Quote to Invoice

100% free to use. Built for South Africa's small businesses.

Privacy Policy

PRIVACY POLICY

Legal EntityQuote To Invoice (Pty) Ltd
Effective / Last Updated27 August 2026
Public Websitehttps://www.quotetoinvoice.co.za/
Applicationhttps://app.quotetoinvoice.co.za/

1. Introduction and Scope

Quote To Invoice (Pty) Ltd ("Quote to Invoice", "Company", "we", "us" or "our") is committed to processing personal information lawfully, reasonably and transparently. This Privacy Policy explains how personal information is handled when a person visits https://www.quotetoinvoice.co.za/, uses https://www.quotetoinvoice.co.za/signup, accesses https://app.quotetoinvoice.co.za/, creates an account, uses the Quote to Invoice software-as-a-service platform, communicates with us, or otherwise interacts with our services (collectively, the "Platform").

This Policy is governed principally by the Protection of Personal Information Act 4 of 2013 ("POPIA") and must be read together with our Terms of Service and PAIA Manual. Where another South African law imposes a stricter requirement, that requirement will apply.

2. Our Roles Under POPIA

2.1 Responsible Party for User Data. When we determine why and how personal information about account holders, visitors, prospective users, support contacts, suppliers or other persons is processed for our own business purposes, we act as the Responsible Party.

2.2 Operator for Client Data. When a User enters personal information about its own clients, customers, contacts or other third parties into the Platform ("Client Data"), we generally process that Client Data as an Operator on the User's documented instructions. The User remains responsible for ensuring that it has a lawful basis and appropriate authority to collect, upload, use, disclose and otherwise process Client Data.

2.3 No transfer of responsibility. The Platform is a business tool. Using it does not transfer a User's statutory record-keeping, tax, privacy, employment, consumer-protection or other legal responsibilities to the Company.

3. Personal Information We May Collect

  • Account and identity information: name, email address, telephone number, authentication information, account identifiers and login activity.
  • Business profile information: trading name, company name, registration number, VAT number, business address, contact details, logo and other information a User chooses to place on business documents.
  • Document and transaction information: quotations, invoices, statements, expenses, line items, amounts, dates, payment status, references, notes and attachments created or stored through the Platform.
  • Client Data: names, contact details, addresses, company or VAT details, transaction information and other information a User chooses to enter about its clients or customers.
  • Support and communications information: messages, support requests, feedback and records of communications with us.
  • Technical and usage information: IP address, browser type, operating system, device information, session information, timestamps, security logs, diagnostic information and Platform activity.
  • Payment or billing information, if paid functionality is introduced or used: billing details and transaction references. Full payment-card credentials should be processed by the relevant authorised payment service provider and are not intended to be stored by us.
  • Cookies and similar technologies: necessary session, authentication and security cookies, and optional analytics or preference technologies where implemented.

4. How We Obtain Information

We obtain information directly from Users, automatically when the Platform is used, from authorised service providers, from a User's clients where they interact with a User-generated document or public link, and from lawful public or business sources where necessary. We do not intentionally collect more personal information than is reasonably required for the relevant purpose.

5. Purposes and Grounds for Processing

  • Providing, operating, securing, maintaining and improving the Platform.
  • Creating, storing, calculating, rendering, transmitting and managing quotations, invoices, statements and related business records at a User's request.
  • Authenticating Users, managing sessions and preventing fraud, abuse and unauthorised access.
  • Providing customer support and communicating service, security, legal and operational notices.
  • Administering subscriptions, billing or payments where applicable.
  • Maintaining audit, security, diagnostic and business records.
  • Complying with legal, regulatory, tax, law-enforcement and lawful disclosure obligations.
  • Establishing, exercising or defending legal rights and managing disputes.
  • Improving product performance and user experience using information that is aggregated, de-identified or otherwise handled in accordance with law where reasonably possible.

Depending on the circumstances, processing may be based on consent, the performance of an agreement, compliance with law, the protection of a legitimate interest, or another ground permitted by POPIA.

6. Client Data and User Responsibilities

Users control the Client Data they enter into the Platform. A User must not upload personal information that it is not entitled to process. Where consent, notice, a contract, a statutory basis or another lawful ground is required, the User is responsible for obtaining and maintaining it. Users must also avoid including unnecessary special personal information, confidential data or identity documents in public-facing fields or share links.

We may process Client Data only to provide, secure, support and maintain the Platform, to comply with law, or as otherwise authorised by the User and permitted by POPIA. We do not acquire ownership of Client Data merely because it is stored on the Platform.

7. Cookies, Analytics and Similar Technologies

The Platform uses or may use cookies and similar technologies required for authentication, session management, security, fraud prevention, preferences and core functionality. Optional analytics or measurement tools may also be used where appropriate. Where consent is required by law, we will seek it before using non-essential technologies. Blocking essential cookies may prevent parts of the Platform from functioning correctly.

