SPREADSHEET BANKING: PRIVACY POLICY

1. Definitions:

In this Agreement, the following definitions are used:

1.1 TLS means Transport Layer Security. It is a cryptographic protocol designed to provide communications security over a computer network. The protocol is widely used in applications such as email, instant messaging, and voice over IP, but its use in securing HTTPS remains the most publicly visible. The TLS protocol aims primarily to provide security, including privacy (confidentiality), integrity, and authenticity through the use of cryptography, such as the use of certificates, between two or more communicating computer applications. It runs in the presentation layer and is Itself composed of two layers: the TLS record and the TLS handshake protocols. (Source: https://en.wikipedia.org/wiki/Transport_Layer_Security).

1.2 Platform45 means Platform 45 (Pty) Limited (registration number: 2018/466769/07), a company registered in accordance with the laws of the Republic of South Africa.

1.3 Services means connect to an Investec account, retrieve transactions and display them In an Excel document.

1.4 Spreadsheet Banking Spreadsheet Banking is an Excel add-in that pulls transaction or account information from your Investec bank account directly into an Excel workbook. This add-in makes use of Investec's Programmable Banking API. available at https://connectorhub.dev/.

1.5 Us means Platform 45 and Spreadsheet Banking.

1/6 User means any person or entity who accesses the website and who has a programmable banking enabled bank account.

1.7 We means Platform 45 and Spreadsheet Banking.

1.8 Website means the website displayed and accessed on the domain https://connectorhub.dev/. All references to use of the website in this Agreement extends mutatis mutandis to use of any associated applications.

2. Introduction

2.1 We respect the privacy of every User who visits this Website. As a result of this, we would like to inform you regarding the way we would use your personal data.

2.2 We are committed to protecting your privacy and personal data. This Privacy Policy describes how we collect and process personal data collected through our website , and any of our products and services.

2.3 We encourage you to read this Privacy Policy carefully when using our website or Services. By using our Services, you are telling us that you agree to our collection and use of data in accordance with this Privacy Policy and any privacy documentation related to this policy which may be referenced herein. If you have any questions about this policy, our privacy practices or don’t agree with this policy, please let us know (refer to the end of this Privacy Policy for information on how to contact us) and don’t request to use the Services until your query/ issue has been resolved.

2.4 This Privacy Policy also applies if you contact us or we contact you about our Services, whether by telephone, email, text message, post, push notifications or via third party platforms (including websites or social media platforms).

2.5 The points below will help you understand our general approach towards the use of your personal data, however, to the extent that there is any conflict as a result of a waiver of this clause by a User, that specific clause, and not the general approach, will be enforced and supersedes the general approach.

2.6 By submitting your personal data to us, it will be deemed to have been given with your permission, where necessary and appropriate, for disclosures referred to in this policy.

3. General Approach to Personal data

3.1 We do not and will not amend or alter any personal information provided by a User, unless expressly authorised by the User to do so. It is the User’s responsibility to update their information.

3.2 We will collect and use personal information solely with the objective of fulfilling those purposes specified and for other compatible purposes, unless it obtains the consent of the individual concerned or as required by law.

3.3 We will only retain personal information as long as necessary for the provision of software for Platform 45 and Spreadsheet Banking, maintenance of the same, and any related activities.

3.4 We will only collect personal information by lawful and fair means and, where appropriate, with the knowledge or consent of the individual concerned.

3.5 Personal data should be relevant to the purposes for which it is to be used, and, to the extent necessary for those purposes, should be accurate, complete, and up-to-date.

3.6 We will protect personal information by reasonable security safeguards against loss or theft, as well as unauthorized access, disclosure, copying, use or modification.

3.7 We are committed to conducting business in accordance with these principles in order to ensure that the confidentiality of personal information is protected and maintained, however we do not guarantee a breach of such confidentiality arising out of malicious activities and/or activities over which it has no control.

3.8 It is recognised and agreed that we store backups of all data, as part of our best practice standard operating procedure.

3.9 All Users expressly opt-in and agree that all Platform 45 and Spreadsheet Banking technical support personnel are entitled to access all personal data. It is recognised, expressly, that without opting-in and agreeing to this, it is entirely impossible for us to offer any technical support to Users.

3.10 You may not request our Services if you are younger than 18 years old or do not have the legal capacity to conclude legally binding contracts.

4. Types of Data We Process

4.1 You control the data that you provide to us and we will always strive to process your data consistently with the purposes for which you’ve engaged us. You may only send us your own personal data or the information of another data subject where you have their consent to do so.

4.2 Identity and contact data. This is personal data that can identify you, such as your name and email address. We collect information when you register an account or create a profile to use our Service.

4.3 Bank account data. This may also include usernames and access tokens in order to access transactional information from your bank account and credit cards, investment accounts and/or loans. Platform 45 and Spreadsheet Banking may store your usernames and access tokens for related financial institutions on our servers. If you choose to use the Platform 45 or Spreadsheet Banking service, we will request this kind of data from you. We work with our banking partners like Investec Bank Limited, to collect your bank account data from your accounts on your behalf. Your bank account transaction data is transmitted securely with TLS and stored on our servers with 256-bit AES encryption. Our banking partners also store your bank account data, subject to their own privacy policies.

