where that system is hosted abroad, we are the party sending personal information out of South Africa, and the responsibility for justifying the transfer is ours rather than the client's. This is the smaller of the two flows and the one we hold ourselves to most strictly. It currently goes to:

  • Xero - accounting write-back, to whichever region hosts the client's own Xero account. Xero operates data centres in Australia, the United States and the EU; which one applies to a given client is set by that client's Xero account and is something we are establishing rather than something we currently record
  • Asana - project write-back, United States
  • Client-nominated file transfer endpoints, including a European endpoint used for logistics document exchange

Which of these apply to any one client depends entirely on the systems that client asks us to connect. A client whose systems are all South African has no cross-border flow at all, in either direction. The Data Processing Register records the position per activity, and marks the direction.

For the transfers we send out, these are the safeguards that apply. We have marked which are in place today and which we are still putting in place, because listing an intended safeguard as a current one would misdescribe our position:

  • A lawful ground under section 72 of POPIA for each destination. We are determining which ground applies to each one rather than asserting a single answer here, because the people the data describes are our clients' customers rather than our clients themselves, and that distinction changes the analysis.
  • Written operator agreements recording the systems, the fields and the destinations in scope. Not yet in place. We are drafting a standard agreement and executing it across our client base, and until that is done this safeguard is an undertaking rather than a control.
  • Sending only the records the client nominates, rather than mirroring a whole dataset outward. In place.
  • Encryption of the data in transit to every destination. In place.

We are completing this work rather than reporting it as done. Where a ground or an agreement is not yet recorded for a destination, it is carried in our internal risk register as an open item, not treated as closed.

9. Data Retention

We retain your personal information for as long as necessary to:

  • Provide our services to you
  • Comply with legal and regulatory requirements (typically 7 years for financial data)
  • Resolve disputes and enforce our agreements

When we no longer need your information, we securely delete or anonymize it.

10. Changes to This Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes via email or through our website.

11. Contact Us

If you have any questions about this Privacy Notice or our privacy practices, please contact us:

Email: hello@larasoft.global

Phone: +27 82 457 8390

Information Regulator: www.justice.gov.za/inforeg