Who operates DAFNI
DAFNI is operated by Esteni Van Niekerk in a personal capacity. In this notice, “we” and “us” refer to that operator. Contact [email protected] for privacy questions.
Correspondence address: 29 Margaret Maytom Avenue, Durban North, Durban, 4051, South Africa.
For account administration and enquiries addressed to us, we determine how information is used. For customer records managed by a business using DAFNI, that business generally determines the purpose of processing, and DAFNI handles the records on its instructions. Questions about an invoice or its accuracy should also be directed to the business that issued it.
Current development stage
Development and controlled testing of DAFNI uses fictional invoice data; account details and authorised test communications may contain real personal information.
Direct Meta WhatsApp integration is under development and testing. Live synchronisation of invoice, payment and allocation information from the connected accounting platform, and live AI model calls, are not currently active. These capabilities must not be assumed to be available from this notice.
This notice covers the current development service and describes connected-service handling where a connection is enabled. We will update the notice before material changes to data use or a wider launch.
Information handled
- Account information: name, email address, company membership, role, invitations and authentication records.
- Business and invoice records: customer names and reference codes, contact details, invoice references, dates, amounts, balances, documents and payment or credit information supplied to the workspace.
- Communications: outbound email recipients including To, CC and BCC, subject and message content, attachments, sending outcomes, and WhatsApp messages, recipient numbers, provider identifiers, replies and delivery information where received.
- Workflow records: messaging permission evidence, recipient changes, follow-up notes, payment promises, instalment arrangements, exclusions, pauses and staff audit history.
- Technical information: connection settings, protected integration credentials, session information and operational or security logs. Hosting and communication providers may also process IP addresses and device or request information.
Information comes from users and business administrators, contacts who communicate with a connected business, enabled providers, and the operation of the service. Please do not send passwords, payment-card details or unrelated sensitive information in messages or support requests.
Why information is used
We use information to provide account access, organise authorised invoice follow-ups, send requested documents and communications, record arrangements and permission choices, investigate errors, protect company data and respond to support or privacy requests.
The appropriate basis depends on the activity: providing a requested service, legitimate operational and security needs, legal obligations, or consent where required. An existing business relationship or a phone number in an accounting record is not automatically treated as WhatsApp messaging permission.
We do not sell personal information or use invoice messages for advertising.
The connected accounting platform remains the authoritative source of financial records. Financial transactions, payment allocations and corrections are processed there. DAFNI reads the relevant information to support invoice follow-ups and does not create or amend accounting transactions or independently determine outstanding balances. DAFNI does not make creditworthiness decisions. Staff handle disputes and uncertain cases.
Live AI processing is not enabled; its provider and data use would need to be disclosed before activation.
Storage and protection
DAFNI’s current development database is hosted in Ireland. Other service providers may process information in additional countries, including through support services and subprocessors. Information is therefore not necessarily processed exclusively in Ireland or South Africa. Applicable provider terms and legal requirements govern these arrangements, including safeguards required for international transfers.
Controls include authenticated access, company and role restrictions, encrypted integration-secret storage and protected document access. No service can guarantee absolute security.
Retention and deletion
The following rules are agreed for the intended service. Retention and deletion operations still require implementation and verification; this notice does not claim that automatic cleanup is operating.
- Company workspace: necessary records remain while the business uses DAFNI, subject to the record-specific rules below. A workspace does not expire simply because it is five years old.
- Invoice conversations and follow-up history: five years after settlement or final resolution, with documented exceptions for disputes, investigations or applicable obligations. Open invoices and arrangements remain while needed. This is an operational default, not a claim that every message is a statutory financial record or that this period alone satisfies tax-record requirements.
- Customer profiles: retain necessary details while the business relationship continues. After five years without meaningful business activity, review the record for deletion or de-identification. Genuine work, invoices, payments or customer interactions count as activity; a background synchronisation does not restart the clock. Unpaid invoices, retention obligations and documented exceptions must be considered. Unanswered reviews must not allow indefinite retention without justification.
- Messaging permissions: preserve relevant permission evidence, recipient, number, scope, date and withdrawals independently of individual invoice cleanup. Changes of number, recipient or scope require appropriate review; permission is not automatically transferred. Keep only the information needed to honour an opt-out and demonstrate relevant choices.