4.4 Interactive Data. We use various technologies to collect data from your devices and about your activities and interactions on our website. We gather certain information automatically and store it in log files. This information may include Internet Protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, operating system, date/time stamp, and/or clickstream data. We do not link this automatically collected data to other information we collect about you.

4.5 Cookies. We use cookies to remember users’ settings, for authentication. Users can control the use of cookies at the individual browser level. If you reject cookies, you may still use our website, but your ability to use some features or areas of our Services may be limited.

4.6 Personal data does not include data that has been made anonymous to the extent that it does not identify a specific person; or permanently de-identified data that does not relate or cannot be traced back to a person specifically; and non-personal aggregated and/or statistical information collected and compiled by us. This data is not covered by this Policy.

4.7 Support: If you reach out to Platform 45 or Spreadsheet Banking, we’ll gather the information you provide so that we may best support you as a User of the Services. You may receive administrative messages from us regarding our Service, our terms of service or this Privacy Policy.

5. How We Use the Information We Collect

5.1 We may use or process the information that we collect about you to:

5.1.1 deliver, operate and maintain the Services;

5.1.2 provide you with user support;

5.1.3 perform research and analysis about your use of the Services;

5.1.4 communicate with you by email or telephone about Platform 45 and Spreadsheet Banking products or services;

5.1.5 enforce our terms and conditions;

5.1.6 comply with applicable laws and administrative requests, protect our rights, assert and defend against claims;

5.1.7 detect, prevent, or otherwise address fraud, security, unlawfulness, or technical issues; or

5.1.8 perform functions as otherwise described to you at the time of collection.

5.2 We aggregate your data and similar data from other users into larger sets of anonymous personal financial data. This aggregated information does not identify particular users or otherwise allow anyone to recover sensitive information about individual users. Aggregate information belongs to Platform 45 and Spreadsheet Banking, and is not subject to this Privacy Policy.

6. Data Security

6.1 We use commercially reasonable efforts to implement technical, administrative, and physical safeguards to protect the functionality of the services and the functionality and availability of the platform. However, no security system is perfect, and you agree that while we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.

6.2 We take appropriate security measures (including physical, electronic and procedural measures) to help safeguard your personal data from unauthorised access and disclosure. For example, only authorised employees are permitted to access personal data, and they may do so only for permitted business functions. In addition, we use encryption in the transmission of your personal data (such as credit card number) between your computer and our system, we encrypt the transmission of that information using Transport Layer Security (TLS) technology, and we also use firewalls to help prevent unauthorised persons from gaining access to your personal information.

6.3 Platform 45 and Spreadsheet Banking undertake to take all necessary precautions to preserve the security of personal data and, in particular, to protect personal data against any accidental or unlawful destruction, accidental loss, corruption, distribution or unauthorised access, as well as against any other form of unlawful processing or disclosure to unauthorised individuals.

6.4 You are solely responsible with regard to usage and security of your credentials and any activities that occur under your account. You shall not use the account of anyone else at any time. You shall ensure that your users are aware of and adhere to these obligations.

7. Data Transfer and Retention

7.1 When you provide personal data through our website and Service, the data may be sent from South Africa to and/or stored on servers located outside of the Republic of South Africa. If you provide data to us, please note that we may transfer the data to the European Union or other jurisdictions for processing. You consent to the transfer of your data when agreeing to this Privacy Policy. Platform 45 and Spreadsheet Banking will take reasonable steps to ensure that your data is secure and will not transfer personal data you provide to any location or organisation that does not have adequate privacy and security controls in place.

7.2 Platform 45 and Spreadsheet Banking will retain your personal data only for as long as is necessary for the purposes set out in this Privacy Policy. We generally retain your personal data for as long as you keep an active account with us or we are providing you with a Service. Even if your account is not active for a certain period of time, we may keep it open or may notify you of our intention to deactivate your account due to non-use and you can choose whether to keep it open or not.

7.3 We also retain certain data in a depersonalised or aggregated form for legitimate business reasons, e.g. to improve our Service or create new Services. We will also retain and use your personal data to the extent necessary to comply with our legal obligations (for example, to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

7.4 When we dispose of personally identifiable information, we aim to use secure means, such as either physically or electronically erasing this information or making it anonymous in a non-recoverable manner. Any personal data provided to our service providers will be retained in accordance with those service providers’ data retention policies, which we make sure are in line with applicable laws.

8. Access

8.1 If you have an online account with us, you have the ability to delete your personal data online and close your account by contacting our support team at developer@investec.co.za.

8.2 If you request to cancel your account we will delete your personal financial and transaction data. After you close your account, you will not be able to sign in to the Service or your account or access any of your personal data. However, you can open a new account at any time. If you close your account, we may still retain certain information associated with your account (such as your email address and certain communications with you) for analytical purposes and recordkeeping integrity, as well as to prevent fraud, enforce our terms and conditions, take actions we deem necessary to protect the integrity of our website or our users, or take other actions otherwise permitted by law. If you close your account, we will delete the transaction data we collected from your bank/ financial institution.

