IBIS — Integrated Business Intelligence System

Privacy Policy

Version 1.1 · Effective 17 September 2026

IBIS (the Integrated Business Intelligence System) is a product of Legacy Live Web (Pty) Ltd. This policy explains how we collect, use, share, and protect your personal information when you use IBIS, and the rights you have under the Protection of Personal Information Act, 2013 (POPIA).

In this policy, "we", "us", and "our" mean Legacy Live Web (Pty) Ltd — the responsible party for the personal information processed through IBIS. Payments you make for IBIS are taken by Legacy Live Web (Pty) Ltd, so the name on your invoice or bank statement is the same company described here.

1. Who is responsible for your information

The responsible party is Legacy Live Web (Pty) Ltd (registration number 2019/034831/07), of 5 Villa Rochelle, 10 Werda Crescent, Uitsig, Bloemfontein, South Africa.

We have appointed an Information Officer as required by POPIA. You can reach them about anything in this policy, or to exercise any of your rights, at:

  • Information Officer: Ryan Mayne
  • Email: [email protected]
  • Postal/physical address: 5 Villa Rochelle, 10 Werda Crescent, Uitsig, Bloemfontein, South Africa

2. The personal information we collect

We collect only what we need to run the service for you and your business:

  • Account details — your name, email address, and a securely hashed password.
  • Business records you enter — clients, quotes, invoices, payments, accounting entries, inventory, employee and payroll information, appointments, and goals. Some of this (for example employee or client details) may be the personal information of other people, which you provide to us as the operator of your business records.
  • Community content — if you choose to publish a community profile, the display name, headline, bio, region, industry, interests, contact email, and website you self-publish, plus anything you post in directories, groups, check-ins, messages, and the Global Network.
  • Payment information — when you pay, our payment processor handles your card details directly; we receive a payment reference and status, not your full card number.
  • Technical and usage data — session and security logs, a correlation identifier per request, your selected Live/Test mode, and basic device/browser information needed to keep the service secure and working.

3. Why we process your information and on what legal basis

We process personal information for these purposes, each with a lawful basis under POPIA:

  • To provide the service — creating your account, running your business modules, and showing your data back to you (performance of our contract with you).
  • To take payment — processing subscription and service payments through our payment processor (performance of our contract).
  • To keep the service secure and accountable — authentication, audit logging, fraud and abuse prevention (our legitimate interests and legal obligations).
  • To provide optional features you switch on — anonymised peer benchmarking and the community platform are off by default and run only on your explicit consent (consent).
  • To meet legal and accounting obligations — for example retaining financial records as required by law (legal obligation).
  • To support you and communicate — responding to support tickets and sending service notifications you have asked for (contract / legitimate interests).

4. Optional features that share data — and your consent

Two features share information more widely than your own account. Both are off by default and operate only after you opt in. We record a durable consent (who opted in, when, and the version of this policy in force) each time, and you can withdraw at any time.

  • Peer benchmarking — when you switch this on, your business contributes anonymised, aggregate statistics (your Compass stage by industry and size band) to a shared pool, and in return you can see how you compare to similar businesses. We never expose your individual figures to anyone, and a peer group is only shown when enough businesses have contributed (a minimum-contributor threshold protects anonymity).
  • Community platform — when you publish a community profile, the fields you choose to publish become visible to other IBIS businesses in the same mode, so you can be found in the directory, connect, form accountability groups, message, and post to the Global Network. Only the fields you self-publish are ever shared, and a connected business sees the contact details you chose to reveal. You can unlist or stop publishing at any time.

Withdrawing consent does not affect processing that already happened, and does not stop processing we do on another lawful basis (for example keeping your account and financial records).

5. Who we share information with (operators and third parties)

We do not sell your personal information. We share it only with operators who process it on our behalf under contract, and only as needed to run the service:

  • Payment processing — our payment gateway, Paystack, to take card payments securely in South African Rand. They receive the payment details needed to process your transaction, and where you choose to keep a card on file for your monthly subscription, the card is held by them and never by us. A business that collects payments from its own customers through IBIS may connect its own gateway account (Paystack or Yoco) instead, in which case that gateway is their operator, not ours.
  • AI insights (optional) — when a business turns on AI insights, the limited business context needed to generate a narrative is sent to our AI provider, Anthropic, solely to produce that insight. AI is off by default and metered per use.
  • Email and notifications — our email delivery provider, to send service emails and notifications you have requested.
  • Hosting and infrastructure — the cloud providers that host the application and database.
  • Other IBIS businesses — only through the optional community and benchmarking features described above, and only the data you chose to share.
  • Legal and safety — authorities or advisors where we are required by law, or to establish, exercise, or defend legal claims.

