Privacy Policy
Last updated: 31 July 2026
This Privacy Policy explains how EasyQuo("EasyQuo", "we", "us", or "our") collects, uses, discloses, and protects personal information when you visit our marketing websites, use the EasyQuo web application and related services (collectively, the "Service"), or otherwise interact with us. It is intended to align with the Protection of Personal Information Act, 2013 ("POPIA") and other applicable laws in South Africa.
By using the Service, you acknowledge this Policy. If you do not agree, please do not use the Service. Capitalised terms used in our Terms of Service have the same meaning here unless stated otherwise.
1. Who is responsible for your information?
EasyQuo is the responsible party for personal information we process in connection with operating the Service and our websites, except where we act strictly as an operator on behalf of your Business (see section 7).
- Operator of the Service: EasyQuo is currently published under its product name while the registered operating entity is confirmed. For the formal legal identity of the operator, email [email protected] and we will provide it in writing.
- Registered / physical address: Available on request from [email protected].
- Country: South Africa
- Privacy enquiries: [email protected]
2. Information Officer
POPIA requires a responsible party to have an Information Officer, who is also the point of contact for requests under the Promotion of Access to Information Act 2 of 2000 ("PAIA").
- Information Officer: The appointment and registration of our Information Officer with the Information Regulator is being completed. Until the name is published, requests sent to the addresses below reach the person performing that function.
- POPIA and privacy requests: [email protected]
- PAIA access requests: [email protected]
Our PAIA Manual sets out the categories of records we hold, how to submit a formal request for access using the prescribed form, the fees that may apply, and the grounds on which access may be refused.
3. Personal information we collect
We may collect the following categories of information:
3.1 Information you provide
- Account and profile: name, email address, password (stored in hashed form), phone number if you choose to provide it, and role or title where relevant.
- Business details: trading or registered name, VAT number where applicable, address, branding or logo uploads, and other fields you complete in settings.
- Operational data you enter: customer and contact records, quote and invoice content, line items, notes, message templates, automation settings, and attachments you upload to the Service.
- Billing-related data: subscription plan, billing status, and transaction references. Card and banking details are typically collected and stored by our payment service provider (for example Paystack), not on our servers, except limited metadata we need to reconcile subscriptions.
- Support and communications: content of emails, chat, or in-product messages you send us, and feedback you volunteer.
3.2 Information collected automatically
- Usage and diagnostics: features used, actions in the product, approximate timestamps, crash or error reports, and performance data to keep the Service reliable.
- Technical data: IP address, device type, browser and operating system, language preference, and identifiers from cookies or similar technologies on our sites and app.
3.3 Information from third parties
We may receive information from payment providers (for example payment success or failure events), authentication partners if we offer social or SSO login, or from you via integrations you enable. We may also receive fraud-prevention signals from service providers.
4. How we use personal information
We use personal information to:
- Create and maintain your account and Business workspace
- Provide, operate, secure, and improve the Service (including automation, notifications, and features you configure)
- Process subscriptions, trials, and payments with our partners
- Communicate with you about the Service, security, support, and lawful marketing where permitted (see section 11)
- Detect, prevent, and address fraud, abuse, and technical issues
- Comply with legal obligations and enforce our terms
- Analyse aggregated or de-identified usage to understand product performance and plan improvements
Under POPIA, we rely on appropriate lawful bases such as: performance of a contract with you, our legitimate interests (for example securing and improving the Service, provided these are not overridden by your rights), your consent where required (for example certain cookies or marketing), and legal obligation.
5. Cookies and similar technologies
Our Cookie Notice is the detailed statement of what we set, in which category, and how to control it. In summary: the marketing site currently uses only strictly necessary technologies and a first-party preference for your light/dark theme choice, and loads no analytics or advertising technologies. The application additionally uses the session and security storage needed to keep you signed in.
6. Sharing and disclosure
We do not sell your personal information. We may share information with:
- Service providers and operators who host infrastructure, send email or SMS, process payments, provide analytics or security tools, or support customer service, under contracts that require them to protect the data and use it only for our instructions
- Professional advisers such as lawyers or auditors where necessary
- Authorities when required by law, court order, or to protect rights, safety, and security
- Business transfers in connection with a merger, acquisition, or asset sale, subject to appropriate safeguards
Where we use sub-operators outside South Africa, we take steps required by law (such as appropriate safeguards or your consent where needed) to protect the information.
7. Your customers and contacts (our operator role)
When you store personal information about your customers, suppliers, or staff in the Service, you are typically the responsible party for that data and determine why and how it is processed. EasyQuo processes that information on your instructions to provide the Service. You must have a lawful basis under POPIA (and other laws) to collect and use that data and to send communications (including automated reminders) through EasyQuo. You are responsible for your own privacy notices and consents.
A person whose information is held in a Business's workspace should direct access, correction, and objection requests to that Business. If such a request reaches us, we will normally redirect it to the relevant Business and assist where it is appropriate for us to do so.