9. Sharing Data

9.1 Platform 45 and Spreadsheet Banking do not sell your personal data to others.

9.2 We may share your personal data with third-party service providers or affiliates to help us operate our business and develop and improve the Services or administer activities on our behalf, such as analysing the behaviour of users on our website. We may share your personal data to these third parties for those limited purposes. The processing of information on this basis will always be based on our instructions and in compliance with our Privacy Policy and any other appropriate confidentiality and security measures we have set in place.

9.3 We may also combine information internally across the different Services covered by this Privacy Policy to help improve our Services and help our Services be more relevant and useful to you and others.

9.4 Some of our pages utilise framing techniques to serve content from our partners. Please be aware that you are providing your personal data to these third parties.

9.5 You understand that we rely on a number of business partners and suppliers to provide the Services and agree to us engaging a subcontractor to process personal data on your behalf, to the extent necessary to provide the Services. We will ensure that any such subcontractor is bound by data protection obligations equivalent to those set out in this Privacy Policy. We will notify you of any significant changes to our subcontracting policy such as the addition or replacement of a subcontractor. If you are not in agreement with any change, please contact us and do not use the Services.

9.6 We may have to share or disclose your personal data if the law requires us to or if we have to respond to valid requests by public authorities.

9.7 We will only disclose your personal data in the reasonable and good faith belief that it is necessary to:

9.7.1 comply with legal obligations;

9.7.2 protect or defend our rights;

9.7.3 prevent or investigate possible wrongdoing in connection with the Service; and

9.7.3 protect the safety of other users or the public ; or protect against legal liability or action.

10. Protection of personal information act (POPIA)

10.1 We abide by the principles set out in POPIA which governs data processing activities in South Africa. In accordance with POPIA requirements we only collect personal data for one or more of the following legal purposes:

10.1.1 Based on your consent: We will collect certain personal data because you have consented to us collecting it and will only use it for a lawful purpose and the purpose for which the data is required.

10.1.2 To satisfy a legitimate interest: We are allowed to collect certain personal data where it satisfies a legitimate business interest. For example, where we collect data about how you use our website, we will use such information to improve our services, prevent fraud and improve your user experience.

10.1.3 To comply with legal obligations: We will collect certain data, such as details about your browser and transactions to enforce our terms and conditions and comply with applicable laws (for example, where we are required to maintain records of transactions for certain periods).

10.1.4 To honour a contract: We will process personal data to provide the Service and to perform in terms of a contract we have with you.

11. Your rights under POPIA

11.1 Withdrawing your consent: If you have consented to our use of your personal information for a specific purpose, you have the right to change your mind at any time (though this will not affect any processing that has already taken place). Where we are using your personal data because we or a third party have a legitimate interest to do so, you have the right to object to that use, though in some cases this may mean you may no longer be able to use the Services.

11.2 Data access and correction: You have the right to request access to and edit, correct or update the personal data you have submitted to us. You may request to exercise this right by directly emailing us through our contact details below.

11.3 Data deletion: You have the right to request the deletion of your data or client account at any time. To request the deletion of your personal data or client account, directly email us via our contact details below. Please, note that we will only delete certain data to the extent permissible by law or where it does not override our legitimate interest (for example, where we are required by applicable law to retain records of transactions).

12. Additional Rights:

12.1 The right to request access to the personal data we hold about you in a usable/readable format;

12.2 The right to request that we move your data to another IT environment without affecting its usability;

12.3 The right to object to or restrict the processing of certain data about you;

12.4 The right to know which third parties we have shared your data with; and

12.5 The right to report us to any data authority in your location if you believe we are processing your data unlawfully. If you are in South Africa, you may relay any complaint you may have to the Information Regulator (South Africa) if you feel we are using your personally identifiable information unlawfully. The Information Regulator can be contacted at inforeg@justice.gov.za.

13. Third Parties

Any third parties to whom we may disclose personal information, including Microsoft and Investec Bank Limited and any of our banking partners as may be applicable, may have their own privacy policies which describe how they use and disclose personal information. Those policies will govern use, handling, and disclosure of your personal data once we have shared it with those third parties as described in this Policy. If you want to learn more about their privacy practices, we encourage you to visit the websites of those third parties.

14. No Rights of Third Parties

This Privacy Policy does not create rights enforceable by third parties or require disclosure of any personal information relating to users of the website or Services.

15. Changes to this Privacy Policy

We will occasionally update this Privacy Policy to reflect changes in our practices and services. When we post changes to this Privacy Policy, we will revise the “last updated” date at the bottom of this document. If we make any material changes in the way we collect, use, and/or share your personal information, we will notify you by sending an email to the email address you most recently provided us in your account registration (unless we do not have such an email address), and/or by prominently posting notice of the changes on our website prior to the change becoming effective. We recommend that you check our website from time to time to inform yourself of any changes in this Privacy Policy or any of our other policies.

16. You may contact us

If you have any concerns, questions, issues, feedback, suggestions or ideas about this Privacy Policy, other agreements or our services, please reach out on the email addresses below: developer@investec.co.za

(last updated 21 April 2023)