Presiesby Grey Matter

Privacy Policy (POPIA)

Grey Matter Consulting (Pty) Ltd · Reg No. 2020/255888/07 · Effective 12 August 2026

1. Roles under POPIA

Your practice is the responsible party for the personal information in the bank statements you upload. Grey Matter Consulting (Pty) Ltd is your operator: we process those documents only to perform the conversion you asked for, under your instructions, with confidentiality and security safeguards, and we will notify you without delay if we ever have reason to believe statement data was accessed unlawfully.

2. Statements are processed and deleted, not stored

Uploaded statement PDFs are converted in memory and never written to disk or database. The converted CSV is returned to your browser and is not kept either. Once your conversion finishes, the document is gone from our systems. Where a statement renders description text as images, those small image fragments are read by an AI model via Anthropic's API during the conversion; they are processed in memory and are not used to train models.

3. What we do keep

  • Conversion history (metadata only): the file name you uploaded, the bank, row/page counts, credits used, who converted it and when, and any warning shown. No transactions, no balances, no account numbers.
  • Duplicate protection: a one-way cryptographic fingerprint of each converted statement's identity, so a statement already converted anywhere in your practice triggers a warning. The fingerprint cannot be reversed into an account number or anything else.
  • Your team's accounts: names, email addresses, roles and sign-in times.
  • Billing records: payment references and amounts. Card details are handled entirely by Paystack; we never see them.

Note: the uploaded file's NAME is kept in your history for your own audit trail - if your file names contain client names, that is visible to your own team and to us as your operator.

4. Where processing happens

Presies runs on Vercel (processing) and Supabase (account and metadata storage), with account email via Resend - reputable providers with industry-standard security, which may process data outside South Africa. We rely on section 72 of POPIA for these transfers: the recipients are bound by agreements upholding protection comparable to POPIA.

5. Security

All traffic is encrypted in transit. Database access is locked to server-side service credentials with row-level security enabled; browsers have no direct database access. Every account action is logged.

6. Retention and your rights

Conversion metadata and account records are kept while your workspace is active, so your practice keeps its audit trail. When your workspace closes you may ask us to delete them. You may request access to, correction of, or deletion of personal information we hold by emailing hello@greymc.co.za. If you are not satisfied, you may complain to the Information Regulator (South Africa) - inforeg.org.za.

Terms · Privacy · Refunds & cancellation · Sign in