Legal
Privacy Policy
Effective date: 22 July 2026
1. Who we are
Vyso is an operations software and implementation business operated by Joshua Moreira as a sole proprietor in South Africa. In this policy, “Vyso”, “we”, “us” and “our” mean that business. We are committed to processing personal information lawfully and in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”).
For privacy questions or requests, contact us at joshua@vyso.co.za.
2. When this policy applies
This policy applies to personal information processed through vyso.co.za, the Vyso platform, enquiries and implementation or support services. It explains how we handle information about website visitors, prospective customers, Vyso users and people whose information is included in a customer’s account or records.
3. Information we process
Depending on how you use Vyso, we may process:
- contact and identity information, such as a name, business name, email address, telephone number and job role;
- account and organisational information, including authorised-user details and access roles;
- business-operational information entered into the platform, such as customer and supplier contacts, delivery addresses, quotes, orders, invoices, payments, stock and related records;
- documents, email messages and attachments submitted, forwarded or connected by a customer for processing, including information contained in those materials;
- communications, support requests, feedback and website enquiry information; and
- limited technical and security information needed to operate and protect our services, such as IP address and request data used for abuse prevention.
Please do not provide special personal information—such as health, biometric, religious, political, trade-union or criminal-record information—unless it is necessary for an agreed service and you are authorised to provide it.
4. How we collect information
We collect information directly from you when you contact us, create or use an account, request support or provide records for implementation. We also receive information from a Vyso customer when that customer adds authorised users or business contacts to its workspace, or enables an agreed integration such as email ingestion or a connected Gmail inbox.
5. Why we use information
We process personal information to:
- respond to enquiries, arrange meetings and provide requested information;
- set up, operate, support, secure and improve the Vyso service;
- process documents, emails and business records when a customer has enabled those features;
- communicate about an account, service changes, support and billing;
- prevent fraud, misuse and security incidents; and
- meet legal, tax, accounting and record-keeping obligations that apply to us.
We rely on the grounds allowed by POPIA, including consent where required, performance of an agreement, our legitimate interests in operating and securing Vyso, and compliance with legal obligations. We do not sell personal information or use a customer’s contacts, documents or inbox content for Vyso’s own marketing.
6. Our role and our customers’ role
For information we collect for our own website, sales, accounts and service operations, Vyso is generally the responsible party under POPIA. Where a customer uses Vyso to store or process its own employees’, customers’, suppliers’ or other contacts’ information, that customer generally determines the purpose and means of processing and is the responsible party. Vyso generally acts as its operator and processes that information only to provide and support the agreed service, or as otherwise required by law.
7. Service providers and international processing
We use carefully selected service providers to run Vyso. Depending on the features used, this may include Supabase for authentication, database and file storage; Resend for email delivery and inbound email handling; Google for a customer-authorised Gmail connection; and Anthropic for AI-assisted extraction, categorisation and summaries. We may also use professional advisers and hosting or infrastructure providers where needed to operate the service.
Some providers may process information outside South Africa. Where this occurs, we take reasonable steps to ensure the transfer is permitted by POPIA and that appropriate contractual, technical or organisational safeguards apply.
8. Security
We use reasonable technical and organisational safeguards appropriate to the nature of the information and service. These include access controls, organisation-level separation of platform data, authentication, restricted administrative access, protected service credentials, and measures intended to prevent unauthorised access, loss, destruction or disclosure. No online service can guarantee absolute security; please use strong, unique credentials and notify us promptly if you suspect unauthorised account access.
9. Retention and deletion
We retain personal information only for as long as it is reasonably necessary for the purpose for which it was collected, to provide the service, resolve disputes, enforce agreements or meet legal obligations. Customer workspace data is retained for the duration of the customer relationship and then returned or deleted in accordance with the applicable agreement or documented instructions, unless we must retain it by law. We may retain de-identified information that no longer identifies a person.
10. Your rights and choices
Subject to POPIA and applicable law, you may ask us to confirm whether we hold your personal information, request access to it, ask for correction or deletion of inaccurate or unnecessary information, object to certain processing, or withdraw consent where processing relies on consent. You may also opt out of direct marketing at any time.
Send requests to joshua@vyso.co.za. If your information is in a customer’s Vyso workspace, please contact that customer first; we will assist the customer to respond where appropriate. You may also lodge a complaint with the South African Information Regulator.
11. Direct marketing
We will only send direct marketing where permitted by law. Every marketing message will identify Vyso and provide a practical way to opt out. Service messages about an existing account, security or a requested service are not marketing messages.
12. Children
Vyso is intended for business users and is not directed to children. We do not knowingly collect personal information from children for our own purposes. If you believe a child’s information has been provided to us in error, please contact us so that we can assess and address it.
13. Changes to this policy
We may update this policy as Vyso or the law changes. We will publish the updated version here and change the effective date. Where a material change affects an existing customer’s use of the service, we will provide additional notice where appropriate.