8. Retention
We retain personal information for as long as your account is active, as needed to provide the Service, and as necessary to comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. When data is no longer required, we delete or de-identify it in line with our retention practices, subject to backup cycles and legal holds.
9. Security
We implement technical and organisational measures appropriate to the risk, including role-based access controls, isolation between Business workspaces, encryption of credentials and secrets at rest, encryption in transit, audit logging, and vendor due diligence. No online service is completely secure; please use a strong password and protect your devices.
9.1 Security incidents
We investigate and assess security incidents affecting the Service. Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, POPIA requires us to notify the Information Regulator and the affected data subjects, and we will do so as soon as reasonably possible after determining the scope and taking steps to restore the integrity of our systems. Where we act as an operator for a Business, we will notify that Business so it can meet its own notification obligations.
This is not a commitment to notify you of every technical fault, failed login attempt, blocked intrusion, or defect. Notification follows the legal test above and our assessment of the incident, not the existence of an error.
10. Your rights and how to exercise them
Subject to applicable law, you may ask us to:
- Confirm and give access to the personal information we hold about you
- Correct or update information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully
- Delete or destroy information, where we no longer have a lawful ground to retain it
- Object to processing that we base on legitimate interests, on reasonable grounds relating to your situation
- Withdraw consent where our processing relies on your consent, without affecting processing already carried out
- Object to direct marketing at any time (see section 11)
- Be told about the processing of your personal information, including the categories held and to whom it has been disclosed
10.1 How to make a request
Send your request to [email protected]. POPIA prescribes forms for certain requests, and PAIA prescribes the form for a formal access request - our PAIA Manual explains that route and where to obtain the current forms.
10.2 What happens next
- We may verify your identitybefore acting, so that we do not disclose someone's information to the wrong person.
- We may ask for more detail to locate the relevant records. The more precisely you can describe what you are looking for, the faster we can respond.
- We may refuse or limit a requestwhere the law allows or requires it - for example where complying would disclose another person's personal information, breach legal privilege, or defeat the purpose of an ongoing investigation. We will tell you the reason.
- We may be required to retain records even after a deletion request, where tax, accounting, or other legislation obliges us to keep them for a set period.
- We may redirect your request to the Business whose workspace holds the data, where we act only as its operator (see section 7).
We will respond within the timelines required by law where applicable, and will tell you if we need longer and why.
11. Direct marketing
- Consent where required. Where POPIA or the Consumer Protection Act requires your consent before we send electronic direct marketing, we will obtain it before sending, and we will not treat silence as consent.
- Existing customers. Where you are an existing customer and the law permits it, we may send marketing about our own similar products and services, having given you the opportunity to object when we collected your details and on every message.
- Opting out. Every marketing email includes an unsubscribe mechanism, and you can email [email protected] at any time. Opting out of marketing does not stop transactional and service messages such as billing notices, security alerts, and messages about your account, which you cannot unsubscribe from while you hold an account.
- Suppression. When you opt out, we record that in a suppression list so the preference survives future imports and campaigns. That record is retained precisely so we do not contact you again.
- Messages a Business sends through EasyQuo.When a Business uses EasyQuo to send quotes, invoices, reminders, or broadcasts to its own customers, that Business decides who is contacted and why, and is responsible for having a lawful basis and any required consent. EasyQuo provides the tooling; it does not make a Business's communications lawful, and we make no representation that any Business's campaign complies with POPIA or the Consumer Protection Act. Recipients of such messages should direct opt-out requests to the Business that sent them.
12. Automated decision-making
EasyQuo does not currently make decisions about you based solely on the automated processing of your personal information that have legal consequences for you or otherwise affect you to a substantial degree. Automated features in the product - such as reminder scheduling, automation rules you configure, and AI-assisted drafts and summaries - support decisions that a person makes and reviews. Our AI features do not send messages on their own, do not change invoice, payment, quote, or subscription status on their own, and do not make credit, lending, or approval decisions.
If we introduce a capability that does involve automated decision-making of that kind, we will update this Policy before or when it becomes available and describe the logic involved and your rights in relation to it, including the right under POPIA to make representations about such a decision.
13. Children
The Service is not directed at individuals under 18. We do not knowingly collect personal information from children. If you believe we have done so, contact us and we will take steps to delete it.
14. Complaints
If you are not satisfied with how we have handled your personal information or your request, please raise it with us first at [email protected] so we have a chance to put it right.
You also have the right to lodge a complaint with the Information Regulator (South Africa) (opens in a new tab), which regulates both POPIA and PAIA in South Africa. The Regulator publishes its current complaint forms and submission channels on its website. You may also approach a competent court where the law provides for it.
15. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may be communicated by email or in-product notice where appropriate.
16. Contact
For privacy questions or requests, contact:
- Privacy and POPIA: [email protected]
- PAIA access requests: [email protected] (see our PAIA Manual)
- Accessibility: Accessibility Statement
- Country: South Africa
This Policy describes our privacy practices in good faith. Laws and products evolve; consult a qualified professional if you need advice tailored to your organisation.

