FLOU · PRIVACY POLICY

Privacy Policy (POPIA)

Effective 1 August 2026 · Version 1.0

1. Roles under POPIA

The Flou platform is operated by Peluve (Pty) Ltd (registration number 2021/406050/07). For the personal information that subscribing firms and their clients place on the Platform, the subscribing firm is the Responsible Party and we act as its Operator under section 20–21 of POPIA: we process that information only on the firm's behalf, on its instructions, to provide the service. For the limited information we collect about the firm's own users (names, work emails, usage and security logs) we are the Responsible Party.

2. What is processed

Depending on the firm's use: client identity and contact details, identity and registration numbers, FICA verification documents, beneficial-ownership structures, relationship and source-of-funds declarations, financial records the firm captures, advice records, and the platform's own audit and security logs. Special personal information is processed only because the firm's compliance obligations (FICA/FAIS) require it.

3. Why it is processed

Solely to provide the subscribed service: maintaining the firm's client files and registers, running guided onboarding journeys, generating the firm's compliance outputs, securing accounts and meeting our own legal obligations. We do not sell personal information and do not use client data for advertising.

4. Where it is stored (cross-border transfer)

The Platform is hosted on enterprise cloud infrastructure (Supabase on Amazon Web Services, EU/London region, with content delivery via Vercel). Personal information is therefore transferred outside South Africa as permitted by section 72 of POPIA: the hosting providers are bound by contractual data-protection terms that uphold protection comparable to POPIA, and data is encrypted in transit and at rest. Firms tell their clients about this hosting arrangement through their own privacy notices.

5. Security safeguards

Row-level isolation between firms enforced in the database, role-based access, encrypted transport and storage, private document storage with short-lived signed access, audit logging of security-relevant events, tamper-evident record trails, and routine backups with rotation. Access to production systems is restricted to the Operator.

6. Retention

We retain data for as long as the firm's subscription is active, plus 60 days after termination for retrieval, after which it is deleted from production (backups expire on rotation). Firms configure their own client-record retention within the Platform to meet their FICA/FAIS retention duties — those legal duties are the firm's.

7. Data subject rights

Clients of a subscribing firm exercise their POPIA rights (access, correction, deletion, objection) against that firm as the Responsible Party; the Platform gives firms the tools to respond, including a structured client-data export. The firm's own users may contact us directly at support@peluve.com about information we hold as Responsible Party. Complaints may also be lodged with the Information Regulator (South Africa).

8. Changes and contact

We may update this policy by publishing a new version at this address with an updated effective date. Questions: support@peluve.com.

Terms of Service · Pricing