8. Sharing Personal Information

We do not sell or rent personal information. We may disclose information only where reasonably necessary to:

  • Authorised service providers that support cloud hosting, data storage, email delivery, authentication, monitoring, analytics, customer support, payments (if applicable), backups and cybersecurity.
  • Professional advisers, auditors, insurers or contractors subject to appropriate confidentiality obligations.
  • Courts, regulators, SARS, law-enforcement agencies or other authorities where disclosure is legally required or reasonably necessary to protect rights, safety or security.
  • A successor or participant in a lawful corporate transaction, subject to appropriate confidentiality and data-protection safeguards.
  • A User or other person where the relevant information belongs to that User or disclosure has been authorised by the data subject or is otherwise lawful.

Where third parties process personal information for us as Operators, we seek to impose appropriate data-protection, confidentiality and security obligations consistent with POPIA.

9. Cross-Border Transfers

Cloud infrastructure and service providers may process or store information outside South Africa. Where personal information is transferred outside the Republic, we take reasonable steps to ensure that the transfer is permitted under section 72 of POPIA, including through applicable law, contractual safeguards, consent or another lawful mechanism.

The Platform may allow a User to generate or share a public or externally accessible link to a quotation, invoice or other document. The User is responsible for deciding who receives that link and for ensuring the document contains only information that may lawfully be shared. A share link should not be treated as a substitute for a dedicated confidential-access control unless the Platform expressly states otherwise. If a User sends a link to the wrong person or publishes it publicly, resulting access may fall outside the Company's control.

11. Retention, Deletion and Backups

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, to provide the Platform, to meet legal obligations, to resolve disputes, to enforce agreements and to maintain appropriate security or audit records.

Deleted user documents may remain recoverable in a Platform trash or recovery area for up to 30 days before scheduled deletion from active systems. Copies may remain for a limited period in encrypted backups, logs or disaster-recovery systems and may be retained longer where required by law, litigation hold, fraud prevention or another lawful purpose.

Users remain responsible for their own statutory record-keeping obligations. Quote to Invoice is a document-generation and management platform and is not a substitute for a User's required accounting, tax, legal or archival records.

12. Security Measures

We implement reasonable technical and organisational safeguards appropriate to the nature of the information processed. Measures may include encryption in transit, access controls, authentication controls, logging, monitoring, secure development practices, backups and restricted administrative access. No online service can guarantee absolute security, and Users remain responsible for safeguarding passwords, devices, email accounts, MFA methods and public document links.

13. Security Compromises

If we reasonably believe that unauthorised access to or acquisition of personal information has occurred, we will investigate and take steps required by applicable law. Where POPIA requires notification to the Information Regulator and affected data subjects, we will make the notifications in the manner and within the circumstances required by law.

14. Your Rights Under POPIA

Subject to applicable law, a data subject may request confirmation of whether we hold personal information about them, request access to it, ask for correction or deletion/destruction where permitted, object to certain processing, withdraw consent where processing depends on consent, or lodge a complaint with the Information Regulator. We may request reasonable proof of identity and may refuse or limit a request where the law permits or requires us to do so.

Requests should be sent to support@quotetoinvoice.co.za. Requests for formal access to records may also be handled under our PAIA Manual.

15. Service and Direct-Marketing Communications

We may send operational communications needed to administer an account or the Platform, including security alerts, password or login notices, document-delivery events and material legal or service changes. Marketing communications, where used, will be sent in accordance with applicable law and will provide an appropriate way to opt out. Opting out of marketing does not stop essential service or security communications.

16. Children

The Platform is intended for business users and is not directed at children. A person who lacks legal capacity to enter into these Terms should not independently create or operate an account. If we become aware that personal information of a child has been processed unlawfully, we will take appropriate steps in accordance with POPIA.

17. Third-Party Sites and Services

The Platform may contain links to or integrate with third-party websites or services. Their privacy practices are governed by their own policies. We are not responsible for a third party's independent processing, security or content, except to the extent the law provides otherwise.

18. Changes to this Privacy Policy

We may update this Policy to reflect changes in the Platform, law, security practices or processing activities. The updated version will be published on the Platform with a revised effective or last-updated date. Material changes may also be communicated through the Platform or by email where appropriate.

19. Company and Contact Details

ItemDetail
Legal entityQuote To Invoice (Pty) Ltd
Place of registrationRepublic of South Africa
Public websitehttps://www.quotetoinvoice.co.za/
Sign-up pagehttps://www.quotetoinvoice.co.za/signup
Applicationhttps://app.quotetoinvoice.co.za/
Support / privacy / PAIA emailsupport@quotetoinvoice.co.za

20. Information Regulator

A data subject may contact or lodge a complaint with the Information Regulator (South Africa):

  • Physical address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191, South Africa
  • Postal address: P.O. Box 31533, Braamfontein, Johannesburg, 2017
  • Telephone: 010 023 5200; Toll-free: 0800 017 160
  • Email: enquiries@inforegulator.org.za
  • Website: https://inforegulator.org.za/