1Who we are
DocFilla is operated by [legal entity name] (registration number [registration number]), a business based in South Africa at [physical address] (“DocFilla”, “we”, “us”). For POPIA we are the responsible party for the personal information described in this policy.
Our Information Officer is [name of Information Officer], who can be reached at support@docfilla.co.za. The service runs at usedocfilla.com.
2What we collect
We collect only what the service needs to work. In each case you decide whether to give it to us.
- Account information. Your email address, a display name, and a password (stored only as a one-way hash). If you sign in with Google, we receive your Google email address, name and profile picture URL; we never see your Google password.
- Saved details (“My details”). The information you choose to save so forms can be filled automatically: names, ID or passport number, date of birth, nationality, contact details, physical address, employer and income, banking details, and a next-of-kin contact. Some of this is special or financial information under POPIA, and we treat it accordingly (see section 5).
- Documents and answers. The forms you upload (PDF, JPG or PNG), the questions DocFilla finds on them, your answers, your drawn signature, and the settings you choose for the document.
- Payment records. If you buy a Pro pass, we keep the amount, date, status, card brand and the last four digits of the card, as reported to us by Yoco. We never receive or store full card numbers, expiry dates or security codes.
- Technical information. Standard server logs (IP address, browser type, pages requested, timestamps), and an audit trail of security-relevant actions on your account (sign-ins, uploads, downloads, deletions, payments). The audit trail records what happened, never the contents of your documents.
Guest trial. If you use the one-document trial without an account, the document stays in your browser and is never uploaded to our storage or database. It is sent to our form-reading service only for the moment of analysis (section 4) and is not kept. A signed cookie records that the trial has been used on your browser.
3Why we use it and on what basis
- To provide the service you asked for (performing our contract with you): reading your form, filling it from your saved details, letting you sign and download it, keeping your documents until you delete them or they expire, and billing Pro passes.
- With your consent, for the saved details themselves. You choose which fields to save, you can change or delete any of them at any time, and deleting them stops autofill.
- To keep the service secure (our legitimate interest and legal duty): sign-in verification, rate limits, the audit trail, fraud and abuse prevention.
- To meet legal obligations, such as keeping payment records for tax purposes.
We do not sell your information, share it with advertisers, build marketing profiles from it, or use your documents or details to train artificial intelligence models. We will not send you marketing email unless you ask for it.
4How your form is read
When you upload a form, DocFilla reads the page’s own printed lines, boxes and text and asks an AI model to work out which question each blank belongs to. For that step the page’s printed layout, and for scanned pages an image of the page, is sent to our AI provider, Anthropic PBC (United States), over an encrypted connection.
Only the blank form is analysed. Your saved details and your answers are never sent to the AI provider; filling happens on our own servers and in your browser. Under our agreement with Anthropic, data sent through its API is not used to train its models. Where a form is already fillable or its layout can be read by rules alone, no AI call is made.
5How we protect it
- Encryption in transit. Every connection to DocFilla and between DocFilla and its providers uses TLS.
- Encryption at rest, twice. Our database and file storage are encrypted at rest by our hosting provider. On top of that, your saved details and every document’s answers and signature are encrypted by DocFilla itself (AES-256-GCM) under a key derived for your account alone, before they reach the database. A copy of the database on its own cannot reveal them.
- Access control. Every database table enforces row-level security: a signed-in user can only ever reach their own rows, and files are stored in a private folder per user. Our own server code writes billing records; users cannot alter them.
- Minimal display. ID and account numbers are masked on screen until you choose to reveal them.
- Hardened application. A strict content security policy, signed and time-limited webhooks for payments, verified sign-in tokens on every request, and rate limits on expensive operations.
No system is perfectly secure. If we learn of a breach affecting your information we will notify you and the Information Regulator as POPIA requires.
6Where it is stored and who processes it
We use a small number of specialist providers (“operators” under POPIA), each bound by contract to process your information only on our instructions:
- Supabase (database, authentication and file storage), hosted in Frankfurt, Germany, in the European Union.
- Vercel (application hosting), serving DocFilla from Cape Town, South Africa, with global edge infrastructure.
- Anthropic (form analysis), United States, as described in section 4.
- Yoco (payments), South Africa. Card details are entered on Yoco’s own secure page and handled under Yoco’s privacy policy.
- Google (optional sign-in), under Google’s privacy policy.
Some of this processing happens outside South Africa. We only transfer information to countries or operators that provide protection substantially similar to POPIA, or under contracts that require it, as section 72 of POPIA allows.
7How long we keep it
- Documents. You choose. By default a document is deleted 24 hours after you download it; you can instead delete it immediately, after 7 days, or keep it until you remove it. Deleting a document removes the file and every answer with it. Documents in progress stay until you delete them.
- Saved details. Until you change or delete them, or delete your account.
- Account. Until you delete it. Deleting your account from Settings removes your documents, saved details, audit trail and login immediately.
- Payment records. Five years after the payment, as required by South African tax law, in a form that does not include your documents or details.
- Server logs. Up to 30 days, for security and troubleshooting.
- Guest trial. Nothing is stored beyond the analysis itself; the “trial used” cookie lasts up to a year.
8Your rights
Under POPIA you may:
- ask what personal information we hold about you and receive a copy;
- correct or update it (you can do this yourself under My details and Settings);
- have it deleted (Settings → Delete account removes everything at once);
- withdraw consent for saved details at any time by deleting them;
- object to processing, and lodge a complaint with the Information Regulator of South Africa (complaints.IR@justice.gov.za, www.justice.gov.za/inforeg).
To exercise any of these, email support@docfilla.co.za from the address on your account. We respond within 30 days and never charge for a first request.
10Children
DocFilla is for people aged 18 and over. Forms about a child (for example a school admission) may be filled in by a parent or guardian, who is responsible for the child’s information they enter. We do not knowingly open accounts for children.
11Changes to this policy
If we change how we handle your information we will update this page and, for material changes, tell signed-in users by email or a notice in the app before the change takes effect. The date at the top shows the current version.
12Contact
Questions, requests or complaints: support@docfilla.co.za, or write to [postal address]. Our terms of service are at usedocfilla.com/terms-of-service.