Vireza
  • Features
  • Pricing
  • Contact
Sign inGet Started Free

Privacy Policy

Last updated: 1 May 2026

This Privacy Policy explains how Vireza ("we", "us", "our") collects, uses, stores, and protects your personal information when you use our cloud accounting platform. We are committed to protecting your privacy and complying with applicable data protection laws, including the South African Protection of Personal Information Act (POPIA) and the EU General Data Protection Regulation (GDPR) where applicable.

1. Information We Collect

We collect the following categories of information:

  • Account information: Your name, email address, password (stored as a salted hash), and organisation details provided during registration.
  • Financial data: Invoices, bills, contacts, bank transactions, journal entries, accounts, and reports that you create or import into the Service.
  • Usage data: Log data including IP address, browser type, pages visited, and actions taken within the application, collected for security and product improvement purposes.
  • Billing information: Payment and subscription details managed by Paddle (our payment processor). We do not store your full card number or banking details on our servers.
  • Communications: Emails you send us, support requests, and feedback.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process transactions and manage subscriptions via Paddle
  • Send transactional emails (account confirmation, password reset, billing receipts)
  • Monitor and analyse usage to improve the Service
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations, including tax and financial reporting requirements
  • Respond to support requests and communications

We do not sell your personal information to third parties. We do not use your financial data for advertising or profiling purposes.

3. Data Storage and Security

Your data is stored on Neon PostgreSQL, a cloud-hosted managed database service operating in the EU (eu-west-2 region). Data is encrypted at rest and in transit using industry-standard TLS encryption.

Access to production databases is restricted to authorised systems only. Passwords are stored using Argon2 hashing. Sensitive fields (such as encryption keys) use AES-256 encryption. We maintain audit logs of all data access and modification events within the application.

While we implement appropriate technical and organisational security measures, no system is completely secure. In the event of a data breach affecting your personal information, we will notify you and the relevant authorities as required by law.

4. Third-Party Processors

We share data with the following third-party service providers to deliver the Service:

  • Paddle — Payment processing and subscription management (Merchant of Record). Paddle processes billing information on our behalf and is subject to their own privacy policy.
  • Railway — Cloud infrastructure and API hosting. Your application data is processed on Railway's servers.
  • Vercel — Hosting for the web application front-end. Vercel may process request metadata (IP addresses, headers) for routing and performance purposes.
  • Neon — Managed PostgreSQL database hosting. All persistent application data is stored in Neon's infrastructure.
  • Resend — Transactional email delivery (account activation, password resets, billing notifications). Email addresses are shared with Resend solely for delivery purposes.

All third-party processors are contractually bound to use your data only for the purposes of providing their services to us and to maintain appropriate data security standards.

5. Cookies and Tracking

The Vireza web application uses strictly necessary cookies for authentication (secure, httpOnly session tokens) and CSRF protection. We do not use third-party advertising cookies or tracking pixels within the application.

The marketing website (vireza.co.za) may use minimal analytics to understand visitor behaviour. No personally identifiable information is collected through marketing site analytics.

6. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data, subject to legal retention requirements.
  • Portability: Request an export of your data in a machine-readable format.
  • Objection: Object to processing based on legitimate interests.
  • Withdrawal of consent: Withdraw consent where processing is based on consent.

To exercise any of these rights, please contact us at privacy@vireza.co.za. We will respond within 30 days. For GDPR requests, we will respond within the statutory 30-day period. For POPIA requests, we will respond within the statutory period prescribed by the Act.

7. Data Retention

We retain your account and financial data for as long as your account is active. If you cancel your subscription, your data is retained for 30 days to allow for reactivation, after which it is permanently deleted from production systems.

Backup data may be retained for up to 90 days. Audit logs are retained for 24 months to comply with financial record-keeping requirements. Anonymised usage analytics may be retained indefinitely.

8. International Data Transfers

As our infrastructure providers operate internationally, your data may be transferred to and processed in countries outside South Africa or the European Economic Area. Where such transfers occur, we ensure appropriate safeguards are in place, including standard contractual clauses where required by GDPR.

9. Children's Privacy

The Service is not directed at children under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a child, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by displaying a prominent notice in the application. Continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact

For privacy-related queries, data access requests, or complaints, please contact us at privacy@vireza.co.za.

Vireza

Where vision meets precision.

Product
  • Features
  • Pricing
Company
  • About
  • Contact
  • Security
Legal
  • Privacy Policy
  • Terms of Service
  • Refund Policy
© 2026 Vireza. All rights reserved.