Privacy policy
Published in terms of the Protection of Personal Information Act (POPIA) §17 and §18. This notice tells you what personal information Estateeze processes, why, on what lawful basis, who receives it, and how to exercise your rights as a data subject.
Version 1.0 · Last reviewed 2026-07-10 · Owner: Phia (Information Officer).
Who is the responsible party?
Estateeze is the responsible party for the personal information processed on this platform. Estateeze is a South African-registered platform that helps fiduciary firms and their clients maintain Life Files, Wills, Trust deeds, and estate-administration records.
Information Officer
Phia (Platform Support Lead) serves as the Estateeze Information Officer per POPIA §55. Contact her at
phia@trusteeze.co.za
for any privacy-related enquiry, request, or complaint. Formal breach-related contact should go to
security@estateeze.co.za
which is forwarded to the Information Officer.
What personal information we process
Estateeze processes the following categories of personal information about firm clients, family members, beneficiaries, and heirs listed on Life Files:
- Identifiers — full names, RSA ID numbers, passport numbers, dates of birth, gender, marital status
- Contact information — physical + postal addresses, phone numbers, email addresses
- Financial information — asset inventories, liability schedules, bank account details, tax reference numbers
- Family relationships — spouse, parent, child, sibling links used to build the family tree
- Wills + trust deeds — legal instruments uploaded as PDFs, plus the wizard-captured structured data (bequests, trustees, testamentary provisions)
- Special personal information (POPIA §26) — organ + tissue donation preferences, medical directives, religious burial wishes. Processed only with explicit consent.
- Account information — email, password (bcrypt-hashed, never stored in plaintext), sign-in timestamps, IP address, user-agent
Lawful basis for processing (POPIA §11)
Different data categories are processed under different lawful bases:
- Consent — Special personal information (organ donation, medical directives, religious wishes) is processed only after the data subject or their authorised representative gives explicit written consent.
- Contract — Client account data + Life File contents are processed to give effect to the fiduciary services contract between the firm and its client.
- Legal obligation — Certain estate-administration records are retained to comply with the Estate Duty Act, the Administration of Estates Act, POPIA §14 retention requirements, and Master's Office reporting duties.
- Legitimate interest — Application logs, security event logs, and audit trails (see PlatformAuditLog) are processed for the legitimate interest of preventing fraud, investigating incidents, and demonstrating regulatory compliance.
Purposes
Estateeze processes personal information for the following purposes only:
- Delivering the fiduciary services platform to firms and their clients
- Facilitating the drafting, storage, and eventual execution of Wills and Trust deeds
- Managing the family-tree, beneficiary, and heir relationships used by the wizard flows
- Producing estate-administration reports (J294, J190, J243) required by the Master's Office
- Sending transactional notifications (invitations, acquittances, section-29 / section-35 reminders) via Mailgun
- Detecting and responding to security incidents
- Complying with regulatory and legal obligations
Who receives your information
Estateeze uses vetted operators to deliver the service. Every operator is bound by POPIA §21 obligations and by the terms of our Supplier Security Policy:
- Heroku (Salesforce) — application hosting, deployed in an EU region for administrative purposes with all storage residency held in South Africa (see below)
- AWS S3 (Amazon Web Services) — document + file object storage, provisioned in the
af-south-1(Cape Town) region to satisfy POPIA at-rest data-residency requirements - Google Gemini API — optional AI-assisted extraction from uploaded documents, opt-in per client; raw model responses are purged from our systems after 90 days
- Mailgun — outbound transactional email delivery
- Sentry — application-error monitoring; personally identifiable information is explicitly stripped before events leave our infrastructure (config/initializers/sentry.rb)
- Fiduciary firms — the client's own firm (e.g., Botha & Co) has access to that client's Life File as necessary to deliver services
- Beneficiaries and heirs — receive limited information (e.g., their own bequest, acquittance) via signed magic-link URLs after the estate is opened
Cross-border transfers
Documents and uploaded files are stored in the AWS af-south-1 region (Cape Town). The application database, which holds the structured personal information you enter, is hosted by Heroku outside South Africa. Some operational processing (the Heroku application-hosting layer, the Sentry error-collection layer, and the Google Gemini AI-processing layer) likewise takes place outside South Africa. Each of these transfers is made under section 72 of POPIA, on the basis that the operator is subject to binding data-protection obligations comparable to POPIA through its contractual data-protection terms.
Retention
Personal information is retained only as long as necessary to fulfil the purpose it was collected for, or as required by law. Specific retention periods:
- Estate administration records — 7 years after estate closure (Administration of Estates Act + POPIA §14)
- Financial + tax records — 6 years (Companies Act + Tax Administration Act)
- Application logs — 30 days rolling
- Platform audit logs — indefinite (compliance requirement for non-repudiation)
- Sentry error events — 90 days
- Google Gemini raw responses — 90 days on our systems, purged nightly
Your rights as a data subject (POPIA §5)
Every data subject has the following statutory rights:
- Right to be informed that personal information is being collected — this notice discharges that duty
- Right of access to your personal information held by Estateeze
- Right to correction of inaccurate or outdated information
- Right to deletion of information no longer needed, subject to legal retention obligations
- Right to object to processing based on legitimate interest
- Right to withdraw consent for consent-based processing at any time
- Right to complain to the Information Regulator (see below)
Requests can be sent to the Information Officer at
phia@trusteeze.co.za.
We respond within 30 days as required by POPIA.
Security
Estateeze applies technical + organisational measures appropriate to the sensitivity of the information processed, including transport encryption (TLS 1.2+), at-rest encryption (AWS S3 SSE-S3 + application-layer encryption on the most sensitive attributes via ActiveRecord::Encryption), strong password requirements (minimum 12 characters + complexity + common-password blocklist), multi-factor authentication on all administrative accounts, role-based access controls (Pundit), append-only audit logging, and continuous static security analysis (brakeman + bundler-audit) on every code change. Full technical detail is in the Security policy.
Breach notification
In the event of a confirmed personal information breach, Estateeze notifies the Information Regulator and affected data subjects within
72 hours
of confirmation, per POPIA §22. Full detail of the response process is in our internal Incident Response Runbook, and the public-facing reporting channel is via
security@estateeze.co.za
or the
Security policy page.
Complaining to the Information Regulator
Data subjects who believe Estateeze has breached POPIA may lodge a complaint with the Information Regulator:
- Postal: 33 Hoofd Street, Forum III, Braampark Office Park, Braamfontein, Johannesburg
- Email:
enquiries@inforegulator.org.za - Web: inforegulator.org.za
- Telephone: +27 10 023 5200
Data subjects are encouraged to raise the complaint with Estateeze first — most concerns can be resolved directly with the Information Officer.
Changes to this notice
This notice is reviewed annually and whenever a material change is made to the personal information practices of the platform. The version number and last-reviewed date at the top of this page reflect the current published version. Substantive changes are notified to registered users via email at least 14 days in advance of taking effect.
Related documents: Security policy · Internal supporting policies are held in the Estateeze policy library and are provided to auditors and integration partners on request via the Information Officer.