Back to CoPortal

Privacy Policy

Effective date: 31 July 2026 · Governing law: Republic of South Africa (POPIA)

1. Who we are

CoPortal Digital (Pty) Ltd (registration number K2026315446), trading as CoPortal (“we”, “us”, “our”), is a private company incorporated in South Africa that operates the software-as-a-service platform at coportal.io. We are the responsible party for personal information processed through this platform, as defined in the Protection of Personal Information Act 4 of 2013 (“POPIA”).

Our Information Officer is contactable at hello@coportal.io.

2. What personal information we collect

We collect and process the following categories of personal information:

  • Account holders (subscribers): Full name, email address, password (hashed — never stored in plain text), business name, business address, VAT number, bank details (for display on invoices only).
  • Team members: Full name, email address, role within the workspace.
  • Your clients (data subjects you add): Name, company name, email address, phone number, and any notes you enter. By adding a client’s personal information, you confirm you have a lawful basis to do so.
  • Payment information: We do not store card numbers or banking credentials. Payments are processed by Paystack, who applies their own security standards (PCI-DSS).
  • Usage data: Technical data necessary to operate and secure the service (error logs, timestamps, IP address at the time of a request).
  • Website analytics and advertising measurement: We use Google Analytics 4 and Google Ads conversion measurement on coportal.io, including our signup and subscription confirmation pages. These set cookies and browser identifiers and record the pages you view, approximate location derived from your IP address, device and browser type, the website or advertisement you arrived from (including a Google click identifier where you arrived from one of our ads), and whether a visit resulted in a signup, a trial, or a subscription. We use this only to measure which of our pages and advertisements produce signups. We do not sell, rent, or trade this data, we do not use it to make automated decisions about you, and we do not send your workspace content, client records, invoices, or uploaded files to Google. See section 8 for the cookies involved, the lawful basis we rely on, and how to stop it.
  • Uploaded files: Documents, images, and other files you upload in connection with projects are stored on our infrastructure.
  • Receipts and expense records: Receipt photos or PDFs you upload to the expense vault, together with the vendor, amount, VAT split, currency, tax category, date, and any notes you enter. We compute and store a SHA-256 hash of every uploaded receipt for audit integrity. These records are subject to tax-retention rules (see section 7).
  • Project update photos and client responses: Photos you attach to project update posts, together with any acknowledgement, reply, approval, or change-request your clients submit through the portal. Client response records include the responder’s email, the response type, and any free-text note they choose to send back.
  • AI-processed content: When you use AI-assisted features (such as generating quotes, invoices, or meeting summaries), the content you submit for processing is sent to OpenAI, Anthropic, and/or Google Gemini. We do not send client personal information to AI providers beyond what you explicitly include in an AI prompt or document generation request.

3. Why we collect it (purpose)

We process personal information only for the following purposes:

  • To provide, operate, and improve the CoPortal service
  • To send transactional emails (invoices, proposals, payment confirmations, password resets, team invitations)
  • To send payment reminder emails on behalf of subscribers to their clients
  • To integrate with third-party accounting and business software (Xero, QuickBooks, Sage Business Cloud, Microsoft Business Central) at the subscriber’s explicit request — only invoice, client, and project data the subscriber chooses to sync is transmitted
  • To deliver automation events to third-party apps via Zapier at the subscriber’s explicit request
  • To authenticate team members via Single Sign-On (SSO) through Google Workspace or Microsoft 365 at the Enterprise subscriber’s configuration
  • To generate AI-assisted content (quote descriptions, invoice line items, meeting summaries, and similar) using OpenAI, Anthropic, and Google Gemini APIs — only content you explicitly submit for AI processing is sent to these providers
  • To check your availability and create booking events via Google Calendar OAuth, when you connect your Google account to the scheduling feature (see section 4 for detail on the specific data accessed)
  • To process payments through Paystack
  • To measure the effectiveness of our own advertising and website — which pages and which advertisements lead to signups — using Google Analytics 4 and Google Ads conversion measurement, on the lawful basis set out in section 8 and subject to your right to decline at any time
  • To comply with legal obligations

We do not sell, rent, or trade personal information to third parties. We do not build advertising or marketing profiles about you, target advertising at you based on what you do inside your workspace, or use your workspace content for advertising. Our use of advertising technology is limited to measuring whether an advertisement we paid for resulted in a signup.

