Xee Security

Privacy Policy

Version 2026-09 · Last updated September 2026
Template for a South African SaaS. Have it reviewed by a qualified attorney before you rely on it in production.

This Policy explains how Xee Holdings (Pty) Ltd processes personal information in line with the Protection of Personal Information Act, 2013 (POPIA).

1. Information officer

Our Information Officer can be reached at privacy@xeesecurity.com.

2. What we collect

Account details (name, work email, company), authentication data (a salted password hash — never the password itself), billing information processed by our payment provider, and product usage and security logs.

3. Why we process it

To provide and secure the Service, to bill you, to send transactional email (verification, password reset, billing notices), and to meet legal obligations. Processing is justified by the performance of our contract with you and our legitimate interest in operating a secure service.

4. Sharing

We share personal information only with sub-processors that help us run the Service (hosting, email delivery, payments), each under appropriate safeguards. We do not sell personal information.

5. Security

Passwords are stored using PBKDF2. Sensitive secrets are encrypted at rest. Access is restricted and logged.

6. Retention

We keep personal information for as long as your account is active and as required by law, then delete or anonymise it.

7. Your rights

Under POPIA you may access, correct or delete your personal information, and object to processing. Contact our Information Officer to exercise these rights. You may also lodge a complaint with the Information Regulator (South Africa).

← Back to sign up