Privacy Policy
Effective date: 24 July 2026 Version: 2026-07-24
This Privacy Policy explains how Cyfher processes personal information in connection with the Cyfher verifiable-credentials platform (the "Service"). It is written primarily against the South African Protection of Personal Information Act, 2013 (POPIA) and, for users and data subjects in the European Union / European Economic Area, the General Data Protection Regulation (GDPR), including the transparency requirements of GDPR Articles 13 and 14.
1. Who we are
The Service is operated by Cyfher (Pty) Ltd (registration number 2026/481869/07), a company incorporated in South Africa, of 5 Yeats Avenue, Bedford Park, Johannesburg, Gauteng, 2008, South Africa ("Cyfher", "we", "us", "our").
For all privacy matters, including exercising the rights described in section 8, contact our privacy team at privacy@cyfher.io.
2. Controller vs processor: our two roles
Cyfher processes personal information in two distinct capacities, and which one applies depends on whose data it is:
- Controller. Cyfher is the data controller for the account and registration data of tenant organisations and their portal users (see section 3), and for the email addresses of credential holders that we collect directly in order to deliver one-time claim codes ("claim OTPs") during the credential-claim flow. For this data, Cyfher decides the purposes and means of processing and this Policy describes that processing in full.
- Processor. Where a tenant organisation ("Tenant", "Issuer") uses the Service to issue, verify, or manage verifiable credentials, the content of those credentials and the personal information of the Tenant's own credential recipients belongs to, and is controlled by, the Tenant. In that relationship Cyfher acts only as a processor, processing that data solely on the Tenant's documented instructions, as configured through the Tenant's own portal. The Tenant is the controller responsible for the lawfulness of that processing towards its recipients, and that relationship is governed by a separate Data Processing Agreement (DPA) between Cyfher and the Tenant, offered as part of the Service (see also our Terms of Service). If you are a credential recipient with a privacy question about a specific credential, please contact the issuing Tenant directly; if you are unsure who that is, we can help you identify them at privacy@cyfher.io.
3. Personal information we process, and where it comes from
We process the following categories of personal information, collected as indicated:
- Registrant and account data (provided directly by you when a Tenant registers or a user is invited): full name, email address, a securely hashed password (we never store passwords in plain text), and role/permissions within the Tenant's account.
- Organisation data (provided during Tenant registration/vetting): organisation legal entity name, jurisdiction/country of incorporation, official website URL, and a description of the intended credential-issuance use case.
- Billing data (provided by the Tenant's billing contact): billing contact name and email, billing address, and VAT/tax identifiers where applicable, used to issue invoices.
- Holder email addresses (provided directly by a credential holder, or by the Tenant on the holder's behalf, at the point a credential is offered): used solely to deliver a time-limited one-time claim code so the holder can retrieve their credential into a wallet.
- Technical and security logs (collected automatically): IP address, user-agent, timestamps, authentication events, and audit-trail records of actions taken in the platform, used to operate, secure, and troubleshoot the Service.
We do not purchase personal information from third parties or data brokers.
4. Why we process it, and our legal bases
We process personal information for the following purposes, each mapped to a legal basis under GDPR Article 6 and, correspondingly, POPIA section 11:
- Performance of a contract — creating and administering Tenant accounts, authenticating users, delivering claim OTPs so holders can receive their credentials, and otherwise providing the Service you or your organisation signed up for.
- Legitimate interests — securing the platform (fraud, abuse, and intrusion prevention), maintaining audit logs, and suppressing email addresses that have bounced or complained, to protect our sending reputation and your inbox. We balance these interests against your rights and freedoms and only rely on this basis where that balance favours processing.
- Legal obligation — retaining financial records (invoices, statements) for the period required by South African tax and companies legislation.
- Consent — where we ask for it explicitly, such as the registration-time acceptance of these Terms and this Policy; consent can be withdrawn at any time by contacting us, without affecting the lawfulness of processing carried out before withdrawal.