4. Google Calendar integration

When you connect your Google account to enable CoPortal’s scheduling features, we request the following Google OAuth scopes:

  • calendar.freebusy — reads only free/busy time windows from your Google Calendar to compute your availability for booking slots. CoPortal does not read the titles, descriptions, attendees, or any other details of your existing calendar events.
  • calendar.app.created — creates and manages only the calendar events that CoPortal itself generates (e.g. booking confirmations). CoPortal does not access, modify, or delete any events it did not create.

How we use this data: Calendar access is used solely to check your availability and to create booking events on your behalf. We do not analyse, export, or use calendar data for any other purpose.

Storage: OAuth access and refresh tokens are stored encrypted. No calendar event content (titles, descriptions, attendee details) is stored on CoPortal’s servers — only the free/busy time windows retrieved in real time for availability computation.

Retention & deletion: Stored tokens and any Google-derived availability data are removed when you disconnect your Google Calendar connection from CoPortal’s settings, or when you close your CoPortal account. You can also revoke access at any time from your Google Account at myaccount.google.com/permissions.

Google’s use of information received from CoPortal is subject to the Google API Services User Data Policy, including the Limited Use requirements.

5. Third parties who process your data

To deliver the service, we share data with the following sub-processors. Each is subject to their own privacy policy and data processing obligations:

ProviderPurposeData location
SupabaseDatabase, file storage (including receipts and project update photos), authenticationAWS eu-west-1 (Ireland)
VercelApplication hostingUS / EU (edge)
ResendTransactional email deliveryUS
PaystackPayment processingSouth Africa / Nigeria
Xero (optional)Accounting sync (subscriber-initiated)New Zealand / AU
QuickBooks (optional)Accounting sync (subscriber-initiated)US
Sage Business Cloud (optional)Accounting sync (subscriber-initiated)UK / EU
Microsoft (Business Central, optional)ERP sync — invoices, customers, projects (subscriber-initiated, Enterprise plan)EU / US (Azure)
Zapier (optional)Automation event delivery (subscriber-initiated, Agency+ plan)US
Google (SSO, optional)Team member authentication via Google Workspace SSO (Enterprise plan, subscriber-configured)US / EU
Google (Calendar, optional)Availability checking (free/busy only) and booking event creation via Google Calendar OAuth — scheduling feature, subscriber-initiatedUS / EU
Microsoft (SSO, optional)Team member authentication via Microsoft 365 SSO (Enterprise plan, subscriber-configured)EU / US (Azure)
OpenAIAI-assisted content generation (quotes, invoices, summaries)US
Anthropic (Claude)AI-assisted content generation (quotes, invoices, summaries) — fallback / extended-context tierUS
Google (Gemini)AI-assisted content generation (quotes, invoices, summaries) — additional fallback tierUS / EU
Google (Analytics & Ads)Website analytics and advertising conversion measurement on coportal.io — active from arrival, and stopped for good in that browser once you decline (see section 8)US / EU

Where personal data is transferred outside South Africa, we ensure that appropriate safeguards are in place, including contractual protections with each sub-processor. Our AI sub-processors' data processing addenda — incorporating EU Standard Contractual Clauses and a UK Addendum where applicable — are auto-incorporated into our commercial terms with each provider and are publicly available:

Google Analytics and Google Ads are operated by Google LLC and, for users in the European Economic Area, Google Ireland Limited (together, “Google”). Google processes the measurement data described in section 8 partly on our instructions and partly for its own purposes as a separate responsible party under its own privacy policy. This processing begins when you arrive on coportal.io and stops in that browser as soon as you decline; for visitors in the EEA, the UK and Switzerland it does not begin at all unless they accept. Section 8.3 sets out the lawful basis for each case.

6. Your rights under POPIA

As a data subject, you have the following rights, which you may exercise by contacting us at hello@coportal.io:

  • Right to access: Request a copy of personal information we hold about you.
  • Right to correction: Request correction of inaccurate or incomplete information.
  • Right to deletion: Request deletion of your personal information. Workspace owners can close a workspace, team members can delete their CoPortal account, and client portal users can delete their portal account. Deletion requests remain subject to legal, accounting, contractual, security, and abuse-prevention retention needs.
  • Right to object: Object to the processing of your personal information in certain circumstances, including processing we carry out on the basis of our legitimate interests. Our website analytics and advertising measurement is the main example: you can object to it yourself, with immediate effect and without contacting us, using the Cookie preferences link in the footer of our public website pages (such as our home and pricing pages), or the control in section 8.3 below.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing. Visitors in the EEA, the UK and Switzerland, whose analytics and advertising measurement is consent-based, withdraw it by the same Cookie preferences control (see section 8.3).
  • Right to complain: You have the right to lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za.

We will respond to requests within 30 days of receipt.

7. Data retention & deletion

We retain personal information only for as long as needed to provide the service, secure the platform, comply with law, and maintain required financial and contractual records.

  • Workspace accounts: Personal login data is retained while an account remains active. Team members may delete their own CoPortal account. Workspace owners may close the workspace, which removes workspace-owned data from CoPortal's live systems, subject to any lawful retention obligations.
  • Client portal accounts: A client or invited contact may delete their portal account from the client portal. This removes their portal login link and PIN from CoPortal, but the underlying client, quote, invoice, message, and project records may continue to be retained by the workspace owner.
  • Financial, contractual, and audit records: Invoices, payment records, signed quotes, communications, and related audit data may be retained for as long as reasonably necessary to comply with legal, tax, accounting, dispute-resolution, fraud-prevention, or evidentiary obligations.
  • Receipts and expense records: Receipt images and the corresponding expense entries are retained for the period required by tax law in the subscriber’s jurisdiction. For South African subscribers, this is at least five (5) years from the end of the relevant tax period under the Tax Administration Act and the Value-Added Tax Act, extending to seven (7) years where the Companies Act applies. Each receipt is stored alongside an immutable SHA-256 hash so that the integrity of the original file can be verified on audit. We compute a tax-retention deadline at upload time and decline early erasure of these records (see “Tax retention overrides erasure” below).
  • Project updates and client responses: Project update posts and the audit trail of client acknowledgements, replies, approvals, and change requests are retained for the lifetime of the project plus any retention required for dispute-resolution or contractual evidence.
  • Uploaded files: Files remain until deleted by the subscriber or removed as part of workspace closure, except where they form part of retained financial, contractual, or dispute records.
  • Email and processor logs: Transactional email records, payment processor records, and hosting/security logs may be retained by our subprocessors under their own retention schedules.
  • Backups and short-term replicas: Deleted information may remain in encrypted backups or system replicas for a limited period until those backups age out in the ordinary course.

Tax retention overrides erasure. Where you exercise a right of deletion (under POPIA section 24, or equivalent rights under the UK GDPR, EU GDPR, the Australian Privacy Act, the New Zealand Privacy Act, or the Singapore PDPA) over a record that we are legally obliged to retain — including receipts, invoices, signed quotes, payment records, and the corresponding tax registers — we will instead restrict processing of that record to the purposes required to satisfy our legal obligations until the applicable retention window passes, and only then delete it. We will confirm in writing when this exception is being applied and explain which retention rule is engaged. Where a receipt is deleted at the subscriber’s request, the corresponding expense row may be retained in restricted form for the remainder of the retention period.

Where we do not need to retain identifying information, we may delete, de-link, or anonymise personal account data while retaining the underlying business record.

8. Cookies, analytics & advertising measurement

CoPortal uses two categories of cookies and similar browser storage. They are treated differently, and you control the second one.

8.1 Strictly necessary cookies. These are required for the platform to work at all and cannot be switched off. They include the authentication and session cookies issued by Supabase, cross-site request forgery (CSRF) state cookies used during third-party connections, short-lived portal PIN and email-verification cookies, and your saved interface preferences (such as light or dark theme). No advertising or analytics identifiers are stored in these cookies. We rely on section 11(1)(b) and section 11(1)(f) of POPIA — processing necessary to perform our contract with you and necessary for our legitimate interest in operating and securing the service. You can block them in your browser, but the service will not function if you do.

8.2 Analytics and advertising cookies. We load Google Analytics 4 and Google Ads conversion measurement, supplied by Google LLC and, for users in the European Economic Area, Google Ireland Limited (together, “Google”). These set cookies and identifiers in your browser — typically cookies whose names begin with _ga (Google Analytics) and _gcl (Google Ads click measurement) — and record:

  • The pages you view on coportal.io and how long you spend on them, including the signup and subscription confirmation pages
  • Your device type, browser, screen size, language, and approximate location derived from your IP address (country or city level)
  • The website, search, or advertisement that referred you, including the Google click identifier attached to one of our ads if you arrived from one
  • Whether a visit resulted in a signup, a trial, or a paid subscription, and which plan was selected

Why: to measure which of our advertisements and pages actually produce signups, so that we do not spend on advertising that does not work. That is the only purpose. We do not sell, rent, or trade this data. We do not use it to make automated decisions or profiling decisions about you under section 71 of POPIA. We do not send your workspace content, client records, invoices, messages, or uploaded files to Google, and we do not use analytics data to target advertising at you inside the product.

