Tallify is a software product of [REGISTERED ENTITY NAME AND REGISTRATION NUMBER], [REGISTERED ADDRESS], South Africa ("we", "us"). Our Information Officer is [NAME], reachable at michael@bluebirddigital.co.za.
Website visitors. This website collects no personal information beyond what your browser sends to load a page (IP address and request logs held by our hosting provider for security). We do not use analytics cookies, advertising trackers or embedded social media.
Practice deployments. Tallify is installed on infrastructure controlled by the financial services provider ("the practice") that licenses it. Client personal information processed inside a deployment is processed by the practice as responsible party. Tallify, as the software provider, does not have access to that information unless the practice specifically requests support and grants access for that purpose.
Within a practice deployment, the software processes client information the practice already holds or captures: identity and contact details, financial position, insurance cover, investment holdings, advice records and communication history. This information stays on the practice's own server.
To draft advice documents and client communications, a deployment sends a de-identified set of facts to a third-party language model provider (Anthropic PBC). Before any such request, the software removes names, identity numbers, dates of birth, contact details and addresses, and scrubs those values from free text. The provider receives figures and circumstances, not an identifiable person. The practice is responsible for naming this operator in its own POPIA processing records.
A deployment only sends communications to clients whose consent to receive them has been recorded by the practice, and only after an advisor of the practice has approved each communication. Clients may withdraw consent at any time by contacting their practice; the withdrawal is applied to all future automated communications.
Practices retain advice records for the period required by the FAIS Act and the General Code of Conduct (currently five years from the date of the advice). Backups are retained by the practice under its own policy. This website retains hosting logs for no more than 90 days.
Deployments run behind private network access with authenticated, role-based logins, audit logging of every change, and encrypted transport. Backups are encrypted at rest where the practice's infrastructure supports it.
Under POPIA you may request access to, correction of, or deletion of personal information held about you, and you may object to processing or lodge a complaint with the Information Regulator (inforegulator.org.za). For information held by a practice using Tallify, direct your request to that practice. For this website, contact our Information Officer at the address above.
We will post any changes to this policy on this page with a new effective date.