Privacy Policy

Effective date: 24 July 2026 Version: 2026-07-24

This Privacy Policy explains how Cyfher processes personal information in connection with the Cyfher verifiable-credentials platform (the "Service"). It is written primarily against the South African Protection of Personal Information Act, 2013 (POPIA) and, for users and data subjects in the European Union / European Economic Area, the General Data Protection Regulation (GDPR), including the transparency requirements of GDPR Articles 13 and 14.

1. Who we are

The Service is operated by Cyfher (Pty) Ltd (registration number 2026/481869/07), a company incorporated in South Africa, of 5 Yeats Avenue, Bedford Park, Johannesburg, Gauteng, 2008, South Africa ("Cyfher", "we", "us", "our").

For all privacy matters, including exercising the rights described in section 8, contact our privacy team at privacy@cyfher.io.

2. Controller vs processor: our two roles

Cyfher processes personal information in two distinct capacities, and which one applies depends on whose data it is:

3. Personal information we process, and where it comes from

We process the following categories of personal information, collected as indicated:

We do not purchase personal information from third parties or data brokers.

4. Why we process it, and our legal bases

We process personal information for the following purposes, each mapped to a legal basis under GDPR Article 6 and, correspondingly, POPIA section 11:

5. Who we share personal information with (sub-processors)

We use a small number of carefully selected service providers ("sub-processors") to operate the Service. We do not sell personal information, and we do not share it for third-party advertising. Current sub-processors:

Each sub-processor is contractually bound to protect personal information and to process it only for the purposes we specify. This list may change as the Service evolves; material changes to our sub-processors are reflected in an updated version of this Policy, dated and versioned as described in section 11.

6. Cross-border processing

Our primary hosting is in South Africa. Our email delivery and backup-storage sub-processors may process personal information in other countries, including outside South Africa and the European Economic Area. Where that happens, we rely on the sub-processor's own appropriate safeguards (such as standard contractual terms and industry-standard encryption both in transit and at rest) to protect the data to a standard consistent with this Policy.

7. How long we keep personal information

8. Your rights

Subject to applicable law, you have the right to:

To exercise any of these rights, contact privacy@cyfher.io. We will respond within the timeframes required by applicable law.

If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority. In South Africa, this is the Information Regulator (inforegulator.org.za). If you are located in the European Union or European Economic Area, you may instead lodge a complaint with your local data protection supervisory authority.

9. How we protect personal information

We take the security of personal information seriously and apply defence-in-depth measures appropriate to the sensitivity of the data, including:

No method of transmission or storage is perfectly secure, but we continuously review and improve these controls.

10. Cookies and tracking

We keep this simple: the Service uses only a session cookie to keep you signed in, and the real-time page-update technology we use (Phoenix LiveView) relies on a WebSocket connection tied to that session. We do not use third-party advertising or analytics trackers, and we do not load fonts, scripts, or other resources from third-party content-delivery networks — everything the Service needs is served by us.

11. Changes to this Policy

We may update this Policy from time to time, for example to reflect a change in our sub-processors, our practices, or applicable law. Each version is dated and carries a version identifier (shown at the top of this page). Material changes will be reflected in a new effective date, and where required by law we will provide additional notice or seek renewed consent.

Version 2026-07-24 · Effective 24 July 2026