- Temporary PDF copies: 30 days for replaceable copies that can reliably be obtained again. Proof of payment, disputed documents and other important evidence follow the relevant longer record-retention rule.
- Routine diagnostic logs: intended retention of 30 days for technical troubleshooting, such as failed requests or timeouts. Provider-managed logs may have different availability. Business audit records follow their associated record requirements; security incidents require a separately justified period. Logs should exclude credentials and unnecessary message content.
A conversation may concern several invoices. The expiry of one invoice’s retention period does not automatically delete messages still needed for another invoice, an active arrangement or relevant permission evidence. Retain only the parts that remain necessary, with a documented purpose and review point; do not retain an entire conversation indefinitely merely because it contains a newer message.
Where deletion is appropriate, remove or irreversibly de-identify the relevant data. Retention exceptions must have a recorded purpose and review point. Deleting DAFNI records does not cancel debts or delete source accounting records or recipients’ copies.
When a business leaves DAFNI
The agreed account-closure policy provides a 30-day export period from closure for a departing business to obtain its information before eligible operational records are removed. The agreed initial approach is an export supplied on request to an authorised company administrator, after verifying their authority and arranging secure delivery. This export process still requires implementation and verification; it is not yet an operational commitment. This period does not guarantee account reactivation.
Specific lawful retention requirements or unresolved disputes may require limited, restricted records to remain. Privacy requests are assessed individually; the export period is not an automatic reason to delay a deletion that must occur sooner.
Backups and recovery
The intended setup keeps protected recovery copies for a rolling 30-day backup recovery window. This is separate from the 30-day account-closure export period and from five-year invoice history. Recovery is limited to available successful backup points; it does not offer a customer-controlled rewind to every moment.
The pilot’s internal recovery targets are no more than one hour of recent work lost and restoration within one business day. These are unverified design targets, not a service guarantee. Database records and important stored files need coverage, alongside recoverable application configuration and secure credential-recovery arrangements.
Company-specific recovery should use an isolated restoration and careful extraction of the affected records to avoid undoing another company’s work. Sending must be paused and reconciled during recovery to avoid duplicate communications.
After eligible records are deleted from the active system, residual protected backup copies may remain until their recovery window expires. Consequently, copies can remain beyond 30 days after a company leaves. Backups are for disaster recovery, not extended customer access. Completed deletions must be reapplied if an older backup is restored.
The backup arrangements and recovery targets above describe the intended setup. They have not yet been fully implemented or verified. Backup coverage, scheduled operation, failure alerts, restoration and handling of previously deleted records must be tested before these arrangements are presented as operational commitments in the published policy.
Your choices and requests
You may contact us to request access to or correction of your information, deletion where applicable, withdrawal of consent, or objection to relevant processing.
Privacy requests are currently handled manually. After verifying your identity and authority, we identify and review the relevant records and arrange an appropriate export, correction or deletion, subject to applicable retention requirements. Requests involving a company’s records may require authorisation from that company.
For records held on a business’s behalf, we may refer the request to that business or coordinate with it. To stop WhatsApp invoice messages, tell the sending business or contact us, identifying the business and the number receiving messages. Opting out of WhatsApp does not itself remove an outstanding invoice or prevent other lawful communication.
Esteni Van Niekerk will monitor privacy requests. We aim to acknowledge requests within five business days and resolve straightforward requests within 30 calendar days, subject to applicable requirements. If verification, coordination or complexity affects completion, we will explain the reason and expected next steps. These targets do not replace applicable legal deadlines.
See the data-deletion instructions for the request process. You may also raise a privacy complaint with South Africa’s Information Regulator or another competent authority.
Website and notice changes
This website contains no advertising trackers, analytics scripts, external fonts or embedded social widgets. The application uses browser storage for sign-in and workspace operation. Hosting providers may process technical request information to deliver and protect this website. We will update this notice if the website’s tracking or cookie use changes.
DAFNI is intended for business use, not for services directed at children. Material privacy changes will be reflected here with an updated date and, where appropriate, brought to affected users’ attention.