8.3 Lawful basis and your choice. This website is aimed at South Africa, and for visitors outside the European Economic Area, the United Kingdom and Switzerland we rely on section 11(1)(f) of POPIA — processing necessary for our legitimate interest in knowing whether the advertising we pay for actually works. We are not relying on your prior consent, so it matters that you know exactly what that means in practice.

Measurement starts when you arrive. The Google tag loads with the page and the cookies described in 8.2 are set from your first pageview, before you have made any choice. A cookie notice appears shortly after the page loads. This policy and that notice are the notification POPIA section 18 requires, and the Decline button is the objection route POPIA section 11(3)(b) requires. We are not asking you to accept anything in order to use the site, and declining costs you nothing.

You can decline at any time — on your first visit or months later — from the Cookie preferences link in the footer of our public coportal.io pages, or from the control at the end of this section, or from the notice itself when it is on screen. Declining does three things: it instructs Google to stop reading and writing analytics and advertising cookies and identifiers, it deletes the _ga and _gcl cookies already set in that browser, and it stops us sending any further measurement events. Your decision is stored in that browser and is applied before the Google tag loads on every later visit, so no analytics or advertising cookie is set or read again in that browser. To be precise rather than reassuring: the tag file itself still loads and, as described above for EEA visitors, may send Google cookieless pings that carry no identifier and cannot be tied back to you or to a returning browser. Being browser-local, the decision does not follow you to another device, and clearing your browser storage clears it. Declining does not erase what was already collected before you declined — for that, email our Information Officer and we will action an erasure request with Google.

Visitors in the EEA, the UK and Switzerland are treated differently, because consent must come first there. For those visitors the Google tag starts in a denied state: it sets no analytics or advertising cookie, reads none, and sends Google only cookieless pings, unless and until you press Accept on the notice. Where you do accept, you may withdraw that consent at any time by the same route, without affecting the lawfulness of the processing carried out beforehand.

You can also, independently of us: clear or block cookies in your browser settings; install Google’s Analytics Opt-out Browser Add-on; manage the advertising settings on your own Google account at myadcenter.google.com; or object to this processing by emailing our Information Officer at hello@coportal.io, in which case we will action it and confirm in writing.

8.4 Transfers and retention. Google processes this data on servers outside South Africa, primarily in the United States and the European Union, under the Google Ads Data Processing Terms and its own privacy policy. Analytics records are held by Google for the retention period configured on our Analytics property and are then deleted or aggregated by Google; CoPortal keeps only aggregated reporting derived from them. Google’s own handling of this data is described in the Google Privacy Policy and in How Google uses information from sites that use our services.

9. Security

We implement appropriate technical and organisational measures to protect personal information, including:

  • All data transmitted via HTTPS/TLS encryption
  • Passwords hashed using industry-standard algorithms (managed by Supabase Auth)
  • Email OTP verification for client portal access and selected onboarding flows
  • Per-person portal PINs for sensitive quote-signing and invoice-payment actions
  • Optional authenticator-app MFA for workspace users
  • Row-level security policies restricting data access to the workspace it belongs to
  • API keys and secrets stored as environment variables, never in source code
  • Payment data never stored on our servers — handled by PCI-DSS compliant Paystack

No system is completely immune to security incidents. In the event of a data breach affecting your personal information, we will notify you and the Information Regulator as required by POPIA.

10. Your clients' personal information

When you use CoPortal to manage your clients, you are the responsible party for your clients' personal information. We process it solely on your instructions as an operator. You are responsible for:

  • Obtaining your clients' consent or establishing another lawful basis for processing
  • Informing your clients that their data is processed via CoPortal
  • Responding to your clients' data rights requests regarding their information

11. Children

The Service is intended for business use by adults (18+). We do not knowingly collect personal information from anyone under the age of 18. If you believe a minor has provided us with personal information, please contact us at hello@coportal.io.

12. Changes to this policy

We may update this Privacy Policy from time to time. For material changes, we will notify subscribers by email at least 14 days before the new policy takes effect. The current version is always available at coportal.io/privacy.

13. Contact

For any privacy-related queries, data rights requests, or concerns, contact our Information Officer:

CoPortal Digital (Pty) Ltd (trading as CoPortal)
Registration number: K2026315446
Email: hello@coportal.io
Website: coportal.io

This Privacy Policy was last updated on 31 July 2026 and is compliant with the Protection of Personal Information Act 4 of 2013 (POPIA).