We require every operator to protect your information and to process it only on our instructions, consistent with POPIA.

6. Cross-border transfers

Some of our operators (for example AI and infrastructure providers) may process information outside South Africa. Where that happens, we only use providers who are subject to laws, binding agreements, or rules that give your information a level of protection comparable to POPIA, as section 72 of POPIA requires.

7. How long we keep your information

We keep personal information only for as long as we need it for the purposes above, and then delete or anonymise it:

  • Account and business data — for as long as your account is active, and for a reasonable period afterwards to handle wind-down, disputes, and backups.
  • Financial and tax records — for the minimum periods required by South African law (generally several years).
  • Consent and audit logs — for as long as needed to demonstrate compliance.

You can ask us to delete information we are not legally required to keep, by contacting our Information Officer. IBIS also gives you a self-service data export — your "wide exit door" — so you can take your data with you at any time.

8. How we protect your information

We take appropriate, reasonable technical and organisational measures to safeguard your information, including: strict per-business (tenant) isolation so one business can never see another's records; passwords stored only as salted hashes; session tokens stored only as hashes; encrypted connections; role-based access controls; and audit logging. No system is perfectly secure, but we work to protect your information against loss, unauthorised access, and misuse, and to notify you and the Information Regulator of a compromise where the law requires.

9. Your rights under POPIA

You have the right to:

  • Know what personal information we hold about you and request access to it.
  • Ask us to correct or delete information that is inaccurate, irrelevant, excessive, or no longer needed.
  • Object to processing based on our legitimate interests, on reasonable grounds.
  • Withdraw consent for any optional feature you opted into, at any time.
  • Not be subject to a decision based solely on automated processing that significantly affects you, without safeguards.
  • Lodge a complaint with the Information Regulator (see below).

To exercise any of these rights, contact our Information Officer at [email protected]. We may need to verify your identity first.

10. Complaints to the Information Regulator

If you believe we have not handled your personal information lawfully, we would like the chance to put it right — please contact our Information Officer first. You also have the right to complain to the Information Regulator of South Africa:

  • Information Regulator (South Africa)
  • JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
  • Email: [email protected] / [email protected]
  • Website: https://inforegulator.org.za

11. Cookies and browser storage

We set a small number of first-party cookies, and only where the cookie earns its place. None of them are advertising cookies, none of them follow you to other websites, and nothing they hold is sold or shared.

  • Signing you in — a session cookie that holds your sign-in and keeps your account secure, together with a few short-lived cookies that carry a Google or X sign-in through to completion. The service cannot work without these.
  • Counting each reader once — a cookie holding a random number that means nothing by itself and is tied to nothing about you. It lets us count how many people read an article, and how many saw each version of our front page, without counting the same browser twice.
  • Keeping the site steady — a single letter recording which version of our front-page wording you were shown, so that it does not change under you between visits.

POPIA asks whether what is gained is worth what you give up, and on the counting cookie we think the honest answer is that it takes almost nothing and prevents something worse. The alternative is to recognise you by your internet address, which means noting where you connect from — and it does not even work: everyone at an innovation hub, a shared office or on a mobile network reaches us from one address, so a whole room is counted as a single person. A random number replaces that. It carries no identity, is never linked to your account, your business or your session, and is put through a one-way code before anything is recorded, so what we store cannot be turned back into the number, let alone into you.

We hold each of these to the least that will do the job: one stated purpose, no profile built about you, no third party involved, and no advertising. Your browser will not hand these cookies to any script running on a page, and you may clear them whenever you wish — the only consequence is that you will be counted once more.

Some things stay in your own browser and never reach us at all, such as your display preferences and a note that an article has already counted you so that it does not count you again.

12. Changes to this policy

We may update this policy from time to time. When we make a material change we will bump the version shown at the top of this page and, where appropriate, ask you to review it again. Continuing to use IBIS after a change means the updated policy applies to ongoing processing.