Effective date: 11 April 2026 · Governing law: Republic of South Africa (POPIA)
CoPortal (“we”, “us”, “our”) operates the software-as-a-service platform at coportal.io. We are the responsible party for personal information processed through this platform, as defined in the Protection of Personal Information Act 4 of 2013 (“POPIA”).
Our Information Officer is contactable at hello@coportal.io.
We collect and process the following categories of personal information:
We process personal information only for the following purposes:
We do not sell, rent, or trade personal information to third parties. We do not use personal information for advertising or marketing profiling.
To deliver the service, we share data with the following sub-processors. Each is subject to their own privacy policy and data processing obligations:
| Provider | Purpose | Data location |
|---|---|---|
| Supabase | Database, file storage, authentication | AWS (South Africa / US) |
| Vercel | Application hosting | US / EU (edge) |
| Resend | Transactional email delivery | US |
| Paystack | Payment processing | South Africa / Nigeria |
| Xero (optional) | Accounting sync (subscriber-initiated) | New Zealand / AU |
| QuickBooks (optional) | Accounting sync (subscriber-initiated) | US |
| OpenAI | AI-assisted content generation (quotes, invoices, summaries) | US |
| Google (Gemini) | AI-assisted content generation (quotes, invoices, summaries) | US / EU |
Where personal data is transferred outside South Africa, we ensure that appropriate safeguards are in place, including contractual protections with each sub-processor.
As a data subject, you have the following rights, which you may exercise by contacting us at hello@coportal.io:
We will respond to requests within 30 days of receipt.
We retain personal information only as long as necessary for the purposes described in this policy:
CoPortal uses only strictly necessary cookies required for authentication and session management (provided by Supabase). We do not use advertising cookies, analytics trackers, or any third-party tracking pixels. No cookie consent banner is required as all cookies are functionally essential.
We implement appropriate technical and organisational measures to protect personal information, including:
No system is completely immune to security incidents. In the event of a data breach affecting your personal information, we will notify you and the Information Regulator as required by POPIA.
When you use CoPortal to manage your clients, you are the responsible party for your clients' personal information. We process it solely on your instructions as an operator. You are responsible for:
The Service is intended for business use by adults (18+). We do not knowingly collect personal information from anyone under the age of 18. If you believe a minor has provided us with personal information, please contact us at hello@coportal.io.
We may update this Privacy Policy from time to time. For material changes, we will notify subscribers by email at least 14 days before the new policy takes effect. The current version is always available at coportal.io/privacy.
For any privacy-related queries, data rights requests, or concerns, contact our Information Officer:
CoPortal
Email: hello@coportal.io
Website: coportal.io
This Privacy Policy was last updated on 11 April 2026 and is compliant with the Protection of Personal Information Act 4 of 2013 (POPIA).