5. Who we share personal information with (sub-processors)
We use a small number of carefully selected service providers ("sub-processors") to operate the Service. We do not sell personal information, and we do not share it for third-party advertising. Current sub-processors:
- Postmark — delivers transactional email (account notifications, claim OTPs, invoices).
- Vultr — hosts the Service's infrastructure, with our primary data centre located in Johannesburg, South Africa.
- Backblaze B2 — stores encrypted, off-site backups of platform data.
Each sub-processor is contractually bound to protect personal information and to process it only for the purposes we specify. This list may change as the Service evolves; material changes to our sub-processors are reflected in an updated version of this Policy, dated and versioned as described in section 11.
6. Cross-border processing
Our primary hosting is in South Africa. Our email delivery and backup-storage sub-processors may process personal information in other countries, including outside South Africa and the European Economic Area. Where that happens, we rely on the sub-processor's own appropriate safeguards (such as standard contractual terms and industry-standard encryption both in transit and at rest) to protect the data to a standard consistent with this Policy.
7. How long we keep personal information
- Account and organisation data is retained for as long as the Tenant account is active, and is deleted or anonymised upon account closure or a valid erasure request (see section 8).
- Financial records (invoices, billing statements) are retained for the statutory period applicable under South African tax and companies legislation (approximately five years), after which they are anonymised.
- Holder claim OTPs are short-lived by design and are retained for no longer than ten (10) minutes, the maximum validity window of a claim code, after which they expire and are not reused.
- Security and audit logs are retained for as long as reasonably necessary for security monitoring and to meet legal or regulatory obligations, consistent with our broader data retention program.
8. Your rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you.
- Rectify inaccurate or incomplete personal information.
- Erasure ("right to be forgotten") — on a verified request, we erase the personal information for which we are the controller. Where Cyfher is the controller (your account and registration data, and its footprint across the platform — see section 2), a Cyfher platform administrator executes the erasure on request, subject to the legal-retention exceptions described in section 7. Because that account data is required to operate the service while your organisation is an active client, this platform-side erasure takes effect when the account is closed (the client relationship ends); during an active relationship we retain the data needed to provide the service on the contractual basis described in section 2. Where a Tenant is the controller of personal information about its own credential recipients (see section 2), that Tenant is responsible for erasing an individual recipient's data using its own tooling, and Cyfher acts on the Tenant's instruction as its processor.
- Restrict processing in certain circumstances.
- Portability — we support this directly in the product via a data-subject-access-request (DSAR) export, which produces your personal information in a structured CSV format.
- Object to processing carried out on the basis of legitimate interests.
To exercise any of these rights, contact privacy@cyfher.io. We will respond within the timeframes required by applicable law.
If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority. In South Africa, this is the Information Regulator (inforegulator.org.za). If you are located in the European Union or European Economic Area, you may instead lodge a complaint with your local data protection supervisory authority.
9. How we protect personal information
We take the security of personal information seriously and apply defence-in-depth measures appropriate to the sensitivity of the data, including:
- Field-level encryption of sensitive database fields using AES-256-GCM.
- Envelope encryption with per-tenant encryption keys, so that a compromise of one Tenant's key material does not expose another Tenant's data.
- Encrypted backups, stored off-site with our backup sub-processor.
- Transport encryption (TLS) for all data in transit between your browser or wallet and our servers.
No method of transmission or storage is perfectly secure, but we continuously review and improve these controls.
10. Cookies and tracking
We keep this simple: the Service uses only a session cookie to keep you signed in, and the real-time page-update technology we use (Phoenix LiveView) relies on a WebSocket connection tied to that session. We do not use third-party advertising or analytics trackers, and we do not load fonts, scripts, or other resources from third-party content-delivery networks — everything the Service needs is served by us.
11. Changes to this Policy
We may update this Policy from time to time, for example to reflect a change in our sub-processors, our practices, or applicable law. Each version is dated and carries a version identifier (shown at the top of this page). Material changes will be reflected in a new effective date, and where required by law we will provide additional notice or seek renewed consent.