Privacy policy

Effective 3 September 2026. Prepared with reference to the Protection of Personal Information Act 4 of 2013 (POPIA).

1. Who we are

Tallify is a software product of [REGISTERED ENTITY NAME AND REGISTRATION NUMBER], [REGISTERED ADDRESS], South Africa ("we", "us"). Our Information Officer is [NAME], reachable at michael@bluebirddigital.co.za.

2. Two kinds of personal information

Website visitors. This website collects no personal information beyond what your browser sends to load a page (IP address and request logs held by our hosting provider for security). We do not use analytics cookies, advertising trackers or embedded social media.

Practice deployments. Tallify is installed on infrastructure controlled by the financial services provider ("the practice") that licenses it. Client personal information processed inside a deployment is processed by the practice as responsible party. Tallify, as the software provider, does not have access to that information unless the practice specifically requests support and grants access for that purpose.

3. What a Tallify deployment processes

Within a practice deployment, the software processes client information the practice already holds or captures: identity and contact details, financial position, insurance cover, investment holdings, advice records and communication history. This information stays on the practice's own server.

4. Use of external processing

To draft advice documents and client communications, a deployment sends a de-identified set of facts to a third-party language model provider (Anthropic PBC). Before any such request, the software removes names, identity numbers, dates of birth, contact details and addresses, and scrubs those values from free text. The provider receives figures and circumstances, not an identifiable person. The practice is responsible for naming this operator in its own POPIA processing records.

5. Client communications and consent

A deployment only sends communications to clients whose consent to receive them has been recorded by the practice, and only after an advisor of the practice has approved each communication. Clients may withdraw consent at any time by contacting their practice; the withdrawal is applied to all future automated communications.

6. Retention

Practices retain advice records for the period required by the FAIS Act and the General Code of Conduct (currently five years from the date of the advice). Backups are retained by the practice under its own policy. This website retains hosting logs for no more than 90 days.

7. Security

Deployments run behind private network access with authenticated, role-based logins, audit logging of every change, and encrypted transport. Backups are encrypted at rest where the practice's infrastructure supports it.

8. Your rights

Under POPIA you may request access to, correction of, or deletion of personal information held about you, and you may object to processing or lodge a complaint with the Information Regulator (inforegulator.org.za). For information held by a practice using Tallify, direct your request to that practice. For this website, contact our Information Officer at the address above.

9. Changes

We will post any changes to this policy on this page with a new effective date.