At TallyWizards, we take the security and privacy of your financial data extremely seriously. This Privacy Policy outlines how we handle, process, and protect your information when you use our website and conversion tools, in strict compliance with the Protection of Personal Information Act (POPI Act) in South Africa and the General Data Protection Regulation (GDPR) in Europe.
1. The Zero-Retention Policy
We operate a strict Zero-Retention Policy for all uploaded financial documents. Here is how your files are handled:
- In-Memory Processing: When you upload a bank statement PDF, it is processed dynamically in secure memory or temporary storage for the sole purpose of running the conversion.
- Immediate Deletion: The uploaded PDF and the generated Excel/Google Sheet output are completely and permanently deleted from our server automatically immediately after you download the file, or within 2 minutes of processing.
- No Permanent Storage: We do not store, copy, analyze, or build profiles from the transaction data extracted from your statements. Once your session ends or you download your file, the data is gone forever.
2. Information We Collect
Because we do not store bank statements, the only information we collect includes:
- Temporary Files: The PDF statement you upload, deleted immediately after processing.
- Usage Data: Anonymized usage statistics (such as the number of conversions performed, processing times, and bank formats detected) to improve our AI parser.
- Account Information: If you purchase a premium credit pack or subscription, we collect your email address and payment details (processed securely via our third-party payment gateways, Stripe/PayFast). We never store your card numbers.
3. Security & Cloud Processing
To convert your statements with high accuracy, TallyWizards utilizes secure cloud infrastructure:
- Encryption: All data transmitted to and from our site is encrypted using secure TLS/SSL technology.
- Processing Partners: We process OCR and text extraction using secure cloud endpoints (including Azure AI Document Intelligence and OCR.space). These partners are compliant with SOC 2, GDPR, and enterprise security standards, and they do not store your data for their own models or logging.
4. POPIA & GDPR Rights
As a user, you have the right to:
- Know what personal data we hold (which is limited to your email and purchase history if you are a paying user).
- Request the deletion of your account and payment records at any time.
- Be assured that your financial statements are never shared, sold, or used for advertising.
5. Contact Us
If you have any questions regarding this Privacy Policy or our security protocols, please contact our Information Officer at: